Phoenix11 | 21.01.2014 17:14 | FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-01-2014
Ran by Philipp (administrator) on DETLEV on 21-01-2014 17:08:17
Running from C:\Users\Philipp\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Updater) C:\ProgramData\Updater\updater.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(WatchDog) C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe
(WatchDog) C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe
(WatchDog) C:\ProgramData\RHelpers\IeHelper\IeHelper.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7156296 2013-03-08] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3015920 2013-02-06] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-02-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.)
HKLM-x32\...\Run: [HPMessageService] - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-02-25] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Updater] - C:\ProgramData\Updater\Updater.exe [481656 2013-11-20] (Updater)
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [766656 2014-01-21] ()
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-01-14] (Hewlett-Packard)
HKLM-x32\...\Runonce: [Del270360031] - cmd.exe /Q /D /c del "C:\Users\Philipp\AppData\Local\Temp\0.del" [x]
HKLM-x32\...\Runonce: [Del270457875] - cmd.exe /Q /D /c del "C:\Users\Philipp\AppData\Local\Temp\0.del" [x]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [RGSC] - C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1823656 2013-12-11] (Valve Corporation)
HKCU\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [481656 2013-11-20] (Updater)
HKCU\...\Run: [NextLive] - C:\Users\Philipp\AppData\Roaming\newnext.me\nengine.dll [1283584 2013-11-14] (NewNextDotMe)
HKCU\...\Runonce: [Uninstall C:\Users\Philipp\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] - C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Philipp\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
HKCU\...\Runonce: [Del270360031] - cmd.exe /Q /D /c del "C:\Users\Philipp\AppData\Local\Temp\0.del"
HKCU\...\Runonce: [Del270457875] - cmd.exe /Q /D /c del "C:\Users\Philipp\AppData\Local\Temp\0.del"
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [1344800 2014-01-01] (Conduit)
AppInit_DLLs-x32: c:\progra~2\searchprotect\searchprotect\bin\spvc32loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [1037600 2014-01-01] (Conduit)
Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP113B145B-8975-401E-9170-6B0DF3A2A330&SSPV=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1390312303&from=bdo&uid=WDCXWD7500BPVX-60JC3T0_WD-WX71E23HYD01HYD01&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1390312303&from=bdo&uid=WDCXWD7500BPVX-60JC3T0_WD-WX71E23HYD01HYD01&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1390312303&from=bdo&uid=WDCXWD7500BPVX-60JC3T0_WD-WX71E23HYD01HYD01&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1390312303&from=bdo&uid=WDCXWD7500BPVX-60JC3T0_WD-WX71E23HYD01HYD01&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1390312303&from=bdo&uid=WDCXWD7500BPVX-60JC3T0_WD-WX71E23HYD01HYD01
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1390312303&from=bdo&uid=WDCXWD7500BPVX-60JC3T0_WD-WX71E23HYD01HYD01&q={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1390312303&from=bdo&uid=WDCXWD7500BPVX-60JC3T0_WD-WX71E23HYD01HYD01&q={searchTerms}
SearchScopes: HKLM - {5FF364C2-BE99-42CD-9B54-D41913EC5E47} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {98A9494D-E34E-40F7-B9D8-737E81AAF8C8} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1390312303&from=bdo&uid=WDCXWD7500BPVX-60JC3T0_WD-WX71E23HYD01HYD01&q={searchTerms}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1390312303&from=bdo&uid=WDCXWD7500BPVX-60JC3T0_WD-WX71E23HYD01HYD01&q={searchTerms}
SearchScopes: HKLM-x32 - {5FF364C2-BE99-42CD-9B54-D41913EC5E47} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP113B145B-8975-401E-9170-6B0DF3A2A330&q={searchTerms}&SSPV=
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP113B145B-8975-401E-9170-6B0DF3A2A330&q={searchTerms}&SSPV=
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {5FF364C2-BE99-42CD-9B54-D41913EC5E47} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {98A9494D-E34E-40F7-B9D8-737E81AAF8C8} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: Websteroids - {44ed99e2-16a6-4b89-80d6-5b21cf42e78b} - C:\ProgramData\Websteroids\IE\common.dll (Creative Island Media, LLC)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\95rtaj7j.default
FF user.js: detected! => C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\95rtaj7j.default\user.js
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Philipp\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Websteroids - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\95rtaj7j.default\Extensions\support@websteroidsapp.com [2013-12-26]
FF Extension: Foxtab Speed Dial - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\95rtaj7j.default\Extensions\{5ebdca98-43b3-45bb-87e0-716029fb42ab} [2014-01-21]
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFF [2013-12-10]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\ []
==================== Services (Whitelisted) =================
U2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [38440 2013-09-19] (Just Develop It)
U4 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2301216 2014-01-01] (Conduit)
U2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-02-01] (Hewlett-Packard Development Company, L.P.)
