|
Log-Analyse und Auswertung: C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werdenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
05.08.2014, 10:53 | #1 |
| C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werden bräuchte bitte eure Hilfe für mein Problem Frst und addition habe ich im Anhang hochgeladen Danke schon mal im Voraus |
05.08.2014, 11:07 | #2 |
/// the machine /// TB-Ausbilder | C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werden Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. Ich kann auf Arbeit keine Anhänge öffnen, danke. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
05.08.2014, 17:26 | #3 |
| C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werdenCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-08-2014 Ran by Michael at 2014-08-05 11:43:35 Running from C:\Users\Michael\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Lavasoft Ad-Aware (Enabled - Up to date) {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Lavasoft Ad-Aware (Enabled - Up to date) {5BB89C30-6480-BC7C-9F17-199BD76F557A} FW: Lavasoft Ad-Aware (Disabled) {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) clear.fi SDK - Video 2 (x32 Version: 2.1.1925 - CyberLink Corp.) Hidden clear.fi SDK- Movie 2 (x32 Version: 2.1.2008 - CyberLink Corp.) Hidden 1&1 EasyLogin (HKLM-x32\...\1&1 EasyLogin) (Version: - ) 1&1 Upload-Manager (HKLM-x32\...\1&1 Upload-Manager) (Version: 2.0.676 - 1&1 Internet AG) 7+ Taskbar Tweaker v4.2.4 (HKCU\...\7 Taskbar Tweaker) (Version: 4.2.4 - RaMMicHaeL) AAVUpdateManager (HKLM-x32\...\{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}) (Version: 18.00.0000 - Wolters Kluwer Deutschland GmbH) ACDSee Pro 6 (HKLM\...\{CAF674E0-808C-4CF4-8868-A755EBABA228}) (Version: 6.1.197 - ACD Systems International Inc.) Acer Backup Manager (HKLM-x32\...\InstallShield_{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}) (Version: 4.0.0.0059 - NTI Corporation) Acer Device Fast-lane (HKLM\...\{3F62D2FD-13C1-49A2-8B5D-47623D9460D7}) (Version: 1.00.3007 - Acer Incorporated) Acer Instant Update Service (HKLM\...\{8215A318-CC27-435E-B3EA-2E3443C8998C}) (Version: 1.00.3013 - Acer Incorporated) Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.3006 - Acer Incorporated) Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.3011 - Acer Incorporated) AcerCloud (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 2.01.3115 - Acer Incorporated) AcerCloud Docs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.00.3201 - Acer Incorporated) Ad-Aware Antivirus (HKLM-x32\...\{944167EA-7F89-4705-8DCD-1D63B53141B0}) (Version: 10.5.3.4405 - Lavasoft) Ad-Aware Browsing Protection (HKLM-x32\...\Ad-Aware Browsing Protection) (Version: 1.0.1.106 - Lavasoft) Ad-Aware Security Add-on (HKLM-x32\...\adawaretb) (Version: 2.5.0.6 - Lavasoft) Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.6 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.2.6 - Adobe Systems Incorporated) Hidden Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Photoshop Lightroom 5.2 64-bit (HKLM\...\{54E6C675-3AD4-42E4-957F-31666ABF1603}) (Version: 5.2.1 - Adobe) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Apple Application Support (HKLM-x32\...\{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}) (Version: 3.0.5 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Ashampoo Burning Studio 12 v.12.0.5 (HKLM-x32\...\{91B33C97-93EB-244C-F687-71D85E45A206}_is1) (Version: 12.0.5 - Ashampoo GmbH & Co. KG) Ashampoo GetBack Photo v.1.0.1 (HKLM-x32\...\Ashampoo GetBack Photo_is1) (Version: 1.0.1 - Ashampoo GmbH & Co. KG) Ashampoo WinOptimizer 10 v.10.2.0 (HKLM-x32\...\{4209F371-88D4-AB00-ED2B-D6520C84D9D5}_is1) (Version: 10.02.00 - Ashampoo GmbH & Co. KG) Atheros Outlook Addin 2010 (HKCU\...\C74B42DAD40776B5A47FF77AE67D68DC289ADFC1) (Version: 1.0.0.0 - Microsoft) Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team) Avery Wizard 5.0 (HKLM\...\{FC3B3A5D-7058-4627-9F1E-F95CC38B6054}) (Version: 5.0.5 - Avery) Avira (HKLM-x32\...\{142be4a8-895b-4ed9-b1ff-11c76357e3df}) (Version: 1.1.17.31000 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.17.31000 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.6.552 - Avira) Backup Manager v4 (x32 Version: 4.0.0.0059 - NTI Corporation) Hidden Benutzerhandbuch anzeigen (HKLM-x32\...\View User Guide) (Version: 3.60.43.0 - ) Bing Maps 3D (HKLM\...\{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}) (Version: 4.0.903.16005 - Microsoft Corporation) BitLord 2.1 (HKLM-x32\...\BitLord) (Version: 2.1.0-74 - House of Life) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Broadcom Card Reader Driver Installer (HKLM\...\{F0A7DF2F-0BE0-470F-B137-D7A19F977189}) (Version: 15.4.7.1 - Broadcom Corporation) CacheStats (HKLM-x32\...\{85118178-54A5-4107-85A3-F23FD4AD239B}) (Version: 3.0.10 - LogicWeave) calibre 64bit (HKLM\...\{C7530E59-3196-4EFD-A7EE-C0BFD80026BC}) (Version: 1.46.0 - Kovid Goyal) CCleaner (HKLM-x32\...\CCleaner) (Version: 2.32 - Piriform) CheckDrive (HKLM-x32\...\{B83513EC-2E4D-4621-816D-4CCF397BE702}_is1) (Version: 4.4 - Abelssoft) CloneCD (HKLM-x32\...\CloneCD) (Version: - SlySoft) CloneDVD2 (HKLM-x32\...\CloneDVD2) (Version: 2.9.3.0 - Elaborate Bytes) Common Desktop Agent (Version: 1.62.0 - OEM) Hidden Content Manager 2 (HKLM-x32\...\Content Manager 2) (Version: 3.18.0.342250 - NNG Llc.) Cross+A (Deutsch) (HKLM-x32\...\Cross+A (Deutsch)) (Version: 8.28.0.1056 - Sergey Kutasov, Ilya Morozov) CyberLink MediaEspresso 6.5 (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.3103_44819 - CyberLink Corp.) CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3103_44819 - CyberLink Corp.) Hidden Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{043645C8-48EC-458F-B9BD-9C8F15CEF6F7}) (Version: - Microsoft) Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D1C35197-B856-45E2-BA67-5ABB6B0CA9C2}) (Version: - Microsoft) DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.8000.13 - Dolby Laboratories Inc) eBay Worldwide (HKLM-x32\...\{A694AF57-9891-4D62-824C-7E55A1361A14}) (Version: 2.3.0630 - OEM) ETDWare PS/2-X64 11.6.9.001_WHQL (HKLM\...\Elantech) (Version: 11.6.9.001 - ELAN Microelectronic Corp.) Exif-Viewer 2.51 (HKLM-x32\...\Exif-Viewer) (Version: 2.51 - Ralf Bibinger) File Type Advisor 1.4 (HKLM-x32\...\File Type Advisor_is1) (Version: - filetypeadvisor.com) FinePrint (HKLM\...\FinePrint) (Version: 6.25 - FinePrint Software, LLC) Free M4a to MP3 Converter 8.1 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com) Free YouTube Download version 3.2.2.430 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.2.430 - DVDVideoSoft Ltd.) Freizeitkarte_ESP (Ausgabe 14.05) (HKLM-x32\...\Freizeitkarte_ESP) (Version: - ) Garmin BaseCamp (HKLM-x32\...\{CBB4288D-2D32-43BB-8FCE-3F102E385956}) (Version: 4.3.5 - Garmin Ltd or its subsidiaries) Garmin MapSource (HKLM-x32\...\{68C17A81-81E1-458C-8555-3131C4D7A8DF}) (Version: 6.16.1 - Garmin Ltd or its subsidiaries) Garmin TOPO Deutschland v3 (HKLM-x32\...\{AE255C55-E0CF-4591-AA86-CAA19AA32C53}) (Version: 3.0.0.0 - Garmin Ltd or its subsidiaries) Garmin TOPO Österreich v2 (HKLM-x32\...\{7AA38575-25A1-4C2F-B40B-2188EB73FF0E}) (Version: 2.0.0.0 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries) GeoGebra 4.4 (HKLM-x32\...\GeoGebra 4.4) (Version: 4.4.10.0 - International GeoGebra Institute) Gigaset QuickSync (HKLM\...\{18e951f2-329a-4ed2-833b-d980960db29e}) (Version: 8.2.0865.2 - Gigaset Communications GmbH) GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team) GMapTool 0.8.67 (HKLM-x32\...\{1873789F-59D5-4002-8A2F-60A827B78F98}_is1) (Version: - AP) Google Apps Migration For Microsoft Outlook® 2.3.12.34 (HKLM\...\{14379BD8-7185-4C13-92DC-576677F9F8C6}) (Version: 2.3.12.34 - Google, Inc.) Google Drive (HKLM-x32\...\{75939021-3B68-419D-8DC1-E9823BFF9658}) (Version: 1.16.7009.9618 - Google, Inc.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden GSAK 8.4.1.55 (HKLM-x32\...\GSAK_is1) (Version: - CWE computer services) Hotspot Shield 3.42 (HKLM-x32\...\HotspotShield) (Version: 3.42 - AnchorFree Inc.) HP Officejet 6500 E710a-f - Grundlegende Software für das Gerät (HKLM\...\{F28BD099-9FC0-4A03-A605-E069B8D17D47}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.) Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.3004 - Acer Incorporated) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3316 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.0.1207 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.36 - Irfan Skiljan) Island-Topo für MapSource (HKLM-x32\...\Island-Topo_is1) (Version: - ) iTunes (HKLM\...\{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}) (Version: 11.3.0.54 - Apple Inc.) Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) KETTLER WORLD TOURS 2.0 (HKLM-x32\...\{2652179b-d7df-4c84-a1cd-f7de4e58f6bd}) (Version: 2.0.1.9 - KETTLER) KETTLER WORLD TOURS 2.0 (x32 Version: 2.0.1.22 - KETTLER) Hidden KETTLER WORLD TOURS 2.0 (x32 Version: 2.0.1.32 - KETTLER) Hidden KETTLER WORLD TOURS 2.0 (x32 Version: 2.0.1.9 - KETTLER) Hidden KETTLER WORLD TOURS 2.0 Courses (x32 Version: 2.0.1.32 - KETTLER) Hidden KETTLER WORLD TOURS 2.0 Courses (x32 Version: 2.0.1.9 - KETTLER) Hidden KETTLER WORLD TOURS 2.0 DEMO (HKLM-x32\...\{6adc5289-fb46-41c9-b2f8-37d42b4ec98a}) (Version: 2.0.1.22 - KETTLER) KETTLER WORLD TOURS 2.0 DEMO (x32 Version: 2.0.1.22 - KETTLER) Hidden KETTLER WORLD TOURS 2.0 DEMO Courses (x32 Version: 2.0.1.22 - KETTLER) Hidden KETTLER WORLD TOURS 2.0 DEMO Help (x32 Version: 2.0.1.22 - KETTLER) Hidden KETTLER WORLD TOURS 2.0 Help (x32 Version: 2.0.1.9 - KETTLER) Hidden KETTLER WORLD TOURS 2.0.1.22 (HKLM-x32\...\{6efe54e6-5d12-457e-b056-d86f8576b3a7}) (Version: 2.0.1.22 - KETTLER) KETTLER WORLD TOURS 2.0.1.32 (HKLM-x32\...\{4b200421-edfe-402f-b07c-0e8f03351efb}) (Version: 2.0.1.32 - KETTLER) KML-Konverter-Tool 1.607 (HKLM-x32\...\Kml-Konverter-Tool-1607) (Version: - Neumann) KWT Database Utility (HKLM-x32\...\{79eefa84-1157-4a2b-bf8c-8c8af2ddabca}) (Version: 1.0.2.4 - WWS) KWT Database Utility (Version: 1.0.2.4 - WWS) Hidden KWT Video Allgäu (x32 Version: 1.0.0.0 - KETTLER) Hidden KWT Video Furka Demo (x32 Version: 1.0.0.0 - KETTLER) Hidden Laplink PCmover Professional (HKLM-x32\...\{A519B6CE-9EDF-451A-B626-C3F8D2C9BFC2}) (Version: 8.00.631.0 - Laplink Software, Inc.) Launch Manager (HKLM-x32\...\LManager) (Version: 7.0.5 - Acer Inc.) LifeScan USB Device Driver vSL2.0 (Driver Removal) (HKLM-x32\...\LFSVCOMM&10C4&85A7) (Version: - LifeScan Inc) Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.3004 - Acer Incorporated) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Master Unit (HKLM-x32\...\Master Unit) (Version: - ) Messgerätetreiber für die OneTouch® Software v1.10.0.0 (HKLM-x32\...\InstallShield_{A2C173E1-FB29-4B31-8ED6-CBEE8025E00A}) (Version: 1.10.0.0 - LifeScan) Meter Drivers for OneTouch(R) Software (x32 Version: 1.10.0.0 - LifeScan) Hidden Meter Drivers for OneTouch(R) Software (x32 Version: 1.9.1.0 - LifeScan) Hidden Microsoft Access MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft AutoRoute 2013 (HKLM-x32\...\{C82185E8-C27B-4EF4-2013-3333BC2C2B6D}) (Version: 19.0.21.0500 - Microsoft Corporation) Microsoft DCF MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Excel MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Groove MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft InfoPath MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Lync MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office 32-bit Components 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM UX MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft OneNote MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Outlook MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft PowerPoint MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Publisher MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{86CE1746-9EFF-3C9C-8755-81EA8903AC34}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2005 Tools for Office Runtime (x32 Version: 8.0.60940.0 - Microsoft Corporation) Hidden Microsoft Word MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden MOBackup - Datensicherung für Outlook (Vollversion) (HKLM-x32\...\MOBackup-DatensicherungfürOutlook) (Version: 7.91 - Heiko Schröder) Mobipocket Reader 6.2 (HKLM-x32\...\{342126E1-173C-4585-BFBE-3EBDD20E3E9E}) (Version: 6.2.608 - Mobipocket.com) Mopsos 1.0.118 28.11.2011 (HKLM-x32\...\KoenigDickBauchMopsos_is1) (Version: - Bornhaupt) Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MyWinLocker (Version: 4.0.14.35 - Egis Technology Inc.) Hidden MyWinLocker 4 (x32 Version: 4.0.14.35 - Egis Technology Inc.) Hidden MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.24 - Egis Technology Inc.) MyWinLocker Suite (x32 Version: 4.0.14.24 - Egis Technology Inc.) Hidden Namo WebEditor 8 Testversion (HKLM-x32\...\{25B9FEB3-2E4C-4D66-A3C4-921FAE9A63DA}) (Version: 8.0 - Namo Interactive, Inc.) Naviextras Toolbox Prerequesities (HKLM-x32\...\{537575D6-3B96-474C-BD8F-DFF667363DBD}) (Version: 1.0.0 - NNG Llc.) Nitro Pro 9 (HKLM\...\{00DF846D-B284-4F46-8E6E-D5423C2B5C57}) (Version: 9.0.4.5 - Nitro) Notepad++ (HKLM-x32\...\Notepad++) (Version: 5.8.2 - ) NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9008 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.9008 - NTI Corporation) Hidden NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.157.1165 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Optimus Update 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden NVIDIA Update 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 15.3.33 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.23 (Version: 1.2.23 - NVIDIA Corporation) Hidden Office Addin (HKLM-x32\...\{6D2BBE1D-E600-4695-BA37-0B0E605542CC}) (Version: 2.01.3200 - Acer) Office Addin 2003 (HKLM-x32\...\{1FCC073B-CC01-4443-AD20-E559F66E6E83}) (Version: 2.01.3200 - Acer) OneTouch-Software (HKLM-x32\...\{82FEBE5D-61EC-4365-A213-2B278780945E}) (Version: - ) OpenText (HKLM-x32\...\{A517D5EF-2BEA-4B7A-9691-03EFB97A4C19}) (Version: 1.4.3 - Michael P. Bedesem) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Paragon Festplatten Manager™ 12 Professional (HKLM-x32\...\{1E104AF0-EA49-11DE-AC07-005056C00008}) (Version: 90.00.0003 - Paragon Software) Pflanzen gegen Zombies (HKLM-x32\...\Pflanzen gegen Zombies) (Version: - PopCap Games) PhotoSync (HKLM\...\{7D69D25B-03CD-4FD3-9E05-7069B8CB88F4}) (Version: 2.1.2 - touchbyte GmbH) Picture Resizer 2.0 (HKLM-x32\...\{D1A85247-63B6-4F20-910E-58377D1B7430}_is1) (Version: - Patrik Abend) PixelNet Software 4.12.2 (HKLM-x32\...\PixelNet Software) (Version: 4.12.2 - ORWO Net) PL-2303 USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.3.0 - Prolific Technology INC) POIbase 1.062 (HKLM-x32\...\POIbase_is1) (Version: - POIbase) Polar WebLink 2.4.14 (HKLM-x32\...\{20614F5A-1D52-49AF-BF2B-010A820BA48F}) (Version: 02.49.0005 - Polar Electro Oy) PSR Style Database / Midi Database V4.4 (HKLM-x32\...\PSR Style Database/Midi Database_is1) (Version: - ) PSRUTI (remove only) (HKLM-x32\...