|
Log-Analyse und Auswertung: Tastatur setzt aus oder Buchstaben mehrfachWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
27.02.2014, 14:51 | #1 |
| Tastatur setzt aus oder Buchstaben mehrfach Hallo, wie schon beschrieben, setzt meine Funk-Tastatur manchmal aus oder erzeugt bei einem Anschlag den Buchstaben gleich mehrfach. Es handelt sich um eine eine Logitech S520. Batterien, Treiber und Chipset sind aktuell. Alternativ habe ich von einem anderen PC eine MS Tastatur zum Test verwendet, gleiches Resultat. SuperAntiSpayware wurde mehrfach komplett durchgeführt. OTL Logfiles anbei. Vielen Dank für eure Hilfe. Win7 64Bit - Gigabyte GA-X58A-UD7 (rev. 1.0) Die OTL konnte ich leider wegen ihrer Größe nicht hochladen und füge deshalb den Link dropbosx ein. https://dl.dropboxusercontent.com/u/108238527/OTL.Txt |
27.02.2014, 15:16 | #2 |
/// the machine /// TB-Ausbilder | Tastatur setzt aus oder Buchstaben mehrfach Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. Ich kann auf Arbeit keine Anhänge öffnen, danke. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
27.02.2014, 16:46 | #3 |
| Tastatur setzt aus oder Buchstaben mehrfachCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-02-2014 02 Ran by Tom at 2014-02-27 16:34:28 Running from C:\Users\Tom\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.9 - Adobe Systems) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.9.0.1210 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.9.0.1210 - Adobe Systems Incorporated) Hidden Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Help Manager (x32 Version: 4.0.244 - Adobe Systems Incorporated) Hidden Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.) Adobe Widget Browser (x32 Version: 2.0.348 - Adobe Systems Incorporated.) Hidden Adobe® Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 3.4.0 - Adobe Systems Incorporated) Adobe® Content Viewer (x32 Version: 3.4.0 - Adobe Systems Incorporated) Hidden ALDI NORD Bestellsoftware 4.13.1 (HKLM-x32\...\ALDI NORD Bestellsoftware) (Version: 4.13.1 - ORWO Net) AMD Accelerated Video Transcoding (Version: 13.15.100.31008 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{308051DA-0048-7A07-FE8B-9B6EC119A9E8}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.81008.0920 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden Anti-Twin (Installation 04.02.2014) (HKLM-x32\...\Anti-Twin 2014-02-04 07.46.22) (Version: - Joerg Rosenthal, Germany) Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) BackUp Maker (HKLM-x32\...\BackUp Maker_is1) (Version: 6.5.0.7 - ASCOMP Software GmbH) bl (x32 Version: 1.0.0 - Your Company Name) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Brother MFL-Pro Suite MFC-7460DN (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.1.3.0 - Brother Industries, Ltd.) Brother Product Research and Support Program (HKLM-x32\...\{8040527F-DD74-4B45-8A06-C4BF145B6C76}) (Version: 2.1.0.0000 - Brother Industries, Ltd.) Brother P-touch Editor 5.1 (HKLM-x32\...\{39270390-A851-4E4B-94A9-D5C468216ED3}) (Version: 5.1.0051 - Brother Industries, Ltd.) Brother P-touch Update Software (HKLM-x32\...\{34A9C5A8-9BB6-4C57-A0D9-1DAAE175009E}) (Version: 1.0.0070 - Brother Industries, Ltd.) calibre (HKLM-x32\...\{F194B9D2-5BB0-4A36-912A-861DE0652181}) (Version: 1.23.0 - Kovid Goyal) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4478 - CDBurnerXP) Citavi 4 (HKLM-x32\...\{CC0A85B2-734A-45B3-B678-05F6A6499AC7}) (Version: 4.3.0.15 - Swiss Academic Software) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{BED39C88-768C-4345-BF11-58436C984F2A}) (Version: - Microsoft) DirPrintOK (HKLM-x32\...\DirPrintOK) (Version: - ) Dropbox (HKCU\...\Dropbox) (Version: 2.6.5 - Dropbox, Inc.) eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden Evernote v. 5.2 (HKLM-x32\...\{6C8A2102-903E-11E3-BF0E-00163E98E7D6}) (Version: 5.2.0.2637 - Evernote Corp.) Fences 2 (HKLM-x32\...\Fences 22.01) (Version: 2.01 - Stardock Corporation) FileZilla Client 3.7.4.1 (HKLM-x32\...\FileZilla Client) (Version: 3.7.4.1 - Tim Kosse) Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.117 - Google Inc.) Google Chrome Canary (HKCU\...\Google Chrome SxS) (Version: 35.0.1862.2 - Google Inc.) Google Drive (HKLM-x32\...\{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}) (Version: 1.14.6059.644 - Google, Inc.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Talk Plugin (HKLM-x32\...\{CCE68200-4ED0-3E0A-A7F2-504897E356AB}) (Version: 5.1.5.17733 - Google) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) Logitech SetPoint 6.61 (HKLM\...\sp6) (Version: 6.61.15 - Logitech) Logitech Webcam Software (HKLM\...\{987FE247-4E69-4A2E-A961-D14F901FDBF6}) (Version: 12.10.1113 - Logitech Inc.) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Access database engine 2010 (German) (HKLM-x32\...\{90140000-00D1-0407-0000-0000000FF1CE}) (Version: 14.0.6029.1000 - Microsoft Corporation) Microsoft Access MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft DCF MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Excel MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Groove MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft InfoPath MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Lync MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office 32-bit Components 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM UX MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft OneNote MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Outlook MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft PowerPoint MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Publisher MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.4.304.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Word MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Monosnap (HKLM-x32\...\{F9D4F00E-581A-454E-BD26-F816531A9E8C}) (Version: 2.0.3.0 - Monosnap) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Mozilla Firefox 27.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Music Manager (HKCU\...\MusicManager) (Version: - Google, Inc.) MyFreeCodec (HKCU\...\MyFreeCodec) (Version: - ) Nuance PaperPort 12 (HKLM-x32\...\{869FCC6C-5669-4B0B-827E-2BBAACD88A87}) (Version: 12.1.0006 - Nuance Communications, Inc.) Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 14.00.0000 - Nuance Communications, Inc.) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden ph (x32 Version: 1.0.0 - Your Company Name) Hidden Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Pixum Fotobuch (HKLM-x32\...\Pixum Fotobuch) (Version: 5.0.1 - CEWE COLOR AG u Co. OHG) QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek Ethernet Diagnostic Utility (HKLM-x32\...\{DADC7AB0-E554-4705-9F6A-83EA82ED708E}) (Version: 1.006 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7083 - Realtek Semiconductor Corp.) SavingsBull (x32 Version: 1.0.0.0 - SavingsBull) Hidden Scansoft PDF Professional (x32 Version: - ) Hidden Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden Sitecom Wireless Network 300N Adapter (HKLM-x32\...\{F912EF57-65C8-48E8-911F-7FCAF8ADD62E}) (Version: 1.5.5.0 - Sitecom) Skitch (HKLM-x32\...\Skitch 2.0.1.5) (Version: 2.0.1.5 - Evernote Corp.) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Spotify (HKCU\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.7.1018 - SUPERAntiSpyware.com) SuperMailer 7.11 (HKLM\...\Newsletter Software SuperMailer (x64)_is1) (Version: 7.11 - Mirko Boeer Softwareentwicklungen) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.25942 - TeamViewer) Update for Microsoft Lync 2013 (KB2817678) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUSR_{237834D6-FA98-44E1-8739-ABD56DDADC59}) (Version: - Microsoft) VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: - Elaborate Bytes) VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN) Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Utils (HKLM-x32\...\Windows Utils) (Version: - ) WISO Mein Geld 2014 Professional (HKLM-x32\...\WISO Mein Geld 2014 Professional) (Version: - Buhl Data Service GmbH) WISO Mein Geld 2014 Professional (x32 Version: 16.0.1.0 - Buhl Data Service GmbH) Hidden Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org) Z Cinema (HKLM\...\{6E166235-49F3-4DFA-A102-1E86675ABD11}) (Version: 1.0.0 - Logitech) ==================== Restore Points ========================= 27-02-2014 01:10:40 Geplanter Prüfpunkt 27-02-2014 11:13:32 Installed QuickTime 7 27-02-2014 14:04:53 Removed inSSIDer 3 ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-04-14 14:20 - 00000922 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com 127.0.0.1 activate.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {0DCB8CE2-0404-4C3E-8656-F65D97CEF75A} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {1419A66F-D0AA-4FF1-804F-992A0F8D5F1F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-21] (Adobe Systems Incorporated) Task: {141AA8AB-B7C1-4A83-BF39-EBCF20B05EE9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2247641735-418790473-2961746829-1000UA => C:\Users\Tom\AppData\Local\Google\Update\GoogleUpdate.exe [2013-04-02] (Google Inc.) Task: {1707BED0-2202-4440-8162-2FC6DF177A42} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe Task: {20CF8371-C36A-4917-8A8A-32A48427A783} - System32\Tasks\SUPERAntiSpyware Scheduled Task cce553f9-8238-4e2e-a8b4-6a9da503768f => C:\PROGRAM FILES\SUPERANTISPYWARE\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {32131334-EE52-4D08-B397-97016575896F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2247641735-418790473-2961746829-1000Core => C:\Users\Tom\AppData\Local\Google\Update\GoogleUpdate.exe [2013-04-02] (Google Inc.) Task: {32972F57-64A6-422C-B9D8-A13CD0B3F7A9} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {4D795E25-F578-4B98-AD0B-D91B296A6613} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-02] (Google Inc.) Task: {5A17819E-2DB1-4B18-B6EC-830E268E998D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {5A73F007-DCC2-4098-822F-5C10FF218C31} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe Task: {6CF7280A-507A-49F8-ACD4-B38833FA0EA2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-02] (Google Inc.) Task: {89E3E63A-528E-4588-BAC5-5DB2A92B634E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {955D6904-6813-487B-9048-553C36B19523} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe Task: {B2F40D82-EAA7-4AF5-A3BB-B05DB6386490} - System32\Tasks\AdobeAAMUpdater-1.0-Tom-PC-Tom => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-03] (Adobe Systems Incorporated) Task: {B4F35EC7-EE6F-41A0-B458-1C1DB3986A94} - System32\Tasks\BetterDesktopTool => C:\Program Files (x86)\BetterDesktopTool\BetterDesktopTool.exe Task: {C69F3C7C-668C-46DC-BD57-E8BD4D45C4F7} - System32\Tasks\BackUp_Maker-Tom => C:\Program Files (x86)\ASCOMP Software\BackUp Maker\bkmaker.exe [2014-01-09] (ASCOMP Software GmbH) Task: {C9E6890F-70E7-4214-B20D-111CA576E2A8} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2013-11-20] (Apple Inc.) Task: {F3E5DE26-4BB8-49D5-9BF1-68E72833F2C1} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Tom-PC-Tom Tom-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2014-01-23] (Microsoft Corporation) Task: {F4168010-FA3D-46D5-B04A-264F14845B25} - System32\Tasks\SUPERAntiSpyware Scheduled Task 13035c2d-b95d-493c-9312-35cd61ea82ce => C:\PROGRAM FILES\SUPERANTISPYWARE\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {F798FBD0-798C-4656-929E-B014C4F10402} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2247641735-418790473-2961746829-1000Core.job => C:\Users\Tom\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2247641735-418790473-2961746829-1000UA.job => C:\Users\Tom\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 13035c2d-b95d-493c-9312-35cd61ea82ce.job => C:\PROGRAM FILES\SUPERANTISPYWARE\SASTask.exe Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task cce553f9-8238-4e2e-a8b4-6a9da503768f.job => C:\PROGRAM FILES\SUPERANTISPYWARE\SASTask.