U2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-10] (Intel Corporation)
U3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
U2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131032 2013-01-14] (Intel Corporation)
U2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2013-01-14] (Intel Corporation)
U2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
U2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-10-31] (Microsoft Corporation)
U2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-09] ()
U2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [239176 2013-02-20] (Realtek Semiconductor)
U3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
U0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-14] (Advanced Micro Devices, Inc.)
U3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\BASHDefs\20140110.001\BHDrvx64.sys [1526488 2013-12-18] (Symantec Corporation)
U3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
U1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
U3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-12-09] (Symantec Corporation)
U3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-12-09] (Symantec Corporation)
U3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\IPSDefs\20140118.001\IDSvia64.sys [521944 2014-01-21] (Symantec Corporation)
U3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20140120.023\ENG64.SYS [126040 2013-12-09] (Symantec Corporation)
U3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20140120.023\EX64.SYS [2099288 2013-12-09] (Symantec Corporation)
U3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [288328 2013-01-24] (Realtek Semiconductor Corp.)
U3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [448072 2013-02-02] (RTS Corporation)
U3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1516104 2013-02-08] (Realtek Semiconductor Corporation )
U3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [28400 2013-02-06] (Synaptics Incorporated)
U3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31984 2013-02-06] (Synaptics Incorporated)
U3 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
U3 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
U3 SymDS; C:\Windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
U3 SymEFA; C:\Windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
U0 SymELAM; C:\Windows\System32\drivers\NISx64\1404000.028\SymELAM.sys [23448 2012-06-20] (Symantec Corporation)
U3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-12-11] (Symantec Corporation)
U3 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
U3 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
U3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-21 17:07 - 2014-01-21 17:08 - 00021798 _____ C:\Users\Philipp\Downloads\FRST.txt
2014-01-21 17:07 - 2014-01-21 17:07 - 00000000 ____D C:\FRST
2014-01-21 17:05 - 2014-01-21 17:05 - 02077184 _____ (Farbar) C:\Users\Philipp\Downloads\FRST64.exe
2014-01-21 17:03 - 2014-01-21 17:03 - 00001149 _____ C:\Users\Philipp\Desktop\Continue Zip Opener Installation.lnk
2014-01-21 17:02 - 2014-01-21 17:03 - 00686264 _____ C:\Users\Philipp\Downloads\ZipOpenerSetup(1).exe
2014-01-21 16:35 - 2014-01-21 16:56 - 00000000 ____D C:\Users\Philipp\AppData\Local\cache
2014-01-21 16:35 - 2014-01-21 16:51 - 00000000 ____D C:\Users\Philipp\AppData\Local\Mobogenie
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\Documents\Mobogenie
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\newnext.me
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\AppData\Local\genienext
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\.android
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 _____ C:\Users\Philipp\daemonprocess.txt
2014-01-21 16:34 - 2014-01-21 16:56 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2014-01-21 16:34 - 2014-01-21 16:34 - 00001094 _____ C:\Users\Philipp\Desktop\MyPC Backup.lnk
2014-01-21 16:34 - 2014-01-21 16:34 - 00001026 _____ C:\Users\Philipp\Desktop\Mobogenie.lnk
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
2014-01-21 16:31 - 2014-01-21 16:31 - 00003120 _____ C:\Windows\System32\Tasks\Advanced System Protector_startup
2014-01-21 16:30 - 2014-01-21 16:30 - 00001208 _____ C:\Users\Public\Desktop\Advanced System Protector.lnk
2014-01-21 16:30 - 2014-01-21 16:30 - 00000000 ____D C:\ProgramData\Systweak
2014-01-21 16:30 - 2014-01-21 16:30 - 00000000 ____D C:\Program Files (x86)\Advanced System Protector
2014-01-21 16:30 - 2012-07-25 12:03 - 00016896 _____ C:\Windows\system32\sasnative64.exe
2014-01-21 16:25 - 2014-01-21 16:30 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\systweak
2014-01-21 16:25 - 2014-01-21 16:25 - 00003324 _____ C:\Windows\System32\Tasks\Advanced System Protector
