lobowolf | 31.12.2014 14:30 | [CODE] Results of screen317's Security Check version 0.99.93
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
AVG Internet Security 2013
AVG Internet Security Business Edition 2012
Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:`````````
TuneUp Utilities 2014
TuneUp Utilities 2014 (de-DE)
TuneUp Utilities 2014
Java 7 Update 71
Adobe Flash Player 15.0.0.246 Flash Player out of Date!
Adobe Reader XI
Mozilla Firefox (Firefox.)
Mozilla Thunderbird (24.1.0) ````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
AVG avgwdsvc.exe
Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-12-2014
Ran by melsy (administrator) on MELSY-HP on 31-12-2014 14:03:23
Running from C:\Users\melsy\Downloads
Loaded Profile: melsy (Available profiles: melsy & _supereasy_1cbackup_ & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 11\LiveTunerService.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\Ymsgr_tray.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(Farbar) C:\Users\melsy\Downloads\FRST64(1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [Cm106Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd
HKLM\...\Run: [SuperEasy 1-Click Backup] => "C:\Program Files\SuperEasy Software\1-Click Backup Free\bin\backupClient-sez1cb.exe" --hidden
HKLM\...\Run: [Ashampoo WinOptimizer Live-Tuner2] => C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 11\LiveTuner2.exe [3516784 2014-11-18] (Ashampoo Development GmbH & Co. KG)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVG_TRAY] => C:\Program Files (x86)\AVG\AVG2012\avgtray.exe [2598520 2012-11-19] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411952 2014-11-04] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2072928 2014-10-31] (Wondershare)
HKLM-x32\...\Run: [SPM15 Chrome Autofill Relay] => C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe [480120 2014-06-25] (Steganos Software GmbH)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-10-21] (Hewlett-Packard)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Run: [Facebook Update] => C:\Users\melsy\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-10-31] (Facebook Inc.)
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Run: [EssentialPIM] => C:\Program Files (x86)\EssentialPIM\EssentialPIM.exe [17719664 2014-12-01] (Astonsoft)
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\wo11.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
BootExecute: autocheck autochk * DfSDKBt
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
URLSearchHook: HKLM-x32 - (No Name) - {422f7661-9403-4da4-b4ef-cc3e268817b5} - No File
URLSearchHook: HKU\S-1-5-21-3195104690-1283173883-910289243-1001 - (No Name) - {422f7661-9403-4da4-b4ef-cc3e268817b5} - No File
SearchScopes: HKLM -> {8262B94D-0FB8-44AE-AA96-7114154C01C3} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3195104690-1283173883-910289243-1001 -> {8262B94D-0FB8-44AE-AA96-7114154C01C3} URL =
SearchScopes: HKU\S-1-5-21-3195104690-1283173883-910289243-1001 -> ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH)
Toolbar: HKLM-x32 - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKLM-x32 - No Name - {422f7661-9403-4da4-b4ef-cc3e268817b5} - No File
Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar.dll (Steganos Software GmbH)
Toolbar: HKU\S-1-5-21-3195104690-1283173883-910289243-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-3195104690-1283173883-910289243-1001 -> No Name - {422F7661-9403-4DA4-B4EF-CC3E268817B5} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
FireFox:
========
FF ProfilePath: C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693
FF Homepage: https://www.google.at/?gws_rd=cr&ei=3OKMUuu2NOO54AT-pYGQCg
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @Skype Technologies S.A..com/Skype Web Plugin -> C:\Program Files (x86)\SkypeWebPlugin\3.1.15602.22612\npSkypeWebPlugin64.dll (Skype)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @Skype Technologies S.A..com/Skype Web Plugin -> C:\Program Files (x86)\SkypeWebPlugin\3.1.15602.22612\npSkypeWebPlugin.dll (Skype)
FF Plugin-x32: @soft-xpansion/npsxpdf -> C:\Program Files (x86)\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3195104690-1283173883-910289243-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\melsy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKU\S-1-5-21-3195104690-1283173883-910289243-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\melsy\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKU\S-1-5-21-3195104690-1283173883-910289243-1001: @talk.google.com/O1DPlugin -> C:\Users\melsy\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKU\S-1-5-21-3195104690-1283173883-910289243-1001: @tools.google.com/Google Update;version=3 -> C:\Users\melsy\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-3195104690-1283173883-910289243-1001: @tools.google.com/Google Update;version=9 -> C:\Users\melsy\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\melsy\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\melsy\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\searchplugins\google-maps.xml
FF Extension: FDislike - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\fbdislike@doweb.fr.xpi [2014-04-14]
FF Extension: Ghostery - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\firefox@ghostery.com.xpi [2014-04-13]
FF Extension: ZenMate Security & Privacy VPN - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\firefox@zenmate.com.xpi [2014-10-05]
FF Extension: ProxTube - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\ich@maltegoetz.de.xpi [2014-09-11]
FF Extension: convert2mp3.net YouTube2MP3 Converter - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\info@convert2mp3.net.xpi [2014-04-13]
FF Extension: Facebook Select All - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\jid0-n2ISP7BOUOHLqFZBUsiANkm14Ck@jetpack.xpi [2014-04-13]
FF Extension: RequestPolicy - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\requestpolicy@requestpolicy.com.xpi [2014-11-21]
FF Extension: NoScript - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-13]
FF Extension: Adblock Plus - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-13]
FF Extension: OkayFreedom - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\{DB981CCA-088E-4731-A4A2-2FE218703C0E}.xpi [2014-12-24]
FF Extension: Google Privacy - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\{ea61041c-1e22-4400-99a0-aea461e69d04}.xpi [2014-12-08]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-05-20]
FF HKLM-x32\...\Firefox\Extensions: [{1E73965B-8B48-48be-9C8D-68B920ABC1C4}] - C:\Program Files (x86)\AVG\AVG2012\Firefox4
FF Extension: No Name - C:\Program Files (x86)\AVG\AVG2012\Firefox4 [2013-06-28]
FF HKLM-x32\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb [2013-09-02]
FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3
FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 [2014-12-05]
FF HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR Profile: C:\Users\melsy\AppData\Local\Google\Chrome\User Data\Default
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-10-22] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [365568 2011-07-05] (Advanced Micro Devices, Inc.) [File not signed]
R2 avgfws; C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [1432592 2014-11-04] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4942384 2014-10-17] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-11-20] (AVG Technologies CZ, s.r.o.)
S3 CGVPNCliSrvc; C:\Program Files\CyberGhost VPN\CGVPNCliService.exe [2438696 2012-04-26] (mobile concepts GmbH)
S4 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed]
S4 HPAuto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [682040 2011-02-16] (Hewlett-Packard)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89352 2014-09-15] (Hewlett-Packard Company)
S4 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1817088 2010-12-28] (Realsil Microelectronics Inc.) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [87040 2012-03-23] () [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S4 Radio.fx; C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe [3665752 2012-01-26] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S4 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-09-02] (soft Xpansion)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-21] (TuneUp Software)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [111208 2014-12-22] (RaMMicHaeL)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
R2 WO_LiveService2; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 11\LiveTunerService.exe [223600 2014-11-18] ()
S2 supereasy_1cbackup; "c:\Program Files\SuperEasy Software\1-Click Backup Free\bin\backupService-sez1cb.exe" "--controlFolder=c:\ProgramData\SuperEasy 1-Click Backup\control" "--id=supereasy_1cbackup" daemon
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [50296 2012-09-04] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [209720 2014-11-04] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-10-23] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2014-10-17] (AVG Technologies CZ, s.r.o.)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [133160 2011-06-16] (Broadcom Corporation.)
R3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-05-21] (Broadcom Corporation.)