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-27 21:45 - 2014-01-27 21:45 - 00710976 _____ () C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2013-12-19 09:35 - 2013-12-19 09:35 - 01475584 _____ () C:\Program Files (x86)\Monosnap\Monosnap.exe 2009-10-14 12:36 - 2009-10-14 12:36 - 02793304 _____ () C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe 2008-07-04 11:38 - 2008-07-04 11:38 - 00065536 _____ () C:\Brother\BPRSP\resources\BrSupSsp.exe 2009-10-14 12:34 - 2009-10-14 12:34 - 00560472 _____ () C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe 2013-12-18 19:43 - 2013-12-18 19:43 - 00105984 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\de_de\PDFMaker\PDFMOfficeAddin.DEU 2013-11-24 10:50 - 2013-09-06 14:36 - 00425984 _____ () C:\Program Files\Microsoft Office\Office15\ADDINS\Citavi Word AddIn\SwissAcademic.RegularExpressions.dll 2012-10-01 17:56 - 2012-10-01 17:56 - 00240256 _____ () C:\Program Files\Microsoft Office\Office15\IEAWSDC.DLL 2014-02-21 10:43 - 2014-02-20 02:02 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\chrome_elf.dll 2014-02-11 20:29 - 2014-02-11 20:29 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2014-02-21 10:43 - 2014-02-20 02:02 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\libglesv2.dll 2014-02-21 10:43 - 2014-02-20 02:02 - 00100168 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\libegl.dll 2014-02-26 16:56 - 2014-02-26 16:56 - 00041984 _____ () c:\users\tom\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp8a4j02.dll 2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Tom\AppData\Roaming\Dropbox\bin\libcef.dll 2013-12-18 19:43 - 2013-12-18 19:43 - 00019968 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\acrotray.deu 2014-02-21 10:43 - 2014-02-20 02:03 - 04060488 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\pdf.dll 2014-02-21 10:43 - 2014-02-20 02:03 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll 2014-02-21 10:43 - 2014-02-20 02:02 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ffmpegsumo.dll 2014-01-21 05:24 - 2014-01-21 05:24 - 00433664 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll 2014-01-21 05:24 - 2014-01-21 05:24 - 00315392 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll 2014-02-11 14:39 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll 2014-02-21 10:43 - 2014-02-20 02:03 - 13632840 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll 2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 13:16 - 2014-01-20 13:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-02-24 11:08 - 2014-02-24 11:08 - 00358400 _____ () C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\alelhddbbhepgpmgidjdcjakblofbmce\3.6.7_0\plugins\screen_capture.dll 2014-02-27 14:48 - 2014-02-27 09:30 - 00088392 _____ () C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\35.0.1862.2\chrome_elf.dll 2014-02-27 14:48 - 2014-02-27 09:30 - 00673608 _____ () C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\35.0.1862.2\libglesv2.dll 2014-02-27 14:48 - 2014-02-27 09:30 - 00093000 _____ () C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\35.0.1862.2\libegl.dll 2014-02-27 14:49 - 2014-02-27 09:30 - 04083016 _____ () C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\35.0.1862.2\pdf.dll 2014-02-27 14:49 - 2014-02-27 09:30 - 00390472 _____ () C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\35.0.1862.2\ppGoogleNaClPluginChrome.dll 2014-02-27 14:48 - 2014-02-27 09:30 - 01647432 _____ () C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\35.0.1862.2\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: iCloudServices => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (02/27/2014 03:15:54 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: googledrivesync.exe, Version: 1.14.6059.644, Zeitstempel: 0x509418e4 Name des fehlerhaften Moduls: pyexpat.pyd, Version: 0.0.0.0, Zeitstempel: 0x524dc281 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00011140 ID des fehlerhaften Prozesses: 0x2038 Startzeit der fehlerhaften Anwendung: 0xgoogledrivesync.exe0 Pfad der fehlerhaften Anwendung: googledrivesync.exe1 Pfad des fehlerhaften Moduls: googledrivesync.exe2 Berichtskennung: googledrivesync.exe3 Error: (02/27/2014 00:14:20 PM) (Source: MsiInstaller) (User: Tom-PC) Description: Produkt: QuickTime 7 -- Fehler 1303. Die Rechte von Installer reichen nicht aus, um auf diesen Ordner zuzugreifen: C:\Program Files (x86)\QuickTime. Die Installation kann nicht fortgesetzt werden. Melden Sie sich als Administrator an oder wenden Sie sich an den Systemadministrator. Error: (02/27/2014 00:04:58 PM) (Source: MsiInstaller) (User: Tom-PC) Description: Produkt: QuickTime 7 -- Fehler 1303. Die Rechte von Installer reichen nicht aus, um auf diesen Ordner zuzugreifen: C:\Program Files (x86)\QuickTime. Die Installation kann nicht fortgesetzt werden. Melden Sie sich als Administrator an oder wenden Sie sich an den Systemadministrator. Error: (02/27/2014 10:42:42 AM) (Source: MsiInstaller) (User: Tom-PC) Description: Produkt: QuickTime 7 -- Fehler 1303. Die Rechte von Installer reichen nicht aus, um auf diesen Ordner zuzugreifen: C:\Program Files (x86)\QuickTime. Die Installation kann nicht fortgesetzt werden. Melden Sie sich als Administrator an oder wenden Sie sich an den Systemadministrator. Error: (02/27/2014 10:19:27 AM) (Source: MsiInstaller) (User: Tom-PC) Description: Produkt: QuickTime 7 -- Fehler 1303. Die Rechte von Installer reichen nicht aus, um auf diesen Ordner zuzugreifen: C:\Program Files (x86)\QuickTime. Die Installation kann nicht fortgesetzt werden. Melden Sie sich als Administrator an oder wenden Sie sich an den Systemadministrator. Error: (02/27/2014 09:36:46 AM) (Source: Microsoft-Windows-RestartManager) (User: Tom-PC) Description: Die Anwendung oder der Dienst "Google Chrome" konnte nicht heruntergefahren werden. Error: (02/27/2014 04:11:59 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 8128 Error: (02/27/2014 04:11:59 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 8128 Error: (02/27/2014 04:11:59 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (02/27/2014 04:11:58 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7129 System errors: ============= Error: (02/27/2014 04:06:23 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (02/27/2014 04:06:20 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (02/27/2014 04:05:09 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (02/27/2014 04:04:22 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (02/27/2014 04:04:19 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (02/27/2014 04:03:52 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (02/27/2014 04:03:05 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (02/27/2014 04:03:02 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (02/27/2014 04:02:29 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (02/27/2014 04:01:32 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Microsoft Office Sessions: ========================= Error: (02/27/2014 03:15:54 PM) (Source: Application Error)(User: ) Description: googledrivesync.exe1.14.6059.644509418e4pyexpat.pyd0.0.0.0524dc281c000000500011140203801cf330b5c2eca20C:\Program Files (x86)\Google\Drive\googledrivesync.exeC:\Users\Tom\AppData\Local\Temp\_MEI41882\pyexpat.pydaa9c2e83-9fb9-11e3-b2b1-6cf0495c76c3 Error: (02/27/2014 00:14:20 PM) (Source: MsiInstaller)(User: Tom-PC) Description: Produkt: QuickTime 7 -- Fehler 1303. Die Rechte von Installer reichen nicht aus, um auf diesen Ordner zuzugreifen: C:\Program Files (x86)\QuickTime. Die Installation kann nicht fortgesetzt werden. Melden Sie sich als Administrator an oder wenden Sie sich an den Systemadministrator.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (02/27/2014 00:04:58 PM) (Source: MsiInstaller)(User: Tom-PC) Description: Produkt: QuickTime 7 -- Fehler 1303. Die Rechte von Installer reichen nicht aus, um auf diesen Ordner zuzugreifen: C:\Program Files (x86)\QuickTime. Die Installation kann nicht fortgesetzt werden. Melden Sie sich als Administrator an oder wenden Sie sich an den Systemadministrator.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (02/27/2014 10:42:42 AM) (Source: MsiInstaller)(User: Tom-PC) Description: Produkt: QuickTime 7 -- Fehler 1303. Die Rechte von Installer reichen nicht aus, um auf diesen Ordner zuzugreifen: C:\Program Files (x86)\QuickTime. Die Installation kann nicht fortgesetzt werden. Melden Sie sich als Administrator an oder wenden Sie sich an den Systemadministrator.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (02/27/2014 10:19:27 AM) (Source: MsiInstaller)(User: Tom-PC) Description: Produkt: QuickTime 7 -- Fehler 1303. Die Rechte von Installer reichen nicht aus, um auf diesen Ordner zuzugreifen: C:\Program Files (x86)\QuickTime. Die Installation kann nicht fortgesetzt werden. Melden Sie sich als Administrator an oder wenden Sie sich an den Systemadministrator.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (02/27/2014 09:36:46 AM) (Source: Microsoft-Windows-RestartManager)(User: Tom-PC) Description: 1C:\Program Files (x86)\Google\Chrome\Application\chrome.exeGoogle Chrome0211734920 Error: (02/27/2014 04:11:59 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 8128 Error: (02/27/2014 04:11:59 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 8128 Error: (02/27/2014 04:11:59 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (02/27/2014 04:11:58 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7129 ==================== Memory info =========================== Percentage of memory in use: 34% Total physical RAM: 6142.49 MB Available physical RAM: 4053.76 MB Total Pagefile: 12283.16 MB Available Pagefile: 9051.06 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:596.17 GB) (Free:424.63 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (Firma) (Fixed) (Total:298.09 GB) (Free:158.53 GB) NTFS Drive f: (Audio) (Fixed) (Total:596.07 GB) (Free:46.15 GB) NTFS Drive g: (27 Jun 2013) (CDROM) (Total:0.38 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 69C4CD3C) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=596 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: E39CE39C) Partition: GPT Partition Type. ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 51A83C9B) Partition 1: (Active) - (Size=596 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
