Logfile zur Malwarebytes Antimalware Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 28.01.2015
Suchlauf-Zeit: 15:21:12
Logdatei:
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.01.28.06
Rootkit Datenbank: v2015.01.14.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Toshiba
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 345047
Verstrichene Zeit: 35 Min, 30 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 2
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe, 4712, , [71e0c92e97f22d098792836769989769]
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\BackupStack.exe, 6704, , [262b31c6d2b763d3ebac285fa55eae52]
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 4
PUP.Optional.MyPCBackup.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\BackupStack, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MyPC Backup, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\MyPC Backup, , [272a886f90f9102661ddc3bb3ac99b65],
PUP.Optional.MyPCBackup.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\MyPC Backup, , [e66b77805138d561a19de69849ba9d63],
Registrierungswerte: 1
PUP.Optional.MyPCBackup.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\BACKUPSTACK|ImagePath, C:\Program Files (x86)\MyPC Backup\BackupStack.exe, , [8fc27780a8e163d3a5f37d0ace354eb2]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 13
PUP.Optional.MyPCBackup.A, C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup, , [85cc43b4ccbdbe78e6b02c5bbb48c937],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\cache, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Config, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Database, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\x64, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\x86, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\~updates, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.SmartBar.A, C:\Users\Toshiba\AppData\LocalLow\Smartbar, , [76dbc82f0a7f082ebbfa4a278a79619f],
Dateien: 184
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe, , [71e0c92e97f22d098792836769989769],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Service Start.exe, , [b0a1a750b2d7a096dc3d6a807c85da26],
PUP.Optional.MyPCBackup.A, C:\Users\Toshiba\AppData\Local\Temp\BackupSetup.exe, , [0a4732c58900b77f9b7e608a6e9358a8],
PUP.Optional.MyPCBackup.A, C:\Windows\Temp\tmpAA9B.tmp, , [3b1606f16821df57f4258268eb16ed13],
PUP.Optional.AZLyrics.A, C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage, , [ef6225d25237c472e5ed98ea51b260a0],
PUP.Optional.AZLyrics.A, C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal, , [57fac136d4b5f93dc70bf09232d10df3],
PUP.Optional.MyPCBackup.A, C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk, , [7ed3c3344a3f5adceaaaf29558abfa06],
PUP.Optional.MyPCBackup.A, C:\Users\Toshiba\Desktop\MyPC Backup.lnk, , [a5accf28bccd04324e47eb9c33d0926e],
PUP.Optional.MyPCBackup.A, C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup\MyPC Backup.lnk, , [85cc43b4ccbdbe78e6b02c5bbb48c937],
PUP.Optional.MyPCBackup.A, C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup\Uninstall.lnk, , [85cc43b4ccbdbe78e6b02c5bbb48c937],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\pt_PT.mo, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\aff.conf, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\AlphaFS.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\AlphaVSS.51.x86.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\AlphaVSS.52.x64.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\AlphaVSS.52.x86.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\AlphaVSS.60.x64.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\AlphaVSS.60.x86.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\AlphaVSS.Common.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\LogicNP.EZShellExtensions.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Microsoft.Win32.TaskScheduler.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\MPCBClient.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\MPCBContextMenu.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\MPCBIconOverlays.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet20_x86.exe, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet40_x64.exe, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet40_x86.exe, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\RestartExplorer.exe, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\BackupStack.exe, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\BackupStackUI.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\BplusDotNet.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Configuration Updater.exe, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Crypto32.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Crypto64.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\diffstack.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\es_ES.mo, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\fr_FR.mo, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\GetText.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\InstMgr.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Ionic.Zip.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\it_IT.mo, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\LinqBridge.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\AWSSDK.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\de_DE.mo, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet20_x64.exe, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\mypcbackup.ico, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\NativeHashWrapper.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Newtonsoft.Json.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\ObjectListView.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\PipeDiff.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Shared Stack.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\SignupWizard.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\syncicon.ico, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\syncing.ico, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\System.Data.SQLite.DLL, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\tick.ico, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\uninst.exe, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\UnRegisterExtensions.exe, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Updater.exe, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Updater.exe.0.old, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Updater_.