2014-01-21 16:25 - 2014-01-21 16:25 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
2014-01-21 16:25 - 2014-01-21 16:25 - 00003024 _____ C:\Windows\System32\Tasks\RegClean Pro_UPDATES
2014-01-21 16:25 - 2014-01-21 16:25 - 00002868 _____ C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
2014-01-21 16:25 - 2014-01-21 16:25 - 00001057 _____ C:\Users\Public\Desktop\RegClean Pro.lnk
2014-01-21 16:25 - 2014-01-21 16:25 - 00000302 _____ C:\Windows\Tasks\RegClean Pro_UPDATES.job
2014-01-21 16:25 - 2014-01-21 16:25 - 00000294 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2014-01-21 16:25 - 2014-01-21 16:25 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
2014-01-21 16:25 - 2013-12-27 18:10 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe
2014-01-21 16:23 - 2014-01-21 16:23 - 00002648 _____ C:\Windows\System32\Tasks\FoxTab
2014-01-21 16:23 - 2014-01-21 16:23 - 00001117 _____ C:\Users\Public\Desktop\Open It!.lnk
2014-01-21 16:23 - 2014-01-21 16:23 - 00000310 _____ C:\Windows\Tasks\FoxTab.job
2014-01-21 16:23 - 2014-01-21 16:23 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\FoxTab
2014-01-21 16:23 - 2014-01-21 16:23 - 00000000 ____D C:\Program Files (x86)\OpenIt
2014-01-21 16:23 - 2014-01-21 16:23 - 00000000 ____D C:\Program Files (x86)\Foxtab
2014-01-21 16:22 - 2014-01-21 16:22 - 00000109 _____ C:\Users\Philipp\AppData\Roaming\WB.CFG
2014-01-21 16:22 - 2014-01-21 16:22 - 00000005 _____ C:\Users\Philipp\AppData\Roaming\WBPU-TTL.DAT
2014-01-21 16:21 - 2014-01-21 16:21 - 00002652 _____ C:\Windows\System32\Tasks\Digital Sites
2014-01-21 16:21 - 2014-01-21 16:21 - 00000314 _____ C:\Windows\Tasks\Digital Sites.job
2014-01-21 16:21 - 2014-01-21 16:21 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\DigitalSites
2014-01-21 16:20 - 2014-01-21 16:20 - 00686264 _____ C:\Users\Philipp\Downloads\ZipOpenerSetup.exe
2014-01-21 15:03 - 2014-01-21 16:34 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2014-01-21 14:59 - 2014-01-21 14:59 - 00000000 ____D C:\Users\Philipp\Documents\Optimizer Pro
2014-01-21 14:53 - 2014-01-21 16:05 - 00000000 ____D C:\Program Files (x86)\Optimizer Pro
2014-01-21 14:52 - 2014-01-21 16:06 - 00000000 ____D C:\ProgramData\WPM
2014-01-21 14:49 - 2014-01-21 14:49 - 00000000 _____ C:\LIL897.tmp
2014-01-21 14:49 - 2014-01-21 14:49 - 00000000 _____ C:\LIL896.tmp
2014-01-21 14:49 - 2014-01-21 14:49 - 00000000 _____ C:\LIL895.tmp
2014-01-21 14:49 - 2014-01-21 14:49 - 00000000 _____ C:\LIL894.tmp
2014-01-21 14:49 - 2014-01-21 14:49 - 00000000 _____ C:\LIL893.tmp
2014-01-21 14:39 - 2014-01-21 14:40 - 00764360 _____ (Online Media Player ) C:\Users\Philipp\Downloads\setup.exe
2014-01-15 12:39 - 2013-12-07 07:37 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-01-15 12:39 - 2013-12-07 07:37 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 12:39 - 2013-12-07 06:15 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-01-15 12:39 - 2013-12-07 06:15 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 12:20 - 2013-10-31 06:56 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2014-01-15 12:20 - 2013-10-31 06:56 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2014-01-15 12:20 - 2013-10-31 05:01 - 00550400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2014-01-15 12:20 - 2013-10-31 04:42 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2014-01-15 12:20 - 2013-10-28 06:50 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2014-01-15 12:20 - 2013-10-28 05:05 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2014-01-15 12:20 - 2013-10-13 21:49 - 00100696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2014-01-15 12:20 - 2013-08-27 06:21 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-01-15 12:20 - 2013-08-27 06:19 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-01-15 12:20 - 2013-08-26 23:29 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-01-15 12:20 - 2013-08-26 23:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-01-14 12:36 - 2014-01-14 12:36 - 00000000 ____D C:\Users\Public\Documents\Monolith Productions
2014-01-14 12:29 - 2014-01-14 12:29 - 00000860 _____ C:\Users\Public\Desktop\F.E.A.R. - Multiplayer.lnk
2014-01-14 12:29 - 2014-01-14 12:29 - 00000850 _____ C:\Users\Public\Desktop\F.E.A.R. - Einzelspieler.lnk
2014-01-14 12:28 - 2014-01-14 12:28 - 00000000 ____D C:\Program Files (x86)\Sierra
2014-01-12 14:55 - 2014-01-12 14:55 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2014-01-12 14:55 - 2014-01-12 14:55 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2014-01-12 14:52 - 2014-01-12 14:55 - 13079688 _____ (Microsoft Corporation) C:\Users\Philipp\Downloads\Silverlight_x64.exe