27.02.2014, 16:46 | #4 |
| Tastatur setzt aus oder Buchstaben mehrfachFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-02-2014 02 Ran by Tom (administrator) on TOM-PC on 27-02-2014 16:33:00 Running from C:\Users\Tom\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (SUPERAntiSpyware.com) C:\PROGRAM FILES\SUPERANTISPYWARE\SASCORE64.EXE (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe (Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe (ASCOMP Software GmbH) C:\Program Files (x86)\ASCOMP Software\BackUp Maker\bkmaker.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE () C:\Program Files (x86)\Monosnap\Monosnap.exe (Spotify Ltd) C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Update\1.3.22.5\GoogleCrashHandler.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Update\1.3.22.5\GoogleCrashHandler64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe () C:\Brother\BPRSP\resources\BrSupSsp.exe (Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Dropbox, Inc.) C:\Users\Tom\AppData\Roaming\Dropbox\bin\Dropbox.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe (Windows Net) C:\Users\Tom\AppData\Roaming\Windows Net Data\net.exe (Logitech(c)) C:\Program Files\Logitech\Z Cinema\Z Cinema.exe (Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe () C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google) C:\Users\Tom\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\WINWORD.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe (Google Inc.) C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-03] (Adobe Systems Incorporated) HKLM\...\Run: [Fences] - C:\Program Files (x86)\Stardock\Fences\Fences.exe [4017368 2012-10-29] (Stardock Corporation) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936 2013-10-24] (Realtek Semiconductor) HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-07-31] (Logitech, Inc.) HKLM-x32\...\Run: [LogitechQuickCamRibbon] - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2793304 2009-10-14] () HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-25] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2013-12-18] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2013-12-18] (Adobe Systems Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Syncios device service] - C:\Program Files (x86)\Syncios\SynciosDeviceService.exe [723456 2013-12-03] () HKLM-x32\...\Run: [ControlCenter4] - C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.) HKLM-x32\...\Run: [IndexSearch] - C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46952 2011-08-02] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PaperPort PTD] - C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [30568 2011-08-02] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PDFHook] - C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PDF5 Registry Controller] - C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKU\S-1-5-19\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-20\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\Run: [Google Update] - C:\Users\Tom\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-04-02] (Google Inc.) HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\Run: [Monosnap] - C:\Program Files (x86)\Monosnap\Monosnap.exe [1475584 2013-12-19] () HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\Run: [Spotify Web Helper] - C:\Users\Tom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-04] (Spotify Ltd) HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\Run: [Spotify] - C:\Users\Tom\AppData\Roaming\Spotify\spotify.exe [5951488 2013-12-04] (Spotify Ltd) HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\Run: [GoogleChromeAutoLaunch_DB6F457BBD5E7DEE255E89C53530C548] - C:\Users\Tom\AppData\Local\Google\Chrome SxS\Application\chrome.exe [850248 2014-02-27] (Google Inc.) HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google) HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\Run: [MusicManager] - C:\Users\Tom\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7380992 2013-11-12] (Google Inc.) HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\Run: [GoogleChromeAutoLaunch_F6A43803F41C0EE8AA9068339E55A010] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [859464 2014-02-20] (Google Inc.) HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\Run: [SUPERAntiSpyware] - C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE [6563608 2014-01-06] (SUPERAntiSpyware) HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\Run: [9919C2326C0CBD6C8225179850E066432A2C85FF._service_run] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [859464 2014-02-20] (Google Inc.) HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-2247641735-418790473-2961746829-1000\...\MountPoints2: {b05acc00-9bd4-11e2-9a13-6cf0495c76c3} - H:\SETUP.EXE Startup: C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Tom\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Fences.lnk ShortcutTarget: Fences.lnk -> C:\Program Files (x86)\Stardock\Fences\Fences.exe (Stardock Corporation) Startup: C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk ShortcutTarget: Logitech . Produktregistrierung.lnk -> C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech) Startup: C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\Tom\AppData\Roaming\Windows Net Data\net.exe (Windows Net) Startup: C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Persbackup.lnk ShortcutTarget: Persbackup.lnk -> C:\Program Files\Personal Backup 5\Persbackup.exe (No File) Startup: C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Z Cinema.lnk ShortcutTarget: Z Cinema.lnk -> C:\Users\Tom\AppData\Roaming\Microsoft\Installer\{6E166235-49F3-4DFA-A102-1E86675ABD11}\StartupShortcut_6E16623549F34DFAA1021E86675ABD11.exe (Macrovision Corporation) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: IEOptimizer - {10AD2C61-0898-4348-8600-14A342F22AC3} - C:\Program Files (x86)\SavingsBull\IEOptimizer.dll () BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation) BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\3rcnvioq.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Tom\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Tom\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Tom\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Tom\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Tom\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Users\Tom\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Tom\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin ProgramFiles/Appdata: C:\Users\Tom\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-04-14] FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2013-11-24] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-02-10] Chrome: ======= CHR HomePage: hxxp://www.google.de/ CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.1.377\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\pdf.dll () CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll No File CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll No File CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll No File CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll No File CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll No File CHR Plugin: (Microsoft Office 2013) - C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (AdobeExManDetect) - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office 2013) - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Google Update) - C:\Users\Tom\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll No File CHR Plugin: (Google Talk Plugin) - C:\Users\Tom\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Tom\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Tom\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) CHR Extension: (Google Translate) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2013-06-15] CHR Extension: (Google Präsentationen) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-01-14] CHR Extension: (Magic Actions for YouTube™) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2013-06-15] CHR Extension: (Monosnap) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciopjigkkgbpbijaoialognoidodden [2013-06-15] CHR Extension: (ChromeAccess) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeoigbhkilbllfomkmmilbfochhlgdmh [2014-02-18] CHR Extension: (BIODIGITAL HUMAN) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\agoenciogemlojlhccbcpcfflicgnaak [2013-06-15] CHR Extension: (No Name) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\alelhddbbhepgpmgidjdcjakblofbmce [2014-02-26] CHR Extension: (Google Drive) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-06-15] CHR Extension: (BeFunky Photo Editor) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\apfkepiiddolifkgjmfdgpnipgnfejab [2013-06-15] CHR Extension: (Google Groups) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfmbadcfdhiklafcdohpfphhhakmiakk [2013-06-15] CHR Extension: (Kontaktkarte) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bialhhdohbeamjgokicedgcpanocohkf [2014-01-27] CHR Extension: (Shoptimate : Sofort Preise vergleichen) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bibdombdcdbbnfdjkaajfgnfhlapibde [2014-01-27] CHR Extension: (HootSuite Hootlet) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjgfdlplhmndoonmofmflcbiohgbkifn [2013-06-15] CHR Extension: (James White) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm [2013-06-15] CHR Extension: (YouTube) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-15] CHR Extension: (Pushbullet) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2014-02-01] CHR Extension: (Auf den Amazon-Wunschzettel) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciagpekplgpbepdgggflgmahnjgiaced [2013-06-15] CHR Extension: (Webseiten-Screenshot - Webpage Screenshot) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckibcdccnfeookdmbahgiakhnjcddpki [2013-06-15] CHR Extension: (Google-Suche) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-15] CHR Extension: (Search by Image (by Google)) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2014-01-21] CHR Extension: (FullContact beta) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddgjmcgnlpnolanedjohjkfelpmepiob [2014-01-27] CHR Extension: (Cloud Save) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlbemabjbfhjcccahjioenmkgimjbbkd [2013-06-15] CHR Extension: (Google News) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllkocilcinkggkchnjgegijklcililc [2013-06-15] CHR Extension: (Google+) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2014-01-14] CHR Extension: (Google+ - Optimizer) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\edknapjhmlocokbpbihilmjmfmmddhop [2014-01-20] CHR Extension: (backgroundPage) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2014-01-14] CHR Extension: (Google Kalender) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2013-06-15] CHR Extension: (YoWindow Wetter) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\fanogbnclpilemkifpjeglokomebpnef [2013-06-15] CHR Extension: (Cloudy for Gmail™) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfnjfpcmnoabmbhponbioedjceaddaa [2013-06-15] CHR Extension: (Google Tabellen) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-01-14] CHR Extension: (Bookmarks Button) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffieaadkkhencgelmgbbmkkipeocbcbg [2013-06-15] CHR Extension: (PicMonkey) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm [2014-02-14] CHR Extension: (Springpad) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkmopoamfjnmppabeaphohombnjcjgla [2013-06-15] CHR Extension: (EasyDrop) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\flogpfmjdekjoilcnmmchanikomlidie [2013-06-15] CHR Extension: (Planetarium) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp [2013-06-15] CHR Extension: (LastPass: Free Password Manager) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2013-06-15] CHR Extension: (PDF Mergy) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgecghmkcdefnknohcimkoemhaofpoha [2014-01-14] CHR Extension: (Feedly - News, Blogs and Youtube) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\hipbfijinpcgfogaopmgehiegacbhmob [2013-06-15] CHR Extension: (Google Keep) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2014-01-14] CHR Extension: (bitly | ♥ your bitmarks) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic [2013-06-15] CHR Extension: (goo.gl URL Shortener) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblijlcdoidgdpfknkckljiocdbnlagk [2013-06-15] CHR Extension: (Clearly) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\iooicodkiihhpojmmeghjclgihfjdjhj [2013-06-15] CHR Extension: (Panel View for Keep) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\jccocffecajimkdjgfpjhlpiimcnadhb [2013-08-01] CHR Extension: (Google Formulare) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhknlonaankphkkbnmjdlpehkinifeeg [2014-01-14] CHR Extension: (Pocket Website) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\jijgclgmgjipgefcnnnibgllfonlfdap [2013-06-15] CHR Extension: (Hangouts-Anruf) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbpgddbgniojgndnhlkjbkpknjhppkbk [2013-06-15] CHR Extension: (WordPress.com) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\khjnjifipfkgglficmipimgjpbmlbemd [2013-06-15] CHR Extension: (HootSuite) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\kneloppijbcidgidihgdjnooihjcdbij [2013-06-15] CHR Extension: (Google Play) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2014-01-14] CHR Extension: (Evernote Web) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2013-06-15] CHR Extension: (Webcam Toy) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2013-06-15] CHR Extension: (Google Maps) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2013-06-15] CHR Extension: (Music for every moment - Spotify) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhfhbkmihfcbjcoimalmefbkbbepaloj [2013-06-15] CHR Extension: (Google Zeichnungen) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkaakpdehdafacodkgkpghoibnmamcme [2014-01-14] CHR Extension: (DieBuchSuche) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncgbefchahjnmlmcmadlfiigkflfefnk [2014-01-27] CHR Extension: (feedly) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndhinffkekpekljifjkkkkkhopnjodja [2013-06-15] CHR Extension: (Jolidrive) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfakdllpdfjjbfommlcnfkedmbigkfdo [2013-06-15] CHR Extension: (Pocket (formerly Read It Later)) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2013-06-15] CHR Extension: (Google Wallet) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21] CHR Extension: (Personal Blocklist (by Google)) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nolijncfnkgaikbjbdaogikpmpbdcdef [2013-06-15] CHR Extension: (Better History) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\obciceimmggglbmelaidpjlmodcebijb [2013-06-15] CHR Extension: (Adblock Pro) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2014-02-02] CHR Extension: (Citavi Picker) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2014-02-17] CHR Extension: (Print Friendly & PDF) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlencieiipommannpdfcmfdpjjmeolj [2013-06-15] CHR Extension: (Big G Black Bar Sorter) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiamgkpplhllmgmjkmpoapkidpgfhmdo [2013-06-15] CHR Extension: (Click&Clean App) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2013-12-16] CHR Extension: (Fusion Tables in Google Drive (experimentell)) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfoeakahkgllhkommkfeehmkfcloagkl [2014-01-14] CHR Extension: (Facebook Smileys) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfofcadoijmdpaaimobiilheegfmhama [2013-12-20] CHR Extension: (Evernote Web Clipper) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2013-06-15] CHR Extension: (Google Mail) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-15] CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - C:\Program Files (x86)\Citavi 4\Pickers\Chrome\ChromePicker.crx [2014-02-07] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\PROGRAM FILES\SUPERANTISPYWARE\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com) R2 Level Quality Watcher; C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe [710976 2014-01-27] () R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [145256 2011-08-02] (Nuance Communications, Inc.) S2 updatesvca; C:\Windows\system32\updatesvca.dll [209920 2013-04-20] (Digital Dynamic) ==================== Drivers (Whitelisted) ==================== S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1x64.sys [28008 2012-12-13] (Windows (R) Win 7 DDK provider) R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S1 UimBus; C:\Windows\System32\DRIVERS\uimx64.sys [90960 2013-03-15] (Windows (R) 2000 DDK provider) S1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633680 2013-03-15] (Paragon) S1 Uim_VIM; C:\Windows\System32\Drivers\uim_vimx64.sys [390352 2013-03-15] (Paragon) S3 ZCinema_TSHD_x64; C:\Windows\System32\drivers\ZCinema_SRS_amd64.sys [21648 2007-08-22] (SRS Labs, Inc.) S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-27 16:33 - 2014-02-27 16:33 - 00042039 _____ () C:\Users\Tom\Desktop\FRST.txt 2014-02-27 16:31 - 2014-02-27 16:33 - 00000000 ____D () C:\FRST 2014-02-27 16:30 - 2014-02-27 16:30 - 02155520 _____ (Farbar) C:\Users\Tom\Desktop\FRST64.exe 2014-02-27 14:37 - 2014-02-27 14:37 - 00078254 _____ () C:\Users\Tom\Desktop\Extras.Txt 2014-02-27 14:36 - 2014-02-27 14:36 - 00181324 _____ () C:\Users\Tom\Desktop\OTL.Txt 2014-02-27 14:20 - 2014-02-27 14:21 - 00602112 _____ (OldTimer Tools) C:\Users\Tom\Desktop\OTL.exe 2014-02-27 10:30 - 2014-02-27 10:30 - 00001821 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-02-27 10:28 - 2014-02-27 10:30 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-02-27 10:28 - 2014-02-27 10:30 - 00000000 ____D () C:\Program Files\iTunes 2014-02-27 10:28 - 2014-02-27 10:29 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-02-27 10:28 - 2014-02-27 10:28 - 00000000 ____D () C:\Program Files\iPod 2014-02-26 14:41 - 2014-02-26 14:41 - 00923423 _____ () C:\Users\Tom\Downloads\BrIfax420.exe 2014-02-25 21:23 - 2014-02-25 21:23 - 00001185 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-02-25 21:23 - 2014-02-25 21:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-25 20:37 - 2014-02-27 09:30 - 00000336 _____ () C:\Windows\setupact.log 2014-02-25 20:37 - 2014-02-25 20:37 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-25 20:36 - 2014-02-26 16:28 - 00007068 _____ () C:\Windows\PFRO.log 2014-02-25 20:32 - 2014-02-25 20:32 - 00045938 _____ () C:\Users\Tom\Documents\cc_20140225_203215.reg 2014-02-25 20:32 - 2014-02-25 20:32 - 00001044 _____ () C:\Users\Tom\Documents\cc_20140225_203239.reg 2014-02-25 20:21 - 2014-02-25 20:21 - 00002768 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-02-25 20:21 - 2014-02-25 20:21 - 00000860 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-25 20:21 - 2014-02-25 20:21 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-25 20:19 - 2014-02-25 20:20 - 04765152 _____ (Piriform Ltd) C:\Users\Tom\Downloads\ccsetup411.exe 2014-02-25 20:18 - 2014-02-25 20:18 - 00000119 _____ () C:\Users\Tom\Downloads\WRC_Report.txt 2014-02-25 20:07 - 2014-01-09 03:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-02-25 20:07 - 2014-01-03 23:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-02-25 20:03 - 2014-02-25 20:03 - 00283256 _____ (Mozilla) C:\Users\Tom\Downloads\Firefox Setup Stub 27.0.1.exe 2014-02-24 18:03 - 2014-02-24 18:03 - 00105805 _____ () C:\Users\Tom\Downloads\IMG_219987461219887.jpeg 2014-02-24 13:17 - 2014-02-24 13:17 - 00000000 ____D () C:\Users\Tom\Downloads\705f528c9cd05_karma_401 2014-02-24 13:11 - 2014-02-24 13:15 - 38905170 _____ () C:\Users\Tom\Downloads\705f528c9cd05_karma_401.rar 2014-02-21 16:17 - 2014-02-22 07:30 - 00000000 ____D () C:\Program Files (x86)\SavingsBull 2014-02-21 08:14 - 2014-02-21 08:14 - 17858952 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-02-20 16:36 - 2014-02-21 10:21 - 00000000 ____D () C:\Users\Tom\Documents\WISO Mein Geld 2014-02-20 16:36 - 2014-02-20 16:36 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Buhl Data Service GmbH 2014-02-20 16:36 - 2014-02-20 16:36 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Buhl Data Service 2014-02-20 16:36 - 2014-02-20 16:36 - 00000000 ____D () C:\Users\Tom\AppData\Local\Buhl Data Service 2014-02-20 16:34 - 2014-02-20 16:36 - 00000000 ____D () C:\ProgramData\Buhl Data Service GmbH 2014-02-20 16:34 - 2014-02-20 16:34 - 00001227 _____ () C:\Users\Public\Desktop\WISO Mein Geld 2014.lnk 2014-02-20 16:34 - 2014-02-20 16:34 - 00000000 ____D () C:\Program Files (x86)\Buhl 2014-02-20 16:31 - 2014-02-20 16:32 - 91304056 _____ (Buhl Data Service GmbH) C:\Users\Tom\Downloads\WISOMeinGeldTrial2014.exe 2014-02-20 14:08 - 2014-02-20 14:09 - 00000000 ____D () C:\Users\Tom\Documents\Anke Iphone 2014-02-20 12:32 - 2014-02-20 12:39 - 20432776 _____ () C:\Users\Tom\Downloads\3941404369_Acabu_Leben_1_2009.rar 2014-02-20 11:37 - 2014-02-26 21:07 - 00005104 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Tom-PC-Tom Tom-PC 2014-02-20 09:30 - 2010-10-31 13:38 - 