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\websocket-sharp.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_08b72a97-6564-49f2-89f5-4f12cb886fdb_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_08b72a97-6564-49f2-89f5-4f12cb886fdb_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_0aee48fc-94af-4845-a368-46e8495d5a76_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_0aee48fc-94af-4845-a368-46e8495d5a76_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_0d3049e5-2969-4932-9260-8d688a472ae0_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_0d3049e5-2969-4932-9260-8d688a472ae0_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_0dae33ba-02a0-4b87-ade8-ba522ff19c62_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_0dae33ba-02a0-4b87-ade8-ba522ff19c62_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_55b73a1f-8a1c-4ae6-8a94-3fb68e99d83f_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_55b73a1f-8a1c-4ae6-8a94-3fb68e99d83f_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_71528662-805b-4cdf-a44b-abd85511b825_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_71528662-805b-4cdf-a44b-abd85511b825_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_79efa83d-0709-42be-90e9-f7ef3294f780_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_79efa83d-0709-42be-90e9-f7ef3294f780_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_b1037739-5aa4-454d-87df-3350fed4e08e_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_b1037739-5aa4-454d-87df-3350fed4e08e_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_b76a404a-ade3-45f0-8b8b-4a4f454d1f01_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_b76a404a-ade3-45f0-8b8b-4a4f454d1f01_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_ba2d1aab-1230-482d-a5d8-87e16c2129f6_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_ba2d1aab-1230-482d-a5d8-87e16c2129f6_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_c0464bc0-cf44-480b-b4c4-02abc78dc467_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_c0464bc0-cf44-480b-b4c4-02abc78dc467_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_cd4f9e92-27ef-45a1-83ba-207d7c777563_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_cd4f9e92-27ef-45a1-83ba-207d7c777563_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_df100580-2f5e-41d7-9d60-da2a678ddad7_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_df100580-2f5e-41d7-9d60-da2a678ddad7_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_eeaa790f-550e-4010-93d0-02b89434b6b5_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_eeaa790f-550e-4010-93d0-02b89434b6b5_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_f34b8a4e-ff14-44ce-b8fe-a4e62ee21738_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_f34b8a4e-ff14-44ce-b8fe-a4e62ee21738_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_fa7deb3f-7894-4115-bfdc-3a407990ed2f_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_fa7deb3f-7894-4115-bfdc-3a407990ed2f_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_fd87c9f4-6355-4d0a-8e67-7658c1829cb6_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_fd87c9f4-6355-4d0a-8e67-7658c1829cb6_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_10912641-ee27-4bd4-8875-71df69121eb0_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_125f5773-5467-4d65-b437-1b07a0214363_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_125f5773-5467-4d65-b437-1b07a0214363_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_145fd996-d035-4d36-b775-fc635f236212_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_145fd996-d035-4d36-b775-fc635f236212_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_4001d173-433b-4d8a-b7ee-57ae5d7b5bf5_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_4001d173-433b-4d8a-b7ee-57ae5d7b5bf5_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_41ab70c7-7424-46d2-9ee2-ad7514eaa54b_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_41ab70c7-7424-46d2-9ee2-ad7514eaa54b_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_42ff2cec-d99b-4f3a-9e69-3113e79d0418_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_42ff2cec-d99b-4f3a-9e69-3113e79d0418_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_4b718295-ffa9-46ef-ba28-95c26fa59cc1_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_10912641-ee27-4bd4-8875-71df69121eb0_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_4b718295-ffa9-46ef-ba28-95c26fa59cc1_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_7b06e67d-1509-46b0-b839-909dc1398b47_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_7b06e67d-1509-46b0-b839-909dc1398b47_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_843b5b2f-383d-4790-b5c7-ec0ad5a2d2e6_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_843b5b2f-383d-4790-b5c7-ec0ad5a2d2e6_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_9d1558c3-1b19-45aa-b0a9-c6c3cc66d57f_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_9d1558c3-1b19-45aa-b0a9-c6c3cc66d57f_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_aefed84e-d67c-4c0f-bfb9-944908785768_backupKeyCache.block, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Resources\keycache\_aefed84e-d67c-4c0f-bfb9-944908785768_backupKeyCache.tree, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1420379845.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1418770163.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1418848149.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1418931359.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1419017746.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1419105196.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1419618845.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1420301248.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1420574710.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1420659353.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1420745721.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1420832707.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1420918523.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421004938.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421093095.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421177713.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421264135.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421373677.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421460076.