S3 L6UX1; C:\Windows\System32\Drivers\L6UX164.sys [772864 2013-07-11] (Line 6)
R3 leawo_vad; C:\Windows\System32\drivers\leawo_vad.sys [33048 2013-05-21] (Shenzhen Moyea Software)
R2 LiveTuner2PM; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 11\LiveTuner64.sys [14320 2014-03-20] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-31] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
S3 REN2CAP_DRIVER; C:\Windows\System32\drivers\ren2cap.sys [46728 2011-11-07] ()
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-04-28] (Audials AG)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-03] (Anchorfree Inc.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-11-12] (TuneUp Software)
S3 USBMULCD; C:\Windows\System32\drivers\CM10664.sys [1451008 2008-10-13] (C-Media Electronics Inc)
S3 YMIDUSBW; C:\Windows\System32\drivers\ymidusbx64.sys [51016 2011-11-01] (Yamaha Corporation)
S3 CpqDfw; system32\drivers\CpqDfw.sys [X]
U3 DfSdkS; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-31 13:19 - 2014-12-31 13:19 - 00852505 _____ () C:\Users\melsy\Downloads\SecurityCheck.exe
2014-12-30 20:26 - 2014-12-30 20:26 - 02347384 _____ (ESET) C:\Users\melsy\Downloads\esetsmartinstaller_deu(1).exe
2014-12-29 23:44 - 2014-12-31 13:18 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-12-29 23:43 - 2014-12-29 23:43 - 02347384 _____ (ESET) C:\Users\melsy\Downloads\esetsmartinstaller_deu.exe
2014-12-29 15:43 - 2014-12-29 15:43 - 00028392 _____ () C:\Users\melsy\Documents\Synth Kick.txt
2014-12-29 14:14 - 2014-12-29 14:14 - 00000971 _____ () C:\Users\melsy\Desktop\HammerHead 1.0.lnk
2014-12-29 14:14 - 2014-12-29 14:14 - 00000971 _____ () C:\Users\_supereasy_1cbackup_\Desktop\HammerHead 1.0.lnk
2014-12-29 14:14 - 2014-12-29 14:14 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HammerHead Rhythm Station
2014-12-29 14:12 - 2014-12-29 14:19 - 01508117 _____ () C:\Users\melsy\Downloads\hh10_install(2).exe
2014-12-29 13:34 - 2014-12-29 13:34 - 00000045 _____ () C:\Users\melsy\Downloads\lay_back.ram
2014-12-29 13:34 - 2014-12-29 13:34 - 00000043 _____ () C:\Users\melsy\Downloads\sharky.ram
2014-12-29 13:34 - 2014-12-29 13:34 - 00000043 _____ () C:\Users\melsy\Downloads\mellow.ram
2014-12-29 13:34 - 2014-12-29 13:34 - 00000042 _____ () C:\Users\melsy\Downloads\stomp.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000045 _____ () C:\Users\melsy\Downloads\jumpdude.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000045 _____ () C:\Users\melsy\Downloads\hardcore.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000045 _____ () C:\Users\melsy\Downloads\chemical.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000044 _____ () C:\Users\melsy\Downloads\coolhop.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000043 _____ () C:\Users\melsy\Downloads\jungle.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000043 _____ () C:\Users\melsy\Downloads\hiphop.ram
2014-12-29 13:32 - 2014-12-29 13:32 - 00000041 _____ () C:\Users\melsy\Downloads\acid.ram
2014-12-29 13:22 - 2014-12-30 16:59 - 00000000 ____D () C:\Program Files (x86)\HammerHead
2014-12-29 13:22 - 2014-12-29 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HammerHead Rhythm Station
2014-12-29 13:21 - 2014-12-29 13:21 - 01508117 _____ () C:\Users\melsy\Downloads\hh10_install.exe
2014-12-29 12:21 - 2014-12-29 12:21 - 02123264 _____ (Farbar) C:\Users\melsy\Downloads\FRST64(1).exe
2014-12-29 11:59 - 2014-12-29 11:59 - 01707939 _____ (Thisisu) C:\Users\melsy\Downloads\JRT(1).exe
2014-12-29 11:55 - 2014-12-29 11:55 - 00818637 _____ (Thisisu) C:\Users\melsy\Downloads\JRT.exe
2014-12-29 11:27 - 2014-12-29 11:28 - 02173952 _____ () C:\Users\melsy\Downloads\AdwCleaner_4.106(1).exe
2014-12-29 11:16 - 2014-12-29 11:16 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-12-29 11:15 - 2014-12-29 11:15 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\melsy\Downloads\revosetup95.exe
2014-12-29 10:00 - 2014-12-29 10:00 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2014-12-27 09:35 - 2014-12-27 09:35 - 02173952 _____ () C:\Users\melsy\Downloads\AdwCleaner_4.106.exe
2014-12-26 18:50 - 2014-12-26 18:52 - 00071035 _____ () C:\Users\melsy\Downloads\Addition.txt
2014-12-26 18:48 - 2014-12-31 14:03 - 00028412 _____ () C:\Users\melsy\Downloads\FRST.txt
2014-12-26 18:47 - 2014-12-31 14:03 - 00000000 ____D () C:\FRST
2014-12-26 18:47 - 2014-12-26 18:47 - 02122752 _____ (Farbar) C:\Users\melsy\Downloads\FRST64.exe
2014-12-26 15:25 - 2014-12-26 15:25 - 00001455 _____ () C:\trojaner.txt
2014-12-24 15:10 - 2014-12-29 11:50 - 00000600 _____ () C:\Windows\PFRO.log
2014-12-24 15:02 - 2014-12-24 15:02 - 16520304 _____ (Steganos Software GmbH) C:\Users\melsy\Downloads\okayfreedomwr.exe
2014-12-24 14:01 - 2014-12-24 14:01 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Steganos Updates
2014-12-24 13:59 - 2014-12-24 14:11 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Steganos VPN
2014-12-24 13:56 - 2014-12-24 13:56 - 01174352 _____ () C:\Users\melsy\Downloads\Vollversion OkayFreedom Premium Flat - CHIP-Installer.exe
2014-12-22 02:54 - 2014-12-22 02:54 - 05164040 _____ (DigitalVolcano Software Ltd) C:\Users\melsy\Downloads\DuplicateCleaner_setup(1).exe
2014-12-22 01:01 - 2014-12-29 11:20 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\DigitalVolcano
2014-12-22 00:59 - 2014-12-22 00:59 - 05164040 _____ (DigitalVolcano Software Ltd) C:\Users\melsy\Downloads\DuplicateCleaner_setup.exe
2014-12-21 02:14 - 2014-12-21 02:14 - 01174352 _____ () C:\Users\melsy\Downloads\Vollversion Magix Music Maker 2013 - CHIP-Installer.exe
2014-12-20 18:36 - 2014-12-20 18:36 - 00001152 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Rip CD Ripper Software.lnk
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-12-20 18:32 - 2014-12-31 05:41 - 00001568 _____ () C:\Windows\setupact.log
2014-12-20 18:32 - 2014-12-20 18:32 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-18 12:27 - 2014-12-31 05:45 - 00374048 _____ () C:\Windows\WindowsUpdate.log
2014-12-17 00:38 - 2014-12-17 00:38 - 00000000 ____D () C:\Users\melsy\Documents\DesignCAD 3D MAX 22
2014-12-17 00:37 - 2014-12-17 00:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DesignCAD Toolkit Maschinenbau & Konstruktion 22
2014-12-17 00:37 - 2014-12-17 00:37 - 00000000 ____D () C:\Program Files (x86)\DCToolkit
2014-12-17 00:36 - 2014-12-17 00:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DesignCAD 3D Max 22
2014-12-17 00:35 - 2014-12-17 00:35 - 00000000 ____D () C:\ProgramData\IMSIDesign
2014-12-17 00:35 - 2014-12-17 00:35 - 00000000 ____D () C:\Program Files (x86)\IMSIDesign
2014-12-17 00:15 - 2014-12-17 00:18 - 95590424 _____ () C:\Users\melsy\Downloads\DesignCAD-V22-3D-Triple-Toolkits-Complete-CHIP.exe
2014-12-16 14:47 - 2014-12-21 19:57 - 00168064 _____ () C:\Users\melsy\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-15 21:05 - 2014-12-15 21:05 - 00000000 ____D () C:\Users\melsy\Downloads\Office 2007
2014-12-15 19:04 - 2014-12-15 19:11 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Scribus
2014-12-15 18:59 - 2014-12-15 19:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scribus 1.4.4
2014-12-15 18:57 - 2014-12-15 19:03 - 00000000 ____D () C:\Program Files\Scribus 1.4.4
2014-12-15 17:02 - 2014-12-15 17:04 - 86069640 _____ (The Scribus Team) C:\Users\melsy\Downloads\scribus-1.4.4-windows-x64.exe
2014-12-15 15:06 - 2014-12-15 15:06 - 00001148 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-12-15 15:06 - 2014-12-15 15:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audioverwandte Programme
2014-12-15 11:46 - 2014-12-15 11:46 - 01177424 _____ () C:\Users\melsy\Downloads\TuxGuitar - CHIP-Installer.exe
2014-12-14 23:48 - 2014-12-14 23:48 - 00000000 _____ () C:\Windows\SysWOW64\shoFA1F.tmp
2014-12-14 23:31 - 2014-12-14 23:31 - 00000000 __SHD () C:\WISE_DISKSCRUBTEMP
2014-12-14 16:30 - 2014-12-14 16:32 - 43145168 _____ (Ashampoo GmbH & Co. KG ) C:\Users\melsy\Downloads\ashampoo_winoptimizer_11_11.00.50_18137.exe
2014-12-13 09:28 - 2014-12-15 11:35 - 00000000 ____D () C:\Users\melsy\HDR Projects
2014-12-13 09:26 - 2014-12-13 09:26 - 00001045 _____ () C:\Users\Public\Desktop\HDR Projects platin (64-Bit).lnk
2014-12-13 09:26 - 2014-12-13 09:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Franzis
2014-12-13 09:26 - 2014-12-13 09:26 - 00000000 ____D () C:\Program Files\Franzis
2014-12-13 09:09 - 2014-12-13 09:09 - 00000000 ____D () C:\Users\melsy\Documents\HDR-projects-platin-win-mac-CHIP
2014-12-12 13:24 - 2014-12-12 13:24 - 00000000 _____ () C:\Windows\SysWOW64\sho287C.tmp
2014-12-11 19:52 - 2014-12-11 19:52 - 00000000 ____D () C:\Users\melsy\Documents\FlashIntegro
2014-12-11 19:52 - 2014-12-11 19:52 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\VideoEditor
2014-12-11 19:52 - 2014-12-11 19:52 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\FlashIntegro
2014-12-11 19:51 - 2014-12-15 11:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlashIntegro
2014-12-11 19:51 - 2014-12-15 11:35 - 00000000 ____D () C:\Program Files (x86)\FlashIntegro
2014-12-11 19:51 - 2014-12-09 13:21 - 00081792 _____ (Flash-Integro LLC) C:\Windows\SysWOW64\mslvddsfilter2.ax
2014-12-11 19:51 - 2011-12-07 19:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\Lagarith.dll