00000000 ____D () C:\Users\Tom\Downloads\Borderline Grenzposten PDF 2014-02-20 09:28 - 2014-02-20 09:30 - 08957434 _____ () C:\Users\Tom\Downloads\Borderline Grenzposten PDF.rar 2014-02-20 08:46 - 2014-02-27 09:30 - 00000506 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task cce553f9-8238-4e2e-a8b4-6a9da503768f.job 2014-02-20 08:46 - 2014-02-27 02:00 - 00000506 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 13035c2d-b95d-493c-9312-35cd61ea82ce.job 2014-02-20 08:46 - 2014-02-20 08:46 - 00003572 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 13035c2d-b95d-493c-9312-35cd61ea82ce 2014-02-20 08:46 - 2014-02-20 08:46 - 00003498 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task cce553f9-8238-4e2e-a8b4-6a9da503768f 2014-02-20 08:46 - 2014-02-20 08:46 - 00001846 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2014-02-20 08:46 - 2014-02-20 08:46 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\SUPERAntiSpyware.com 2014-02-20 08:46 - 2014-02-20 08:46 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com 2014-02-20 08:46 - 2014-02-20 08:46 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware 2014-02-20 08:37 - 2014-02-20 08:37 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-02-18 10:40 - 2014-02-18 10:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_wpdcomp_01_09_00.Wdf 2014-02-18 10:13 - 2014-02-18 10:13 - 00001249 _____ () C:\Users\Public\Desktop\ALDI NORD Bestellsoftware.lnk 2014-02-18 10:09 - 2014-02-18 10:12 - 00000000 ____D () C:\Program Files (x86)\ALDI NORD Bestellsoftware 2014-02-18 10:01 - 2014-02-18 10:01 - 00000000 ____D () C:\Users\Tom\Documents\Eigene PaperPort-Dokumente 2014-02-18 10:01 - 2014-02-18 10:01 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Zeon 2014-02-18 07:44 - 2014-02-20 08:33 - 00002268 _____ () C:\Users\Tom\Desktop\Rkill.txt 2014-02-18 07:19 - 2014-02-20 08:38 - 00000000 ____D () C:\Program Files\SavingsbullFilter 2014-02-18 07:19 - 2014-02-18 07:45 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-02-18 07:19 - 2014-02-18 07:19 - 00000000 ____D () C:\Program Files\Level Quality Watcher 2014-02-18 07:11 - 2014-02-18 07:11 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\vlc 2014-02-18 07:00 - 2014-02-18 07:00 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\FLEXnet 2014-02-17 21:10 - 2014-02-17 21:10 - 00000000 ____D () C:\MATS 2014-02-17 20:57 - 2014-02-17 20:57 - 00002985 _____ () C:\Users\Anke\Downloads\Kreditkartenabrechnung-2014-01-29.csv 2014-02-17 20:47 - 2014-02-17 20:47 - 00002945 _____ () C:\Users\Anke\Downloads\Kreditkartenumsätze-2014-02-17.csv 2014-02-17 19:30 - 2014-02-17 19:30 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\Logitech 2014-02-17 19:30 - 2014-02-17 19:30 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\ControlCenter4 2014-02-17 11:49 - 2014-02-17 11:49 - 00000000 ____D () C:\Program Files\Nuance 2014-02-17 11:48 - 2014-02-17 11:48 - 00000000 ____D () C:\ProgramData\zeon 2014-02-17 11:43 - 2014-02-18 10:01 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Nuance 2014-02-17 11:43 - 2014-02-17 11:43 - 00000000 ____D () C:\ProgramData\ScanSoft 2014-02-17 11:42 - 2014-02-17 13:02 - 00000000 ____D () C:\ProgramData\Nuance 2014-02-17 11:42 - 2014-02-17 11:48 - 00000000 ____D () C:\Program Files (x86)\Nuance 2014-02-17 11:42 - 2014-02-17 11:42 - 00000000 ____D () C:\Users\Tom\Documents\MeineWebSeiten 2014-02-17 11:42 - 2014-02-17 11:42 - 00000000 ____D () C:\ProgramData\FLEXnet 2014-02-17 11:39 - 2014-02-17 11:39 - 00000000 ____D () C:\Program Files (x86)\Brother Industries, Ltd 2014-02-17 11:35 - 2014-02-17 11:35 - 00000000 ____D () C:\Users\Tom\Downloads\PP12Downloader 2014-02-17 11:19 - 2014-02-17 11:19 - 00000000 _____ () C:\Users\Tom\Sti_Trace.log 2014-02-17 11:01 - 2014-02-17 11:01 - 00115361 _____ () C:\Users\Tom\Downloads\1207_dina4_dinnorm50081.dotx 2014-02-17 09:45 - 2014-02-17 09:45 - 00002038 _____ () C:\Users\Public\Desktop\FileZilla Client.lnk 2014-02-15 20:16 - 2013-07-15 03:13 - 00000000 ____D () C:\Users\Tom\Downloads\sugar_skulls 2014-02-15 18:51 - 2014-02-15 20:16 - 258837526 _____ () C:\Users\Tom\Downloads\AvaxHo.Me-sugar_skulls.rar 2014-02-14 16:02 - 2014-02-25 21:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-13 21:37 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-02-13 21:37 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-02-13 21:37 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-02-13 21:37 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-02-13 21:37 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-02-13 21:37 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-02-13 21:37 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-02-13 21:37 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-02-13 21:37 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-02-13 21:37 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-02-13 21:37 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-02-13 21:37 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-02-13 21:37 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-02-13 21:37 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-02-13 21:37 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-02-13 21:37 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-02-13 21:32 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 21:32 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-13 21:31 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 21:31 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 21:31 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-13 21:31 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 21:31 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 21:31 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 21:31 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 21:31 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 21:31 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-13 21:31 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 21:31 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 21:31 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 21:31 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 21:31 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 21:31 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 21:31 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 21:31 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 21:31 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 21:31 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 21:31 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 21:31 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 21:31 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 21:31 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 21:31 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 21:31 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-13 21:31 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 21:31 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 21:31 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 21:31 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 21:31 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 21:31 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 21:31 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 21:31 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 21:31 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 21:31 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 21:31 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 21:31 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 21:31 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 21:31 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 21:30 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-02-13 21:30 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-02-13 11:46 - 2014-02-13 12:11 - 00000000 ____D () C:\Users\Tom\Downloads\Frances, Allen - Normal 2014-02-13 11:44 - 2014-02-13 11:46 - 04850267 _____ () C:\Users\Tom\Downloads\FranNorm.rar 2014-02-13 09:54 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-13 09:54 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-13 09:54 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-13 09:54 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-13 09:54 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-13 09:54 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-13 09:53 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-13 09:53 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-13 09:53 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-13 09:53 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-13 09:53 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-13 09:53 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-13 09:53 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-13 09:53 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-13 09:53 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-13 09:53 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-13 09:53 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-13 09:53 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-13 09:53 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-13 09:53 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-13 09:53 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-13 09:53 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-13 09:53 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-13 09:53 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-13 09:53 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-13 09:53 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-13 09:53 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-13 09:53 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-11 14:51 - 2014-02-26 14:06 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\ControlCenter4 2014-02-11 14:43 - 2014-02-11 14:43 - 00002178 _____ () C:\Users\Public\Desktop\Brother Creative Center.lnk 2014-02-11 14:43 - 2014-02-11 14:43 - 00000258 _____ () C:\Windows\Brpfx04a.ini 2014-02-11 14:43 - 2014-02-11 14:43 - 00000064 _____ () C:\Windows\brpcfx.ini 2014-02-11 14:40 - 2014-02-12 08:22 - 00000000 ____D () C:\Brother 2014-02-11 14:40 - 2014-02-11 14:40 - 00000066 _____ () C:\Windows\Brfaxrx.ini 2014-02-11 14:40 - 2014-02-11 14:40 - 00000000 ____D () C:\Users\Public\Documents\BrFaxRx 2014-02-11 14:40 - 2014-02-11 14:40 - 00000000 ____D () C:\ProgramData\ControlCenter4 2014-02-11 14:40 - 2014-02-11 14:40 - 00000000 ____D () C:\Program Files (x86)\ControlCenter4 2014-02-11 14:40 - 2014-02-11 14:40 - 00000000 ____D () C:\Program Files (x86)\Browny02 2014-02-11 14:40 - 2012-07-31 08:39 - 01439744 _____ (Brother Industries, Ltd.) C:\Windows\system32\BrWi209d.dll 2014-02-11 14:40 - 2012-07-05 12:32 - 00084480 _____ (Brother