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421546485.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421632949.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421719276.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421782511.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421877456.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1421978538.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1422276023.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1422303867.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Compressed\BACKUP_1422387357.clog, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Config\api.ts2, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Database\mpcb_backup_conf.db, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Database\mpcb_backup_id.db, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Database\mpcb_file_cache.db, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Database\mpcb_queues.db, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Database\mpcb_settings.db, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Database\mpcb_sig_cache.db, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\Database\mpcb_version_queue.db, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\APPLICATION.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\AUTH.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\BACKOFF.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\BACKUP.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\BACKUP_COMPLETE.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\CLIENT.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\CORE.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\GRID_RECOVERY.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\GRID_RECOVERY_INIT.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\LICENCE.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\NETWORK_SHARES.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\POPUPS.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\REMOTING.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\REQUEST.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\RESTRICTIONS.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\SERVICE.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\SHELL.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\STACK_BASE.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\UPDATER.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\UTC_MIGRATION.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\log\WAIT_HANDLES.log, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\x64\SQLite.Interop.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\x86\SQLite.Interop.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.MyPCBackup.A, C:\Program Files (x86)\MyPC Backup\x86\System.Data.SQLite.dll, , [262b31c6d2b763d3ebac285fa55eae52],
PUP.Optional.SmartBar.A, C:\Users\Toshiba\AppData\LocalLow\Smartbar\smartbar_state.config, , [76dbc82f0a7f082ebbfa4a278a79619f],
PUP.Optional.HelperBar.A, C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=bcc6e3e5-0a05-7482-0f44-956ab4c169ed&searchtype=nt&fr=linkury-tb&installDate={installDate}&type=hp1000&q=");), ,[2928d52202870f27f8d5b0330cf94ab6]
PUP.Optional.HelperBar.A, C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=bcc6e3e5-0a05-7482-0f44-956ab4c169ed&searchtype=ds&fr=linkury-tb&installDate=17/03/2014&type=hp1000&p=");), ,[4a0713e4fb8e88aea42af9ea24e13bc5]
PUP.Optional.HelperBar.A, C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=bcc6e3e5-0a05-7482-0f44-956ab4c169ed&searchtype=hp&fr=linkury-tb&installDate=17/03/2014&type=hp1000");), ,[a3ae14e30386e35391a129bbda2bf709]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
HitmanPro 3.7.9.234
www.hitmanpro.com
Computer name . . . . : TOSHIBA-TOSH
Windows . . . . . . . : 6.1.1.7601.X64/2
User name . . . . . . : Toshiba-TOSH\Toshiba
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2015-01-28 16:43:24
Scan mode . . . . . . : Normal
Scan duration . . . . : 13m 42s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 1
Traces . . . . . . . : 155
Objects scanned . . . : 1.635.354
Files scanned . . . . : 55.816
Remnants scanned . . : 499.782 files / 1.079.756 keys
Suspicious files ____________________________________________________________
C:\Users\Toshiba\Downloads\FRST64.exe
Size . . . . . . . : 2.067.456 bytes
Age . . . . . . . : 240.7 days (2014-06-01 23:07:02)
Entropy . . . . . : 7.5
SHA-256 . . . . . : AD71762ECB8EE2C9B4F49803B940ED620C533B0EFA76C189A633796BC155A1EA
Needs elevation . : Yes
Fuzzy . . . . . . : 22.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Malware remnants ____________________________________________________________
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}\ (Jotzey)
Potential Unwanted Programs _________________________________________________
C:\Program Files (x86)\MyPC Backup\ (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\AlphaFS.dll (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\BackupStack.exe (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\BackupStackUI.dll (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\BplusDotNet.dll (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Database\ (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Database\mpcb_settings.db (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Database\mpcb_version_queue.db (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\GetText.dll (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Ionic.Zip.dll (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\LinqBridge.dll (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\log\ (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\log\COLLECTION_QUERIES.log (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\log\SCHEDULE.log (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\log\STACK_BASE.log (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Microsoft.Win32.TaskScheduler.dll (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\MPCBClient.dll (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Newtonsoft.Json.dll (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\ObjectListView.dll (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Resources\keycache\ (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Resources\keycache\_4001d173-433b-4d8a-b7ee-57ae5d7b5bf5_backupKeyCache.block (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Resources\keycache\_4001d173-433b-4d8a-b7ee-57ae5d7b5bf5_backupKeyCache.tree (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Resources\keycache\_42ff2cec-d99b-4f3a-9e69-3113e79d0418_backupKeyCache.block (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Resources\keycache\_42ff2cec-d99b-4f3a-9e69-3113e79d0418_backupKeyCache.tree (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Resources\keycache\_7b06e67d-1509-46b0-b839-909dc1398b47_backupKeyCache.block (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Resources\keycache\_7b06e67d-1509-46b0-b839-909dc1398b47_backupKeyCache.tree (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\Shared Stack.dll (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\System.Data.SQLite.DLL (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\x64\ (MyPC Backup)