\PSRUTI) (Version: - ) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.220 - Qualcomm Atheros Communications) Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 11.41 - Qualcomm Atheros) QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) RCH65 Spoiler Downloader (HKLM-x32\...\{51CE71F2-00FD-4A74-9577-79BC8F2E6E58}) (Version: 1.0.27 - RCH65) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6657 - Realtek Semiconductor Corp.) Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.03.60.00(23.07.2013) - Samsung Electronics Co., Ltd.) Samsung Easy Wireless Setup (HKLM-x32\...\Easy Wireless Setup) (Version: 3.60.47.0 - Samsung Electronics Co., Ltd.) Samsung M2020 Series (HKLM-x32\...\Samsung M2020 Series) (Version: 1.10 (12.02.2014) - Samsung Electronics Co., Ltd.) Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden Sibelius 7.0.0.23 (HKLM\...\Sibelius 7.0.0.23_is1) (Version: 7.0.0.23 - Avid) SqliteBrowser3 (HKLM-x32\...\SqliteBrowser3) (Version: 3.2.0 - oldsch00l) StarMoney (x32 Version: 4.0.0.203 - StarFinanz) Hidden StarMoney 8.0 (HKLM-x32\...\{69ED1411-962B-4B09-B4A4-E0266203593A}) (Version: 8.0 - Star Finanz GmbH) StarMoney 9.0 (HKLM-x32\...\{4D021042-CA84-4F6F-BE41-D3567E6A7C3A}) (Version: 9.0 - Star Finanz GmbH) Start Menu 8 (HKLM-x32\...\IObit_StartMenu8_is1) (Version: 1.5.0.0 - IObit) Start8 (HKLM-x32\...\{F9FADF71-8E4E-4482-B95C-0F7A9F1B68AF}_is1) (Version: 1.11 - Stardock Corperation) StartIsBack (HKLM-x32\...\StartIsBack) (Version: - startisback.com) Steuer-Spar-Erklärung 2012 (HKLM-x32\...\{CCD2BAD2-0919-40CB-80CC-E9538B0E4C2E}) (Version: 17.11 - Wolters Kluwer Deutschland GmbH) Steuer-Spar-Erklärung 2013 (HKLM-x32\...\{AEB61F7A-4BBA-4292-A096-7893E09034A4}) (Version: 18.09 - Wolters Kluwer Deutschland GmbH) SteuerSparErklärung 2014 (HKLM-x32\...\{A463EB06-22A6-47F5-9593-E52B291EF13E}) (Version: 19.11.90 - Akademische Arbeitsgemeinschaft) System Requirements Lab for Intel (HKLM-x32\...\{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}) (Version: 4.5.13.0 - Husdawg, LLC) Texas Hold'em Poker 3D - Deluxe Edition 1.0 (HKLM-x32\...\{E26DEDC7-1A99-4F8C-9615-6DB112E6495B}_is1) (Version: Texas Hold'em Poker 3D - Deluxe Edition - Play + Smile Marketing GmbH) TOPO Czech 3 PRO (HKLM-x32\...\{4F50C25D-9236-42EE-86A4-F0BC39A543AE}) (Version: 3.00 - Picodas Praha, spol. s r.o.) Topomap Benelux (HKLM-x32\...\{5140C97D-FE5A-41BF-AF03-5C7350B42F7C}) (Version: 1.00 - Garmin Belux - Sailtron) Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH) True Image 2013 (HKLM-x32\...\{59F3D2AC-5F1F-4A93-8F23-6FD4F029D9A9}Visible) (Version: 16.0.5551 - Acronis) True Image 2013 (x32 Version: 16.0.5551 - Acronis) Hidden True Image 2013 Plus Pack (HKLM-x32\...\{C408E706-94A7-454C-8B52-538AA6CBD0FB}) (Version: 16.0.5551 - Acronis) Turbo Lister 2 (HKLM-x32\...\{8927E07C-97F7-4A54-88FB-D976F50DD46E}) (Version: 2.00.0000 - eBay Inc.) TV-Browser 3.3.2 (HKLM-x32\...\tvbrowser) (Version: 3.3.2 - TV-Browser Team) Tyros Registration Memory Editor - 1 (HKCU\...\3b826b783ab170b8) (Version: 1.5.9.1 - Tyros Utility) UltraISO Premium V9.53 (HKLM-x32\...\UltraISO_is1) (Version: - ) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{FEF4C57D-0975-4D3C-ACC7-DCD038C3788F}) (Version: - Microsoft) Update for Microsoft Excel 2010 (KB2837600) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{17815BC8-062D-49BE-B40C-B54149C85CE3}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0018-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-001B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{84B191B5-5319-463A-A305-8C4D53B1D20A}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{DB0B0CDF-77EC-47B0-94E2-4738573A1E58}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817396) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{1AA82E2E-7DB7-4C70-910C-BBB657A6B3A5}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2850074) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{CE9A9D7C-B6FB-4F6C-8BDE-9A1ADBBAC1EE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2553092) (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E636FE63-842B-4F4B-9884-DA189ACC0B91}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2553092) (HKLM\...\{90140000-0044-0407-1000-0000000FF1CE}_Office14.PROPLUS_{E636FE63-842B-4F4B-9884-DA189ACC0B91}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825635) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{6E760BBA-B83F-4C2D-918F-5F91EF6C9861}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{90140000-0044-0407-1000-0000000FF1CE}_Office14.PROPLUS_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{D1F3B526-7EB2-4701-92DB-0784988D78DE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837606) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{52BEF8AE-9324-40A1-9A92-E5A8FB63A475}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUS_{8F699D53-05FB-488E-B7D3-E4E47257BE5D}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{324703B5-6765-489D-9B9B-B082D34F882E}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUS_{4B9B2BAF-EE1F-4B60-A4D9-17B7BEEB13A1}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760344) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EF77B4A6-DFEC-4010-A87D-9B6BF87FABEC}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760544) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{62857CDD-2985-4939-91BA-19ED0B0031A5}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2768012) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{0814662C-FD28-4DE0-ACE5-EE50D1D6C8FB}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{E79EFFDB-192A-4D9E-A2DB-C0F774E6EC32}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{E79EFFDB-192A-4D9E-A2DB-C0F774E6EC32}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2826040) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C4AEA56A-0759-4D08-9FAB-31A92137D0B8}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2837644) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D692E9FF-84BF-4F44-A0EA-D58ECE0D538E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863843) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{290D80DE-03AB-47EC-9402-108AF4CE4F66}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880457) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EC2AF602-2730-4B05-9438-06CDE43153F2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880464) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{88B29AA5-71EE-4692-91E2-E89407F0B783}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880478) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8116ED50-F1E7-49E1-9D8D-421497D34B0F}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880987) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6F540E80-4BB2-413F-9648-52031AA237B7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880987) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{6F540E80-4BB2-413F-9648-52031AA237B7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880987) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6F540E80-4BB2-413F-9648-52031AA237B7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0090-0407-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881074) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{9A479F9C-C1EC-4833-A115-A8B7A60480BD}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0407-1000-0000000FF1CE}_Office15.PROPLUS_{00BBBFFE-8889-4953-956A-77DDE975A947}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0409-1000-0000000FF1CE}_Office15.PROPLUS_{3A12DFA2-3FF5-450E-BDB1-A742551A5D1A}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}_Office15.PROPLUS_{EA8072E8-E3CF-46DF-A5DE-9F5975344327}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0410-1000-0000000FF1CE}_Office15.PROPLUS_{BF0D921F-E77E-4E03-BE71-46D9D2C7A36A}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881086) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{ED3A8E98-FDD4-493F-A0EC-141821573EC2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881086) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{ED3A8E98-FDD4-493F-A0EC-141821573EC2}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00BA-0407-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-00A1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{DDDC32A5-9528-4771-B91A-97A8E1D7957B}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-001A-0407-1000-0000000FF1CE}_Office14.PROPLUS_{6164E0E5-C903-488C-93AF-1B7AF7EBC331}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{34A169EC-990A-4DAE-AC65-9F981158B7DB}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 64-Bit Edition (HKLM\...\{90150000-001A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{34A169EC-990A-4DAE-AC65-9F981158B7DB}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A20A650C-F820-4CE4-AEA5-EC140192FAFB}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0018-0407-1000-0000000FF1CE}_Office14.PROPLUS_{FD360122-6829-4497-97C1-1BF578EF695B}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2881075) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C8955821-EDAC-4E65-BEF3-C9C0A049517A}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2881075) 64-Bit Edition (HKLM\...\{90150000-0018-0407-1000-0000000FF1CE}_Office15.PROPLUS_{C8955821-EDAC-4E65-BEF3-C9C0A049517A}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C07147B9-CC0B-4CC1-A107-A705889A54F2}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 64-Bit Edition (HKLM\...\{90150000-0019-0407-1000-0000000FF1CE}_Office15.PROPLUS_{C07147B9-CC0B-4CC1-A107-A705889A54F2}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F6F342A1-530B-4D48-A468-1E3F70928984}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2837587) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{C950A55F-82E3-4CC8-8FA2-E8A2A0F651F3}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2880529) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{89FDC8D9-FB84-4EFE-950D-AF4EECC3B64C}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2878319) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BC51FE30-3A56-4802-8D9E-E9BC05B56B49}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881080) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{F96FE9BB-CD90-472B-852E-156342618C54}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881080) 64-Bit Edition (HKLM\...\{90150000-001A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{F96FE9BB-CD90-472B-852E-156342618C54}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881080) 64-Bit Edition (HKLM\...\{90150000-001B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{F96FE9BB-CD90-472B-852E-156342618C54}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881080) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{F96FE9BB-CD90-472B-852E-156342618C54}) (Version: - Microsoft) Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN) WD Quick View (HKLM-x32\...\{124310E8-7C49-4C33-B4F2-3CF43F3830B7}) (Version: 2.0.1.2 - Western Digital Technologies, Inc.) WD SmartWare (HKLM\...\{DD178D9D-89DD-4F15-9E56-57C85D1EDF36}) (Version: 2.0.1.2 - Western Digital Technologies, Inc.) WD SmartWare Installer (HKLM-x32\...\{bfb9000e-e7d4-490f-a873-ec2c9cab3b3d}) (Version: 2.0.1.2 - Western Digital Technologies, Inc.) Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin) Windows Driver Package - Silicon Laboratories (silabenm) Ports (12/10/2012 6.6.1.0) (HKLM\...\D680DEE0F68D64EC53D0C5769879D15D387054CC) (Version: 12/10/2012 6.6.1.0 - Silicon Laboratories) WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) XnView 2.04 (HKLM-x32\...\XnView_is1) (Version: 2.04 - Gougelet Pierre-e) Your Uninstaller! 7 (HKLM-x32\...\YU2010_is1) (Version: 7.5.2013.2 - URSoft, Inc.) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{1082C812-D727-45CD-A31C-DAAC84FF09D0}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\RTFfilter.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{1701D2CE-B30E-4a76-AC65-25231D7F1529}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\HTMLfilter.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{1C473E52-3450-4A11-9683-EFEFA78B589E}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\EMFFilter.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{36116392-F445-4775-BA72-A90A4B18B4CF}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\PDFImport\PDFImport.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{51044162-9C29-430D-A48B-F0E97325F8E2}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\PPImport.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{5D096382-CEC5-4695-86CD-8C725D4514D2}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\SVGFilter.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{7070ED46-4C64-4D92-9511-0239B25B56E1}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\RAWImport\RAWImport.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{8D3E633C-DC8D-4446-88D5-FA149B562F36}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\PSDFilter.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{CB58FF31-2539-11D0-BDEE-0020AFE14B84}\localserver32 -> C:\PROGRA~1\MAGIX\WEBDES~1\WEBDES~1.EXE No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{CB58FF32-2539-11D0-BDEE-0020AFE14B84}\localserver32 -> C:\PROGRA~1\MAGIX\WEBDES~1\WEBDES~1.EXE No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{CBAA4D0A-9F10-41AF-B61F-2C6241CE8930}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\ODPImport.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{F0A2F714-AAAB-40F9-AA86-54C74DD28A38}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\TIFFImport.dll No File ==================== Restore Points ========================= 17-07-2014 07:01:31 Windows Update 24-07-2014 15:21:28 Windows Update 29-07-2014 18:15:28 KETTLER WORLD TOURS 2.0.1.32 05-08-2014 08:07:18 DirectX wurde installiert ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-07-26 07:26 - 2014-05-11 12:30 - 00001168 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 activation.acronis.com 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com 127.0.0.1 na1r.services.adobe.com 127.0.0.1 hlrcv.stage.adobe.com ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {01C2174F-0C01-4A56-B2BD-80874329EAF5} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {09D863F1-9C7B-447E-B232-5C9CAFEBE7B1} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {0AD7725D-3AB6-4C3C-B3E8-DF14CDFE900C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-09] (Google Inc.) Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {0DBC845C-AB33-4307-8534-8797BA5D3714} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {1C4E3FB9-5228-412C-837C-4FA3D9046B07} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {20251B22-540C-4B67-BAF0-C652B58BDEFE} - System32\Tasks\StartMenuAutoupdate => C:\Program Files (x86)\IObit\Start Menu 8\AutoUpdate.exe [2014-06-06] (IObit) Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {26622E3C-D5DA-441D-88B4-57128C19F395} - System32\Tasks\Software Updater => C:\PROGRAM FILES (X86)\SOFTWAREUPDATER\SOFTWAREUPDATER.BOOTSTRAPPER.EXE [2013-12-18] () Task: {27949D9D-ABF9-436E-A568-6B88DBF87C2B} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2012-07-04] (CyberLink) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3764ACD2-537D-4A2A-B876-701C956B9C2B} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2012-08-30] () Task: {38F15E6B-D90D-47F6-BAAC-35CC0F28C426} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {3AE1903A-C82E-47BC-A828-CC02EF6A1C1D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-09] (Google Inc.) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {40A2A512-7EFC-491F-9522-0DBD1F61B4E1} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {4A8F5D9D-69E0-4E64-A8B0-066E8926AEB8} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {4B00FDD1-AE5E-44FB-8A8E-9127DAB18AAF} - System32\Tasks\Software Updater Ui => C:\PROGRAM FILES (X86)\SOFTWAREUPDATER\SoftwareUpdater.Ui.exe [2013-12-18] () Task: {4D02C09C-7EC1-4366-89F4-A63219B60ED6} - System32\Tasks\iuBrowserIEAgent => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe [2012-08-23] () Task: {5684C451-228C-495B-A04D-4C0C76463363} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {5BBAFF37-BCB3-4604-B881-A930CDAF627A} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {69AC89AD-0274-4668-8047-BEEAA6D194B4} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2012-07-12] (Egis Technology Inc.) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {82B33C67-F329-458D-B9FC-BD1FEDEC1E40} - System32\Tasks\iuEmailOutlookAgent => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe [2012-08-23] () Task: {82EE0DCA-A3FB-4502-9AEE-DD18DC024CFF} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [2012-08-22] (Acer Incorporated) Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8B2ED5EF-52A4-41AA-ABF6-9602AAC421C8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-07-10] (Microsoft Corporation) Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {8D71B8DF-2A46-4C7B-90D9-CCFC5BFDBD95} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2012-07-12] (Egis Technology Inc.) Task: {8EDF7391-BE15-4370-B355-5C3530024276} - System32\Tasks\APM_off => C:\hdparm\hdparm.exe Task: {93DBF3D0-A9EF-47B6-915D-705848D179CC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {C1B8B2DB-D4E2-4F80-A1F4-158C8E292165} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe [2013-06-13] (Lavasoft Limited) Task: {C2DE7166-6278-4412-95BB-517B6FFE6079} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe Task: {C3130A3A-D06F-4FF9-9880-0CC78D104382} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {CBCC905B-2F9E-4C65-8190-66BCC485E24D} - System32\Tasks\FileAdvisorCheck => C:\Program Files (x86)\File Type Advisor\file-type-advisor.exe [2013-09-05] (filetypeadvisor.com ) Task: {CDADAF36-53C4-4392-937A-458825AB781A} - System32\Tasks\Western Digital\SmartWare\____Volume_9a21b32e_ee89_47be_9a71_2867908abcfb______Volume_494b1ee2_a5ee_11e2_bec8_b888e3ac2d28__ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [2013-04-22] (Western Digital Technologies, Inc.) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D15B094F-CC10-421D-923B-AA74D0716B22} - System32\Tasks\Freemium1ClickMaint => C:\Users\Michael\Downloads\1Click.exe Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {DDADEDBD-2B56-4634-9D9F-F4CED38F85BA} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2012-06-22] () Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {E85B317E-DAC0-49D6-BCCB-2A3D8A855D36} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-13] (Adobe Systems Incorporated) Task: {FA580E20-87EA-4D5E-A5DD-3A04BEC1E4F9} - System32\Tasks\FileAdvisorUpdate => C:\Program Files (x86)\File Type Advisor\fileadvisor.exe [2013-09-04] (File Type Advisor) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\AutoKMS.job => C:\WINDOWS\AutoKMS\AutoKMS.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-08-05 11:15 - 2014-07-02 22:48 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2013-10-26 11:20 - 2012-09-18 15:27 - 00192512 _____ () C:\WINDOWS\System32\zlhp1020.dll 2014-07-16 10:00 - 2013-12-27 11:33 - 00034304 _____ () C:\WINDOWS\System32\ssj2mlm.dll 2013-10-20 13:05 - 2012-09-18 15:27 - 00065024 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\pphp1020.dll 2013-10-20 13:04 - 2012-09-18 15:27 - 03162624 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\suhp1020.dll 2013-10-20 13:04 - 2012-09-18 15:27 - 01236992 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\gchp1020.dll 2008-10-24 16:35 - 2008-10-24 16:35 - 00128296 _____ () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe 2014-05-17 00:34 - 2014-05-17 00:34 - 00430344 _____ () C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe 2013-12-27 20:41 - 2013-12-27 20:41 - 00066872 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2013-12-27 20:41 - 2013-12-27 20:41 - 00107832 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe 2013-07-31 20:22 - 2013-04-10 15:28 - 00885096 _____ () C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2013-10-04 00:42 - 2013-10-04 00:42 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-03-09 09:58 - 2012-03-09 09:58 - 00462712 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe 2012-03-09 09:58 - 2012-03-09 09:58 - 00057208 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll 2014-01-23 16:05 - 2014-01-23 16:05 - 01424552 _____ () C:\Program Files\Microsoft Office\Office15\ADDINS\UmOutlookAddin.dll 2012-08-23 00:04 - 2012-08-23 00:04 - 00025232 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe 2012-08-23 00:04 - 2012-08-23 00:04 - 00044176 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe 2014-08-05 11:37 - 2014-07-02 20:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-05-17 02:11 - 2014-05-17 02:11 - 00908584 _____ () C:\Program Files (x86)\Hotspot Shield\bin\af_proxy.dll 2014-05-17 02:37 - 2014-05-17 02:37 - 00506664 _____ () C:\Program Files (x86)\Hotspot Shield\bin\HssRep.dll 2014-07-31 08:49 - 2011-01-13 11:44 - 00232800 _____ () C:\Program Files (x86)\StarMoney 9.0\ouservice\PATCHW32.dll 2013-05-15 11:09 - 2014-06-06 13:07 - 00348960 _____ () C:\Program Files (x86)\IObit\Start Menu 8\madExcept_.bpl 2013-05-15 11:09 - 2014-06-06 13:07 - 00183584 _____ () C:\Program Files (x86)\IObit\Start Menu 8\madBasic_.bpl 2013-05-15 11:09 - 2014-06-06 13:07 - 00050976 _____ () C:\Program Files (x86)\IObit\Start Menu 8\madDisAsm_.bpl 2014-07-07 13:53 - 2014-07-07 13:53 - 00137296 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll 2014-07-07 13:52 - 2014-07-07 13:52 - 00065616 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2013-02-28 13:38 - 2014-06-20 06:08 - 00192376 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libBase64.dll 2013-02-28 13:38 - 2014-06-20 06:08 - 00180088 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libMachoUniv.dll 2013-10-20 14:04 - 2014-06-06 13:08 - 00041248 _____ () C:\Program Files (x86)\IObit\Start Menu 8\winkey.dll 2014-06-25 21:31 - 2014-07-07 13:53 - 00049744 _____ () C:\Users\Michael\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2013-05-25 19:27 - 2014-08-01 09:27 - 03800688 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00013272 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Windows:EFBA2313AE7FEED3 AlternateDataStreams: C:\ProgramData\Temp:1CE11B51 AlternateDataStreams: C:\ProgramData\Temp:BEACE4C8 AlternateDataStreams: C:\ProgramData\Temp:BF31A799 AlternateDataStreams: C:\ProgramData\Temp:C9633DEB ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: AcrSch2Svc => 2 MSCONFIG\Services: Ad-Aware Service => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: afcdpsrv => 3 MSCONFIG\Services: Apple Mobile Device => 2 MSCONFIG\Services: AtherosSvc => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: BrcmCardReader => 2 MSCONFIG\Services: CCDMonitorService => 2 MSCONFIG\Services: cphs => 3 MSCONFIG\Services: DeviceFastLaneService => 3 MSCONFIG\Services: DsiWMIService => 2 MSCONFIG\Services: EgisTec Ticket Service => 3 MSCONFIG\Services: ePowerSvc => 3 MSCONFIG\Services: ETDService => 2 MSCONFIG\Services: FLEXnet Licensing Service => 3 MSCONFIG\Services: IDriverT => 3 MSCONFIG\Services: Intel(R) Capability Licensing Service Interface => 2 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: jhi_service => 2 MSCONFIG\Services: LMS => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: NitroDriverReadSpool8 => 2 MSCONFIG\Services: nlsX86cc => 2 MSCONFIG\Services: NTI IScheduleSvc => 2 MSCONFIG\Services: nvsvc => 2 MSCONFIG\Services: nvUpdatusService => 3 MSCONFIG\Services: RfButtonDriverService => 2 MSCONFIG\Services: SBAMSvc => 2 MSCONFIG\Services: SDScannerService => 3 MSCONFIG\Services: SDUpdateService => 3 MSCONFIG\Services: SDWSCService => 3 MSCONFIG\Services: Start8 => 2 MSCONFIG\Services: StrartMenuService => 2 MSCONFIG\Services: UNS => 2 MSCONFIG\Services: WDBackup => 2 MSCONFIG\Services: WDDriveService => 2 MSCONFIG\Services: WDRulesService => 2 HKLM\...\StartupApproved\StartupFolder: => "Google Calendar Sync.lnk" HKLM\...\StartupApproved\Run: => "BCSSync" HKLM\...\StartupApproved\Run: => "RtHDVCpl" HKLM\...\StartupApproved\Run: => "ACPW06DE" HKLM\...\StartupApproved\Run: => "SpywareTerminatorShield" HKLM\...\StartupApproved\Run: => "SpywareTerminatorUpdater" HKLM\...\StartupApproved\Run32: => "APSDaemon" HKLM\...\StartupApproved\Run32: => "Dolby Home Theater v4" HKLM\...\StartupApproved\Run32: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "QuickTime Task" HKLM\...\StartupApproved\Run32: => "BCSSync" HKLM\...\StartupApproved\Run32: => "HP Software Update" HKLM\...\StartupApproved\Run32: => "HTC Sync Loader" HKLM\...\StartupApproved\Run32: => "Ad-Aware Browsing Protection" HKLM\...\StartupApproved\Run32: => "SDTray" HKLM\...\StartupApproved\Run32: => "WD Quick View" HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe" HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact" HKLM\...\StartupApproved\Run32: => "CloneCDTray" HKCU\...\StartupApproved\StartupFolder: => "jAnrufmonitor 5.0.lnk" HKCU\...\StartupApproved\StartupFolder: => "OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk" HKCU\...\StartupApproved\StartupFolder: => "An OneNote senden.lnk" HKCU\...\StartupApproved\Run: => "Password Guard v3" HKCU\...\StartupApproved\Run: => "7 Taskbar Tweaker" HKCU\...\StartupApproved\Run: => "1&1_1&1 Upload-Manager" HKCU\...\StartupApproved\Run: => "Spotify Web Helper" HKCU\...\StartupApproved\Run: => "iCloudServices" HKCU\...\StartupApproved\Run: => "Wondershare Helper Compact" ==================== Faulty Device Manager Devices ============= Name: AVM USB-Fernanschluss Description: AVM USB-Fernanschluss Class Guid: {59e75f1d-160e-4aba-bb5c-1c179b8e9b7a} Manufacturer: AVM Berlin Service: avmaura Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: AVM USB-Fernanschluss Description: AVM USB-Fernanschluss Class Guid: {59e75f1d-160e-4aba-bb5c-1c179b8e9b7a} Manufacturer: AVM Berlin Service: avmaura Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver ==================== Event log errors: ========================= Application errors: ================== Error: (08/05/2014 11:32:33 AM) (Source: Avira Service Host) (EventID: 0) (User: ) Description: Fehler beim Verarbeiten von Sitzungsänderung. System.InvalidOperationException: Die Sequenz enthält keine Elemente. bei System.Linq.Enumerable.First[TSource](IEnumerable`1 source) bei Avira.OE.BrowserExtensionConnector.FirefoxProductInfo.ExtensionIsInstalled(String extensionId) bei Avira.OE.BrowserExtensionConnector.ExtensionStatusMonitor`1.StartWatching(TimeSpan timeSpan) bei Avira.OE.BrowserExtensionConnector.AviraSafeSearchStatusConnector.OnSessionChange(Int32 sessionId, SessionChangeReason reason) bei Avira.OE.ServiceHost.ServiceHost.OnSessionChange(SessionChangeDescription changeDescription) bei System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId) Error: (08/05/2014 11:19:57 AM) (Source: Perflib) (EventID: 1023) (User: ) Description: rdyboost4 Error: (08/05/2014 11:19:56 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll4 Error: (08/05/2014 09:26:33 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT) Description: Die Namenszeichenfolgenwert für den Leistungsindikator in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "11178". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten. Error: (08/05/2014 09:26:32 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/05/2014 08:22:13 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT) Description: Die Namenszeichenfolgenwert für den Leistungsindikator in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "10998". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten. Error: (08/05/2014 08:22:13 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/04/2014 09:40:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT) Description: Die Namenszeichenfolgenwert für den Leistungsindikator in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "10818". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten. Error: (08/04/2014 09:40:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/04/2014 03:12:36 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm BaseCamp.exe, Version 4.3.3.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 12c4 Startzeit: 01cfafe574b8448c Endzeit: 50 Anwendungspfad: C:\Program Files (x86)\Garmin\BaseCamp\BaseCamp.exe Berichts-ID: fc9e127f-1bd8-11e4-bf6e-b888e3ac2d28 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: System errors: ============= Error: (08/05/2014 11:18:19 AM) (Source: avmaura) (EventID: 4012) (User: ) Description: AURA Error: (08/05/2014 11:18:19 AM) (Source: avmaura) (EventID: 4012) (User: ) Description: AURA Error: (08/05/2014 10:41:20 AM) (Source: DCOM) (EventID: 10010) (User: MichiLaptop) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (08/05/2014 08:21:59 AM) (Source: DCOM) (EventID: 10010) (User: MichiLaptop) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (08/05/2014 03:25:49 AM) (Source: DCOM) (EventID: 10010) (User: MichiLaptop) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (08/03/2014 05:48:20 PM) (Source: DCOM) (EventID: 10010) (User: MichiLaptop) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (08/03/2014 11:51:58 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. Error: (08/03/2014 11:51:47 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/03/2014 11:51:37 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/03/2014 11:50:29 AM) (Source: DCOM) (EventID: 10016) (User: MichiLaptop) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}MichiLaptopMichaelS-1-5-21-587935961-2775860875-2407296441-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Microsoft Office Sessions: ========================= Error: (08/05/2014 11:32:33 AM) (Source: Avira Service Host) (EventID: 0) (User: ) Description: Fehler beim Verarbeiten von Sitzungsänderung. System.InvalidOperationException: Die Sequenz enthält keine Elemente. bei System.Linq.Enumerable.First[TSource](IEnumerable`1 source) bei Avira.OE.BrowserExtensionConnector.FirefoxProductInfo.ExtensionIsInstalled(String extensionId) bei Avira.OE.BrowserExtensionConnector.ExtensionStatusMonitor`1.StartWatching(TimeSpan timeSpan) bei Avira.OE.BrowserExtensionConnector.AviraSafeSearchStatusConnector.OnSessionChange(Int32 sessionId, SessionChangeReason reason) bei Avira.OE.ServiceHost.ServiceHost.OnSessionChange(SessionChangeDescription changeDescription) bei System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId) Error: (08/05/2014 11:19:57 AM) (Source: Perflib) (EventID: 1023) (User: ) Description: rdyboost4 Error: (08/05/2014 11:19:56 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll4 Error: (08/05/2014 09:26:33 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT) Description: 1117816AA2B0000A82B0000A82B000070010000 Error: (08/05/2014 09:26:32 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Performance1637070000A82B0000000000008F020000 Error: (08/05/2014 08:22:13 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT) Description: 1099816F62A0000F42A0000F42A000070010000 Error: (08/05/2014 08:22:13 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Performance1637070000F42A0000000000008F020000 Error: (08/04/2014 09:40:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT) Description: 1081816422A0000402A0000402A000070010000 Error: (08/04/2014 09:40:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Performance1637070000402A0000000000008F020000 Error: (08/04/2014 03:12:36 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: BaseCamp.exe4.3.3.012c401cfafe574b8448c50C:\Program Files (x86)\Garmin\BaseCamp\BaseCamp.exefc9e127f-1bd8-11e4-bf6e-b888e3ac2d28 CodeIntegrity Errors: =================================== Date: 2014-03-14 13:56:03.164 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:51.743 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:51.527 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:51.413 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.759 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.622 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.478 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.349 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.216 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.126 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Percentage of memory in use: 29% Total physical RAM: 8007.27 MB Available physical RAM: 5629.6 MB Total Pagefile: 10507.27 MB Available Pagefile: 7224.83 MB Total Virtual: 131072 MB Available Virtual: 131071.79 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:678.85 GB) (Free:170.44 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 699 GB) (Disk ID: 821BE156) Partition: GPT Partition Type. ==================== End Of Log ============================ |