Industries, Ltd.) C:\Windows\system32\BrNetSti.dll 2014-02-11 14:40 - 2012-03-19 05:09 - 00316928 _____ (brother) C:\Windows\system32\NSSRH64.dll 2014-02-11 14:40 - 2010-09-23 09:14 - 00058880 _____ (Brother Industries,Ltd.) C:\Windows\system32\BrWiaNCp.dll 2014-02-11 14:40 - 2010-09-23 09:13 - 00051712 _____ (Brother Industries,Ltd) C:\Windows\system32\Brnsplg.dll 2014-02-11 14:40 - 2010-05-10 09:45 - 00103736 _____ (Brother Industries Ltd) C:\Windows\SysWOW64\BRRBTOOL.EXE 2014-02-11 14:40 - 2010-04-01 11:27 - 00278528 _____ (Brother Industries, Ltd.) C:\Windows\system32\BrJDec.dll 2014-02-11 14:40 - 2009-12-08 16:19 - 00290304 ____N (Brother Industries, Ltd.) C:\Windows\system32\BrfxDA5c.dll 2014-02-11 14:40 - 2005-04-22 05:36 - 00143360 _____ () C:\Windows\system32\BrSNMP64.dll 2014-02-11 14:40 - 2005-01-17 08:10 - 00045056 _____ () C:\Windows\SysWOW64\BRTCPCON.DLL 2014-02-11 14:40 - 2003-11-28 18:57 - 00000000 _____ () C:\Windows\brdfxspd.dat 2014-02-11 14:39 - 2012-09-10 16:31 - 00245760 ____N (brother) C:\Windows\SysWOW64\NSSearch.dll 2014-02-11 14:39 - 2012-07-09 17:19 - 00005120 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2S.dll 2014-02-11 14:39 - 2012-06-05 07:59 - 00025299 _____ (Brother Industries, Ltd) C:\Windows\SysWOW64\BRLM03A.DLL 2014-02-11 14:39 - 2010-03-15 19:45 - 00073728 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2.dll 2014-02-11 14:39 - 2010-02-05 03:42 - 00180224 _____ (Brother Industries, Ltd.) C:\Windows\SysWOW64\BROSNMP.DLL 2014-02-11 14:39 - 2007-12-13 22:16 - 00005632 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2L.dll 2014-02-11 14:39 - 2004-08-09 08:00 - 00000114 _____ () C:\Windows\SysWOW64\BRLMW03A.INI 2014-02-11 14:39 - 2004-08-09 07:42 - 00077824 _____ (Brother Industries, Ltd.) C:\Windows\SysWOW64\BRLMW03A.DLL 2014-02-11 14:39 - 1999-10-26 17:00 - 00000050 _____ () C:\Windows\system32\BRADM10A.DAT 2014-02-11 14:38 - 2014-02-11 14:38 - 00000055 _____ () C:\Windows\SysWOW64\BRDM7460DN.DAT 2014-02-11 14:37 - 2014-02-11 14:43 - 00000000 ____D () C:\ProgramData\Brother 2014-02-11 14:37 - 2014-02-11 14:37 - 00000000 ____D () C:\Users\Tom\Downloads\install 2014-02-11 12:30 - 2014-02-17 11:40 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0 2014-02-10 18:19 - 2014-02-10 18:21 - 00002411 _____ () C:\Windows\SysWOW64\lgAxconfig.ini 2014-02-10 18:19 - 2014-02-10 18:20 - 00000000 ____D () C:\ProgramData\LGMOBILEAX 2014-02-10 18:19 - 2014-02-10 18:19 - 00000869 _____ () C:\Users\Tom\Desktop\LGMobile Support Tool.lnk 2014-02-10 18:19 - 2011-05-06 19:37 - 00655872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr90.dll 2014-02-10 18:19 - 2011-05-06 19:37 - 00568832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp90.dll 2014-02-10 18:19 - 2011-05-06 19:37 - 00224768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcm90.dll 2014-02-10 18:19 - 2006-04-30 14:33 - 00053248 _____ () C:\Windows\SysWOW64\CommonDL.dll 2014-02-10 18:19 - 2005-09-30 07:39 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml4a.dll 2014-02-10 08:22 - 2014-02-10 08:22 - 00000000 ____D () C:\Users\Public\Documents\Logishrd 2014-02-10 08:21 - 2014-02-10 08:21 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2014-02-10 08:19 - 2014-02-10 08:22 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Logitech 2014-02-10 08:19 - 2014-02-10 08:19 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Logishrd 2014-02-04 10:32 - 2014-02-04 10:32 - 00000000 ____D () C:\PCWELT 2014-02-04 07:46 - 2014-02-04 07:46 - 00001047 _____ () C:\Users\Public\Desktop\Anti-Twin.lnk 2014-02-04 07:46 - 2014-02-04 07:46 - 00000000 ____D () C:\Program Files (x86)\AntiTwin 2014-02-03 18:14 - 2014-02-03 21:17 - 00000000 ____D () C:\Users\Tom\Downloads\Lexmark_X54x 2014-02-03 10:58 - 2014-02-13 12:25 - 00000000 ____D () C:\Users\Tom\AppData\Local\calibre-cache 2014-02-03 10:57 - 2014-02-13 16:47 - 00000000 ____D () C:\Users\Tom\Documents\Calibre-Bibliothek 2014-02-03 10:57 - 2014-02-13 12:24 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\calibre 2014-02-03 10:57 - 2014-02-10 10:19 - 00000998 _____ () C:\Users\Public\Desktop\calibre - E-book management.lnk 2014-02-03 10:56 - 2014-02-10 10:19 - 00000000 ____D () C:\Program Files (x86)\Calibre2 2014-02-03 10:52 - 2014-02-26 13:37 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Windows Net Data 2014-02-02 12:10 - 2014-02-03 21:17 - 00000000 ____D () C:\Users\Tom\Downloads\pd123w550avt64ger 2014-02-02 12:09 - 2014-02-11 15:44 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Brother 2014-02-02 12:09 - 2014-02-02 12:09 - 00002028 _____ () C:\Users\Public\Desktop\P-touch Update Software.lnk 2014-02-02 12:08 - 2014-02-17 12:00 - 00000000 ____D () C:\Program Files (x86)\Brother 2014-02-02 12:08 - 2014-02-02 12:08 - 00001909 _____ () C:\Users\Public\Desktop\P-touch Editor 5.1.lnk 2014-02-02 12:08 - 2014-02-02 12:08 - 00000000 ____D () C:\Program Files (x86)\MSECache 2014-01-31 14:04 - 2014-01-22 16:02 - 00000000 ____D () C:\Users\Tom\Downloads\ff5frehor 2014-01-31 13:11 - 2014-01-31 14:04 - 161147863 _____ () C:\Users\Tom\Downloads\ff5frehor.rar 2014-01-30 16:22 - 2014-01-30 16:22 - 00000000 ____D () C:\Users\Anke\AppData\Local\Stardock_Corporation 2014-01-30 16:21 - 2014-02-21 11:03 - 00123784 _____ () C:\Users\Anke\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-30 16:21 - 2014-01-30 16:21 - 00001459 _____ () C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ___RD () C:\Users\Anke\Virtual Machines 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ___RD () C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ___RD () C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\Syncios 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\Stardock 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\ATI 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\Apple Computer 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\Adobe 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Local\DFX 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Local\ATI 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Local\Adobe 2014-01-30 16:20 - 2014-01-30 16:24 - 00000000 ____D () C:\Users\Anke\AppData\Local\Google 2014-01-30 16:20 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke 2014-01-30 16:20 - 2014-01-30 16:20 - 00000020 ___SH () C:\Users\Anke\ntuser.ini 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Vorlagen 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Startmenü 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Netzwerkumgebung 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Lokale Einstellungen 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Eigene Dateien 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Druckumgebung 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Documents\Eigene Musik 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Documents\Eigene Bilder 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\AppData\Local\Verlauf 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\AppData\Local\Anwendungsdaten 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Anwendungsdaten 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 ____D () C:\Users\Anke\AppData\Local\VirtualStore 2014-01-30 16:20 - 2013-04-05 02:41 - 00000000 ____D () C:\Users\Anke\AppData\Local\Microsoft Help 2014-01-30 16:20 - 2013-04-03 01:08 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\Macromedia 2014-01-30 16:20 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-01-30 16:20 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-01-30 09:38 - 2014-01-30 09:39 - 03546568 _____ () C:\Users\Tom\Downloads\JeJKr-Ihassdiverlass.rar 2014-01-29 17:15 - 2014-01-29 17:15 - 00000000 ____D () C:\Users\Tom\Downloads\downthemall-2.0.16.xpi 2014-01-29 15:36 - 2014-01-29 15:36 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\DropboxMaster 2014-01-29 14:25 - 2012-08-19 16:17 - 00000000 ____D () C:\Users\Tom\Downloads\Ostfront-Ave_Maria-DE-2012-NGE 2014-01-29 10:49 - 2014-01-23 23:38 - 00000000 ____D () C:\Users\Tom\Downloads\Ost+Front - Olympia (Deluxe Edition) (2014) 2014-01-29 10:09 - 2014-01-29 10:09 - 02421200 _____ () C:\Users\Tom\Downloads\3642026664_..BWStatistik.rar 2014-01-28 14:19 - 2014-02-03 21:17 - 00000000 ____D () C:\Users\Tom\Downloads\Medina_Welcome To Medina 2014-01-28 14:18 - 2014-01-28 14:19 - 62982085 _____ () C:\Users\Tom\Downloads\AL-Med-WelToMed.rar 2014-01-28 12:16 - 2014-01-28 12:16 - 00001742 _____ () C:\Users\Tom\Desktop\Wörterbücher - Verknüpfung.lnk ==================== One Month Modified Files and Folders ======= 2014-02-27 16:33 - 2014-02-27 16:33 - 00042039 _____ () C:\Users\Tom\Desktop\FRST.txt 2014-02-27 16:33 - 2014-02-27 16:31 - 00000000 ____D () C:\FRST 2014-02-27 16:30 - 2014-02-27 16:30 - 02155520 _____ (Farbar) C:\Users\Tom\Desktop\FRST64.exe 2014-02-27 16:14 - 2013-12-09 19:39 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-27 16:10 - 2013-04-02 15:05 - 01447357 _____ () C:\Windows\WindowsUpdate.log 2014-02-27 15:45 - 2013-04-03 11:05 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2247641735-418790473-2961746829-1000UA.job 2014-02-27 15:44 - 2013-04-02 18:18 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-27 15:03 - 2014-01-10 16:03 - 00000000 ____D () C:\Program Files (x86)\Syncios 2014-02-27 14:49 - 2013-04-03 11:05 - 00002394 _____ () C:\Users\Tom\Desktop\Google Chrome Canary.lnk 2014-02-27 14:44 - 2013-04-02 20:50 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Dropbox 2014-02-27 14:37 - 2014-02-27 14:37 - 00078254 _____ () C:\Users\Tom\Desktop\Extras.Txt 2014-02-27 14:36 - 2014-02-27 14:36 - 00181324 _____ () C:\Users\Tom\Desktop\OTL.Txt 2014-02-27 14:21 - 2014-02-27 14:20 - 00602112 _____ (OldTimer Tools) C:\Users\Tom\Desktop\OTL.exe 2014-02-27 10:30 - 2014-02-27 10:30 - 00001821 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-02-27 10:30 - 2014-02-27 10:28 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-02-27 10:30 - 2014-02-27 10:28 - 00000000 ____D () C:\Program Files\iTunes 2014-02-27 10:29 - 2014-02-27 10:28 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-02-27 10:28 - 2014-02-27 10:28 - 00000000 ____D () C:\Program Files\iPod 2014-02-27 10:19 - 2013-05-23 18:05 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-02-27 09:36 - 2013-04-03 01:48 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Mozilla 2014-02-27 09:30 - 2014-02-25 20:37 - 00000336 _____ () C:\Windows\setupact.log 2014-02-27 09:30 - 2014-02-20 08:46 - 00000506 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task cce553f9-8238-4e2e-a8b4-6a9da503768f.job 2014-02-27 09:30 - 2013-04-02 15:35 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs 2014-02-27 02:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-02-27 02:00 - 2014-02-20 08:46 - 00000506 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 13035c2d-b95d-493c-9312-35cd61ea82ce.job 2014-02-27 02:00 - 2013-04-03 00:54 - 