C:\Program Files (x86)\MyPC Backup\x64\SQLite.Interop.dll (MyPC Backup)
C:\Users\Toshiba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Search.lnk (Tuvaro)
browser.newtab.url
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\prefs.js
browser.startup.homepage
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\prefs.js
keyword.URL
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\prefs.js
C:\Users\Toshiba\AppData\Roaming\Systweak\ (Systweak)
Search.lnk
C:\Users\Toshiba\Desktop\
C:\Users\Toshiba\Desktop\Sync Folder.lnk (MyPC Backup)
C:\Windows\system32\roboot64.exe (PCPerformer)
Size . . . . . . . : 17.080 bytes
Age . . . . . . . : 813.8 days (2012-11-05 21:30:20)
Entropy . . . . . : 5.6
SHA-256 . . . . . : E1D16ADC369E9C53325CEB569B5629A2AEA4228A19189EEC8D30E41CED6F7D1B
Product . . . . . : Systweak Regclean Pro
Publisher . . . . : Systweak Inc., (www.systweak.com)
Description . . . : Regclean Pro
Version . . . . . : 6.1
Copyright . . . . : Copyright (C) 2012 Systweak Inc., All rights reserved.
RSA Key Size . . . : 1024
LanguageID . . . . : 1033
Authenticode . . . : Valid
Fuzzy . . . . . . : -5.0
HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}\ (FLV Player)
HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}\ (FLV Player)
HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}\ (FLV Player)
HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}\ (FLV Player)
HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}\ (FLV Player)
HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}\ (FLV Player)
HKLM\SOFTWARE\Classes\IESmartBar.BandObjectAttribute\ (FLV Player)
HKLM\SOFTWARE\Classes\IESmartBar.DockingPanel\ (FLV Player)
HKLM\SOFTWARE\Classes\IESmartBar.IESmartBar\ (FLV Player)
HKLM\SOFTWARE\Classes\IESmartBar.IESmartBarBandObject\ (FLV Player)
HKLM\SOFTWARE\Classes\IESmartBar.SmartbarDisplayState\ (FLV Player)
HKLM\SOFTWARE\Classes\IESmartBar.SmartbarMenuForm\ (FLV Player)
HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}\ (FLV Player)
HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}\ (FLV Player)
HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}\ (FLV Player)
HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}\ (FLV Player)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}\ (RegClean Pro)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}\ (FLV Player)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}\ (FLV Player)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}\ (FLV Player)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}\ (FLV Player)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}\ (FLV Player)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}\ (FLV Player)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4\ (FLV Player)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964\ (FLV Player)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467\ (FLV Player)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32\ (AdvSysProtector)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS\ (AdvSysProtector)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskPartnerCobrandingTool_RASAPI32\ (AskBar)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskPartnerCobrandingTool_RASMANCS\ (AskBar)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegCleanPro_RASAPI32\ (RegClean Pro)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegCleanPro_RASMANCS\ (RegClean Pro)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32\ (AdvSysProtector)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS\ (AdvSysProtector)
HKLM\SOFTWARE\Wow6432Node\Systweak\ (AdvSysProtector)
HKLM\SYSTEM\ControlSet002\services\BackupStack\ (MyPC Backup)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4\ (FLV Player)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}\ (FLV Player)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\Software\Microsoft\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4\ (FLV Player)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}\ (FLV Player)
Cookies _____________________________________________________________________
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.ad-srv.net
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.zanox.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.p161.net
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.stickyadstv.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtechus.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:bs.serving-sys.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:burstnet.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:media6degrees.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:tribalfusion.com
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\1DBZP95N.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\1N3UFJVZ.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\2WUYF9KJ.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\44416MQS.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\478ZW44W.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\4KJZHEPR.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\55CDML2S.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\5HXABR9Q.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\70ASOXF8.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\82OSKZQ4.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\8KRIR2ZV.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\96E0CB91.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\C5X9GAB2.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\F5CVTHZU.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\FH6X5S9M.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\G1IKKZUQ.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\MOCCI60O.