05.08.2014, 17:26 | #4 |
| C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werdenFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-08-2014 Ran by Michael (administrator) on MICHILAPTOP on 05-08-2014 11:40:51 Running from C:\Users\Michael\Downloads Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe () C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe () C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe (Apple Inc.) C:\AirPrint\airprint.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\InstallServices64.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\OUTLOOK.EXE (Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\HSSCP.exe (Intel Corporation) C:\Windows\System32\igfxext.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212048 2012-06-07] (Realtek Semiconductor) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [ACPW06DE] => C:\Program Files\ACD Systems\ACDSee Pro\6.0\ACDSeePro6InTouch2.exe [1231992 2012-11-14] (ACD Systems) HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-41 (the data entry has 36 more characters). HKLM\...\Run: [SBRegRebootCleaner] => C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] () HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Dolby PCEE4\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554408 2013-05-15] (Lavasoft) HKLM-x32\...\Run: [SearchProtection] => C:\ProgramData\Search Protection\_run.bat [168 2013-02-28] () HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [uni mouse driver] => "C:\Mouse driver\mouse_driver.exe" /hide HKLM-x32\...\Run: [uni mouse driver tilt] => "C:\Mouse driver\wh_exec.exe" HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [CloneCDTray] => C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [189520 2014-07-07] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoDriveAutoRun] 0x0000 HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Agent] => "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse] => "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [7 Taskbar Tweaker] => C:\Users\Michael\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe [283648 2013-04-30] (RaMMicHaeL) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [1&1_1&1 Upload-Manager] => C:\Program Files (x86)\1&1\1&1 Upload-Manager\DAVSRV.EXE [989264 2011-11-21] (1&1 Internet AG) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [Rainlendar2] => C:\Program Files\Rainlendar2\Rainlendar2.exe HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Policies\Explorer: [NoDriveAutoRun] 0x0000 HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation) AppInit_DLLs: , C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation) AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [146480 2014-07-02] (NVIDIA Corporation) Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: AcronisSyncError -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncInProgress -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncOk -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers-x32: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: CloudIcon_DOWNLOAD -> {C3DBFBE2-A521-4619-9F32-502318CB4EC2} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_ERROR -> {851C758E-C636-4045-B323-059931A3A331} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_INSYNC -> {580030D3-492E-45EA-A1C9-A0AC525BEB26} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_REFRESH -> {FEBF62C8-B6B3-43B7-BEC4-1A9CD61BDCD2} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_UPLOAD -> {EBED3602-8915-43F9-81F7-CAA6FC4F70D6} => No File ShellIconOverlayIdentifiers-x32: Offline Files -> {4E77131D-3629-431c-9818-C5679DC83E81} => No File ShellIconOverlayIdentifiers-x32: SharingPrivate -> {08244EE6-92F0-47f2-9FC9-929BAA2E7235} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: http=;ftp=;https=; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM - {2C67950C-8251-481E-B96D-A28F2062192E} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS SearchScopes: HKLM - {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM-x32 - {2C67950C-8251-481E-B96D-A28F2062192E} URL = hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.6&ts=1369502554751&tguid=43169-3580-1369502554751-9FDCF2CB6E989C42D8699C8283EE7782&q={searchTerms} SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.5&ts=1369502554751&tguid=43169-3580-1369502554751-9FDCF2CB6E989C42D8699C8283EE7782&q={searchTerms} SearchScopes: HKCU - DefaultScope {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=112250&babsrc=SP_ss&mntrId=245fb41d0000000000000022fa23189d SearchScopes: HKCU - {2C67950C-8251-481E-B96D-A28F2062192E} URL = hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.6&ts=1369502554751&tguid=43169-3580-1369502554751-9FDCF2CB6E989C42D8699C8283EE7782&q={searchTerms} SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://lavasoft.blekko.com/ws/?source=f439e2c0&tbp=rbox&toolbarid=adawaretb&u=05998C3B7CD943D17EE7A8512F40DDF9&q={searchTerms} SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.5&ts=1369502554751&tguid=43169-3580-1369502554751-9FDCF2CB6E989C42D8699C8283EE7782&q={searchTerms} SearchScopes: HKCU - {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Ad-Aware Security Add-on -> {6c97a91e-4524-4019-86af-2aa2d567bf5c} -> C:\Program Files (x86)\adawaretb\adawareDx.dll () BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - No Name - {C7DDDD27-F303-42A5-B979-51559F7DC0F0} - No File Toolbar: HKLM-x32 - Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll () Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006 FF SearchEngineOrder.1: SuchMaschine FF Homepage: web.de FF Keyword.URL: hxxp://www.sm.de/?q= FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VLC Player\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\McAfee Security Scan\3.0.313\npMcAfeeMss.dll No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF user.js: detected! => C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\searchplugins\search_engine.xml FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Garmin Communicator - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-07-26] FF Extension: ColorZilla - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2014-03-18] FF Extension: Personas Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\personas@christopher.beard.xpi [2013-08-06] FF Extension: Leet Key - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{3335F91D-2AEF-4097-B831-C96C60349822}.xpi [2014-03-18] FF Extension: Adblock Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-07] FF Extension: Greasemonkey - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-01-01] FF Extension: Hotspot Shield Extension - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afproxy@anchorfree.com [2014-07-17] FF HKLM-x32\...\Firefox\Extensions: [webbooster@iminent.com] - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\ta4ni95k.default\extensions\webbooster@iminent.com FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited) R2 AirPrint; C:\AirPrint\airprint.exe [234784 2014-07-07] (Apple Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-05] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-05] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227456 2013-01-28] (Qualcomm Atheros Commnucations) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-07] (Avira Operations GmbH & Co. KG) S4 BrcmCardReader; C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe [176640 2012-08-20] (Broadcom Corp.) [File not signed] S4 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2435728 2012-08-23] (Acer Incorporated) S4 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [468624 2012-08-23] (Acer Incorporated) S4 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658576 2012-08-22] (Acer Incorporated) R2 HPSLPSVC; C:\Users\Michael\AppData\Local\Temp\7zS57EE\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed] R2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [919040 2014-05-17] (AnchorFree Inc.) [File not signed] S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [78512 2014-05-17] () R2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [430344 2014-05-17] () S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-11-12] (Nitro PDF Software) S4 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-08-23] (NTI Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [66872 2013-12-27] () R2 PnkBstrB; C:\WINDOWS\SysWOW64\PnkBstrB.exe [107832 2013-12-27] () S4 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2012-11-23] (Dritek System INC.) R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software) S4 StarMoney 8.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S4 Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [142960 2013-01-31] (Stardock Software, Inc) R2 StartMenuService; C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe [72992 2014-06-06] (IObit) S2 SystemStoreService; C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe [297984 2014-04-09] () [File not signed] R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2013-04-22] (Western Digital Technologies, Inc.) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270192 2013-03-21] (Western Digital Technologies, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) R2 WO_LiveService; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe [885096 2013-04-10] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-06-17] (Avira Operations GmbH & Co. KG) R3 avmaura; C:\Windows\System32\drivers\avmaura.sys [116480 2013-10-20] (AVM Berlin) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-28] (Qualcomm Atheros) S3 bthav; C:\Windows\system32\drivers\bthav.sys [40448 2008-07-10] (CSR, plc) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.) R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.) S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-06-28] (GFI Software) S3 GigasetGenericUSB_x64; C:\Windows\system32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2013-03-05] (Siemens Home and Office Communication Devices GmbH & Co. KG) R1 HssDRV6; C:\Windows\system32\DRIVERS\hssdrv6.sys [44744 2014-05-17] (AnchorFree Inc.) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) R2 LiveTunerPM; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerProcessMonitor64.sys [12824 2011-03-08] () R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-11-23] (Dritek System Inc.) R3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [1093256 2013-02-14] (Acronis) R1 ui11rdr; C:\Windows\System32\DRIVERS\ui11rdr.sys [199752 2011-11-21] (1&1 Internet AG) R1 UimBus; C:\Windows\System32\drivers\uimx64.sys [90960 2012-08-07] (Windows (R) 2000 DDK provider) R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633552 2012-08-07] (Paragon) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) R3 whfltr2k; C:\Windows\System32\drivers\whfltr2k.sys [10368 2009-09-16] () ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-05 11:40 - 2014-08-05 11:41 - 00033734 _____ () C:\Users\Michael\Downloads\FRST.txt 2014-08-05 11:40 - 2014-08-05 11:41 - 00000000 ____D () C:\FRST 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\system32\NV 2014-08-05 11:37 - 2014-08-05 11:38 - 02094080 _____ (Farbar) C:\Users\Michael\Downloads\FRST64.exe 2014-08-05 11:37 - 2014-07-02 20:55 - 06783776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 03522392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 02559960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 01084704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00935368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2014-08-05 11:37 - 2014-07-02 20:55 - 00386520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00067072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00062808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2014-08-05 11:37 - 2014-07-02 12:14 - 03826628 _____ () C:\WINDOWS\system32\nvcoproc.bin 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~Outlook.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~mkoelbl@online.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~mike1k@gmx.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~homeshopper66@online.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~hdampff@gmx.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~FTF-Hunter@online.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~FTF-Hunter@gmx.