2014-01-02 15:50 - 2014-01-02 15:50 - 00401752 _____ (Softonic ) C:\Users\Philipp\Downloads\SoftonicDownloader_fuer_operation7.exe
2013-12-28 18:12 - 2013-12-28 18:13 - 00000000 ____D C:\Users\Philipp\Desktop\Neuer Ordner
2013-12-23 11:51 - 2013-12-23 11:51 - 00432600 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 ____D C:\sources
2013-12-22 21:55 - 2014-01-17 15:37 - 00000000 ____D C:\Windows\system32\MRT
2013-12-22 21:55 - 2014-01-17 15:35 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== One Month Modified Files and Folders =======
2014-01-21 17:08 - 2014-01-21 17:07 - 00021798 _____ C:\Users\Philipp\Downloads\FRST.txt
2014-01-21 17:07 - 2014-01-21 17:07 - 00000000 ____D C:\FRST
2014-01-21 17:07 - 2013-12-09 17:30 - 02045234 _____ C:\Windows\WindowsUpdate.log
2014-01-21 17:05 - 2014-01-21 17:05 - 02077184 _____ (Farbar) C:\Users\Philipp\Downloads\FRST64.exe
2014-01-21 17:03 - 2014-01-21 17:03 - 00001149 _____ C:\Users\Philipp\Desktop\Continue Zip Opener Installation.lnk
2014-01-21 17:03 - 2014-01-21 17:02 - 00686264 _____ C:\Users\Philipp\Downloads\ZipOpenerSetup(1).exe
2014-01-21 17:00 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\sru
2014-01-21 16:56 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\AppData\Local\cache
2014-01-21 16:56 - 2014-01-21 16:34 - 00000000 ____D C:\Program Files (x86)\Mobogenie
2014-01-21 16:51 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\AppData\Local\Mobogenie
2014-01-21 16:47 - 2013-12-12 16:59 - 00000000 ____D C:\Users\Philipp\Desktop\Zugänge
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\Documents\Mobogenie
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\newnext.me
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\AppData\Local\genienext
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Philipp\.android
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 _____ C:\Users\Philipp\daemonprocess.txt
2014-01-21 16:35 - 2013-12-09 17:30 - 00000000 ____D C:\Users\Philipp
2014-01-21 16:34 - 2014-01-21 16:34 - 00001094 _____ C:\Users\Philipp\Desktop\MyPC Backup.lnk
2014-01-21 16:34 - 2014-01-21 16:34 - 00001026 _____ C:\Users\Philipp\Desktop\Mobogenie.lnk
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
2014-01-21 16:34 - 2014-01-21 15:03 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2014-01-21 16:34 - 2013-12-09 17:33 - 00000000 ___RD C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-21 16:31 - 2014-01-21 16:31 - 00003120 _____ C:\Windows\System32\Tasks\Advanced System Protector_startup
2014-01-21 16:30 - 2014-01-21 16:30 - 00001208 _____ C:\Users\Public\Desktop\Advanced System Protector.lnk
2014-01-21 16:30 - 2014-01-21 16:30 - 00000000 ____D C:\ProgramData\Systweak
2014-01-21 16:30 - 2014-01-21 16:30 - 00000000 ____D C:\Program Files (x86)\Advanced System Protector
2014-01-21 16:30 - 2014-01-21 16:25 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\systweak
2014-01-21 16:25 - 2014-01-21 16:25 - 00003324 _____ C:\Windows\System32\Tasks\Advanced System Protector
2014-01-21 16:25 - 2014-01-21 16:25 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
2014-01-21 16:25 - 2014-01-21 16:25 - 00003024 _____ C:\Windows\System32\Tasks\RegClean Pro_UPDATES
2014-01-21 16:25 - 2014-01-21 16:25 - 00002868 _____ C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
2014-01-21 16:25 - 2014-01-21 16:25 - 00001057 _____ C:\Users\Public\Desktop\RegClean Pro.lnk
2014-01-21 16:25 - 2014-01-21 16:25 - 00000302 _____ C:\Windows\Tasks\RegClean Pro_UPDATES.job
2014-01-21 16:25 - 2014-01-21 16:25 - 00000294 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2014-01-21 16:25 - 2014-01-21 16:25 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
2014-01-21 16:23 - 2014-01-21 16:23 - 00002648 _____ C:\Windows\System32\Tasks\FoxTab
2014-01-21 16:23 - 2014-01-21 16:23 - 00001117 _____ C:\Users\Public\Desktop\Open It!.lnk
2014-01-21 16:23 - 2014-01-21 16:23 - 00000310 _____ C:\Windows\Tasks\FoxTab.job
2014-01-21 16:23 - 2014-01-21 16:23 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\FoxTab
2014-01-21 16:23 - 2014-01-21 16:23 - 00000000 ____D C:\Program Files (x86)\OpenIt
2014-01-21 16:23 - 2014-01-21 16:23 - 00000000 ____D C:\Program Files (x86)\Foxtab
2014-01-21 16:22 - 2014-01-21 16:22 - 00000109 _____ C:\Users\Philipp\AppData\Roaming\WB.CFG
2014-01-21 16:22 - 2014-01-21 16:22 - 00000005 _____ C:\Users\Philipp\AppData\Roaming\WBPU-TTL.DAT
2014-01-21 16:21 - 2014-01-21 16:21 - 00002652 _____ C:\Windows\System32\Tasks\Digital Sites
2014-01-21 16:21 - 2014-01-21 16:21 - 00000314 _____ C:\Windows\Tasks\Digital Sites.job
2014-01-21 16:21 - 2014-01-21 16:21 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\DigitalSites