2014-12-11 19:51 - 2004-12-10 10:03 - 00438272 _____ (On2.com) C:\Windows\SysWOW64\vp6vfw.dll
2014-12-11 19:51 - 2004-09-06 16:06 - 00053248 _____ () C:\Windows\SysWOW64\xvid.ax
2014-12-11 19:51 - 2004-07-03 21:08 - 00139264 _____ () C:\Windows\SysWOW64\xvidvfw.dll
2014-12-11 19:51 - 2004-07-03 20:59 - 00524288 _____ () C:\Windows\SysWOW64\xvidcore.dll
2014-12-11 19:51 - 2004-02-04 21:11 - 00081920 _____ (fccHandler) C:\Windows\SysWOW64\AC3ACM.acm
2014-12-11 19:51 - 2003-05-22 12:26 - 00638976 _____ (DivXNetworks, Inc.) C:\Windows\SysWOW64\divx.dll
2014-12-11 19:51 - 2003-05-22 12:26 - 00221215 _____ (DivXNetworks, Inc.) C:\Windows\SysWOW64\divxdec.ax
2014-12-11 19:51 - 2003-05-21 23:50 - 00261632 _____ (MainConcept) C:\Windows\SysWOW64\mcdvd_32.dll
2014-12-11 19:51 - 2003-05-21 23:50 - 00156910 _____ () C:\Windows\WMSysPr8.prx
2014-12-11 19:51 - 2003-05-21 23:50 - 00082944 _____ (Voxware, Inc.) C:\Windows\SysWOW64\vct3216.acm
2014-12-11 19:51 - 2003-05-21 23:50 - 00038912 _____ (NCT Company) C:\Windows\SysWOW64\alf2cd.acm
2014-12-11 19:51 - 2003-03-25 05:49 - 00098304 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\SysWOW64\L3CODECX.AX
2014-12-11 19:51 - 2002-08-20 00:41 - 00413760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg4c32.dll
2014-12-11 19:51 - 2000-03-14 20:55 - 00013239 _____ (SHARP Corporation) C:\Windows\SysWOW64\Scg726.acm
2014-12-11 19:47 - 2014-12-11 19:47 - 01177424 _____ () C:\Users\melsy\Downloads\VSDC Free Video Editor - CHIP-Installer.exe
2014-12-10 19:29 - 2014-12-10 19:29 - 17103000 _____ (Electronic Arts, Inc.) C:\Users\melsy\Downloads\OriginThinSetup.exe
2014-12-10 18:55 - 2014-12-10 19:40 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Origin
2014-12-10 18:53 - 2014-12-10 19:54 - 00000000 ____D () C:\ProgramData\Origin
2014-12-10 14:14 - 2014-12-16 08:59 - 00000412 _____ () C:\Windows\Tasks\Wise Care 365 PC Checkup Task.job
2014-12-10 14:14 - 2014-12-10 14:14 - 00002834 _____ () C:\Windows\System32\Tasks\Wise Care 365 PC Checkup Task
2014-12-10 09:50 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-10 09:50 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-10 09:21 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-10 09:21 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-10 09:21 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-10 09:21 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-10 09:21 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-10 09:21 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-10 09:21 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-10 09:21 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-10 09:21 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-10 09:21 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-10 09:21 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-10 09:21 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-10 09:21 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-10 09:21 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-10 09:21 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-10 09:12 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-10 09:12 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-09 13:07 - 2014-12-22 13:17 - 00000000 ____D () C:\Users\melsy\Documents\camera musik
2014-12-09 12:29 - 2014-12-09 12:30 - 11669724 _____ () C:\Users\melsy\Downloads\Camera Rare Grooves Aluminium Edition - 02 Donny Hathaway - The Ghetto.mp4.part
2014-12-09 11:06 - 2014-12-09 11:06 - 00003070 _____ () C:\Windows\System32\Tasks\Wise Turbo Checker
2014-12-09 11:06 - 2014-12-09 11:06 - 00002848 _____ () C:\Windows\System32\Tasks\Wise Care 365
2014-12-09 11:06 - 2014-12-09 11:06 - 00000422 _____ () C:\Windows\Tasks\Wise Care 365.job
2014-12-09 11:06 - 2014-12-09 11:06 - 00000402 _____ () C:\Windows\Tasks\Wise Turbo Checker.job
2014-12-09 10:33 - 2014-12-20 02:15 - 00000000 ____D () C:\Program Files (x86)\Wise
2014-12-09 10:31 - 2014-12-09 10:31 - 01174352 _____ () C:\Users\melsy\Downloads\Wise Care 365 - CHIP-Installer.exe
2014-12-07 14:45 - 2014-12-07 14:46 - 11553744 _____ () C:\Users\melsy\Downloads\EssentialPIM6.exe
2014-12-05 17:37 - 2014-12-05 17:37 - 00001170 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoStage Diashow-Ersteller.lnk
2014-12-05 17:37 - 2014-12-05 17:37 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Produktpalette
2014-12-05 17:37 - 2014-12-05 17:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Videoverwandte Programme
2014-12-05 16:44 - 2014-12-05 16:44 - 00001110 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoPad Image Editor.lnk
2014-12-05 16:44 - 2014-12-05 16:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-12-05 16:43 - 2014-12-05 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Produktpalette
2014-12-05 16:43 - 2014-12-05 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grafikverwandte Programme
2014-12-05 16:42 - 2014-12-05 16:42 - 00001160 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pixillion Imagedatei-Konverter.lnk
2014-12-05 16:29 - 2014-12-05 16:30 - 00505376 _____ (NCH Software) C:\Users\melsy\Downloads\pixpsetup.exe
2014-12-05 13:02 - 2014-12-24 14:32 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Steganos
2014-12-05 13:02 - 2014-12-05 13:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steganos Passwort-Manager 15
2014-12-05 13:02 - 2014-12-05 13:03 - 00000000 ____D () C:\Program Files (x86)\Steganos Password Manager 15
2014-12-05 13:00 - 2014-12-05 13:00 - 01174352 _____ () C:\Users\melsy\Downloads\Vollversion Steganos Passwort Manager 15 - CHIP-Installer.exe
2014-12-04 18:05 - 2014-12-04 18:05 - 00001964 _____ () C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2014-12-03 19:41 - 2014-12-03 19:41 - 07270351 _____ () C:\Users\melsy\Downloads\meine 68 jährige (2).mp4
2014-12-02 16:16 - 2014-12-08 03:47 - 00000000 ____D () C:\Users\melsy\AppData\Local\SuperEasy 1-Click Backup
2014-12-02 16:16 - 2014-12-03 16:04 - 00000000 ___HD () C:\ProgramData\sysnfxo
2014-12-02 16:15 - 2014-12-29 11:51 - 00000000 ____D () C:\Users\_supereasy_1cbackup_
2014-12-02 16:15 - 2014-12-02 16:15 - 00000020 ___SH () C:\Users\_supereasy_1cbackup_\ntuser.ini
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Vorlagen
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Startmenü
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Netzwerkumgebung
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Lokale Einstellungen
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Eigene Dateien
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Druckumgebung
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Documents\Eigene Musik
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Documents\Eigene Bilder
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\AppData\Local\Verlauf
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\AppData\Local\Anwendungsdaten
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Anwendungsdaten
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 ____D () C:\ProgramData\SuperEasy 1-Click Backup
2014-12-02 16:15 - 2013-08-14 10:34 - 00000000 ____D () C:\Users\_supereasy_1cbackup_\AppData\Local\Microsoft Help
2014-12-02 16:15 - 2013-07-31 08:12 - 00000000 ____D () C:\Users\_supereasy_1cbackup_\AppData\Roaming\TuneUp Software
2014-12-02 16:15 - 2013-07-26 03:08 - 00000000 ____D () C:\Users\_supereasy_1cbackup_\AppData\Local\ScreenCapture
2014-12-02 16:15 - 2012-12-03 06:32 - 00000000 ____D () C:\Users\_supereasy_1cbackup_\AppData\Roaming\Macromedia
2014-12-02 16:15 - 2012-08-12 01:32 - 00002134 _____ () C:\Users\_supereasy_1cbackup_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
2014-12-02 16:15 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\_supereasy_1cbackup_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-02 16:15 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\_supereasy_1cbackup_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-12-02 16:13 - 2014-12-02 16:13 - 28074616 _____ (SuperEasy Software GmbH & Co. KG ) C:\Users\melsy\Downloads\supereasy_1-click_backup_free_1.13.0_8279.exe
2014-12-02 14:03 - 2014-12-02 14:03 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\EAC
2014-12-02 14:03 - 2014-12-02 14:03 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\AccurateRip
2014-12-02 14:02 - 2014-12-02 14:02 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Cliqz
2014-12-02 14:02 - 2014-12-02 14:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exact Audio Copy
2014-12-02 14:02 - 2014-12-02 14:02 - 00000000 ____D () C:\Program Files (x86)\Exact Audio Copy
2014-12-02 13:57 - 2014-12-02 13:57 - 01174352 _____ () C:\Users\melsy\Downloads\Exact Audio Copy - CHIP-Installer.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-31 14:02 - 2012-05-18 12:08 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Skype
2014-12-31 13:55 - 2014-10-15 14:50 - 00003094 _____ () C:\Windows\System32\Tasks\{B2E8F773-5F5C-4836-8957-FEE3042EABFC}
2014-12-31 13:55 - 2014-09-21 08:03 - 00003088 _____ () C:\Windows\System32\Tasks\{C0C124F4-41F2-47D4-860C-4FCF583875C1}