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\N0W56YXH.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\NKTHV77E.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\NYFY3D1D.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\PZLDKX46.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\QLN0URHR.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\SMO5D1KM.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\TNWUDU5J.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\toshiba@ad.360yield[2].txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\toshiba@ad.ad-srv[1].txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\toshiba@ad.zanox[2].txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\toshiba@ads.creative-serving[2].txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\toshiba@apmebf[1].txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\toshiba@invitemedia[1].txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\toshiba@revsci[1].txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\toshiba@track.adform[2].txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\WAHKESWJ.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\WUBIJV4W.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\YAWVNZXW.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\YNNAVUBS.txt
C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Cookies\ZSIGFDFD.txt
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:ad.360yield.com
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:ad.auditude.com
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:ad.zanox.com
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:ads.stickyadstv.com
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:ads.yahoo.com
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:adtech.de
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:atdmt.com
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:doubleclick.net
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:emjcd.com
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:linksynergy.com
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:questionmarket.com
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:revsci.net
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:serving-sys.com
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:smartadserver.com
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:track.zalando.de
C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\cookies.sqlite:www.googleadservices.com FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by Toshiba (administrator) on TOSHIBA-TOSH on 28-01-2015 17:08:20
Running from C:\Users\Toshiba\Downloads
Loaded Profiles: Toshiba & (Available profiles: Toshiba)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Windows\System32\CISVC.EXE
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Microsoft Corporation) C:\Windows\System32\snmp.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
(Telefónica) C:\Program Files (x86)\o2\Mobile Connection Manager\ImpWiFiSvc.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe
(Spotify Ltd) C:\Users\Toshiba\AppData\Roaming\Spotify\spotify.exe
(Nokia) C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe
(Comfort Software Group) C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Bluetooth Monitor\BtMon2.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Nokia.) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Dropbox, Inc.) C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\Dropbox.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Bluetooth Monitor\BtMon64.exe
(MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
() C:\Program Files (x86)\MyPC Backup\BackupStack.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
() C:\Users\Toshiba\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Toshiba\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
() C:\Users\Toshiba\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Toshiba\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Toshiba\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Toshiba\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
() C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe
() C:\Users\Toshiba\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() Q:\140066.deu\Office14\WINWORDC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
() Q:\140066.deu\Office14\OffSpon.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [35672 2010-03-03] (TOSHIBA Corporation)
HKLM\...\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [595816 2010-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1050072 2010-02-11] (Toshiba Europe GmbH)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] ()
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [520760 2010-03-10] (Conexant Systems, Inc.)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [505696 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [913720 2010-03-03] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1489760 2010-03-17] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [705368 2010-02-23] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [SmartFaceVWatcher] => C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation)
HKLM-x32\...\Run: [NBAgent] => c:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe [1086760 2010-03-09] (Nero AG)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288088 2009-11-11] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-15] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1294136 2009-10-06] (TOSHIBA Corporation)
HKLM-x32\...\Run: [TWebCamera] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2454840 2010-02-24] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-04] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2014-11-21] (Malwarebytes Corporation)
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\...\Run: [Spotify Web Helper] => C:\Users\Toshiba\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-17] (Spotify Ltd)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\...\Run: [Spotify] => C:\Users\Toshiba\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-17] (Spotify Ltd)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\...\Run: [NokiaPCInternetAccess] => C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [663552 2009-09-17] (Nokia)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\...\Run: [FreeAC] => C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe [1328976 2012-04-25] (Comfort Software Group)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_257_Plugin.exe -update plugin