2014-01-21 16:20 - 2014-01-21 16:20 - 00686264 _____ C:\Users\Philipp\Downloads\ZipOpenerSetup.exe
2014-01-21 16:06 - 2014-01-21 14:52 - 00000000 ____D C:\ProgramData\WPM
2014-01-21 16:06 - 2013-12-12 16:25 - 00000000 ____D C:\Program Files (x86)\PC Speed Maximizer
2014-01-21 16:05 - 2014-01-21 14:53 - 00000000 ____D C:\Program Files (x86)\Optimizer Pro
2014-01-21 16:04 - 2013-12-09 17:33 - 00001445 _____ C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-21 15:46 - 2013-12-10 19:26 - 00000000 ____D C:\Users\Philipp\Desktop\Office
2014-01-21 15:04 - 2013-12-11 19:17 - 00001073 _____ C:\Users\Public\Desktop\VLC media player.lnk
2014-01-21 14:59 - 2014-01-21 14:59 - 00000000 ____D C:\Users\Philipp\Documents\Optimizer Pro
2014-01-21 14:49 - 2014-01-21 14:49 - 00000000 _____ C:\LIL897.tmp
2014-01-21 14:49 - 2014-01-21 14:49 - 00000000 _____ C:\LIL896.tmp
2014-01-21 14:49 - 2014-01-21 14:49 - 00000000 _____ C:\LIL895.tmp
2014-01-21 14:49 - 2014-01-21 14:49 - 00000000 _____ C:\LIL894.tmp
2014-01-21 14:49 - 2014-01-21 14:49 - 00000000 _____ C:\LIL893.tmp
2014-01-21 14:40 - 2014-01-21 14:39 - 00764360 _____ (Online Media Player ) C:\Users\Philipp\Downloads\setup.exe
2014-01-19 16:05 - 2013-12-11 11:51 - 00281688 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2014-01-19 16:05 - 2013-12-09 18:28 - 00281688 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2014-01-18 14:17 - 2013-12-11 19:18 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\vlc
2014-01-18 13:22 - 2013-06-22 19:33 - 00831158 _____ C:\Windows\system32\perfh007.dat
2014-01-18 13:22 - 2013-06-22 19:33 - 00188760 _____ C:\Windows\system32\perfc007.dat
2014-01-18 13:22 - 2012-07-26 08:28 - 01952854 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-18 13:19 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2014-01-18 13:16 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-18 13:15 - 2012-08-03 23:23 - 00024232 _____ C:\Windows\PFRO.log
2014-01-18 13:15 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2014-01-17 16:18 - 2013-12-09 17:49 - 00000000 ____D C:\Program Files\Microsoft Office 15
2014-01-17 15:37 - 2013-12-22 21:55 - 00000000 ____D C:\Windows\system32\MRT
2014-01-17 15:35 - 2013-12-22 21:55 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-17 15:34 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\WinStore
2014-01-16 16:06 - 2013-12-12 16:35 - 00000000 ____D C:\Program Files (x86)\SearchProtect
2014-01-15 12:16 - 2013-12-09 18:28 - 00281688 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2014-01-14 12:36 - 2014-01-14 12:36 - 00000000 ____D C:\Users\Public\Documents\Monolith Productions
2014-01-14 12:36 - 2013-06-22 11:05 - 00056188 _____ C:\Windows\DirectX.log
2014-01-14 12:29 - 2014-01-14 12:29 - 00000860 _____ C:\Users\Public\Desktop\F.E.A.R. - Multiplayer.lnk
2014-01-14 12:29 - 2014-01-14 12:29 - 00000850 _____ C:\Users\Public\Desktop\F.E.A.R. - Einzelspieler.lnk
2014-01-14 12:29 - 2013-06-22 11:11 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-14 12:28 - 2014-01-14 12:28 - 00000000 ____D C:\Program Files (x86)\Sierra
2014-01-12 14:55 - 2014-01-12 14:55 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2014-01-12 14:55 - 2014-01-12 14:55 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2014-01-12 14:55 - 2014-01-12 14:52 - 13079688 _____ (Microsoft Corporation) C:\Users\Philipp\Downloads\Silverlight_x64.exe
2014-01-09 09:02 - 2012-07-26 09:14 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-09 09:02 - 2012-07-26 09:14 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-05 15:36 - 2013-12-15 09:35 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log
2014-01-05 15:35 - 2013-12-15 09:34 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-01-02 15:50 - 2014-01-02 15:50 - 00401752 _____ (Softonic ) C:\Users\Philipp\Downloads\SoftonicDownloader_fuer_operation7.exe
2014-01-02 13:36 - 2013-12-09 17:54 - 00000000 ____D C:\Users\Philipp\Documents\Youcam
2013-12-28 18:13 - 2013-12-28 18:12 - 00000000 ____D C:\Users\Philipp\Desktop\Neuer Ordner
2013-12-28 18:13 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-12-27 18:10 - 2014-01-21 16:25 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe
2013-12-23 11:57 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\rescache
2013-12-23 11:51 - 2013-12-23 11:51 - 00432600 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-22 22:05 - 2012-07-26 09:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-12-22 22:05 - 2012-07-26 09:12 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-12-22 22:05 - 2012-07-26 09:12 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-12-22 22:05 - 2012-07-26 09:12 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-12-22 22:05 - 2012-07-26 06:38 - 00000000 ____D C:\Windows\SysWOW64\Dism