2014-12-31 13:55 - 2014-09-21 08:03 - 00003088 _____ () C:\Windows\System32\Tasks\{5C4F42ED-5832-48B4-BCB9-D77730EC38C1}
2014-12-31 13:55 - 2014-08-28 18:24 - 00003076 _____ () C:\Windows\System32\Tasks\{8795FFFA-4029-4A70-B1CF-0C3C57CDEE7C}
2014-12-31 13:55 - 2013-10-09 17:59 - 00003102 _____ () C:\Windows\System32\Tasks\{AD7AC0AF-B335-4FB0-ABC0-6583AD2EE938}
2014-12-31 13:55 - 2013-05-03 19:39 - 00003086 _____ () C:\Windows\System32\Tasks\{2A792A14-06ED-4493-81D7-2A64E97EA462}
2014-12-31 13:55 - 2012-11-20 13:26 - 00002966 _____ () C:\Windows\System32\Tasks\{69CD82CA-4612-410F-907D-CE1E674B652E}
2014-12-31 13:55 - 2012-11-20 13:26 - 00002966 _____ () C:\Windows\System32\Tasks\{670A25EF-5F02-41BB-BB0D-827A205D5869}
2014-12-31 13:54 - 2014-09-10 08:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-31 13:50 - 2013-10-31 22:45 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3195104690-1283173883-910289243-1001UA.job
2014-12-31 13:41 - 2014-05-20 14:57 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-31 13:23 - 2011-08-09 21:16 - 00774266 _____ () C:\Windows\system32\perfh007.dat
2014-12-31 13:23 - 2011-08-09 21:16 - 00175794 _____ () C:\Windows\system32\perfc007.dat
2014-12-31 13:23 - 2009-07-14 06:13 - 01808064 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-31 13:22 - 2013-01-23 23:10 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3195104690-1283173883-910289243-1001UA.job
2014-12-31 13:11 - 2012-08-13 22:06 - 00000386 _____ () C:\Windows\Tasks\WpsUpdateTask_melsy.job
2014-12-31 12:13 - 2013-05-07 17:00 - 00000000 ____D () C:\ProgramData\MFAData
2014-12-31 05:49 - 2009-07-14 05:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-31 05:49 - 2009-07-14 05:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-31 05:42 - 2012-07-27 20:04 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-31 05:41 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-31 00:22 - 2013-01-23 23:10 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3195104690-1283173883-910289243-1001Core.job
2014-12-30 22:50 - 2013-10-31 22:45 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3195104690-1283173883-910289243-1001Core.job
2014-12-30 19:03 - 2014-04-22 13:06 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\vlc
2014-12-30 09:45 - 2014-10-15 16:42 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-12-29 12:20 - 2012-05-21 13:38 - 00000000 ___RD () C:\Users\melsy\Desktop\Sicherheit
2014-12-29 11:48 - 2013-09-19 13:30 - 00000000 ____D () C:\AdwCleaner
2014-12-29 11:34 - 2012-05-20 16:38 - 00000000 ____D () C:\Users\melsy\AppData\Local\CrashDumps
2014-12-29 02:58 - 2012-07-02 01:36 - 00000410 _____ () C:\Windows\Tasks\EasyShare Registration Task.job
2014-12-29 01:46 - 2014-07-19 10:21 - 00003186 _____ () C:\Windows\System32\Tasks\HPCeeScheduleFormelsy
2014-12-29 01:46 - 2014-07-19 10:21 - 00000332 _____ () C:\Windows\Tasks\HPCeeScheduleFormelsy.job
2014-12-27 23:22 - 2012-05-21 23:39 - 00000000 ___RD () C:\Users\melsy\Desktop\TONSTUDIO
2014-12-27 18:36 - 2012-09-23 02:50 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-12-26 15:24 - 2014-05-20 14:57 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-25 20:44 - 2014-09-21 08:17 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-25 20:44 - 2012-05-18 12:07 - 00000000 ____D () C:\ProgramData\Skype
2014-12-24 15:22 - 2014-10-15 17:01 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2014-12-22 13:37 - 2013-03-26 14:54 - 00000000 ____D () C:\Users\melsy\Documents\RAF
2014-12-22 13:37 - 2013-01-23 02:22 - 00000000 ____D () C:\Users\melsy\Documents\Cybershapes
2014-12-22 13:26 - 2012-09-23 01:41 - 00000000 ____D () C:\Users\melsy\Documents\soz-österr
2014-12-22 13:26 - 2012-05-19 10:40 - 00000000 ____D () C:\Users\melsy\Documents\Meine empfangenen Dateien
2014-12-22 08:20 - 2009-07-14 05:45 - 00539840 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-21 19:56 - 2012-05-20 12:12 - 00000000 ____D () C:\Users\melsy\Documents\Gitarre
2014-12-21 04:24 - 2013-03-16 19:48 - 00000000 ____D () C:\Users\Public\Documents\MAGIX
2014-12-21 02:59 - 2012-07-01 18:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-12-21 02:57 - 2012-07-01 18:18 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-12-21 02:52 - 2013-03-16 19:56 - 00000000 ___RD () C:\Users\melsy\Documents\MAGIX
2014-12-21 02:52 - 2012-07-01 18:18 - 00000000 ____D () C:\ProgramData\MAGIX
2014-12-20 18:34 - 2012-05-18 15:45 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Audacity
2014-12-20 02:31 - 2013-10-11 13:45 - 00000000 ___RD () C:\Users\melsy\Desktop\radios
2014-12-20 02:31 - 2012-09-08 11:59 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\XnView
2014-12-20 01:57 - 2012-11-03 14:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCFinder
2014-12-20 01:57 - 2012-11-03 14:18 - 00000000 ____D () C:\Program Files (x86)\CCFinder
2014-12-18 12:24 - 2012-05-21 03:47 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-12-18 12:24 - 2012-05-21 03:47 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-12-18 12:22 - 2011-12-10 05:20 - 00000000 ____D () C:\ProgramData\Temp
2014-12-17 00:39 - 2012-07-18 02:06 - 00000000 ___RD () C:\Users\melsy\Desktop\Foto Video
2014-12-16 19:19 - 2012-07-24 21:06 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2014-12-15 19:01 - 2013-09-02 13:26 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-15 18:40 - 2014-10-23 10:29 - 00000000 ____D () C:\Users\melsy\Documents\KPÖ
2014-12-15 14:25 - 2012-05-21 03:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-12-15 11:49 - 2013-02-03 15:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuxGuitar
2014-12-15 11:49 - 2013-02-03 15:57 - 00000000 ____D () C:\Program Files (x86)\TuxGuitar
2014-12-15 11:35 - 2013-05-18 21:52 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\EssentialPIM
2014-12-15 11:35 - 2013-02-03 15:59 - 00000000 ____D () C:\Users\melsy\.tuxguitar-1.2
2014-12-15 11:35 - 2012-12-14 19:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2014-12-15 11:35 - 2012-12-05 11:56 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-12-15 11:35 - 2012-05-20 17:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-15 11:35 - 2012-05-19 13:23 - 00000000 ____D () C:\Program Files (x86)\ScanIT-Client
2014-12-15 11:35 - 2012-05-18 11:43 - 00000000 ____D () C:\Users\melsy
2014-12-15 11:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-12-15 10:43 - 2012-05-20 12:52 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\SoftGrid Client
2014-12-15 10:02 - 2013-09-29 09:43 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-14 23:43 - 2013-01-03 14:29 - 00000000 ____D () C:\Users\melsy\AppData\Local\Downloaded Installations
2014-12-14 16:36 - 2012-05-21 13:33 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-12-13 13:09 - 2014-09-09 13:12 - 00000000 ____D () C:\Users\melsy\Documents\demos
2014-12-13 12:35 - 2012-09-21 20:10 - 00038311 _____ () C:\Users\melsy\Documents\Passwörter.xlsx
2014-12-10 19:50 - 2012-06-02 18:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-10 17:54 - 2014-09-10 08:01 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-12-10 17:54 - 2014-07-04 14:07 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-12-10 17:54 - 2014-07-04 14:07 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-10 10:52 - 2013-02-25 20:12 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\{90140011-0066-0407-0000-0000000FF1CE}
2014-12-10 10:52 - 2013-02-25 20:11 - 00000000 ____D () C:\ProgramData\Virtualized Applications
2014-12-10 10:52 - 2012-05-20 12:52 - 00000000 ____D () C:\Users\melsy\AppData\Local\SoftGrid Client
2014-12-10 10:39 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-12-10 10:31 - 2013-05-20 18:34 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-10 10:24 - 2013-07-11 11:55 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-10 09:53 - 2012-05-21 03:56 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-09 14:02 - 2013-05-29 17:59 - 00000000 ____D () C:\Users\melsy\Documents\Essential Kalender
2014-12-09 13:48 - 2013-03-05 13:41 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\TS3Client
2014-12-09 10:51 - 2013-11-11 15:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-12-09 10:35 - 2007-01-02 02:25 - 00000000 ____D () C:\Windows\Panther
2014-12-07 14:47 - 2013-05-25 09:47 - 00001023 _____ () C:\Users\Public\Desktop\EssentialPIM.lnk
2014-12-03 12:40 - 2014-08-21 22:58 - 00000000 ____D () C:\Users\melsy\Documents\Norma A2
Some content of TEMP:
====================
C:\Users\melsy\AppData\Local\Temp\abelssoft.setup.exe
C:\Users\melsy\AppData\Local\Temp\Quarantine.exe
C:\Users\melsy\AppData\Local\Temp\ripsetup.exe
C:\Users\melsy\AppData\Local\Temp\SkypeSetup.exe
C:\Users\melsy\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-15 04:32
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
[CODE] Results of screen317's Security Check version 0.99.93
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
AVG Internet Security 2013
AVG Internet Security Business Edition 2012
Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:`````````
TuneUp Utilities 2014
TuneUp Utilities 2014 (de-DE)
TuneUp Utilities 2014
Java 7 Update 71
Adobe Flash Player 15.0.0.246 Flash Player out of Date!
Adobe Reader XI
Mozilla Firefox (Firefox.)