00000000 ____D () C:\Users\Tom\AppData\Local\Adobe 2014-02-26 21:07 - 2014-02-20 11:37 - 00005104 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Tom-PC-Tom Tom-PC 2014-02-26 20:29 - 2013-12-01 20:39 - 00000000 ___RD () C:\Users\Tom\Google Drive 2014-02-26 20:25 - 2013-04-03 11:05 - 00001060 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2247641735-418790473-2961746829-1000Core.job 2014-02-26 20:19 - 2013-04-02 18:18 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-26 16:58 - 2013-04-02 20:58 - 00000000 ___RD () C:\Users\Tom\Dropbox 2014-02-26 16:57 - 2013-04-03 17:14 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Spotify 2014-02-26 16:56 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\FxsTmp 2014-02-26 16:36 - 2009-07-14 05:45 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-26 16:36 - 2009-07-14 05:45 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-26 16:28 - 2014-02-25 20:36 - 00007068 _____ () C:\Windows\PFRO.log 2014-02-26 16:28 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-26 14:41 - 2014-02-26 14:41 - 00923423 _____ () C:\Users\Tom\Downloads\BrIfax420.exe 2014-02-26 14:06 - 2014-02-11 14:51 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\ControlCenter4 2014-02-26 13:37 - 2014-02-03 10:52 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Windows Net Data 2014-02-26 12:55 - 2013-04-20 10:51 - 00000000 ____D () C:\Users\Tom\Documents\Benutzerdefinierte Office-Vorlagen 2014-02-26 07:37 - 2013-04-02 18:17 - 00123784 _____ () C:\Users\Tom\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-26 07:37 - 2009-07-14 05:45 - 05106728 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-26 07:34 - 2013-04-05 01:36 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-02-26 07:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-02-25 21:23 - 2014-02-25 21:23 - 00001185 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-02-25 21:23 - 2014-02-25 21:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-25 21:23 - 2014-02-14 16:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-25 20:37 - 2014-02-25 20:37 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-25 20:32 - 2014-02-25 20:32 - 00045938 _____ () C:\Users\Tom\Documents\cc_20140225_203215.reg 2014-02-25 20:32 - 2014-02-25 20:32 - 00001044 _____ () C:\Users\Tom\Documents\cc_20140225_203239.reg 2014-02-25 20:26 - 2014-01-09 13:03 - 00000000 ____D () C:\Windows\Minidump 2014-02-25 20:26 - 2013-04-02 16:02 - 00000000 ____D () C:\Windows\Panther 2014-02-25 20:21 - 2014-02-25 20:21 - 00002768 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-02-25 20:21 - 2014-02-25 20:21 - 00000860 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-25 20:21 - 2014-02-25 20:21 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-25 20:20 - 2014-02-25 20:19 - 04765152 _____ (Piriform Ltd) C:\Users\Tom\Downloads\ccsetup411.exe 2014-02-25 20:18 - 2014-02-25 20:18 - 00000119 _____ () C:\Users\Tom\Downloads\WRC_Report.txt 2014-02-25 20:03 - 2014-02-25 20:03 - 00283256 _____ (Mozilla) C:\Users\Tom\Downloads\Firefox Setup Stub 27.0.1.exe 2014-02-24 19:53 - 2013-04-03 10:10 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\FileZilla 2014-02-24 18:03 - 2014-02-24 18:03 - 00105805 _____ () C:\Users\Tom\Downloads\IMG_219987461219887.jpeg 2014-02-24 13:17 - 2014-02-24 13:17 - 00000000 ____D () C:\Users\Tom\Downloads\705f528c9cd05_karma_401 2014-02-24 13:15 - 2014-02-24 13:11 - 38905170 _____ () C:\Users\Tom\Downloads\705f528c9cd05_karma_401.rar 2014-02-24 12:22 - 2014-01-13 10:23 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\vlc 2014-02-22 07:30 - 2014-02-21 16:17 - 00000000 ____D () C:\Program Files (x86)\SavingsBull 2014-02-21 11:03 - 2014-01-30 16:21 - 00123784 _____ () C:\Users\Anke\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-21 10:58 - 2013-04-14 16:08 - 00000000 ____D () C:\Users\Tom\Documents\Citavi 4 2014-02-21 10:45 - 2013-04-04 02:12 - 00001456 _____ () C:\Users\Tom\AppData\Local\Adobe Für Web speichern 13.0 Prefs 2014-02-21 10:21 - 2014-02-20 16:36 - 00000000 ____D () C:\Users\Tom\Documents\WISO Mein Geld 2014-02-21 08:14 - 2014-02-21 08:14 - 17858952 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-02-21 08:14 - 2013-12-09 19:39 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-21 08:14 - 2013-12-09 19:39 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-21 08:14 - 2013-12-09 19:39 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-20 16:36 - 2014-02-20 16:36 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Buhl Data Service GmbH 2014-02-20 16:36 - 2014-02-20 16:36 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Buhl Data Service 2014-02-20 16:36 - 2014-02-20 16:36 - 00000000 ____D () C:\Users\Tom\AppData\Local\Buhl Data Service 2014-02-20 16:36 - 2014-02-20 16:34 - 00000000 ____D () C:\ProgramData\Buhl Data Service GmbH 2014-02-20 16:34 - 2014-02-20 16:34 - 00001227 _____ () C:\Users\Public\Desktop\WISO Mein Geld 2014.lnk 2014-02-20 16:34 - 2014-02-20 16:34 - 00000000 ____D () C:\Program Files (x86)\Buhl 2014-02-20 16:32 - 2014-02-20 16:31 - 91304056 _____ (Buhl Data Service GmbH) C:\Users\Tom\Downloads\WISOMeinGeldTrial2014.exe 2014-02-20 14:09 - 2014-02-20 14:08 - 00000000 ____D () C:\Users\Tom\Documents\Anke Iphone 2014-02-20 12:39 - 2014-02-20 12:32 - 20432776 _____ () C:\Users\Tom\Downloads\3941404369_Acabu_Leben_1_2009.rar 2014-02-20 09:30 - 2014-02-20 09:28 - 08957434 _____ () C:\Users\Tom\Downloads\Borderline Grenzposten PDF.rar 2014-02-20 09:26 - 2013-04-02 22:38 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2014-02-20 08:46 - 2014-02-20 08:46 - 00003572 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 13035c2d-b95d-493c-9312-35cd61ea82ce 2014-02-20 08:46 - 2014-02-20 08:46 - 00003498 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task cce553f9-8238-4e2e-a8b4-6a9da503768f 2014-02-20 08:46 - 2014-02-20 08:46 - 00001846 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2014-02-20 08:46 - 2014-02-20 08:46 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\SUPERAntiSpyware.com 2014-02-20 08:46 - 2014-02-20 08:46 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com 2014-02-20 08:46 - 2014-02-20 08:46 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware 2014-02-20 08:38 - 2014-02-18 07:19 - 00000000 ____D () C:\Program Files\SavingsbullFilter 2014-02-20 08:37 - 2014-02-20 08:37 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-02-20 08:33 - 2014-02-18 07:44 - 00002268 _____ () C:\Users\Tom\Desktop\Rkill.txt 2014-02-18 17:29 - 2013-04-02 18:18 - 00000000 ____D () C:\Users\Tom\AppData\Local\Google 2014-02-18 10:40 - 2014-02-18 10:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_wpdcomp_01_09_00.Wdf 2014-02-18 10:13 - 2014-02-18 10:13 - 00001249 _____ () C:\Users\Public\Desktop\ALDI NORD Bestellsoftware.lnk 2014-02-18 10:12 - 2014-02-18 10:09 - 00000000 ____D () C:\Program Files (x86)\ALDI NORD Bestellsoftware 2014-02-18 10:01 - 2014-02-18 10:01 - 00000000 ____D () C:\Users\Tom\Documents\Eigene PaperPort-Dokumente 2014-02-18 10:01 - 2014-02-18 10:01 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Zeon 2014-02-18 10:01 - 2014-02-17 11:43 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Nuance 2014-02-18 07:45 - 2014-02-18 07:19 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-02-18 07:19 - 2014-02-18 07:19 - 00000000 ____D () C:\Program Files\Level Quality Watcher 2014-02-18 07:19 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-02-18 07:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-02-18 07:18 - 2013-11-30 09:05 - 00000000 ____D () C:\Program Files (x86)\spotimote 2014-02-18 07:18 - 2013-04-17 18:05 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Spotydl 2014-02-18 07:11 - 2014-02-18 07:11 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\vlc 2014-02-18 07:00 - 2014-02-18 07:00 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\FLEXnet 2014-02-17 21:10 - 2014-02-17 21:10 - 00000000 ____D () C:\MATS 2014-02-17 21:09 - 2013-04-03 00:34 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Skype 2014-02-17 20:57 - 2014-02-17 20:57 - 00002985 _____ () C:\Users\Anke\Downloads\Kreditkartenabrechnung-2014-01-29.csv 2014-02-17 20:47 - 2014-02-17 20:47 - 00002945 _____ () C:\Users\Anke\Downloads\Kreditkartenumsätze-2014-02-17.csv 2014-02-17 19:30 - 2014-02-17 19:30 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\Logitech 2014-02-17 19:30 - 2014-02-17 19:30 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\ControlCenter4 2014-02-17 13:02 - 2014-02-17 11:42 - 00000000 ____D () C:\ProgramData\Nuance 2014-02-17 12:00 - 2014-02-02 12:08 - 00000000 ____D () C:\Program Files (x86)\Brother 2014-02-17 11:49 - 2014-02-17 11:49 - 00000000 ____D () C:\Program Files\Nuance 2014-02-17 11:48 - 2014-02-17 11:48 - 00000000 ____D () C:\ProgramData\zeon 2014-02-17 11:48 - 2014-02-17 11:42 - 00000000 ____D () C:\Program Files (x86)\Nuance 2014-02-17 11:43 - 2014-02-17 11:43 - 00000000 ____D () C:\ProgramData\ScanSoft 2014-02-17 11:42 - 2014-02-17 11:42 - 00000000 ____D () C:\Users\Tom\Documents\MeineWebSeiten 2014-02-17 11:42 - 2014-02-17 11:42 - 00000000 ____D () C:\ProgramData\FLEXnet 2014-02-17 11:40 - 2014-02-11 12:30 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0 2014-02-17 11:39 - 2014-02-17 11:39 - 00000000 ____D () C:\Program Files (x86)\Brother Industries, Ltd 2014-02-17 11:35 - 2014-02-17 11:35 - 00000000 ____D () C:\Users\Tom\Downloads\PP12Downloader 2014-02-17 11:19 - 2014-02-17 11:19 - 00000000 _____ () C:\Users\Tom\Sti_Trace.log 2014-02-17 11:19 - 2013-04-02 15:10 - 00000000 ____D () C:\Users\Tom 2014-02-17 11:01 - 2014-02-17 11:01 - 00115361 _____ () C:\Users\Tom\Downloads\1207_dina4_dinnorm50081.dotx 2014-02-17 09:45 - 2014-02-17 09:45 - 00002038 _____ () C:\Users\Public\Desktop\FileZilla Client.lnk 2014-02-17 09:45 - 2013-04-03 00:38 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-02-17 09:24 - 2013-11-24 10:50 - 00001987 _____ () C:\Users\Public\Desktop\Citavi 4.lnk 2014-02-17 09:24 - 2013-04-14 16:01 - 00000000 ____D () C:\ProgramData\Swiss Academic Software 2014-02-17 09:22 - 2013-04-14 15:58 - 00000000 ____D () C:\Users\Tom\AppData\Local\Downloaded Installations 2014-02-15 20:16 - 2014-02-15 18:51 - 258837526 _____ () C:\Users\Tom\Downloads\AvaxHo.Me-sugar_skulls.rar 2014-02-15 18:39 - 2013-04-02 18:18 - 00004100 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-15 18:39 - 2013-04-02 18:18 - 00003848 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-13 21:40 - 2013-07-11 10:39 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-13 21:38 - 2013-04-02 16:36 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-13 21:33 - 2013-04-14 15:47 - 01596372 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-13 21:33 - 2011-04-12 08:43 - 00700986 _____ () C:\Windows\system32\perfh007.dat 2014-02-13 21:33 - 2011-04-12 08:43 - 00149886 _____ () C:\Windows\system32\perfc007.dat 2014-02-13 