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\...\MountPoints2: {4beab978-1ce3-11e2-9fbf-00266c94536c} - F:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Users\Toshiba\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-17] (Spotify Ltd)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify] => C:\Users\Toshiba\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-17] (Spotify Ltd)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [NokiaPCInternetAccess] => C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [663552 2009-09-17] (Nokia)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [FreeAC] => C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe [1328976 2012-04-25] (Comfort Software Group)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_257_Plugin.exe -update plugin
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {4beab978-1ce3-11e2-9fbf-00266c94536c} - F:\NokiaPCIA_Autorun.exe
HKU\S-1-5-18\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Monitor.lnk
ShortcutTarget: Bluetooth Monitor.lnk -> C:\Program Files (x86)\TOSHIBA\Bluetooth Monitor\BtMon2.exe (TOSHIBA CORPORATION)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Toshiba\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3737254009-2587710715-760453973-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba.msn.com
HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba.msn.com
SearchScopes: HKLM -> DefaultScope {70062ECD-D40D-471F-8395-3DA6D219F41A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {70062ECD-D40D-471F-8395-3DA6D219F41A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3737254009-2587710715-760453973-1000 -> DefaultScope {70062ECD-D40D-471F-8395-3DA6D219F41A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3737254009-2587710715-760453973-1000 -> {70062ECD-D40D-471F-8395-3DA6D219F41A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {70062ECD-D40D-471F-8395-3DA6D219F41A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {70062ECD-D40D-471F-8395-3DA6D219F41A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.217.1.1
FireFox:
========
FF ProfilePath: C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default
FF NewTab: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=bcc6e3e5-0a05-7482-0f44-956ab4c169ed&searchtype=nt&fr=linkury-tb&installDate={installDate}&type=hp1000&q=
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Ask.com
FF Homepage: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=bcc6e3e5-0a05-7482-0f44-956ab4c169ed&searchtype=hp&fr=linkury-tb&installDate=17/03/2014&type=hp1000
FF Keyword.URL: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=bcc6e3e5-0a05-7482-0f44-956ab4c169ed&searchtype=ds&fr=linkury-tb&installDate=17/03/2014&type=hp1000&p=
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20us07.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll No File
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\user.js
FF Extension: ProxTube - Unblock YouTube - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\Extensions\ich@maltegoetz.de [2013-01-08]
FF Extension: Hola Better Internet - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\Extensions\jid1-4P0kohSJxU1qGg@jetpack [2015-01-14]
FF Extension: YouTube Unblocker - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\Extensions\youtubeunblocker@unblocker.yt [2014-08-10]
FF Extension: Block site - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\Extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc} [2014-01-21]
FF Extension: ProxMate - Proxy on steroids! - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2014-08-14]
FF Extension: {31168ec7-77f8-4687-b1ca-346619abb543} - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\Extensions\{31168ec7-77f8-4687-b1ca-346619abb543}.xpi [2014-09-14]
FF Extension: FTPExtension - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\Extensions\{5496a459-6415-41e3-800e-48f31887919c}.xpi [2014-09-27]
FF Extension: Adblock Plus - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\jcwa3way.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-21]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-12-07]
FF HKU\S-1-5-21-3737254009-2587710715-760453973-1000\...\Firefox\Extensions: [{33044118-6597-4D2F-ABEA-7974BB185379}] - C:\Users\Toshiba\AppData\Roaming\16001.007
FF HKU\S-1-5-21-3737254009-2587710715-760453973-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [{33044118-6597-4D2F-ABEA-7974BB185379}] - C:\Users\Toshiba\AppData\Roaming\16001.007
FF HKU\S-1-5-21-3737254009-2587710715-760453973-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
Chrome:
=======
CHR Profile: C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-29]
CHR Extension: (Google Docs) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-29]
CHR Extension: (Google Drive) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-29]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-06]
CHR Extension: (YouTube) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-29]
CHR Extension: (Google Search) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-29]
CHR Extension: (Google Sheets) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-29]
CHR Extension: (Avira Browser Safety) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-11-29]
CHR Extension: (Google Wallet) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-29]
CHR Extension: (Gmail) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-29]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [992560 2014-12-04] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG)
R2 iprip; C:\Windows\System32\iprip.dll [35328 2009-07-14] (Microsoft Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
R3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [575488 2008-09-23] (Nokia.) [File not signed]
R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 SNMP; C:\Windows\System32\snmp.exe [49664 2010-11-20] (Microsoft Corporation)
R2 SNMP; C:\Windows\SysWOW64\snmp.exe [47616 2010-11-20] (Microsoft Corporation)
R2 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [124368 2010-02-11] (Toshiba Europe GmbH)
R2 TGCM_ImportWiFiSvc; C:\Program Files (x86)\o2\Mobile Connection Manager\ImpWiFiSvc.exe [201344 2012-01-10] (Telefónica)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-01-12] (Avira Operations GmbH & Co. KG)
R3 CnxtHdmiAudService; C:\Windows\System32\drivers\CHDMI64.sys [720952 2010-03-05] (Conexant Systems Inc.)