Mozilla Thunderbird (24.1.0) ````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
AVG avgwdsvc.exe
Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-12-2014
Ran by melsy (administrator) on MELSY-HP on 31-12-2014 14:03:23
Running from C:\Users\melsy\Downloads
Loaded Profile: melsy (Available profiles: melsy & _supereasy_1cbackup_ & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 11\LiveTunerService.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\Ymsgr_tray.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(Farbar) C:\Users\melsy\Downloads\FRST64(1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [Cm106Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd
HKLM\...\Run: [SuperEasy 1-Click Backup] => "C:\Program Files\SuperEasy Software\1-Click Backup Free\bin\backupClient-sez1cb.exe" --hidden
HKLM\...\Run: [Ashampoo WinOptimizer Live-Tuner2] => C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 11\LiveTuner2.exe [3516784 2014-11-18] (Ashampoo Development GmbH & Co. KG)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVG_TRAY] => C:\Program Files (x86)\AVG\AVG2012\avgtray.exe [2598520 2012-11-19] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411952 2014-11-04] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2072928 2014-10-31] (Wondershare)
HKLM-x32\...\Run: [SPM15 Chrome Autofill Relay] => C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe [480120 2014-06-25] (Steganos Software GmbH)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-10-21] (Hewlett-Packard)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Run: [Facebook Update] => C:\Users\melsy\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-10-31] (Facebook Inc.)
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Run: [EssentialPIM] => C:\Program Files (x86)\EssentialPIM\EssentialPIM.exe [17719664 2014-12-01] (Astonsoft)
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\wo11.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
BootExecute: autocheck autochk * DfSDKBt
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3195104690-1283173883-910289243-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
URLSearchHook: HKLM-x32 - (No Name) - {422f7661-9403-4da4-b4ef-cc3e268817b5} - No File
URLSearchHook: HKU\S-1-5-21-3195104690-1283173883-910289243-1001 - (No Name) - {422f7661-9403-4da4-b4ef-cc3e268817b5} - No File
SearchScopes: HKLM -> {8262B94D-0FB8-44AE-AA96-7114154C01C3} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3195104690-1283173883-910289243-1001 -> {8262B94D-0FB8-44AE-AA96-7114154C01C3} URL =
SearchScopes: HKU\S-1-5-21-3195104690-1283173883-910289243-1001 -> ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ*´Ñ;áa´[¦†8*º~RÙxœòÜ8'£-)x*ä* URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH)
Toolbar: HKLM-x32 - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKLM-x32 - No Name - {422f7661-9403-4da4-b4ef-cc3e268817b5} - No File
Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar.dll (Steganos Software GmbH)
Toolbar: HKU\S-1-5-21-3195104690-1283173883-910289243-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-3195104690-1283173883-910289243-1001 -> No Name - {422F7661-9403-4DA4-B4EF-CC3E268817B5} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
FireFox:
========
FF ProfilePath: C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693
FF Homepage: https://www.google.at/?gws_rd=cr&ei=3OKMUuu2NOO54AT-pYGQCg
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @Skype Technologies S.A..com/Skype Web Plugin -> C:\Program Files (x86)\SkypeWebPlugin\3.1.15602.22612\npSkypeWebPlugin64.dll (Skype)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @Skype Technologies S.A..com/Skype Web Plugin -> C:\Program Files (x86)\SkypeWebPlugin\3.1.15602.22612\npSkypeWebPlugin.dll (Skype)
FF Plugin-x32: @soft-xpansion/npsxpdf -> C:\Program Files (x86)\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3195104690-1283173883-910289243-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\melsy\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKU\S-1-5-21-3195104690-1283173883-910289243-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\melsy\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKU\S-1-5-21-3195104690-1283173883-910289243-1001: @talk.google.com/O1DPlugin -> C:\Users\melsy\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKU\S-1-5-21-3195104690-1283173883-910289243-1001: @tools.google.com/Google Update;version=3 -> C:\Users\melsy\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-3195104690-1283173883-910289243-1001: @tools.google.com/Google Update;version=9 -> C:\Users\melsy\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\melsy\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\melsy\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\searchplugins\google-maps.xml
FF Extension: FDislike - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\fbdislike@doweb.fr.xpi [2014-04-14]
FF Extension: Ghostery - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\firefox@ghostery.com.xpi [2014-04-13]
FF Extension: ZenMate Security & Privacy VPN - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\firefox@zenmate.com.xpi [2014-10-05]
FF Extension: ProxTube - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\ich@maltegoetz.de.xpi [2014-09-11]
FF Extension: convert2mp3.net YouTube2MP3 Converter - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\info@convert2mp3.net.xpi [2014-04-13]
FF Extension: Facebook Select All - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\jid0-n2ISP7BOUOHLqFZBUsiANkm14Ck@jetpack.xpi [2014-04-13]
FF Extension: RequestPolicy - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\requestpolicy@requestpolicy.com.xpi [2014-11-21]
FF Extension: NoScript - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-13]
FF Extension: Adblock Plus - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-13]
FF Extension: OkayFreedom - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\{DB981CCA-088E-4731-A4A2-2FE218703C0E}.xpi [2014-12-24]
FF Extension: Google Privacy - C:\Users\melsy\AppData\Roaming\Mozilla\Firefox\Profiles\ztxv0dqa.default-1397397919693\Extensions\{ea61041c-1e22-4400-99a0-aea461e69d04}.xpi [2014-12-08]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-05-20]
FF HKLM-x32\...\Firefox\Extensions: [{1E73965B-8B48-48be-9C8D-68B920ABC1C4}] - C:\Program Files (x86)\AVG\AVG2012\Firefox4
FF Extension: No Name - C:\Program Files (x86)\AVG\AVG2012\Firefox4 [2013-06-28]
FF HKLM-x32\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb [2013-09-02]
FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3
FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 [2014-12-05]
FF HKU\S-1-5-21-3195104690-1283173883-910289243-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR Profile: C:\Users\melsy\AppData\Local\Google\Chrome\User Data\Default
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-10-22] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [365568 2011-07-05] (Advanced Micro Devices, Inc.) [File not signed]
R2 avgfws; C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [1432592 2014-11-04] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4942384 2014-10-17] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-11-20] (AVG Technologies CZ, s.r.o.)
S3 CGVPNCliSrvc; C:\Program Files\CyberGhost VPN\CGVPNCliService.exe [2438696 2012-04-26] (mobile concepts GmbH)
S4 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed]
S4 HPAuto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [682040 2011-02-16] (Hewlett-Packard)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89352 2014-09-15] (Hewlett-Packard Company)
S4 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1817088 2010-12-28] (Realsil Microelectronics Inc.) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [87040 2012-03-23] () [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S4 Radio.fx; C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe [3665752 2012-01-26] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S4 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-09-02] (soft Xpansion)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-21] (TuneUp Software)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [111208 2014-12-22] (RaMMicHaeL)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
R2 WO_LiveService2; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 11\LiveTunerService.exe [223600 2014-11-18] ()
S2 supereasy_1cbackup; "c:\Program Files\SuperEasy Software\1-Click Backup Free\bin\backupService-sez1cb.exe" "--controlFolder=c:\ProgramData\SuperEasy 1-Click Backup\control" "--id=supereasy_1cbackup" daemon
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [50296 2012-09-04] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [209720 2014-11-04] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-10-23] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2014-10-17] (AVG Technologies CZ, s.r.o.)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [133160 2011-06-16] (Broadcom Corporation.)
R3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-05-21] (Broadcom Corporation.)