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~bayanbua@gmx.de.pst.tmp 2014-08-05 11:15 - 2014-07-02 22:48 - 31512520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 24196896 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 22994208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 18626304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 17555104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 16122344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 15294296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 14498552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 13922752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 13835208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 12866008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys 2014-08-05 11:15 - 2014-07-02 22:48 - 11283344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 11222048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 04247000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 03989960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 03196816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 02814656 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 01890080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6434052.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 01539928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6434052.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00965312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00944928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00907096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00903624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00869152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00846832 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00354016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00305600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00166568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00146480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00032544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys 2014-08-05 11:15 - 2014-07-02 22:48 - 00026353 _____ () C:\WINDOWS\system32\nvinfo.pb 2014-08-05 10:07 - 2014-07-25 15:50 - 01715224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2014-08-05 10:07 - 2014-07-25 15:50 - 01291280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2014-08-05 10:06 - 2014-08-05 10:06 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp 2014-08-05 10:06 - 2014-03-31 18:42 - 00040392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys 2014-08-05 10:06 - 2014-03-31 18:42 - 00034760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll 2014-08-05 09:58 - 2014-08-05 09:58 - 00000218 _____ () C:\Users\Michael\AppData\Local\recently-used.xbel 2014-08-05 09:43 - 2014-08-05 09:43 - 00040104 _____ () C:\Users\Michael\Desktop\radlriddle.htm 2014-08-05 08:15 - 2014-08-05 08:33 - 520324935 _____ () C:\Users\Michael\Downloads\Demo_Flakstad.exe 2014-08-05 08:08 - 2014-08-05 08:08 - 00053507 _____ () C:\Users\Michael\Downloads\route_1325.gpx 2014-08-05 04:08 - 2014-08-05 04:08 - 00064602 _____ () C:\Users\Michael\Downloads\IT_Stelvio2013_Control.rar 2014-08-05 03:43 - 2014-08-05 03:43 - 00031250 _____ () C:\Users\Michael\Downloads\NO_Gullingen.rlv 2014-08-05 03:35 - 2014-08-05 03:38 - 183717406 _____ () C:\Users\Michael\Downloads\Demo_Furka2011.exe 2014-08-04 15:36 - 2014-08-04 15:36 - 00961405 _____ () C:\Users\Michael\Downloads\GpsiesTrack.gpx 2014-08-04 15:36 - 2014-08-04 15:36 - 00074226 _____ () C:\Users\Michael\Downloads\Innradtour09Obernberg-Erlau.gpx 2014-08-03 17:38 - 2014-08-03 17:38 - 00490166 _____ () C:\Users\Michael\Downloads\09-Movie&Show.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00352614 _____ () C:\Users\Michael\Downloads\Arabic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00269690 _____ () C:\Users\Michael\Downloads\12-Ethnic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00265411 _____ () C:\Users\Michael\Downloads\Turkish&Greek.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00263102 _____ () C:\Users\Michael\Downloads\06-Country.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00610081 _____ () C:\Users\Michael\Downloads\01-Pop&Rock.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00564588 _____ () C:\Users\Michael\Downloads\05-R&B.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00541643 _____ () C:\Users\Michael\Downloads\02-Ballad.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00524065 _____ () C:\Users\Michael\Downloads\03-Dance.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00394653 _____ () C:\Users\Michael\Downloads\07-Latin.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00347569 _____ () C:\Users\Michael\Downloads\04-Swing&Jazz.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00310825 _____ () C:\Users\Michael\Downloads\10-Entertainer.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00165856 _____ () C:\Users\Michael\Downloads\08-Ballroom.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00161112 _____ () C:\Users\Michael\Downloads\11-World.zip 2014-08-03 09:28 - 2014-08-03 09:29 - 02252800 _____ () C:\Users\Michael\Downloads\Google.rar.part 2014-07-29 20:14 - 2014-07-29 20:15 - 32040040 _____ (KETTLER) C:\Users\Michael\AVM_Driver\Pictures\Documents\KWT20Update20132.exe 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 ____D () C:\Users\Michael\Downloads\bosch 2014-07-29 18:54 - 2014-07-29 18:59 - 14162083 _____ () C:\Users\Michael\Downloads\Geoc0314.rar 2014-07-29 18:52 - 2014-07-29 18:59 - 19768581 _____ () C:\Users\Michael\Downloads\160720141227.rar 2014-07-29 13:24 - 2014-07-29 13:25 - 61689856 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.46.0.msi 2014-07-29 09:54 - 2014-07-29 09:54 - 00108809 _____ () C:\Users\Michael\Downloads\no_gullingen.zip 2014-07-28 10:13 - 2014-07-28 10:13 - 00296888 _____ () C:\WINDOWS\Minidump\072814-61468-01.dmp 2014-07-28 10:13 - 2014-07-28 10:13 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-28 05:59 - 2014-07-28 05:59 - 00000000 ____D () C:\Users\Michael\Downloads\Wo Bleibt die Musik 2014-07-28 05:17 - 2014-07-28 05:58 - 126414632 _____ () C:\Users\Michael\Downloads\Wo Bleibt die Musik.rar 2014-07-27 13:25 - 2014-07-27 13:28 - 125274721 _____ () C:\Users\Michael\Downloads\Klangkarussell-Netzwerk-2014-VOiCE.rar 2014-07-27 13:25 - 2014-07-27 13:27 - 84846335 _____ () C:\Users\Michael\Downloads\Tom_Petty_And_The_Heartbreakers-Hypnotic_Eye-2014-404.rar 2014-07-27 13:18 - 2014-07-27 13:21 - 20921388 _____ () C:\Users\Michael\Downloads\031120132206.rar 2014-07-26 19:33 - 2014-07-27 06:11 - 00000000 ____D () C:\Users\Michael\Downloads\Midi_Hüttenmusikant 2014-07-26 19:07 - 2014-07-26 19:07 - 00046745 _____ () C:\Users\Michael\Downloads\xt Amoi seg ma uns.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00094136 _____ () C:\Users\Michael\Downloads\xt Atemlos.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00080784 _____ () C:\Users\Michael\Downloads\SRP021 S910.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT(1).zip 2014-07-26 19:01 - 2014-07-26 19:01 - 00062888 _____ () C:\Users\Michael\Downloads\klingande-jubel.mid 2014-07-26 18:59 - 2014-07-26 18:59 - 00019221 _____ () C:\Users\Michael\Downloads\one_republic-love_runs_out.mid 2014-07-26 18:58 - 2014-07-26 18:58 - 00032868 _____ () C:\Users\Michael\Downloads\golden_earing-twilight_zone.mid 2014-07-25 17:21 - 2014-07-25 17:23 - 111246046 _____ () C:\Users\Michael\Downloads\OneRepublic-Nature-%28Special_Edition%29-2014-MTD.rar 2014-07-25 15:07 - 2014-07-29 13:23 - 00000000 ____D () C:\Users\Michael\Downloads\tanja Kruse 2014-07-25 15:06 - 2014-07-25 15:11 - 13567374 _____ () C:\Users\Michael\Downloads\Vita0814.rar 2014-07-25 15:02 - 2014-07-25 15:02 - 03151820 _____ () C:\Users\Michael\Downloads\t_k_na_fa_hac.rar 2014-07-25 15:01 - 2014-07-25 15:03 - 12253886 _____ () C:\Users\Michael\Downloads\290320142142.rar 2014-07-25 14:25 - 2014-07-25 14:25 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog_-_axel_f.mid 2014-07-25 14:24 - 2014-07-25 14:24 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog-axel_f.mid 2014-07-25 07:56 - 2014-07-25 07:56 - 00003164 _____ () C:\WINDOWS\System32\Tasks\StartMenuAutoupdate 2014-07-25 07:56 - 2014-07-25 07:56 - 00001279 _____ () C:\Users\Public\Desktop\Start Menu 8.lnk 2014-07-25 07:56 - 2014-07-25 07:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu 8 2014-07-22 18:26 - 2014-07-22 18:26 - 00000000 ____D () C:\WINDOWS\SysWOW64\Hotspot Shield 2014-07-21 21:10 - 2014-07-21 21:10 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-07-21 18:50 - 2014-07-21 18:50 - 00000000 ____D () C:\Users\Michael\AppData\Local\Intel_Corporation 2014-07-20 12:52 - 2014-07-20 12:52 - 00030891 _____ () C:\Users\Michael\Downloads\peterburgsky-donnaklara.zip 2014-07-20 09:28 - 2014-07-20 09:43 - 47978285 _____ () C:\Users\Michael\Downloads\01belle30.rar 2014-07-17 19:00 - 2014-07-17 19:01 - 69767374 _____ () C:\Users\Michael\Downloads\32pfl4308k_12_fus_deu.zip 2014-07-17 10:04 - 2014-07-17 13:41 - 00000000 ____D () C:\Users\Michael\Downloads\Garmin Topo Österreich V4_3086_imgUL-sql 2014-07-17 09:47 - 2014-07-17 09:49 - 06094554 _____ () C:\Users\Michael\Downloads\3222_gmapUL.part01(1).rar 2014-07-17 09:40 - 2014-07-17 10:04 - 363182599 _____ () C:\Users\Michael\Downloads\_3086_imgUL-sql.rar_ 2014-07-17 09:31 - 2014-07-17 09:31 - 00000000 ____D () C:\Users\Michael\Downloads\188 2014-07-17 09:30 - 2014-07-17 09:30 - 03704534 _____ () C:\Users\Michael\Downloads\188.rar 2014-07-17 09:21 - 2014-07-17 09:21 - 00001140 _____ () C:\Users\Public\Desktop\Hotspot Shield.lnk 2014-07-17 09:21 - 2014-07-17 09:21 - 00000176 _____ () C:\Users\Michael\Downloads\hotspotshield-setup_540.exe 2014-07-17 08:55 - 2014-05-17 04:35 - 00044744 _____ (AnchorFree Inc.) C:\WINDOWS\system32\Drivers\hssdrv6.sys 2014-07-17 08:54 - 2014-07-17 08:55 - 00000000 ____D () C:\ProgramData\Hotspot Shield 2014-07-17 08:54 - 2014-07-17 08:55 - 00000000 ____D () C:\Program Files (x86)\Hotspot Shield 2014-07-17 08:54 - 2014-07-17 08:54 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Hotspot Shield 2014-07-17 08:54 - 2014-07-17 08:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield 2014-07-17 08:53 - 2014-07-17 08:53 - 07787136 _____ () C:\Users\Michael\Downloads\HSS-3.42-install-e-550-plain.exe 2014-07-17 07:15 - 2014-07-17 07:15 - 00000000 ____D () C:\Users\Michael\Downloads\Sam_Smith-In_The_Lonely_Hour 2014-07-17 07:04 - 2014-07-17 07:04 - 00001799 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-07-17 07:04 - 2014-07-17 07:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-07-17 07:03 - 2014-07-17 07:04 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-07-17 07:03 - 2014-07-17 07:04 - 00000000 ____D () C:\Program Files\iTunes 2014-07-17 07:03 - 2014-07-17 07:03 - 00000000 ____D () C:\Program Files\iPod 2014-07-16 11:23 - 2014-07-16 11:23 - 00000000 ____D () C:\Users\Michael\Downloads\Onerepublic-Native 2014-07-16 11:15 - 2014-07-16 11:17 - 129360596 _____ () C:\Users\Michael\Downloads\Onerepublic-Native-2013-OMA.rar 2014-07-16 11:00 - 2014-07-16 11:00 - 02426602 _____ () C:\Users\Michael\Desktop\Lenker_0882.MOV 2014-07-16 10:59 - 2014-07-16 10:59 - 00670852 _____ () C:\Users\Michael\Desktop\IMG_0883.MOV 2014-07-16 10:04 - 2014-08-03 12:09 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-07-16 10:03 - 2014-07-16 10:04 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers 2014-07-16 10:02 - 2014-07-16 10:02 - 00000000 ____D () C:\Program Files\Common Files\Common Desktop Agent 2014-07-16 10:01 - 2014-07-16 10:04 - 00000000 ____D () C:\Program Files (x86)\SamsungPrinterLiveUpdate 2014-07-16 10:00 - 2014-07-16 10:04 - 00000000 ____D () C:\Program Files (x86)\Samsung 2014-07-16 10:00 - 2013-12-27 11:33 - 00226424 _____ () C:\WINDOWS\system32\SBuySupplies.exe 2014-07-16 10:00 - 2013-12-27 11:33 - 00158040 _____ (SS) C:\WINDOWS\system32\ssj2mci.exe 2014-07-16 10:00 - 2013-12-27 11:33 - 00089600 _____ (SS) C:\WINDOWS\system32\ssj2mci.dll 2014-07-16 10:00 - 2013-12-27 11:33 - 00034304 _____ () C:\WINDOWS\system32\ssj2mlm.dll 2014-07-16 10:00 - 2013-12-27 11:33 - 00000359 _____ () C:\WINDOWS\system32\ssj2mlm.smt 2014-07-16 10:00 - 2013-12-06 10:24 - 00101518 ____N () C:\WINDOWS\ssj2mLTR.prn 2014-07-16 10:00 - 2013-12-06 10:23 - 00107317 ____N () C:\WINDOWS\ssj2mA4.prn 2014-07-16 10:00 - 2013-07-05 08:20 - 00094208 ____N () C:\WINDOWS\SysWOW64\ssdevm.dll 2014-07-16 10:00 - 2013-07-05 08:20 - 00091136 ____N () C:\WINDOWS\system32\ssdevm64.dll 2014-07-15 10:55 - 2014-07-15 10:56 - 94166931 _____ () C:\Users\Michael\Downloads\Marquess-Favoritas-ES-2014-VOiCE.rar 2014-07-13 17:00 - 2014-07-13 17:01 - 00000862 _____ () C:\Users\Michael\Downloads\garmin alpenvereinskarten.nzb 2014-07-13 16:50 - 2014-07-13 16:50 - 07315296 _____ (IObit ) C:\Users\Michael\Downloads\startmenu-setup.exe 2014-07-13 12:03 - 2014-07-13 11:28 - 01104896 _____ () C:\Users\Michael\Desktop\michalt.db 2014-07-13 11:39 - 2014-07-29 13:26 - 00000946 _____ () C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk 2014-07-13 11:35 - 2014-07-13 11:36 - 61681664 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.44.0.msi 2014-07-13 09:08 - 2014-07-13 09:10 - 05083103 _____ () C:\Users\Michael\Downloads\Hartmann-Sechs.rar 2014-07-13 09:00 - 2014-07-13 09:00 - 00632784 _____ () C:\Users\Michael\Downloads\FRITZ.Box Fon WLAN 7390 (UI) 84.06.03_13.07.14_0859.export 2014-07-12 19:46 - 2014-07-12 19:46 - 04849874 _____ () C:\Users\Michael\Downloads\lkblijb3.rar 2014-07-12 19:14 - 2014-07-12 19:16 - 10233600 _____ () C:\Users\Michael\Downloads\c2gd7DhVt.rar 2014-07-12 18:33 - 2014-07-12 18:35 - 01144832 _____ () C:\Users\Michael\Desktop\test.db 2014-07-12 16:02 - 2014-07-12 16:04 - 10462813 _____ () C:\Users\Michael\Downloads\160520141214.rar 2014-07-12 16:02 - 2014-07-12 16:03 - 03237196 _____ () C:\Users\Michael\Downloads\ja-bo-bob.rar 2014-07-10 11:06 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll 2014-07-10 11:01 - 2014-07-10 11:01 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2014-07-10 08:52 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe 2014-07-10 08:52 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe 2014-07-10 08:52 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-07-10 08:52 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2014-07-10 08:51 - 2014-07-01 00:45 - 00688128 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2014-07-10 08:51 - 2014-06-28 09:48 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2014-07-10 08:51 - 2014-06-28 09:07 - 00385536 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2014-07-10 08:51 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-07-10 08:51 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-07-10 08:51 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-07-10 08:51 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2014-07-10 08:51 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-07-10 08:51 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-07-10 08:51 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2014-07-10 08:51 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2014-07-10 08:51 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-07-10 08:51 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-07-10 08:51 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-07-10 08:51 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-07-10 08:51 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-07-10 08:51 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-07-10 08:51 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-07-10 08:51 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2014-07-10 08:51 