2013-12-22 22:05 - 2012-07-26 06:38 - 00000000 ____D C:\Windows\system32\Dism
2013-12-22 22:04 - 2013-06-22 19:36 - 00000000 ____D C:\Windows\en-GB
2013-12-22 22:04 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2013-12-22 22:04 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\SysWOW64\en-GB
2013-12-22 22:04 - 2012-07-26 09:12 - 00000000 ____D C:\Program Files\Windows Defender
2013-12-22 22:04 - 2012-07-26 09:12 - 00000000 ____D C:\Program Files\Common Files\System
2013-12-22 22:04 - 2012-07-26 09:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-12-22 22:04 - 2012-07-26 08:52 - 00000000 ____D C:\Program Files\Windows Journal
2013-12-22 22:04 - 2012-07-26 08:51 - 00000000 ____D C:\Windows\SysWOW64\winrm
2013-12-22 22:04 - 2012-07-26 08:51 - 00000000 ____D C:\Windows\SysWOW64\sysprep
2013-12-22 22:04 - 2012-07-26 08:51 - 00000000 ____D C:\Windows\SysWOW64\slmgr
2013-12-22 22:04 - 2012-07-26 06:38 - 00000000 ____D C:\Windows\SysWOW64\oobe
2013-12-22 22:03 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\SysWOW64\inetsrv
2013-12-22 22:02 - 2012-07-26 09:12 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2013-12-22 22:02 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\SysWOW64\MUI
2013-12-22 22:02 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\SysWOW64\Com
2013-12-22 22:02 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\migwiz
2013-12-22 22:02 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\inetsrv
2013-12-22 22:02 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\en-GB
2013-12-22 22:02 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-12-22 22:02 - 2012-07-26 08:51 - 00000000 ____D C:\Windows\SysWOW64\WCN
2013-12-22 22:02 - 2012-07-26 08:51 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2013-12-22 22:02 - 2012-07-26 08:51 - 00000000 ____D C:\Windows\system32\winrm
2013-12-22 22:02 - 2012-07-26 08:51 - 00000000 ____D C:\Windows\system32\slmgr
2013-12-22 22:02 - 2012-07-26 06:38 - 00000000 ____D C:\Windows\system32\Sysprep
2013-12-22 22:01 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\MUI
2013-12-22 22:01 - 2012-07-26 08:51 - 00000000 ____D C:\Windows\system32\WCN
2013-12-22 22:00 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\SystemResetPlatform
2013-12-22 22:00 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\Com
2013-12-22 22:00 - 2012-07-26 08:51 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 ____D C:\sources
2013-12-22 15:54 - 2013-12-09 17:54 - 00000000 ____D C:\Users\Philipp\AppData\Local\CyberLink
Some content of TEMP:
====================
C:\Users\Philipp\AppData\Local\Temp\BackupSetup.exe
C:\Users\Philipp\AppData\Local\Temp\drm_dyndata_7380014.dll
C:\Users\Philipp\AppData\Local\Temp\ICReinstall_ZipOpenerSetup(1).exe
C:\Users\Philipp\AppData\Local\Temp\nsu5585.exe
C:\Users\Philipp\AppData\Local\Temp\nsvB7B.exe
C:\Users\Philipp\AppData\Local\Temp\OfficeSetup.exe
C:\Users\Philipp\AppData\Local\Temp\PrefJsonCpp.exe
C:\Users\Philipp\AppData\Local\Temp\SPSetup.exe
C:\Users\Philipp\AppData\Local\Temp\sqlite3.exe
C:\Users\Philipp\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Philipp\AppData\Local\Temp\vlc-2.1.2-win32.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-12 18:27
==================== End Of Log ============================ --- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-01-2014
Ran by Philipp at 2014-01-21 17:08:37
Running from C:\Users\Philipp\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
==================== Installed Programs ======================
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (x32 Version: 11.6.6.636 - Adobe Systems, Inc.)
Advanced System Protector (x32 Version: 2.1.1000.12580 - Systweak Software) <==== ATTENTION
AMD APP SDK Runtime (Version: 10.0.1124.2 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
Bonjour (Version: 3.0.0.10 - Apple Inc.)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center (x32 Version: 2013.0225.1859.34051 - Ihr Firmenname) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0225.1859.34051 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.0225.1859.34051 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Profiles Mobile (x32 Version: 2013.0225.1859.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.0225.1858.34051 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.0225.1859.34051 - Advanced Micro Devices, Inc.) Hidden
CyberLink LabelPrint (x32 Version: 2.5.3.5901 - CyberLink Corp.)
CyberLink LabelPrint (x32 Version: 2.5.3.5901 - CyberLink Corp.) Hidden
CyberLink Media Suite 10 (x32 Version: 10.0.3.2608 - CyberLink Corp.)