S3 L6UX1; C:\Windows\System32\Drivers\L6UX164.sys [772864 2013-07-11] (Line 6)
R3 leawo_vad; C:\Windows\System32\drivers\leawo_vad.sys [33048 2013-05-21] (Shenzhen Moyea Software)
R2 LiveTuner2PM; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 11\LiveTuner64.sys [14320 2014-03-20] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-31] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
S3 REN2CAP_DRIVER; C:\Windows\System32\drivers\ren2cap.sys [46728 2011-11-07] ()
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-04-28] (Audials AG)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-03] (Anchorfree Inc.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-11-12] (TuneUp Software)
S3 USBMULCD; C:\Windows\System32\drivers\CM10664.sys [1451008 2008-10-13] (C-Media Electronics Inc)
S3 YMIDUSBW; C:\Windows\System32\drivers\ymidusbx64.sys [51016 2011-11-01] (Yamaha Corporation)
S3 CpqDfw; system32\drivers\CpqDfw.sys [X]
U3 DfSdkS; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-31 13:19 - 2014-12-31 13:19 - 00852505 _____ () C:\Users\melsy\Downloads\SecurityCheck.exe
2014-12-30 20:26 - 2014-12-30 20:26 - 02347384 _____ (ESET) C:\Users\melsy\Downloads\esetsmartinstaller_deu(1).exe
2014-12-29 23:44 - 2014-12-31 13:18 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-12-29 23:43 - 2014-12-29 23:43 - 02347384 _____ (ESET) C:\Users\melsy\Downloads\esetsmartinstaller_deu.exe
2014-12-29 15:43 - 2014-12-29 15:43 - 00028392 _____ () C:\Users\melsy\Documents\Synth Kick.txt
2014-12-29 14:14 - 2014-12-29 14:14 - 00000971 _____ () C:\Users\melsy\Desktop\HammerHead 1.0.lnk
2014-12-29 14:14 - 2014-12-29 14:14 - 00000971 _____ () C:\Users\_supereasy_1cbackup_\Desktop\HammerHead 1.0.lnk
2014-12-29 14:14 - 2014-12-29 14:14 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HammerHead Rhythm Station
2014-12-29 14:12 - 2014-12-29 14:19 - 01508117 _____ () C:\Users\melsy\Downloads\hh10_install(2).exe
2014-12-29 13:34 - 2014-12-29 13:34 - 00000045 _____ () C:\Users\melsy\Downloads\lay_back.ram
2014-12-29 13:34 - 2014-12-29 13:34 - 00000043 _____ () C:\Users\melsy\Downloads\sharky.ram
2014-12-29 13:34 - 2014-12-29 13:34 - 00000043 _____ () C:\Users\melsy\Downloads\mellow.ram
2014-12-29 13:34 - 2014-12-29 13:34 - 00000042 _____ () C:\Users\melsy\Downloads\stomp.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000045 _____ () C:\Users\melsy\Downloads\jumpdude.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000045 _____ () C:\Users\melsy\Downloads\hardcore.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000045 _____ () C:\Users\melsy\Downloads\chemical.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000044 _____ () C:\Users\melsy\Downloads\coolhop.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000043 _____ () C:\Users\melsy\Downloads\jungle.ram
2014-12-29 13:33 - 2014-12-29 13:33 - 00000043 _____ () C:\Users\melsy\Downloads\hiphop.ram
2014-12-29 13:32 - 2014-12-29 13:32 - 00000041 _____ () C:\Users\melsy\Downloads\acid.ram
2014-12-29 13:22 - 2014-12-30 16:59 - 00000000 ____D () C:\Program Files (x86)\HammerHead
2014-12-29 13:22 - 2014-12-29 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HammerHead Rhythm Station
2014-12-29 13:21 - 2014-12-29 13:21 - 01508117 _____ () C:\Users\melsy\Downloads\hh10_install.exe
2014-12-29 12:21 - 2014-12-29 12:21 - 02123264 _____ (Farbar) C:\Users\melsy\Downloads\FRST64(1).exe
2014-12-29 11:59 - 2014-12-29 11:59 - 01707939 _____ (Thisisu) C:\Users\melsy\Downloads\JRT(1).exe
2014-12-29 11:55 - 2014-12-29 11:55 - 00818637 _____ (Thisisu) C:\Users\melsy\Downloads\JRT.exe
2014-12-29 11:27 - 2014-12-29 11:28 - 02173952 _____ () C:\Users\melsy\Downloads\AdwCleaner_4.106(1).exe
2014-12-29 11:16 - 2014-12-29 11:16 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-12-29 11:15 - 2014-12-29 11:15 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\melsy\Downloads\revosetup95.exe
2014-12-29 10:00 - 2014-12-29 10:00 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2014-12-27 09:35 - 2014-12-27 09:35 - 02173952 _____ () C:\Users\melsy\Downloads\AdwCleaner_4.106.exe
2014-12-26 18:50 - 2014-12-26 18:52 - 00071035 _____ () C:\Users\melsy\Downloads\Addition.txt
2014-12-26 18:48 - 2014-12-31 14:03 - 00028412 _____ () C:\Users\melsy\Downloads\FRST.txt
2014-12-26 18:47 - 2014-12-31 14:03 - 00000000 ____D () C:\FRST
2014-12-26 18:47 - 2014-12-26 18:47 - 02122752 _____ (Farbar) C:\Users\melsy\Downloads\FRST64.exe
2014-12-26 15:25 - 2014-12-26 15:25 - 00001455 _____ () C:\trojaner.txt
2014-12-24 15:10 - 2014-12-29 11:50 - 00000600 _____ () C:\Windows\PFRO.log
2014-12-24 15:02 - 2014-12-24 15:02 - 16520304 _____ (Steganos Software GmbH) C:\Users\melsy\Downloads\okayfreedomwr.exe
2014-12-24 14:01 - 2014-12-24 14:01 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Steganos Updates
2014-12-24 13:59 - 2014-12-24 14:11 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Steganos VPN
2014-12-24 13:56 - 2014-12-24 13:56 - 01174352 _____ () C:\Users\melsy\Downloads\Vollversion OkayFreedom Premium Flat - CHIP-Installer.exe
2014-12-22 02:54 - 2014-12-22 02:54 - 05164040 _____ (DigitalVolcano Software Ltd) C:\Users\melsy\Downloads\DuplicateCleaner_setup(1).exe
2014-12-22 01:01 - 2014-12-29 11:20 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\DigitalVolcano
2014-12-22 00:59 - 2014-12-22 00:59 - 05164040 _____ (DigitalVolcano Software Ltd) C:\Users\melsy\Downloads\DuplicateCleaner_setup.exe
2014-12-21 02:14 - 2014-12-21 02:14 - 01174352 _____ () C:\Users\melsy\Downloads\Vollversion Magix Music Maker 2013 - CHIP-Installer.exe
2014-12-20 18:36 - 2014-12-20 18:36 - 00001152 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Rip CD Ripper Software.lnk
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-12-20 18:32 - 2014-12-31 05:41 - 00001568 _____ () C:\Windows\setupact.log
2014-12-20 18:32 - 2014-12-20 18:32 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-18 12:27 - 2014-12-31 05:45 - 00374048 _____ () C:\Windows\WindowsUpdate.log
2014-12-17 00:38 - 2014-12-17 00:38 - 00000000 ____D () C:\Users\melsy\Documents\DesignCAD 3D MAX 22
2014-12-17 00:37 - 2014-12-17 00:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DesignCAD Toolkit Maschinenbau & Konstruktion 22
2014-12-17 00:37 - 2014-12-17 00:37 - 00000000 ____D () C:\Program Files (x86)\DCToolkit
2014-12-17 00:36 - 2014-12-17 00:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DesignCAD 3D Max 22
2014-12-17 00:35 - 2014-12-17 00:35 - 00000000 ____D () C:\ProgramData\IMSIDesign
2014-12-17 00:35 - 2014-12-17 00:35 - 00000000 ____D () C:\Program Files (x86)\IMSIDesign
2014-12-17 00:15 - 2014-12-17 00:18 - 95590424 _____ () C:\Users\melsy\Downloads\DesignCAD-V22-3D-Triple-Toolkits-Complete-CHIP.exe
2014-12-16 14:47 - 2014-12-21 19:57 - 00168064 _____ () C:\Users\melsy\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-15 21:05 - 2014-12-15 21:05 - 00000000 ____D () C:\Users\melsy\Downloads\Office 2007
2014-12-15 19:04 - 2014-12-15 19:11 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Scribus
2014-12-15 18:59 - 2014-12-15 19:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scribus 1.4.4
2014-12-15 18:57 - 2014-12-15 19:03 - 00000000 ____D () C:\Program Files\Scribus 1.4.4
2014-12-15 17:02 - 2014-12-15 17:04 - 86069640 _____ (The Scribus Team) C:\Users\melsy\Downloads\scribus-1.4.4-windows-x64.exe
2014-12-15 15:06 - 2014-12-15 15:06 - 00001148 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
2014-12-15 15:06 - 2014-12-15 15:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audioverwandte Programme
2014-12-15 11:46 - 2014-12-15 11:46 - 01177424 _____ () C:\Users\melsy\Downloads\TuxGuitar - CHIP-Installer.exe
2014-12-14 23:48 - 2014-12-14 23:48 - 00000000 _____ () C:\Windows\SysWOW64\shoFA1F.tmp
2014-12-14 23:31 - 2014-12-14 23:31 - 00000000 __SHD () C:\WISE_DISKSCRUBTEMP
2014-12-14 16:30 - 2014-12-14 16:32 - 43145168 _____ (Ashampoo GmbH & Co. KG ) C:\Users\melsy\Downloads\ashampoo_winoptimizer_11_11.00.50_18137.exe
2014-12-13 09:28 - 2014-12-15 11:35 - 00000000 ____D () C:\Users\melsy\HDR Projects
2014-12-13 09:26 - 2014-12-13 09:26 - 00001045 _____ () C:\Users\Public\Desktop\HDR Projects platin (64-Bit).lnk
2014-12-13 09:26 - 2014-12-13 09:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Franzis
2014-12-13 09:26 - 2014-12-13 09:26 - 00000000 ____D () C:\Program Files\Franzis
2014-12-13 09:09 - 2014-12-13 09:09 - 00000000 ____D () C:\Users\melsy\Documents\HDR-projects-platin-win-mac-CHIP
2014-12-12 13:24 - 2014-12-12 13:24 - 00000000 _____ () C:\Windows\SysWOW64\sho287C.tmp
2014-12-11 19:52 - 2014-12-11 19:52 - 00000000 ____D () C:\Users\melsy\Documents\FlashIntegro
2014-12-11 19:52 - 2014-12-11 19:52 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\VideoEditor
2014-12-11 19:52 - 2014-12-11 19:52 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\FlashIntegro
2014-12-11 19:51 - 2014-12-15 11:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlashIntegro
2014-12-11 19:51 - 2014-12-15 11:35 - 00000000 ____D () C:\Program Files (x86)\FlashIntegro
2014-12-11 19:51 - 2014-12-09 13:21 - 00081792 _____ (Flash-Integro LLC) C:\Windows\SysWOW64\mslvddsfilter2.ax