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.)
S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [12800 2010-10-15] (ZTE Incorporated)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [129752 2015-01-28] (Malwarebytes Corporation)
U0 memedy; C:\Windows\System32\drivers\rrcckcqq.sys [79064 2015-01-28] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-10-16] (Anchorfree Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-28 17:05 - 2015-01-28 17:05 - 00000000 ____D () C:\Users\Toshiba\Downloads\FRST-OlderVersion
2015-01-28 17:02 - 2015-01-28 17:02 - 00032392 _____ () C:\Users\Toshiba\Desktop\HitmanPro_20150128_1702.log
2015-01-28 16:42 - 2015-01-28 17:02 - 00000000 ____D () C:\ProgramData\HitmanPro
2015-01-28 16:41 - 2015-01-28 16:43 - 11225840 _____ (SurfRight B.V.) C:\Users\Toshiba\Downloads\HitmanPro_x64.exe
2015-01-28 16:28 - 2015-01-28 16:28 - 00079064 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\rrcckcqq.sys
2015-01-28 15:04 - 2015-01-28 15:04 - 03007700 _____ () C:\Users\Toshiba\Downloads\revouninstaller.zip
2015-01-28 13:56 - 2015-01-28 14:26 - 00000000 ____D () C:\Users\Toshiba\Documents\Bewerbungsunterlagen
2015-01-27 22:53 - 2015-01-27 22:53 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Peter Morphose
2015-01-27 22:53 - 2015-01-27 22:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Peter Morphose
2015-01-27 22:53 - 2015-01-27 22:53 - 00000000 ____D () C:\Program Files (x86)\Peter Morphose
2015-01-27 22:51 - 2015-01-27 22:51 - 01825580 _____ () C:\Users\Toshiba\Downloads\pm_setup.exe
2015-01-27 20:04 - 2015-01-27 20:04 - 00244203 _____ () C:\Users\Toshiba\Documents\Notenspiegel_Uni.xps
2015-01-27 20:01 - 2015-01-27 20:01 - 00241380 _____ () C:\Users\Toshiba\Documents\Notenspiegel2.xps
2015-01-27 20:00 - 2015-01-27 20:00 - 00241403 _____ () C:\Users\Toshiba\Documents\Notenspiegel.xps
2015-01-15 09:54 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-15 09:54 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-15 09:54 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-15 09:54 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-15 09:54 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-15 09:54 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-15 09:54 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 12:23 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 12:23 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 12:23 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 12:23 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 12:23 - 2014-12-06 05:17 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\tlntsess.exe
2015-01-14 12:23 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 12:23 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-03 17:11 - 2015-01-03 17:11 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-28 17:09 - 2014-06-01 23:08 - 00033864 _____ () C:\Users\Toshiba\Downloads\FRST.txt
2015-01-28 17:08 - 2014-06-01 23:08 - 00000000 ____D () C:\FRST
2015-01-28 17:05 - 2014-06-01 23:07 - 02130432 _____ (Farbar) C:\Users\Toshiba\Downloads\FRST64.exe
2015-01-28 17:04 - 2012-10-19 09:24 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Spotify
2015-01-28 16:48 - 2014-11-29 22:43 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-28 16:45 - 2013-01-06 10:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-28 16:28 - 2014-09-14 22:58 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup
2015-01-28 16:28 - 2012-10-10 12:11 - 01241583 _____ () C:\Windows\WindowsUpdate.log
2015-01-28 16:28 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SchCache