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-07-10 08:51 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-07-10 08:51 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-07-10 08:51 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-07-10 08:51 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-07-10 08:51 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-07-10 08:51 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-07-10 08:51 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-07-10 08:51 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-07-10 08:51 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-07-10 08:51 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-07-10 08:51 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll 2014-07-10 08:51 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll 2014-07-10 08:51 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2014-07-10 08:51 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2014-07-10 08:51 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2014-07-10 08:51 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2014-07-10 08:51 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2014-07-10 08:51 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2014-07-10 08:50 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2014-07-10 08:50 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2014-07-10 08:50 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2014-07-10 08:50 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2014-07-10 08:50 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-10 08:50 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2014-07-10 08:50 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2014-07-10 08:50 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-10 08:50 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2014-07-10 08:50 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2014-07-10 08:50 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2014-07-10 08:50 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2014-07-10 08:50 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-07-10 08:50 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2014-07-10 08:50 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-07-10 08:42 - 2014-07-10 08:42 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe 2014-07-09 11:39 - 2014-07-09 11:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SqliteBrowser3 2014-07-09 11:39 - 2014-07-09 11:39 - 00000000 ____D () C:\Program Files (x86)\SqliteBrowser3 2014-07-09 11:37 - 2014-07-09 11:38 - 10911328 _____ () C:\Users\Michael\Downloads\sqlitebrowser-3.2.0-win32.exe 2014-07-08 13:49 - 2014-07-08 13:49 - 00000000 ____D () C:\Users\Michael\Downloads\Lindsey_Stirling-Shatter_Me 2014-07-08 13:46 - 2014-07-08 13:48 - 102889698 _____ () C:\Users\Michael\Downloads\Lindsey_Stirling-Shatter_Me-2014-C4.rar 2014-07-08 13:45 - 2014-07-08 13:47 - 151930634 _____ () C:\Users\Michael\Downloads\Blue_Man_Group-The_Complex_Rock_Tour_Live_%28DVD%29-2004-CannaPower.rar 2014-07-08 12:46 - 2014-07-08 13:07 - 315621376 _____ () C:\Users\Michael\Downloads\_3222_gmapUL.part04.rar_ 2014-07-08 12:11 - 2014-07-08 12:32 - 315621376 _____ () C:\Users\Michael\Downloads\3222_gmapUL.part01.rar 2014-07-08 04:10 - 2014-07-09 11:35 - 00344064 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\Datenbank1.accdb 2014-07-07 18:47 - 2014-07-07 18:47 - 06598344 _____ () C:\Users\Michael\Downloads\HPPSdr.exe 2014-07-07 18:46 - 2014-07-07 18:48 - 122606512 _____ () C:\Users\Michael\Downloads\OJ6500_E710a-f_1315.exe 2014-07-07 15:56 - 2014-07-07 15:56 - 00000000 ____D () C:\AirPrint 2014-07-07 07:48 - 2014-07-07 07:48 - 01027470 _____ () C:\Users\Michael\Downloads\AirPrint Activator iOS5_4f2668dc9fdad.zip 2014-07-06 23:01 - 2014-07-06 23:01 - 00038912 _____ () C:\Users\Michael\Desktop\Michi.db 2014-07-06 22:58 - 2014-07-06 22:58 - 06164370 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\Backup_20140706.kwt.zip 2014-07-06 07:31 - 2014-07-06 07:31 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\WWS 2014-07-06 07:29 - 2014-07-06 07:29 - 00002499 _____ () C:\Users\Public\Desktop\KWT Database Utility.lnk 2014-07-06 07:29 - 2014-07-06 07:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WWS 2014-07-06 07:29 - 2014-07-06 07:29 - 00000000 ____D () C:\Program Files\WWS 2014-07-06 07:27 - 2014-07-06 07:27 - 05858024 _____ (WWS) C:\Users\Michael\Downloads\KWTDatabaseUtility10204.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-05 11:41 - 2014-08-05 11:40 - 00033734 _____ () C:\Users\Michael\Downloads\FRST.txt 2014-08-05 11:41 - 2014-08-05 11:40 - 00000000 ____D () C:\FRST 2014-08-05 11:40 - 2013-11-06 14:57 - 01380973 _____ () C:\WINDOWS\WindowsUpdate.log 2014-08-05 11:40 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\system32\NV 2014-08-05 11:38 - 2014-08-05 11:37 - 02094080 _____ (Farbar) C:\Users\Michael\Downloads\FRST64.exe 2014-08-05 11:38 - 2013-02-09 20:07 - 00000000 ____D () C:\Temp 2014-08-05 11:38 - 2012-11-23 04:45 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-08-05 11:37 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Help 2014-08-05 11:36 - 2013-05-25 19:22 - 00004208 _____ () C:\WINDOWS\System32\Tasks\Software Updater 2014-08-05 11:35 - 2009-06-28 12:04 - 568108032 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\Outlook.pst 2014-08-05 11:34 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\mkoelbl@online.de.pst 2014-08-05 11:34 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\mike1k@gmx.de.pst 2014-08-05 11:34 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\homeshopper66@online.de.pst 2014-08-05 11:34 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\hdampff@gmx.de.pst 2014-08-05 11:34 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\FTF-Hunter@online.de.pst 2014-08-05 11:34 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\FTF-Hunter@gmx.de.pst 2014-08-05 11:34 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\bayanbua@gmx.de.pst 2014-08-05 11:34 - 2013-02-17 08:44 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~Outlook.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~mkoelbl@online.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~mike1k@gmx.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~homeshopper66@online.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~hdampff@gmx.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~FTF-Hunter@online.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~FTF-Hunter@gmx.de.pst.tmp 2014-08-05 11:33 - 2014-08-05 11:33 - 00131072 ___HT () C:\Users\Michael\AVM_Driver\Pictures\Documents\~bayanbua@gmx.de.pst.tmp 2014-08-05 11:33 - 2013-02-09 23:55 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\Outlook-Dateien 2014-08-05 11:32 - 2013-07-09 19:43 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-05 11:29 - 2013-07-09 19:43 - 00001136 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-05 11:19 - 2013-04-22 12:00 - 00008192 _____ () C:\WINDOWS\SysWOW64\WDPABKP.dat 2014-08-05 11:18 - 2014-01-17 19:33 - 00000324 _____ () C:\WINDOWS\Tasks\AutoKMS.job 2014-08-05 11:18 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-08-05 11:17 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-08-05 11:17 - 2013-02-07 23:47 - 00000000 ____D () C:\Users\Michael 2014-08-05 11:04 - 2013-11-30 20:51 - 00003950 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{A0BF6906-8E67-4F48-9A06-BFACF99DFEAA} 2014-08-05 11:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-08-05 10:13 - 2013-02-08 14:30 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-587935961-2775860875-2407296441-1002 2014-08-05 10:07 - 2013-08-22 16:46 - 00395073 _____ () C:\WINDOWS\setupact.log 2014-08-05 10:06 - 2014-08-05 10:06 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp 2014-08-05 09:58 - 2014-08-05 09:58 - 00000218 _____ () C:\Users\Michael\AppData\Local\recently-used.xbel 2014-08-05 09:58 - 2014-06-26 14:25 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\BitLord 2014-08-05 09:43 - 2014-08-05 09:43 - 00040104 _____ () C:\Users\Michael\Desktop\radlriddle.htm 2014-08-05 09:26 - 2013-09-30 06:14 - 00731054 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-08-05 09:26 - 2013-09-30 05:56 - 01036102 _____ () C:\WINDOWS\system32\perfh007.dat 2014-08-05 09:26 - 2013-09-30 05:56 - 00239366 _____ () C:\WINDOWS\system32\perfc007.dat 2014-08-05 09:22 - 2014-05-09 06:38 - 00000000 ____D () C:\Users\Michael\Desktop\kabat 2014-08-05 08:33 - 2014-08-05 08:15 - 520324935 _____ () C:\Users\Michael\Downloads\Demo_Flakstad.exe 2014-08-05 08:08 - 2014-08-05 08:08 - 00053507 _____ () C:\Users\Michael\Downloads\route_1325.gpx 2014-08-05 04:08 - 2014-08-05 04:08 - 00064602 _____ () C:\Users\Michael\Downloads\IT_Stelvio2013_Control.rar 2014-08-05 03:43 - 2014-08-05 03:43 - 00031250 _____ () C:\Users\Michael\Downloads\NO_Gullingen.rlv 2014-08-05 03:38 - 2014-08-05 03:35 - 183717406 _____ () C:\Users\Michael\Downloads\Demo_Furka2011.exe 2014-08-04 15:36 - 2014-08-04 15:36 - 00961405 _____ () C:\Users\Michael\Downloads\GpsiesTrack.gpx 2014-08-04 15:36 - 2014-08-04 15:36 - 00074226 _____ () C:\Users\Michael\Downloads\Innradtour09Obernberg-Erlau.gpx 2014-08-04 15:21 - 2013-02-10 01:38 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\gsak8 2014-08-04 15:14 - 2013-02-10 01:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Nitro PDF 2014-08-04 15:13 - 2013-02-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin 2014-08-04 15:13 - 2013-02-09 20:40 - 00000000 ____D () C:\Program Files (x86)\Garmin 2014-08-04 15:05 - 2013-02-09 19:41 - 00000000 ____D () C:\GSAK8 2014-08-04 13:52 - 2014-02-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\FileAdvisor 2014-08-04 13:52 - 2014-02-11 14:52 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor 2014-08-04 12:59 - 2013-11-06 20:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\Deployment 2014-08-04 12:15 - 2013-02-07 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\Packages 2014-08-03 17:38 - 2014-08-03 17:38 - 00490166 _____ () C:\Users\Michael\Downloads\09-Movie&Show.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00352614 _____ () C:\Users\Michael\Downloads\Arabic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00269690 _____ () C:\Users\Michael\Downloads\12-Ethnic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00265411 _____ () C:\Users\Michael\Downloads\Turkish&Greek.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00263102 _____ () C:\Users\Michael\Downloads\06-Country.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00610081 _____ () C:\Users\Michael\Downloads\01-Pop&Rock.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00564588 _____ () C:\Users\Michael\Downloads\05-R&B.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00541643 _____ () C:\Users\Michael\Downloads\02-Ballad.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00524065 _____ () C:\Users\Michael\Downloads\03-Dance.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00394653 _____ () C:\Users\Michael\Downloads\07-Latin.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00347569 _____ () C:\Users\Michael\Downloads\04-Swing&Jazz.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00310825 _____ () C:\Users\Michael\Downloads\10-Entertainer.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00165856 _____ () C:\Users\Michael\Downloads\08-Ballroom.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00161112 _____ () C:\Users\Michael\Downloads\11-World.zip 2014-08-03 12:09 - 2014-07-16 10:04 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-08-03 11:47 - 2013-02-10 10:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-03 11:43 - 2014-01-27 11:29 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\vlc 2014-08-03 09:29 - 2014-08-03 09:28 - 02252800 _____ () C:\Users\Michael\Downloads\Google.rar.part 2014-08-02 14:38 - 2014-01-25 20:26 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0 2014-08-01 09:27 - 2013-05-25 19:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-29 20:17 - 2014-06-26 13:01 - 00002527 _____ () C:\Users\Public\Desktop\KETTLER WORLD TOURS 2.0.lnk 2014-07-29 20:16 - 2013-05-25 19:22 - 00000000 ____D () C:\ProgramData\Package Cache 2014-07-29 20:15 - 2014-07-29 20:14 - 32040040 _____ (KETTLER) C:\Users\Michael\AVM_Driver\Pictures\Documents\KWT20Update20132.exe 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 ____D () C:\Users\Michael\Downloads\bosch 2014-07-29 18:59 - 2014-07-29 18:54 - 14162083 _____ () C:\Users\Michael\Downloads\Geoc0314.rar 2014-07-29 18:59 - 2014-07-29 18:52 - 19768581 _____ () C:\Users\Michael\Downloads\160720141227.rar 2014-07-29 16:40 - 2013-11-01 11:05 - 00000000 ____D () C:\Users\Michael\Desktop\ebook 2014-07-29 16:37 - 2013-11-01 11:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\calibre-cache 2014-07-29 13:26 - 2014-07-13 11:39 - 00000946 _____ () C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk 2014-07-29 13:26 - 2013-11-01 11:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management 2014-07-29 13:26 - 2013-11-01 11:05 - 00000000 ____D () C:\Program Files\Calibre2 2014-07-29 13:25 - 2014-07-29 13:24 - 61689856 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.46.0.msi 2014-07-29 13:23 - 2014-07-25 15:07 - 00000000 ____D () C:\Users\Michael\Downloads\tanja Kruse 2014-07-29 11:34 - 2013-02-10 20:56 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2014-07-29 09:54 - 2014-07-29 09:54 - 00108809 _____ () C:\Users\Michael\Downloads\no_gullingen.zip 2014-07-28 10:13 - 2014-07-28 10:13 - 00296888 _____ () C:\WINDOWS\Minidump\072814-61468-01.dmp 2014-07-28 10:13 - 2014-07-28 10:13 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-28 10:13 - 2013-08-22 16:44 - 05244208 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-07-28 10:12 - 2013-02-25 11:04 - 744034049 _____ () C:\WINDOWS\MEMORY.DMP 2014-07-28 06:05 - 2013-02-10 00:17 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\Steuerfälle 2014-07-28 05:59 - 2014-07-28 05:59 - 00000000 ____D () C:\Users\Michael\Downloads\Wo Bleibt die Musik 2014-07-28 05:58 - 2014-07-28 05:17 - 126414632 _____ () C:\Users\Michael\Downloads\Wo Bleibt die Musik.rar 2014-07-27 13:28 - 2014-07-27 13:25 - 125274721 _____ () C:\Users\Michael\Downloads\Klangkarussell-Netzwerk-2014-VOiCE.rar 2014-07-27 13:27 - 2014-07-27 13:25 - 84846335 _____ () C:\Users\Michael\Downloads\Tom_Petty_And_The_Heartbreakers-Hypnotic_Eye-2014-404.rar 2014-07-27 13:21 - 2014-07-27 13:18 - 20921388 _____ () C:\Users\Michael\Downloads\031120132206.rar 2014-07-27 10:33 - 2013-02-10 02:35 - 01118720 ___SH () C:\Users\Michael\Desktop\Thumbs.db 2014-07-27 06:11 - 2014-07-26 19:33 - 00000000 ____D () C:\Users\Michael\Downloads\Midi_Hüttenmusikant 2014-07-27 06:05 - 2013-06-29 10:28 - 00014741 _____ () C:\missing.ini 2014-07-27 05:58 - 2013-02-10 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\Google 2014-07-27 05:50 - 2012-11-02 05:43 - 00000000 ____D () C:\ProgramData\Temp 2014-07-26 19:24 - 2013-04-07 17:58 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-26 19:24 - 2013-04-07 17:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-07-26 19:07 - 2014-07-26 19:07 - 00046745 _____ () C:\Users\Michael\Downloads\xt Amoi seg ma uns.