2014-12-11 19:51 - 2011-12-07 19:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\Lagarith.dll
2014-12-11 19:51 - 2004-12-10 10:03 - 00438272 _____ (On2.com) C:\Windows\SysWOW64\vp6vfw.dll
2014-12-11 19:51 - 2004-09-06 16:06 - 00053248 _____ () C:\Windows\SysWOW64\xvid.ax
2014-12-11 19:51 - 2004-07-03 21:08 - 00139264 _____ () C:\Windows\SysWOW64\xvidvfw.dll
2014-12-11 19:51 - 2004-07-03 20:59 - 00524288 _____ () C:\Windows\SysWOW64\xvidcore.dll
2014-12-11 19:51 - 2004-02-04 21:11 - 00081920 _____ (fccHandler) C:\Windows\SysWOW64\AC3ACM.acm
2014-12-11 19:51 - 2003-05-22 12:26 - 00638976 _____ (DivXNetworks, Inc.) C:\Windows\SysWOW64\divx.dll
2014-12-11 19:51 - 2003-05-22 12:26 - 00221215 _____ (DivXNetworks, Inc.) C:\Windows\SysWOW64\divxdec.ax
2014-12-11 19:51 - 2003-05-21 23:50 - 00261632 _____ (MainConcept) C:\Windows\SysWOW64\mcdvd_32.dll
2014-12-11 19:51 - 2003-05-21 23:50 - 00156910 _____ () C:\Windows\WMSysPr8.prx
2014-12-11 19:51 - 2003-05-21 23:50 - 00082944 _____ (Voxware, Inc.) C:\Windows\SysWOW64\vct3216.acm
2014-12-11 19:51 - 2003-05-21 23:50 - 00038912 _____ (NCT Company) C:\Windows\SysWOW64\alf2cd.acm
2014-12-11 19:51 - 2003-03-25 05:49 - 00098304 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\SysWOW64\L3CODECX.AX
2014-12-11 19:51 - 2002-08-20 00:41 - 00413760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg4c32.dll
2014-12-11 19:51 - 2000-03-14 20:55 - 00013239 _____ (SHARP Corporation) C:\Windows\SysWOW64\Scg726.acm
2014-12-11 19:47 - 2014-12-11 19:47 - 01177424 _____ () C:\Users\melsy\Downloads\VSDC Free Video Editor - CHIP-Installer.exe
2014-12-10 19:29 - 2014-12-10 19:29 - 17103000 _____ (Electronic Arts, Inc.) C:\Users\melsy\Downloads\OriginThinSetup.exe
2014-12-10 18:55 - 2014-12-10 19:40 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Origin
2014-12-10 18:53 - 2014-12-10 19:54 - 00000000 ____D () C:\ProgramData\Origin
2014-12-10 14:14 - 2014-12-16 08:59 - 00000412 _____ () C:\Windows\Tasks\Wise Care 365 PC Checkup Task.job
2014-12-10 14:14 - 2014-12-10 14:14 - 00002834 _____ () C:\Windows\System32\Tasks\Wise Care 365 PC Checkup Task
2014-12-10 09:50 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-10 09:50 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-10 09:21 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-10 09:21 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-10 09:21 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-10 09:21 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-10 09:21 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-10 09:21 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-10 09:21 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-10 09:21 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-10 09:21 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-10 09:21 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-10 09:21 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-10 09:21 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-10 09:21 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-10 09:21 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-10 09:21 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-10 09:12 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-10 09:12 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-09 13:07 - 2014-12-22 13:17 - 00000000 ____D () C:\Users\melsy\Documents\camera musik
2014-12-09 12:29 - 2014-12-09 12:30 - 11669724 _____ () C:\Users\melsy\Downloads\Camera Rare Grooves Aluminium Edition - 02 Donny Hathaway - The Ghetto.mp4.part
2014-12-09 11:06 - 2014-12-09 11:06 - 00003070 _____ () C:\Windows\System32\Tasks\Wise Turbo Checker
2014-12-09 11:06 - 2014-12-09 11:06 - 00002848 _____ () C:\Windows\System32\Tasks\Wise Care 365
2014-12-09 11:06 - 2014-12-09 11:06 - 00000422 _____ () C:\Windows\Tasks\Wise Care 365.job
2014-12-09 11:06 - 2014-12-09 11:06 - 00000402 _____ () C:\Windows\Tasks\Wise Turbo Checker.job
2014-12-09 10:33 - 2014-12-20 02:15 - 00000000 ____D () C:\Program Files (x86)\Wise
2014-12-09 10:31 - 2014-12-09 10:31 - 01174352 _____ () C:\Users\melsy\Downloads\Wise Care 365 - CHIP-Installer.exe
2014-12-07 14:45 - 2014-12-07 14:46 - 11553744 _____ () C:\Users\melsy\Downloads\EssentialPIM6.exe
2014-12-05 17:37 - 2014-12-05 17:37 - 00001170 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoStage Diashow-Ersteller.lnk
2014-12-05 17:37 - 2014-12-05 17:37 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Produktpalette
2014-12-05 17:37 - 2014-12-05 17:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Videoverwandte Programme
2014-12-05 16:44 - 2014-12-05 16:44 - 00001110 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoPad Image Editor.lnk
2014-12-05 16:44 - 2014-12-05 16:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-12-05 16:43 - 2014-12-05 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Produktpalette
2014-12-05 16:43 - 2014-12-05 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grafikverwandte Programme
2014-12-05 16:42 - 2014-12-05 16:42 - 00001160 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pixillion Imagedatei-Konverter.lnk
2014-12-05 16:29 - 2014-12-05 16:30 - 00505376 _____ (NCH Software) C:\Users\melsy\Downloads\pixpsetup.exe
2014-12-05 13:02 - 2014-12-24 14:32 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Steganos
2014-12-05 13:02 - 2014-12-05 13:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steganos Passwort-Manager 15
2014-12-05 13:02 - 2014-12-05 13:03 - 00000000 ____D () C:\Program Files (x86)\Steganos Password Manager 15
2014-12-05 13:00 - 2014-12-05 13:00 - 01174352 _____ () C:\Users\melsy\Downloads\Vollversion Steganos Passwort Manager 15 - CHIP-Installer.exe
2014-12-04 18:05 - 2014-12-04 18:05 - 00001964 _____ () C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2014-12-03 19:41 - 2014-12-03 19:41 - 07270351 _____ () C:\Users\melsy\Downloads\meine 68 jährige (2).mp4
2014-12-02 16:16 - 2014-12-08 03:47 - 00000000 ____D () C:\Users\melsy\AppData\Local\SuperEasy 1-Click Backup
2014-12-02 16:16 - 2014-12-03 16:04 - 00000000 ___HD () C:\ProgramData\sysnfxo
2014-12-02 16:15 - 2014-12-29 11:51 - 00000000 ____D () C:\Users\_supereasy_1cbackup_
2014-12-02 16:15 - 2014-12-02 16:15 - 00000020 ___SH () C:\Users\_supereasy_1cbackup_\ntuser.ini
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Vorlagen
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Startmenü
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Netzwerkumgebung
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Lokale Einstellungen
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Eigene Dateien
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Druckumgebung
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Documents\Eigene Musik
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Documents\Eigene Bilder
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\AppData\Local\Verlauf
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\AppData\Local\Anwendungsdaten
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 _SHDL () C:\Users\_supereasy_1cbackup_\Anwendungsdaten
2014-12-02 16:15 - 2014-12-02 16:15 - 00000000 ____D () C:\ProgramData\SuperEasy 1-Click Backup
2014-12-02 16:15 - 2013-08-14 10:34 - 00000000 ____D () C:\Users\_supereasy_1cbackup_\AppData\Local\Microsoft Help
2014-12-02 16:15 - 2013-07-31 08:12 - 00000000 ____D () C:\Users\_supereasy_1cbackup_\AppData\Roaming\TuneUp Software
2014-12-02 16:15 - 2013-07-26 03:08 - 00000000 ____D () C:\Users\_supereasy_1cbackup_\AppData\Local\ScreenCapture
2014-12-02 16:15 - 2012-12-03 06:32 - 00000000 ____D () C:\Users\_supereasy_1cbackup_\AppData\Roaming\Macromedia
2014-12-02 16:15 - 2012-08-12 01:32 - 00002134 _____ () C:\Users\_supereasy_1cbackup_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
2014-12-02 16:15 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\_supereasy_1cbackup_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-02 16:15 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\_supereasy_1cbackup_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-12-02 16:13 - 2014-12-02 16:13 - 28074616 _____ (SuperEasy Software GmbH & Co. KG ) C:\Users\melsy\Downloads\supereasy_1-click_backup_free_1.13.0_8279.exe
2014-12-02 14:03 - 2014-12-02 14:03 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\EAC
2014-12-02 14:03 - 2014-12-02 14:03 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\AccurateRip
2014-12-02 14:02 - 2014-12-02 14:02 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Cliqz
2014-12-02 14:02 - 2014-12-02 14:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exact Audio Copy
2014-12-02 14:02 - 2014-12-02 14:02 - 00000000 ____D () C:\Program Files (x86)\Exact Audio Copy
2014-12-02 13:57 - 2014-12-02 13:57 - 01174352 _____ () C:\Users\melsy\Downloads\Exact Audio Copy - CHIP-Installer.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-31 14:02 - 2012-05-18 12:08 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Skype
2014-12-31 13:55 - 2014-10-15 14:50 - 00003094 _____ () C:\Windows\System32\Tasks\{B2E8F773-5F5C-4836-8957-FEE3042EABFC}