CyberLink Media Suite 10 (x32 Version: 10.0.3.2608 - CyberLink Corp.) Hidden
Cyberlink PhotoDirector (x32 Version: 3.0.1.3711 - CyberLink Corp.)
Cyberlink PhotoDirector (x32 Version: 3.0.1.3711 - CyberLink Corp.) Hidden
CyberLink Power2Go 8 (x32 Version: 8.0.3.2527 - CyberLink Corp.)
CyberLink Power2Go 8 (x32 Version: 8.0.3.2527 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (x32 Version: 10.0.3.2606 - CyberLink Corp.)
CyberLink PowerDirector 10 (x32 Version: 10.0.3.2606 - CyberLink Corp.) Hidden
CyberLink PowerDVD (x32 Version: 10.0.8.5004 - CyberLink Corp.)
CyberLink PowerDVD (x32 Version: 10.0.8.5004 - CyberLink Corp.) Hidden
CyberLink YouCam (x32 Version: 3.5.6.6117 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.5.6.6117 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Star (x32 Version: 1.0.9 - Hewlett-Packard Company)
Far Cry 3 (x32 Version: 1.05 - Ubisoft)
FEAR (x32 Version: 1.00.0000 - Vivendi Universal Games, Inc.)
FileParade Bundle (x32 Version: 1.0.0.0 - FileParade Bundle)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Foxtab (x32 Version: - FoxTab) <==== ATTENTION
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto IV (x32 Version: 1.00.0000 - Rockstar Games)
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (Version: 4.2.9.1 - Hewlett-Packard Company)
HP Connected Music (Meridian - installer) (x32 Version: 1.0 - Meridian Audio Ltd)
HP Connected Music (Meridian - player) (HKCU Version: 1.1 (build 77) hp - Meridian Audio Ltd)
HP CoolSense (x32 Version: 2.20.11 - Hewlett-Packard Company)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden
HP Documentation (x32 Version: 1.2.0.0 - Hewlett-Packard)
HP Postscript Converter (Version: 4.0.4100 - Hewlett-Packard) Hidden
HP Quick Start (x32 Version: 1.0.4660.30220 - Hewlett-Packard)
HP Recovery Manager (x32 Version: 9.00 - Hewlett-Packard) Hidden
HP Registration Service (Version: 1.2.6317.4309 - Hewlett-Packard)
HP Support Assistant (x32 Version: 7.0.39.15 - Hewlett-Packard Company)
HP System Event Utility (x32 Version: 1.0.4 - Hewlett-Packard Company)
HP Utility Center (Version: 2.1.5 - Hewlett-Packard Company)
HP Wireless Button Driver (x32 Version: 1.0.6.1 - Hewlett-Packard Company)
Intel(R) Management Engine Components (x32 Version: 8.1.30.1349 - Intel Corporation)
Intel(R) Processor Graphics (x32 Version: 9.18.10.3055 - Intel Corporation)
Intel(R) Rapid Storage Technology (Version: 12.0.7.1002 - Intel Corporation)
Intel(R) Rapid Storage Technology (Version: 12.0.7.1002 - Intel Corporation) Hidden
Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 3.0.0.63463 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.27.757.1 - Intel Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (x32 Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Office 365 Home Premium - de-de (Version: 15.0.4551.1512 - Microsoft Corporation)
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SkyDrive (HKCU Version: 17.0.2015.0811 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Mobogenie (x32 Version: - Mobogenie.com) <==== ATTENTION
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MyPC Backup (Version: - MyPC Backup) <==== ATTENTION
Norton Internet Security (x32 Version: 20.4.0.40 - Symantec Corporation)
OEM Application Profile (x32 Version: 1.00.0000 - Ihr Firmenname)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4551.1512 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4551.1512 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4551.1512 - Microsoft Corporation) Hidden
Open It! (x32 Version: 1.1.1 - OpenIt)
Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
PunkBuster Services (x32 Version: 0.993 - Even Balance, Inc.)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Realtek Ethernet Controller Driver (x32 Version: 8.7.1025.2012 - Realtek)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6856 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (x32 Version: 1.1.9200.007 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (x32 Version: 1.00.12.0906 - REALTEK Semiconductor Corp.)
RegClean Pro (x32 Version: 6.21 - Systweak Inc) <==== ATTENTION
Search Protect (x32 Version: 2.9.40.12 - Conduit) <==== ATTENTION
Steam (x32 Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (Version: 16.3.12.1 - Synaptics Incorporated)
Unity Web Player (HKCU Version: - Unity Technologies ApS)
Update for Zip Opener (HKCU Version: - Update for Zip Opener) <==== ATTENTION
Updater (x32 Version: 2.6.49 - Creative Island Media, LLC)
Uplay (x32 Version: 2.0 - Ubisoft)
VLC media player 2.1.0 (x32 Version: 2.1.0 - VideoLAN)
Websteroids (x32 Version: 2.6.49 - Creative Island Media, LLC) <==== ATTENTION
Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
YTD Video Downloader 4.7.1 (x32 Version: 4.7.1 - GreenTree Applications SRL)
Zip Opener Packages (HKCU Version: - ) <==== ATTENTION
==================== Restore Points =========================
22-12-2013 20:53:37 Windows Update
09-01-2014 15:01:57 Geplanter Prüfpunkt
14-01-2014 11:28:50 Installiert FEAR
17-01-2014 14:32:10 Windows Update
21-01-2014 15:28:25 RegClean Pro Di, Jan 21, 14 16:28
==================== Hosts content: ==========================
2012-07-26 06:26 - 2012-07-26 06:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0678EFDC-A25F-4E2B-83CC-3AC53323A03F} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {18B4A702-649D-44C9-B113-BD5A3B7A5EC3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard)
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2E659F27-07CD-426D-BE3A-244AD862CD43} - System32\Tasks\Hewlett-Packard\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2013-08-19] (Hewlett-Packard Development Company, L.P.)