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00094136 _____ () C:\Users\Michael\Downloads\xt Atemlos.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00080784 _____ () C:\Users\Michael\Downloads\SRP021 S910.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT(1).zip 2014-07-26 19:01 - 2014-07-26 19:01 - 00062888 _____ () C:\Users\Michael\Downloads\klingande-jubel.mid 2014-07-26 18:59 - 2014-07-26 18:59 - 00019221 _____ () C:\Users\Michael\Downloads\one_republic-love_runs_out.mid 2014-07-26 18:58 - 2014-07-26 18:58 - 00032868 _____ () C:\Users\Michael\Downloads\golden_earing-twilight_zone.mid 2014-07-25 17:23 - 2014-07-25 17:21 - 111246046 _____ () C:\Users\Michael\Downloads\OneRepublic-Nature-%28Special_Edition%29-2014-MTD.rar 2014-07-25 15:50 - 2014-08-05 10:07 - 01715224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2014-07-25 15:50 - 2014-08-05 10:07 - 01291280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2014-07-25 15:50 - 2014-04-19 16:27 - 01283136 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2014-07-25 15:50 - 2014-04-19 16:27 - 01126480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2014-07-25 15:11 - 2014-07-25 15:06 - 13567374 _____ () C:\Users\Michael\Downloads\Vita0814.rar 2014-07-25 15:03 - 2014-07-25 15:01 - 12253886 _____ () C:\Users\Michael\Downloads\290320142142.rar 2014-07-25 15:02 - 2014-07-25 15:02 - 03151820 _____ () C:\Users\Michael\Downloads\t_k_na_fa_hac.rar 2014-07-25 14:38 - 2014-07-03 20:03 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys 2014-07-25 14:25 - 2014-07-25 14:25 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog_-_axel_f.mid 2014-07-25 14:24 - 2014-07-25 14:24 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog-axel_f.mid 2014-07-25 07:56 - 2014-07-25 07:56 - 00003164 _____ () C:\WINDOWS\System32\Tasks\StartMenuAutoupdate 2014-07-25 07:56 - 2014-07-25 07:56 - 00001279 _____ () C:\Users\Public\Desktop\Start Menu 8.lnk 2014-07-25 07:56 - 2014-07-25 07:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu 8 2014-07-25 07:54 - 2014-02-02 19:48 - 00165659 _____ () C:\MyXML.xml 2014-07-24 17:24 - 2013-04-07 17:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-22 19:26 - 2013-12-09 10:58 - 00000000 ____D () C:\Users\Michael\Desktop\Apple + Tools 2014-07-22 18:27 - 2013-09-29 21:04 - 00423222 _____ () C:\WINDOWS\PFRO.log 2014-07-22 18:26 - 2014-07-22 18:26 - 00000000 ____D () C:\WINDOWS\SysWOW64\Hotspot Shield 2014-07-21 21:10 - 2014-07-21 21:10 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-07-21 21:10 - 2014-06-25 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-07-21 21:10 - 2014-06-25 21:07 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-07-21 18:50 - 2014-07-21 18:50 - 00000000 ____D () C:\Users\Michael\AppData\Local\Intel_Corporation 2014-07-20 18:57 - 2013-02-25 11:31 - 00043008 ___SH () C:\Users\Michael\Thumbs.db 2014-07-20 12:52 - 2014-07-20 12:52 - 00030891 _____ () C:\Users\Michael\Downloads\peterburgsky-donnaklara.zip 2014-07-20 09:43 - 2014-07-20 09:28 - 47978285 _____ () C:\Users\Michael\Downloads\01belle30.rar 2014-07-17 19:01 - 2014-07-17 19:00 - 69767374 _____ () C:\Users\Michael\Downloads\32pfl4308k_12_fus_deu.zip 2014-07-17 13:41 - 2014-07-17 10:04 - 00000000 ____D () C:\Users\Michael\Downloads\Garmin Topo Österreich V4_3086_imgUL-sql 2014-07-17 13:38 - 2013-02-09 18:54 - 00000000 ___RD () C:\Garmin 2014-07-17 10:04 - 2014-07-17 09:40 - 363182599 _____ () C:\Users\Michael\Downloads\_3086_imgUL-sql.rar_ 2014-07-17 09:49 - 2014-07-17 09:47 - 06094554 _____ () C:\Users\Michael\Downloads\3222_gmapUL.part01(1).rar 2014-07-17 09:31 - 2014-07-17 09:31 - 00000000 ____D () C:\Users\Michael\Downloads\188 2014-07-17 09:30 - 2014-07-17 09:30 - 03704534 _____ () C:\Users\Michael\Downloads\188.rar 2014-07-17 09:21 - 2014-07-17 09:21 - 00001140 _____ () C:\Users\Public\Desktop\Hotspot Shield.lnk 2014-07-17 09:21 - 2014-07-17 09:21 - 00000176 _____ () C:\Users\Michael\Downloads\hotspotshield-setup_540.exe 2014-07-17 08:55 - 2014-07-17 08:54 - 00000000 ____D () C:\ProgramData\Hotspot Shield 2014-07-17 08:55 - 2014-07-17 08:54 - 00000000 ____D () C:\Program Files (x86)\Hotspot Shield 2014-07-17 08:54 - 2014-07-17 08:54 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Hotspot Shield 2014-07-17 08:54 - 2014-07-17 08:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield 2014-07-17 08:53 - 2014-07-17 08:53 - 07787136 _____ () C:\Users\Michael\Downloads\HSS-3.42-install-e-550-plain.exe 2014-07-17 07:15 - 2014-07-17 07:15 - 00000000 ____D () C:\Users\Michael\Downloads\Sam_Smith-In_The_Lonely_Hour 2014-07-17 07:04 - 2014-07-17 07:04 - 00001799 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-07-17 07:04 - 2014-07-17 07:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-07-17 07:04 - 2014-07-17 07:03 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-07-17 07:04 - 2014-07-17 07:03 - 00000000 ____D () C:\Program Files\iTunes 2014-07-17 07:04 - 2013-02-18 19:51 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-07-17 07:03 - 2014-07-17 07:03 - 00000000 ____D () C:\Program Files\iPod 2014-07-16 13:23 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-07-16 11:23 - 2014-07-16 11:23 - 00000000 ____D () C:\Users\Michael\Downloads\Onerepublic-Native 2014-07-16 11:17 - 2014-07-16 11:15 - 129360596 _____ () C:\Users\Michael\Downloads\Onerepublic-Native-2013-OMA.rar 2014-07-16 11:00 - 2014-07-16 11:00 - 02426602 _____ () C:\Users\Michael\Desktop\Lenker_0882.MOV 2014-07-16 10:59 - 2014-07-16 10:59 - 00670852 _____ () C:\Users\Michael\Desktop\IMG_0883.MOV 2014-07-16 10:04 - 2014-07-16 10:03 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers 2014-07-16 10:04 - 2014-07-16 10:01 - 00000000 ____D () C:\Program Files (x86)\SamsungPrinterLiveUpdate 2014-07-16 10:04 - 2014-07-16 10:00 - 00000000 ____D () C:\Program Files (x86)\Samsung 2014-07-16 10:03 - 2013-02-10 01:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Samsung 2014-07-16 10:02 - 2014-07-16 10:02 - 00000000 ____D () C:\Program Files\Common Files\Common Desktop Agent 2014-07-16 10:02 - 2013-02-09 20:20 - 00000000 ____D () C:\ProgramData\Samsung 2014-07-15 10:56 - 2014-07-15 10:55 - 94166931 _____ () C:\Users\Michael\Downloads\Marquess-Favoritas-ES-2014-VOiCE.rar 2014-07-13 17:01 - 2014-07-13 17:00 - 00000862 _____ () C:\Users\Michael\Downloads\garmin alpenvereinskarten.nzb 2014-07-13 16:50 - 2014-07-13 16:50 - 07315296 _____ (IObit ) C:\Users\Michael\Downloads\startmenu-setup.exe 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore 2014-07-13 16:25 - 2013-02-17 08:44 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2014-07-13 14:41 - 2013-02-09 23:47 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\FinePrint-Dateien 2014-07-13 11:36 - 2014-07-13 11:35 - 61681664 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.44.0.msi 2014-07-13 11:28 - 2014-07-13 12:03 - 01104896 _____ () C:\Users\Michael\Desktop\michalt.db 2014-07-13 09:10 - 2014-07-13 09:08 - 05083103 _____ () C:\Users\Michael\Downloads\Hartmann-Sechs.rar 2014-07-13 09:00 - 2014-07-13 09:00 - 00632784 _____ () C:\Users\Michael\Downloads\FRITZ.Box Fon WLAN 7390 (UI) 84.06.03_13.07.14_0859.export 2014-07-12 19:46 - 2014-07-12 19:46 - 04849874 _____ () C:\Users\Michael\Downloads\lkblijb3.rar 2014-07-12 19:28 - 2014-01-17 18:51 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-07-12 19:28 - 2013-02-09 17:16 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-07-12 19:16 - 2014-07-12 19:14 - 10233600 _____ () C:\Users\Michael\Downloads\c2gd7DhVt.rar 2014-07-12 18:35 - 2014-07-12 18:33 - 01144832 _____ () C:\Users\Michael\Desktop\test.db 2014-07-12 16:04 - 2014-07-12 16:02 - 10462813 _____ () C:\Users\Michael\Downloads\160520141214.rar 2014-07-12 16:03 - 2014-07-12 16:02 - 03237196 _____ () C:\Users\Michael\Downloads\ja-bo-bob.rar 2014-07-10 11:32 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2014-07-10 11:31 - 2013-07-20 10:40 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-07-10 11:28 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-07-10 11:28 - 2013-02-11 11:03 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-07-10 11:03 - 2013-09-30 05:59 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 11:01 - 2014-07-10 11:01 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2014-07-10 08:42 - 2014-07-10 08:42 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe 2014-07-09 11:39 - 2014-07-09 11:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SqliteBrowser3 2014-07-09 11:39 - 2014-07-09 11:39 - 00000000 ____D () C:\Program Files (x86)\SqliteBrowser3 2014-07-09 11:38 - 2014-07-09 11:37 - 10911328 _____ () C:\Users\Michael\Downloads\sqlitebrowser-3.2.0-win32.exe 2014-07-09 11:35 - 2014-07-08 04:10 - 00344064 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\Datenbank1.accdb 2014-07-08 13:49 - 2014-07-08 13:49 - 00000000 ____D () C:\Users\Michael\Downloads\Lindsey_Stirling-Shatter_Me 2014-07-08 13:48 - 2014-07-08 13:46 - 102889698 _____ () C:\Users\Michael\Downloads\Lindsey_Stirling-Shatter_Me-2014-C4.rar 2014-07-08 13:47 - 2014-07-08 13:45 - 151930634 _____ () C:\Users\Michael\Downloads\Blue_Man_Group-The_Complex_Rock_Tour_Live_%28DVD%29-2004-CannaPower.rar 2014-07-08 13:07 - 2014-07-08 12:46 - 315621376 _____ () C:\Users\Michael\Downloads\_3222_gmapUL.part04.rar_ 2014-07-08 12:32 - 2014-07-08 12:11 - 315621376 _____ () C:\Users\Michael\Downloads\3222_gmapUL.part01.rar 2014-07-07 18:48 - 2014-07-07 18:46 - 122606512 _____ () C:\Users\Michael\Downloads\OJ6500_E710a-f_1315.exe 2014-07-07 18:47 - 2014-07-07 18:47 - 06598344 _____ () C:\Users\Michael\Downloads\HPPSdr.exe 2014-07-07 18:47 - 2013-02-09 20:44 - 00000000 ____D () C:\Program Files (x86)\HP 2014-07-07 15:56 - 2014-07-07 15:56 - 00000000 ____D () C:\AirPrint 2014-07-07 12:31 - 2014-05-26 15:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2014-07-07 07:48 - 2014-07-07 07:48 - 01027470 _____ () C:\Users\Michael\Downloads\AirPrint Activator iOS5_4f2668dc9fdad.zip 2014-07-06 23:01 - 2014-07-06 23:01 - 00038912 _____ () C:\Users\Michael\Desktop\Michi.db 2014-07-06 22:58 - 2014-07-06 22:58 - 06164370 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\Backup_20140706.kwt.zip 2014-07-06 07:31 - 2014-07-06 07:31 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\WWS 2014-07-06 07:29 - 2014-07-06 07:29 - 00002499 _____ () C:\Users\Public\Desktop\KWT Database Utility.lnk 2014-07-06 07:29 - 2014-07-06 07:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WWS 2014-07-06 07:29 - 2014-07-06 07:29 - 00000000 ____D () C:\Program Files\WWS 2014-07-06 07:27 - 2014-07-06 07:27 - 05858024 _____ (WWS) C:\Users\Michael\Downloads\KWTDatabaseUtility10204.exe Files to move or delete: ==================== C:\ProgramData\JonDoFox.paf.exe C:\Users\Michael\AutoRun.exe C:\Users\Michael\setup.exe C:\Users\Michael\Setup_AR.exe Some content of TEMP: ==================== C:\Users\Michael\AppData\Local\Temp\avgnt.exe C:\Users\Michael\AppData\Local\Temp\bassmod.dll C:\Users\Michael\AppData\Local\Temp\Creative Cloud Helper.exe C:\Users\Michael\AppData\Local\Temp\EasyLogin_setup_DE.exe C:\Users\Michael\AppData\Local\Temp\install_flashplayer13x32au_mssa_aaa_aih(1).exe C:\Users\Michael\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Michael\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Michael\AppData\Local\Temp\Offercast_AVIRAV7_.exe C:\Users\Michael\AppData\Local\Temp\photosync_setup_en_212.exe C:\Users\Michael\AppData\Local\Temp\photosync_setup_en_221.exe C:\Users\Michael\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Michael\AppData\Local\Temp\repair.exe C:\Users\Michael\AppData\Local\Temp\sqlite3.exe C:\Users\Michael\AppData\Local\Temp\tunesgo_full1368.exe C:\Users\Michael\AppData\Local\Temp\vlc-2.1.4-win64.exe C:\Users\Michael\AppData\Local\Temp\vlc-2.1.5-win64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-03 12:18 ==================== End Of Log ============================ |
06.08.2014, 14:13 | #5 | |
/// the machine /// TB-Ausbilder | C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werdenZitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.08.2014, 19:28 | #6 |
| C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werden OK - HIER DIE neue frst FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-08-2014 Ran by Michael (administrator) on MICHILAPTOP on 06-08-2014 20:13:55 Running from C:\Users\Michael\Downloads Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe () C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe () C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe (Apple Inc.) C:\AirPrint\airprint.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\HSSCP.exe (Intel Corporation) C:\Windows\System32\igfxext.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\InstallServices64.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212048 2012-06-07] (Realtek Semiconductor) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [ACPW06DE] => C:\Program Files\ACD Systems\ACDSee Pro\6.0\ACDSeePro6InTouch2.exe [1231992 2012-11-14] (ACD Systems) HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-41 (the data entry has 36 more characters). HKLM\...\Run: [SBRegRebootCleaner] => C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] () HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Dolby PCEE4\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554408 2013-05-15] (Lavasoft) HKLM-x32\...\Run: [SearchProtection] => C:\ProgramData\Search Protection\_run.bat [168 2013-02-28] () HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [uni mouse driver] => "C:\Mouse driver\mouse_driver.exe" /hide HKLM-x32\...