2014-12-31 13:55 - 2014-09-21 08:03 - 00003088 _____ () C:\Windows\System32\Tasks\{C0C124F4-41F2-47D4-860C-4FCF583875C1}
2014-12-31 13:55 - 2014-09-21 08:03 - 00003088 _____ () C:\Windows\System32\Tasks\{5C4F42ED-5832-48B4-BCB9-D77730EC38C1}
2014-12-31 13:55 - 2014-08-28 18:24 - 00003076 _____ () C:\Windows\System32\Tasks\{8795FFFA-4029-4A70-B1CF-0C3C57CDEE7C}
2014-12-31 13:55 - 2013-10-09 17:59 - 00003102 _____ () C:\Windows\System32\Tasks\{AD7AC0AF-B335-4FB0-ABC0-6583AD2EE938}
2014-12-31 13:55 - 2013-05-03 19:39 - 00003086 _____ () C:\Windows\System32\Tasks\{2A792A14-06ED-4493-81D7-2A64E97EA462}
2014-12-31 13:55 - 2012-11-20 13:26 - 00002966 _____ () C:\Windows\System32\Tasks\{69CD82CA-4612-410F-907D-CE1E674B652E}
2014-12-31 13:55 - 2012-11-20 13:26 - 00002966 _____ () C:\Windows\System32\Tasks\{670A25EF-5F02-41BB-BB0D-827A205D5869}
2014-12-31 13:54 - 2014-09-10 08:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-31 13:50 - 2013-10-31 22:45 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3195104690-1283173883-910289243-1001UA.job
2014-12-31 13:41 - 2014-05-20 14:57 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-31 13:23 - 2011-08-09 21:16 - 00774266 _____ () C:\Windows\system32\perfh007.dat
2014-12-31 13:23 - 2011-08-09 21:16 - 00175794 _____ () C:\Windows\system32\perfc007.dat
2014-12-31 13:23 - 2009-07-14 06:13 - 01808064 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-31 13:22 - 2013-01-23 23:10 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3195104690-1283173883-910289243-1001UA.job
2014-12-31 13:11 - 2012-08-13 22:06 - 00000386 _____ () C:\Windows\Tasks\WpsUpdateTask_melsy.job
2014-12-31 12:13 - 2013-05-07 17:00 - 00000000 ____D () C:\ProgramData\MFAData
2014-12-31 05:49 - 2009-07-14 05:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-31 05:49 - 2009-07-14 05:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-31 05:42 - 2012-07-27 20:04 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-31 05:41 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-31 00:22 - 2013-01-23 23:10 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3195104690-1283173883-910289243-1001Core.job
2014-12-30 22:50 - 2013-10-31 22:45 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3195104690-1283173883-910289243-1001Core.job
2014-12-30 19:03 - 2014-04-22 13:06 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\vlc
2014-12-30 09:45 - 2014-10-15 16:42 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-12-29 12:20 - 2012-05-21 13:38 - 00000000 ___RD () C:\Users\melsy\Desktop\Sicherheit
2014-12-29 11:48 - 2013-09-19 13:30 - 00000000 ____D () C:\AdwCleaner
2014-12-29 11:34 - 2012-05-20 16:38 - 00000000 ____D () C:\Users\melsy\AppData\Local\CrashDumps
2014-12-29 02:58 - 2012-07-02 01:36 - 00000410 _____ () C:\Windows\Tasks\EasyShare Registration Task.job
2014-12-29 01:46 - 2014-07-19 10:21 - 00003186 _____ () C:\Windows\System32\Tasks\HPCeeScheduleFormelsy
2014-12-29 01:46 - 2014-07-19 10:21 - 00000332 _____ () C:\Windows\Tasks\HPCeeScheduleFormelsy.job
2014-12-27 23:22 - 2012-05-21 23:39 - 00000000 ___RD () C:\Users\melsy\Desktop\TONSTUDIO
2014-12-27 18:36 - 2012-09-23 02:50 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-12-26 15:24 - 2014-05-20 14:57 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-25 20:44 - 2014-09-21 08:17 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-25 20:44 - 2012-05-18 12:07 - 00000000 ____D () C:\ProgramData\Skype
2014-12-24 15:22 - 2014-10-15 17:01 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2014-12-22 13:37 - 2013-03-26 14:54 - 00000000 ____D () C:\Users\melsy\Documents\RAF
2014-12-22 13:37 - 2013-01-23 02:22 - 00000000 ____D () C:\Users\melsy\Documents\Cybershapes
2014-12-22 13:26 - 2012-09-23 01:41 - 00000000 ____D () C:\Users\melsy\Documents\soz-österr
2014-12-22 13:26 - 2012-05-19 10:40 - 00000000 ____D () C:\Users\melsy\Documents\Meine empfangenen Dateien
2014-12-22 08:20 - 2009-07-14 05:45 - 00539840 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-21 19:56 - 2012-05-20 12:12 - 00000000 ____D () C:\Users\melsy\Documents\Gitarre
2014-12-21 04:24 - 2013-03-16 19:48 - 00000000 ____D () C:\Users\Public\Documents\MAGIX
2014-12-21 02:59 - 2012-07-01 18:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-12-21 02:57 - 2012-07-01 18:18 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-12-21 02:52 - 2013-03-16 19:56 - 00000000 ___RD () C:\Users\melsy\Documents\MAGIX
2014-12-21 02:52 - 2012-07-01 18:18 - 00000000 ____D () C:\ProgramData\MAGIX
2014-12-20 18:34 - 2012-05-18 15:45 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Audacity
2014-12-20 02:31 - 2013-10-11 13:45 - 00000000 ___RD () C:\Users\melsy\Desktop\radios
2014-12-20 02:31 - 2012-09-08 11:59 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\XnView
2014-12-20 01:57 - 2012-11-03 14:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCFinder
2014-12-20 01:57 - 2012-11-03 14:18 - 00000000 ____D () C:\Program Files (x86)\CCFinder
2014-12-18 12:24 - 2012-05-21 03:47 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-12-18 12:24 - 2012-05-21 03:47 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-12-18 12:22 - 2011-12-10 05:20 - 00000000 ____D () C:\ProgramData\Temp
2014-12-17 00:39 - 2012-07-18 02:06 - 00000000 ___RD () C:\Users\melsy\Desktop\Foto Video
2014-12-16 19:19 - 2012-07-24 21:06 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2014-12-15 19:01 - 2013-09-02 13:26 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-15 18:40 - 2014-10-23 10:29 - 00000000 ____D () C:\Users\melsy\Documents\KPÖ
2014-12-15 14:25 - 2012-05-21 03:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-12-15 11:49 - 2013-02-03 15:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuxGuitar
2014-12-15 11:49 - 2013-02-03 15:57 - 00000000 ____D () C:\Program Files (x86)\TuxGuitar
2014-12-15 11:35 - 2013-05-18 21:52 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\EssentialPIM
2014-12-15 11:35 - 2013-02-03 15:59 - 00000000 ____D () C:\Users\melsy\.tuxguitar-1.2
2014-12-15 11:35 - 2012-12-14 19:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2014-12-15 11:35 - 2012-12-05 11:56 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-12-15 11:35 - 2012-05-20 17:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-15 11:35 - 2012-05-19 13:23 - 00000000 ____D () C:\Program Files (x86)\ScanIT-Client
2014-12-15 11:35 - 2012-05-18 11:43 - 00000000 ____D () C:\Users\melsy
2014-12-15 11:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-12-15 10:43 - 2012-05-20 12:52 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\SoftGrid Client
2014-12-15 10:02 - 2013-09-29 09:43 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-14 23:43 - 2013-01-03 14:29 - 00000000 ____D () C:\Users\melsy\AppData\Local\Downloaded Installations
2014-12-14 16:36 - 2012-05-21 13:33 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-12-13 13:09 - 2014-09-09 13:12 - 00000000 ____D () C:\Users\melsy\Documents\demos
2014-12-13 12:35 - 2012-09-21 20:10 - 00038311 _____ () C:\Users\melsy\Documents\Passwörter.xlsx
2014-12-10 19:50 - 2012-06-02 18:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-10 17:54 - 2014-09-10 08:01 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-12-10 17:54 - 2014-07-04 14:07 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-12-10 17:54 - 2014-07-04 14:07 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-10 10:52 - 2013-02-25 20:12 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\{90140011-0066-0407-0000-0000000FF1CE}
2014-12-10 10:52 - 2013-02-25 20:11 - 00000000 ____D () C:\ProgramData\Virtualized Applications
2014-12-10 10:52 - 2012-05-20 12:52 - 00000000 ____D () C:\Users\melsy\AppData\Local\SoftGrid Client
2014-12-10 10:39 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-12-10 10:31 - 2013-05-20 18:34 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-10 10:24 - 2013-07-11 11:55 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-10 09:53 - 2012-05-21 03:56 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-09 14:02 - 2013-05-29 17:59 - 00000000 ____D () C:\Users\melsy\Documents\Essential Kalender
2014-12-09 13:48 - 2013-03-05 13:41 - 00000000 ____D () C:\Users\melsy\AppData\Roaming\TS3Client
2014-12-09 10:51 - 2013-11-11 15:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-12-09 10:35 - 2007-01-02 02:25 - 00000000 ____D () C:\Windows\Panther
2014-12-07 14:47 - 2013-05-25 09:47 - 00001023 _____ () C:\Users\Public\Desktop\EssentialPIM.lnk
2014-12-03 12:40 - 2014-08-21 22:58 - 00000000 ____D () C:\Users\melsy\Documents\Norma A2
Some content of TEMP:
====================
C:\Users\melsy\AppData\Local\Temp\abelssoft.setup.exe
C:\Users\melsy\AppData\Local\Temp\Quarantine.exe
C:\Users\melsy\AppData\Local\Temp\ripsetup.exe
C:\Users\melsy\AppData\Local\Temp\SkypeSetup.exe
C:\Users\melsy\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-15 04:32
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Habe mit dem PC keine Probleme mehr ..... Bitte sende mir mit einer PM deinen Namen deine Kontonr. habe ich noch falls sie sich im den letzten 13 Monaten nicht geändert haben .
Vielen Dank u lg wolfgang |