2015-01-28 15:18 - 2014-09-15 15:50 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-28 15:16 - 2014-09-15 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-28 15:16 - 2014-09-15 15:50 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-28 15:16 - 2012-11-05 18:57 - 00001107 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-28 14:48 - 2012-11-30 22:27 - 00003954 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{823A0A0F-EDB5-4913-9C46-D78F7B773C2B}
2015-01-28 13:34 - 2012-10-14 20:36 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Skype
2015-01-28 13:34 - 2009-07-14 05:51 - 00179330 _____ () C:\Windows\setupact.log
2015-01-27 22:48 - 2014-11-29 22:43 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-27 10:05 - 2014-11-29 22:44 - 00002180 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-26 14:45 - 2013-01-06 10:01 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-26 14:45 - 2013-01-06 10:01 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-26 14:45 - 2013-01-06 10:01 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-26 13:48 - 2009-07-14 05:45 - 00019024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-26 13:48 - 2009-07-14 05:45 - 00019024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-26 13:39 - 2013-08-25 18:47 - 00000000 ___RD () C:\Users\Toshiba\Dropbox
2015-01-26 13:39 - 2013-08-25 18:44 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Dropbox
2015-01-26 13:38 - 2012-10-19 09:24 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\Spotify
2015-01-26 13:35 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-21 16:57 - 2012-12-26 00:02 - 387014415 _____ () C:\Windows\MEMORY.DMP
2015-01-21 16:57 - 2012-12-26 00:02 - 00000000 ____D () C:\Windows\Minidump
2015-01-16 03:15 - 2012-11-05 19:21 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\SoftGrid Client
2015-01-15 14:22 - 2012-12-07 20:12 - 00000000 ____D () C:\Users\Toshiba\Documents\Citavi 3
2015-01-15 08:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2015-01-15 03:14 - 2013-08-19 20:20 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-15 03:02 - 2012-11-22 18:31 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-12 11:35 - 2009-07-14 18:58 - 00745588 _____ () C:\Windows\system32\perfh007.dat
2015-01-12 11:35 - 2009-07-14 18:58 - 00163170 _____ () C:\Windows\system32\perfc007.dat
2015-01-12 11:35 - 2009-07-14 06:13 - 01730150 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-06 04:36 - 2012-10-14 15:41 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
==================== Files in the root of some directories =======
2012-10-30 20:09 - 2012-11-05 10:04 - 0000048 _____ () C:\Users\Toshiba\AppData\Roaming\AcroIEHelpe.txt
2012-10-30 20:08 - 2012-11-06 00:16 - 0000051 _____ () C:\Users\Toshiba\AppData\Roaming\blckdom.res
2012-11-03 16:10 - 2012-11-03 16:10 - 0000000 _____ () C:\Users\Toshiba\AppData\Roaming\jcwa3way.default.tmp
2012-10-30 20:08 - 2012-10-30 20:08 - 0000264 _____ () C:\Users\Toshiba\AppData\Roaming\srvblck5.tmp
2012-11-04 23:00 - 2012-11-04 23:00 - 0000011 _____ () C:\Users\Toshiba\AppData\Roaming\urhtps.dat
Some content of TEMP:
====================
C:\Users\Toshiba\AppData\Local\Temp\avgnt.exe
C:\Users\Toshiba\AppData\Local\Temp\card_setup.exe
C:\Users\Toshiba\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5stam6.dll
C:\Users\Toshiba\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
C:\Users\Toshiba\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Toshiba\AppData\Local\Temp\setup.exe
C:\Users\Toshiba\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Toshiba\AppData\Local\Temp\SpotifyUpgrader.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-15 07:50
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- |