Task: {39505E6D-2F97-451A-800F-F9148BCE5773} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe [2013-12-23] (Systweak) <==== ATTENTION
Task: {3F7A6FE4-607D-401E-BDC2-32F25D54C634} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {409D1FBE-6B48-4329-B785-3C39FD1BFEF4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {4B73C66D-5648-46DA-AF90-A361D70E43A0} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2012-07-24] (CyberLink Corp.)
Task: {5ED4B99B-822B-45D0-A871-D4EC8E643D51} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2013-12-27] (Systweak Inc) <==== ATTENTION
Task: {6A17C042-2D15-4D7E-BF50-709C6375D48E} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-10-31] (Microsoft Corporation)
Task: {6E88CF20-BA3F-479E-AC1F-9E5384E44F10} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-08] (CyberLink)
Task: {7B00435E-9229-4665-B154-5C7201428396} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2013-08-16] (Microsoft Corporation)
Task: {8134B5AB-C671-4FDC-B8D5-EA73E1001E57} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2013-12-27] (Systweak Inc) <==== ATTENTION
Task: {83FE5833-6D40-4D4C-8CF3-5890850F9C39} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-01-15] (Microsoft Corporation)
Task: {87800150-7506-4E9D-BA2D-DD71D224591C} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation)
Task: {9E62DAFA-B94C-45EC-94E5-3F78E235AFC4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater\HPSFUpdater.exe
Task: {A16C5E9B-2864-4769-A5C8-746B940BE077} - System32\Tasks\FoxTab => C:\Users\Philipp\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {B0047E3C-B553-4AD6-B92B-007274793F6B} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2013-01-17] (CyberLink)
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {C6C5B5E2-8245-444F-80E2-7F29DBEBDD48} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {C71D7B58-52C4-4543-88A9-D9EAA21C1216} - System32\Tasks\Microsoft\WINRE\WinRE-Repair => C:\windows\System32\reagentc.exe [2012-10-24] (Microsoft Corporation)
Task: {D737EBEB-B08B-4FEC-88F5-9A64235437B2} - System32\Tasks\Digital Sites => C:\Users\Philipp\AppData\Roaming\DigitalSites\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {E06C6F79-1E53-4692-A471-1BF94ECDFBD6} - System32\Tasks\Advanced System Protector => C:\Program Files (x86)\RegClean Pro\SystweakASP.exe [2013-08-23] (Systweak Inc ) <==== ATTENTION
Task: {E1F3B82D-85DE-4C44-9395-AF95DA9A1DB3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard)
Task: {E9413D49-ADC2-4C01-BAEB-7EEDC6491D91} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2013-12-27] (Systweak Inc) <==== ATTENTION
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: C:\Windows\Tasks\Digital Sites.job => C:\Users\Philipp\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Philipp\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
==================== Loaded Modules (whitelisted) =============
2013-02-22 14:04 - 2013-02-22 14:04 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-09-19 23:37 - 2013-09-19 23:37 - 00012288 _____ () C:\Program Files (x86)\MyPC Backup\GetText.dll
2013-09-19 23:32 - 2013-09-19 23:32 - 01102336 _____ () C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll
2013-08-21 00:10 - 2013-01-14 19:25 - 01200088 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-12-11 18:02 - 2012-05-30 07:51 - 00699280 ____R () C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\wincfi39.dll
2013-08-21 00:28 - 2012-06-08 04:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2012-06-08 10:34 - 2012-06-08 10:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2013-12-13 21:38 - 2013-12-05 20:36 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\Temp:AD022376
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Could not start eventlog service, could not read events.
Der angeforderte Dienst wurde bereits gestartet.
Sie erhalten weitere Hilfe, wenn Sie NET HELPMSG 2182 eingeben.
==================== Memory info ===========================
Percentage of memory in use: 28%
Total physical RAM: 8084.27 MB
Available physical RAM: 5808.04 MB
Total Pagefile: 9300.27 MB
Available Pagefile: 7125.02 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:678.67 GB) (Free:599.84 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVERY) (Fixed) (Total:19.19 GB) (Free:1.94 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 699 GB) (Disk ID: 0A82384C)
Partition: GPT Partition Type
==================== End Of Log ============================ |