21:33 - 2009-07-14 06:13 - 01596372 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-13 19:31 - 2013-04-14 16:08 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Swiss Academic Software 2014-02-13 17:16 - 2013-04-02 15:10 - 00000000 ___RD () C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-13 16:47 - 2014-02-03 10:57 - 00000000 ____D () C:\Users\Tom\Documents\Calibre-Bibliothek 2014-02-13 12:25 - 2014-02-03 10:58 - 00000000 ____D () C:\Users\Tom\AppData\Local\calibre-cache 2014-02-13 12:24 - 2014-02-03 10:57 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\calibre 2014-02-13 12:11 - 2014-02-13 11:46 - 00000000 ____D () C:\Users\Tom\Downloads\Frances, Allen - Normal 2014-02-13 11:46 - 2014-02-13 11:44 - 04850267 _____ () C:\Users\Tom\Downloads\FranNorm.rar 2014-02-12 08:22 - 2014-02-11 14:40 - 00000000 ____D () C:\Brother 2014-02-11 15:44 - 2014-02-02 12:09 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Brother 2014-02-11 14:43 - 2014-02-11 14:43 - 00002178 _____ () C:\Users\Public\Desktop\Brother Creative Center.lnk 2014-02-11 14:43 - 2014-02-11 14:43 - 00000258 _____ () C:\Windows\Brpfx04a.ini 2014-02-11 14:43 - 2014-02-11 14:43 - 00000064 _____ () C:\Windows\brpcfx.ini 2014-02-11 14:43 - 2014-02-11 14:37 - 00000000 ____D () C:\ProgramData\Brother 2014-02-11 14:40 - 2014-02-11 14:40 - 00000066 _____ () C:\Windows\Brfaxrx.ini 2014-02-11 14:40 - 2014-02-11 14:40 - 00000000 ____D () C:\Users\Public\Documents\BrFaxRx 2014-02-11 14:40 - 2014-02-11 14:40 - 00000000 ____D () C:\ProgramData\ControlCenter4 2014-02-11 14:40 - 2014-02-11 14:40 - 00000000 ____D () C:\Program Files (x86)\ControlCenter4 2014-02-11 14:40 - 2014-02-11 14:40 - 00000000 ____D () C:\Program Files (x86)\Browny02 2014-02-11 14:39 - 2013-04-02 19:51 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-02-11 14:38 - 2014-02-11 14:38 - 00000055 _____ () C:\Windows\SysWOW64\BRDM7460DN.DAT 2014-02-11 14:37 - 2014-02-11 14:37 - 00000000 ____D () C:\Users\Tom\Downloads\install 2014-02-10 18:40 - 2013-04-03 11:05 - 00004078 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2247641735-418790473-2961746829-1000UA 2014-02-10 18:40 - 2013-04-03 11:05 - 00003682 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2247641735-418790473-2961746829-1000Core 2014-02-10 18:21 - 2014-02-10 18:19 - 00002411 _____ () C:\Windows\SysWOW64\lgAxconfig.ini 2014-02-10 18:20 - 2014-02-10 18:19 - 00000000 ____D () C:\ProgramData\LGMOBILEAX 2014-02-10 18:19 - 2014-02-10 18:19 - 00000869 _____ () C:\Users\Tom\Desktop\LGMobile Support Tool.lnk 2014-02-10 10:19 - 2014-02-03 10:57 - 00000998 _____ () C:\Users\Public\Desktop\calibre - E-book management.lnk 2014-02-10 10:19 - 2014-02-03 10:56 - 00000000 ____D () C:\Program Files (x86)\Calibre2 2014-02-10 08:22 - 2014-02-10 08:22 - 00000000 ____D () C:\Users\Public\Documents\Logishrd 2014-02-10 08:22 - 2014-02-10 08:19 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Logitech 2014-02-10 08:21 - 2014-02-10 08:21 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2014-02-10 08:21 - 2013-04-02 15:36 - 00000000 ____D () C:\ProgramData\LogiShrd 2014-02-10 08:21 - 2013-04-02 15:35 - 00000000 ____D () C:\Program Files\Common Files\logishrd 2014-02-10 08:20 - 2013-04-02 15:36 - 00000000 ____D () C:\Program Files\Logitech 2014-02-10 08:19 - 2014-02-10 08:19 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Logishrd 2014-02-10 08:10 - 2013-05-06 10:58 - 00000000 ____D () C:\Program Files\Lexmark 2014-02-07 14:56 - 2013-04-06 22:48 - 00000000 ____D () C:\ProgramData\Monosnap 2014-02-06 13:16 - 2014-02-13 21:31 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-13 21:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-13 21:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-13 21:31 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-13 21:31 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-13 21:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-13 21:31 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-13 21:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-13 21:31 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-13 21:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-13 21:31 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-13 21:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-13 21:31 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-13 21:31 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-13 21:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-13 21:31 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-13 21:31 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-13 21:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-13 21:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-13 21:31 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-13 21:31 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-13 21:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-13 21:31 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-13 21:31 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-13 21:31 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-13 21:31 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-13 21:31 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-13 21:31 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-13 21:31 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-13 21:31 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-13 21:31 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-13 21:31 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-13 21:31 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-13 21:31 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-13 21:31 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-13 21:31 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-13 21:31 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-13 21:31 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-13 21:31 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-04 10:32 - 2014-02-04 10:32 - 00000000 ____D () C:\PCWELT 2014-02-04 07:46 - 2014-02-04 07:46 - 00001047 _____ () C:\Users\Public\Desktop\Anti-Twin.lnk 2014-02-04 07:46 - 2014-02-04 07:46 - 00000000 ____D () C:\Program Files (x86)\AntiTwin 2014-02-03 21:19 - 2013-04-21 02:15 - 00000000 ____D () C:\Users\Tom\Downloads\RS3 ENGLISCH (Amerikanisch US, Level 1-5, inkl. Audio Begleiter) 2014-02-03 21:17 - 2014-02-03 18:14 - 00000000 ____D () C:\Users\Tom\Downloads\Lexmark_X54x 2014-02-03 21:17 - 2014-02-02 12:10 - 00000000 ____D () C:\Users\Tom\Downloads\pd123w550avt64ger 2014-02-03 21:17 - 2014-01-28 14:19 - 00000000 ____D () C:\Users\Tom\Downloads\Medina_Welcome To Medina 2014-02-03 21:17 - 2013-12-31 19:49 - 00000000 ____D () C:\Users\Tom\Downloads\Pink Floyd_Wish You Were Here (Experience Edition) 2014-02-03 21:17 - 2013-04-14 23:01 - 00000000 ____D () C:\Users\Tom\Downloads\Rosetta Stone TOTALe v 4.1.15 Windown 2014-02-02 12:09 - 2014-02-02 12:09 - 00002028 _____ () C:\Users\Public\Desktop\P-touch Update Software.lnk 2014-02-02 12:08 - 2014-02-02 12:08 - 00001909 _____ () C:\Users\Public\Desktop\P-touch Editor 5.1.lnk 2014-02-02 12:08 - 2014-02-02 12:08 - 00000000 ____D () C:\Program Files (x86)\MSECache 2014-02-02 12:08 - 2013-04-05 01:36 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-01-31 14:04 - 2014-01-31 13:11 - 161147863 _____ () C:\Users\Tom\Downloads\ff5frehor.rar 2014-01-30 16:24 - 2014-01-30 16:20 - 00000000 ____D () C:\Users\Anke\AppData\Local\Google 2014-01-30 16:22 - 2014-01-30 16:22 - 00000000 ____D () C:\Users\Anke\AppData\Local\Stardock_Corporation 2014-01-30 16:21 - 2014-01-30 16:21 - 00001459 _____ () C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ___RD () C:\Users\Anke\Virtual Machines 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ___RD () C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ___RD () C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\Syncios 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\Stardock 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\ATI 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\Apple Computer 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Roaming\Adobe 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Local\DFX 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Local\ATI 2014-01-30 16:21 - 2014-01-30 16:21 - 00000000 ____D () C:\Users\Anke\AppData\Local\Adobe 2014-01-30 16:21 - 2014-01-30 16:20 - 00000000 ____D () C:\Users\Anke 2014-01-30 16:20 - 2014-01-30 16:20 - 00000020 ___SH () C:\Users\Anke\ntuser.ini 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Vorlagen 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Startmenü 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Netzwerkumgebung 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Lokale Einstellungen 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Eigene Dateien 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Druckumgebung 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Documents\Eigene Musik 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Documents\Eigene Bilder 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\AppData\Local\Verlauf 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\AppData\Local\Anwendungsdaten 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 _SHDL () C:\Users\Anke\Anwendungsdaten 2014-01-30 16:20 - 2014-01-30 16:20 - 00000000 ____D () C:\Users\Anke\AppData\Local\VirtualStore 2014-01-30 09:39 - 2014-01-30 09:38 - 03546568 _____ () C:\Users\Tom\Downloads\JeJKr-Ihassdiverlass.rar 2014-01-29 17:15 - 2014-01-29 17:15 - 00000000 ____D () C:\Users\Tom\Downloads\downthemall-2.0.16.xpi 2014-01-29 15:36 - 2014-01-29 15:36 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\DropboxMaster 2014-01-29 15:36 - 2013-04-02 20:58 - 00001009 _____ () C:\Users\Tom\Desktop\Dropbox.lnk 2014-01-29 15:36 - 2013-04-02 20:51 - 00000000 ____D () C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-29 10:09 - 2014-01-29 10:09 - 02421200 _____ () C:\Users\Tom\Downloads\3642026664_..BWStatistik.rar 2014-01-28 14:19 - 2014-01-28 14:18 - 62982085 _____ () C:\Users\Tom\Downloads\AL-Med-WelToMed.rar 2014-01-28 12:16 - 2014-01-28 12:16 - 00001742 _____ () C:\Users\Tom\Desktop\Wörterbücher - Verknüpfung.lnk Some content of TEMP: ==================== C:\Users\Tom\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp8a4j02.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-21 02:03 ==================== End Of Log ============================ |
28.02.2014, 19:52 | #5 |
/// the machine /// TB-Ausbilder | Tastatur setzt aus oder Buchstaben mehrfach hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Tastatur setzt aus oder Buchstaben mehrfach |
64bit, alter, andere, anderen, anschlag, bat, batterie, buchstaben, gigabyte, größe, hochladen, komplett, konnte, link, logfiles, logitech, mehrfach, setzt, tastatur, test, treiber, verwendet |