\Run: [uni mouse driver tilt] => "C:\Mouse driver\wh_exec.exe" HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [CloneCDTray] => C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-24] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoDriveAutoRun] 0x0000 HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Agent] => "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse] => "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [7 Taskbar Tweaker] => C:\Users\Michael\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe [283648 2013-04-30] (RaMMicHaeL) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [1&1_1&1 Upload-Manager] => C:\Program Files (x86)\1&1\1&1 Upload-Manager\DAVSRV.EXE [989264 2011-11-21] (1&1 Internet AG) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [Rainlendar2] => C:\Program Files\Rainlendar2\Rainlendar2.exe HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Policies\Explorer: [NoDriveAutoRun] 0x0000 HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation) AppInit_DLLs: , C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation) AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [146480 2014-07-02] (NVIDIA Corporation) Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: AcronisSyncError -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncInProgress -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncOk -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers-x32: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: CloudIcon_DOWNLOAD -> {C3DBFBE2-A521-4619-9F32-502318CB4EC2} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_ERROR -> {851C758E-C636-4045-B323-059931A3A331} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_INSYNC -> {580030D3-492E-45EA-A1C9-A0AC525BEB26} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_REFRESH -> {FEBF62C8-B6B3-43B7-BEC4-1A9CD61BDCD2} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_UPLOAD -> {EBED3602-8915-43F9-81F7-CAA6FC4F70D6} => No File ShellIconOverlayIdentifiers-x32: Offline Files -> {4E77131D-3629-431c-9818-C5679DC83E81} => No File ShellIconOverlayIdentifiers-x32: SharingPrivate -> {08244EE6-92F0-47f2-9FC9-929BAA2E7235} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: http=;ftp=;https=; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM - {2C67950C-8251-481E-B96D-A28F2062192E} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS SearchScopes: HKLM - {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM-x32 - {2C67950C-8251-481E-B96D-A28F2062192E} URL = hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.6&ts=1369502554751&tguid=43169-3580-1369502554751-9FDCF2CB6E989C42D8699C8283EE7782&q={searchTerms} SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.5&ts=1369502554751&tguid=43169-3580-1369502554751-9FDCF2CB6E989C42D8699C8283EE7782&q={searchTerms} SearchScopes: HKCU - DefaultScope {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=112250&babsrc=SP_ss&mntrId=245fb41d0000000000000022fa23189d SearchScopes: HKCU - {2C67950C-8251-481E-B96D-A28F2062192E} URL = hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.6&ts=1369502554751&tguid=43169-3580-1369502554751-9FDCF2CB6E989C42D8699C8283EE7782&q={searchTerms} SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://lavasoft.blekko.com/ws/?source=f439e2c0&tbp=rbox&toolbarid=adawaretb&u=05998C3B7CD943D17EE7A8512F40DDF9&q={searchTerms} SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.5&ts=1369502554751&tguid=43169-3580-1369502554751-9FDCF2CB6E989C42D8699C8283EE7782&q={searchTerms} SearchScopes: HKCU - {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Ad-Aware Security Add-on -> {6c97a91e-4524-4019-86af-2aa2d567bf5c} -> C:\Program Files (x86)\adawaretb\adawareDx.dll () BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - No Name - {C7DDDD27-F303-42A5-B979-51559F7DC0F0} - No File Toolbar: HKLM-x32 - Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll () Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006 FF SearchEngineOrder.1: SuchMaschine FF Homepage: web.de FF Keyword.URL: hxxp://www.sm.de/?q= FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VLC Player\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\McAfee Security Scan\3.0.313\npMcAfeeMss.dll No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF user.js: detected! => C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\searchplugins\search_engine.xml FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Garmin Communicator - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-07-26] FF Extension: ColorZilla - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2014-03-18] FF Extension: Personas Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\personas@christopher.beard.xpi [2013-08-06] FF Extension: Leet Key - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{3335F91D-2AEF-4097-B831-C96C60349822}.xpi [2014-03-18] FF Extension: Adblock Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-07] FF Extension: Greasemonkey - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-01-01] FF Extension: Hotspot Shield Extension - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afproxy@anchorfree.com [2014-07-17] FF HKLM-x32\...\Firefox\Extensions: [webbooster@iminent.com] - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\ta4ni95k.default\extensions\webbooster@iminent.com FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited) R2 AirPrint; C:\AirPrint\airprint.exe [234784 2014-07-07] (Apple Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-05] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-05] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227456 2013-01-28] (Qualcomm Atheros Commnucations) S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG) S4 BrcmCardReader; C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe [176640 2012-08-20] (Broadcom Corp.) [File not signed] S4 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2435728 2012-08-23] (Acer Incorporated) S4 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [468624 2012-08-23] (Acer Incorporated) S4 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658576 2012-08-22] (Acer Incorporated) R2 HPSLPSVC; C:\Users\Michael\AppData\Local\Temp\7zS57EE\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed] R2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [919040 2014-05-17] (AnchorFree Inc.) [File not signed] S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [78512 2014-05-17] () R2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [430344 2014-05-17] () S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-11-12] (Nitro PDF Software) S4 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-08-23] (NTI Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [66872 2013-12-27] () R2 PnkBstrB; C:\WINDOWS\SysWOW64\PnkBstrB.exe [107832 2013-12-27] () S4 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2012-11-23] (Dritek System INC.) R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software) S4 StarMoney 8.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S4 Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [142960 2013-01-31] (Stardock Software, Inc) R2 StartMenuService; C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe [72992 2014-06-06] (IObit) S2 SystemStoreService; C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe [297984 2014-04-09] () [File not signed] R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2013-04-22] (Western Digital Technologies, Inc.) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270192 2013-03-21] (Western Digital Technologies, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) R2 WO_LiveService; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe [885096 2013-04-10] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-06-17] (Avira Operations GmbH & Co. KG) R3 avmaura; C:\Windows\System32\drivers\avmaura.sys [116480 2013-10-20] (AVM Berlin) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-28] (Qualcomm Atheros) S3 bthav; C:\Windows\system32\drivers\bthav.sys [40448 2008-07-10] (CSR, plc) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.) R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.) S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-06-28] (GFI Software) S3 GigasetGenericUSB_x64; C:\Windows\system32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2013-03-05] (Siemens Home and Office Communication Devices GmbH & Co. KG) R1 HssDRV6; C:\Windows\system32\DRIVERS\hssdrv6.sys [44744 2014-05-17] (AnchorFree Inc.) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) R2 LiveTunerPM; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerProcessMonitor64.sys [12824 2011-03-08] () R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-11-23] (Dritek System Inc.) R3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [1093256 2013-02-14] (Acronis) R1 ui11rdr; C:\Windows\System32\DRIVERS\ui11rdr.sys [199752 2011-11-21] (1&1 Internet AG) R1 UimBus; C:\Windows\System32\drivers\uimx64.sys [90960 2012-08-07] (Windows (R) 2000 DDK provider) R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633552 2012-08-07] (Paragon) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) R3 whfltr2k; C:\Windows\System32\drivers\whfltr2k.sys [10368 2009-09-16] () ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-06 17:43 - 2014-08-06 17:43 - 02194385 _____ () C:\Users\Michael\Desktop\Lenker_neu3.MOV 2014-08-06 17:42 - 2014-08-06 17:42 - 02977434 _____ () C:\Users\Michael\Desktop\Lenker_neu2.MOV 2014-08-06 17:42 - 2014-08-06 17:42 - 00971867 _____ () C:\Users\Michael\Desktop\Lenker_neu1.MOV 2014-08-06 09:43 - 2014-08-06 09:43 - 00001457 _____ () C:\Users\Michael\AppData\Local\recently-used.xbel 2014-08-06 09:25 - 2014-08-06 09:25 - 00000303 _____ () C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Heimnetzgruppe.lnk 2014-08-06 09:24 - 2014-08-06 09:39 - 976158128 _____ (Adobe Systems Incorporated) C:\Users\Michael\Downloads\Lightroom_5_LS11_win_5_6.exe 2014-08-05 11:45 - 2014-08-05 11:45 - 00086969 _____ () C:\Users\Michael\Desktop\FRST-ALT.txt 2014-08-05 11:45 - 2014-08-05 11:45 - 00082200 _____ () C:\Users\Michael\Desktop\Addition_ALT.txt 2014-08-05 11:43 - 2014-08-05 11:44 - 00082200 _____ () C:\Users\Michael\Downloads\Addition.txt 2014-08-05 11:40 - 2014-08-06 20:17 - 00000000 ____D () C:\FRST 2014-08-05 11:40 - 2014-08-06 20:13 - 00033590 _____ () C:\Users\Michael\Downloads\FRST.txt 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\system32\NV 2014-08-05 11:37 - 2014-08-05 11:38 - 02094080 _____ (Farbar) C:\Users\Michael\Downloads\FRST64.exe 2014-08-05 11:37 - 2014-07-02 20:55 - 06783776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 03522392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 02559960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 01084704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00935368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2014-08-05 11:37 - 2014-07-02 20:55 - 00386520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00067072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00062808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2014-08-05 11:37 - 2014-07-02 12:14 - 03826628 _____ () C:\WINDOWS\system32\nvcoproc.bin 2014-08-05 11:15 - 2014-07-02 22:48 - 31512520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 24196896 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 22994208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 18626304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 17555104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 16122344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 15294296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 14498552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 13922752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 13835208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 12866008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys 2014-08-05 11:15 - 2014-07-02 22:48 - 11283344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 11222048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 04247000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 03989960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 03196816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 02814656 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 01890080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6434052.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 01539928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6434052.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00965312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00944928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00907096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00903624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00869152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00846832 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00354016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00305600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00166568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00146480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00032544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys 2014-08-05 11:15 - 2014-07-02 22:48 - 00026353 _____ () C:\WINDOWS\system32\nvinfo.pb 2014-08-05 10:07 - 2014-07-25 15:50 - 01715224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2014-08-05 10:07 - 2014-07-25 15:50 - 01291280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2014-08-05 10:06 - 2014-08-05 10:06 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp 2014-08-05 10:06 - 2014-03-31 18:42 - 00040392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys 2014-08-05 10:06 - 2014-03-31 18:42 - 00034760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll 2014-08-05 08:15 - 2014-08-05 08:33 - 520324935 _____ () C:\Users\Michael\Downloads\Demo_Flakstad.exe 2014-08-05 08:08 - 2014-08-05 08:08 - 00053507 _____ () C:\Users\Michael\Downloads\route_1325.gpx 2014-08-05 04:08 - 2014-08-05 04:08 - 00064602 _____ () C:\Users\Michael\Downloads\IT_Stelvio2013_Control.rar 2014-08-05 03:43 - 2014-08-05 03:43 - 00031250 _____ () C:\Users\Michael\Downloads\NO_Gullingen.rlv 2014-08-05 03:35 - 2014-08-05 03:38 - 183717406 _____ () C:\Users\Michael\Downloads\Demo_Furka2011.exe 2014-08-04 15:36 - 2014-08-04 15:36 - 00961405 _____ () C:\Users\Michael\Downloads\GpsiesTrack.gpx 2014-08-04 15:36 - 2014-08-04 15:36 - 00074226 _____ () C:\Users\Michael\Downloads\Innradtour09Obernberg-Erlau.gpx 2014-08-03 17:38 - 2014-08-03 17:38 - 00490166 _____ () C:\Users\Michael\Downloads\09-Movie&Show.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00352614 _____ () C:\Users\Michael\Downloads\Arabic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00269690 _____ () C:\Users\Michael\Downloads\12-Ethnic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00265411 _____ () C:\Users\Michael\Downloads\Turkish&Greek.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00263102 _____ () C:\Users\Michael\Downloads\06-Country.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00610081 _____ () C:\Users\Michael\Downloads\01-Pop&Rock.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00564588 _____ () C:\Users\Michael\Downloads\05-R&B.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00541643 _____ () C:\Users\Michael\Downloads\02-Ballad.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00524065 _____ () C:\Users\Michael\Downloads\03-Dance.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00394653 _____ () C:\Users\Michael\Downloads\07-Latin.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00347569 _____ () C:\Users\Michael\Downloads\04-Swing&Jazz.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00310825 _____ () C:\Users\Michael\Downloads\10-Entertainer.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00165856 _____ () C:\Users\Michael\Downloads\08-Ballroom.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00161112 _____ () C:\Users\Michael\Downloads\11-World.zip 2014-08-03 09:28 - 2014-08-03 09:29 - 02252800 _____ () C:\Users\Michael\Downloads\Google.rar.part 2014-07-29 20:14 - 2014-07-29 20:15 - 32040040 _____ (KETTLER) C:\Users\Michael\AVM_Driver\Pictures\Documents\KWT20Update20132.exe 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 ____D () C:\Users\Michael\Downloads\bosch 2014-07-29 18:54 - 2014-07-29 18:59 - 14162083 _____ () C:\Users\Michael\Downloads\Geoc0314.rar 2014-07-29 18:52 - 2014-07-29 18:59 - 19768581 _____ () C:\Users\Michael\Downloads\160720141227.rar 2014-07-29 13:24 - 2014-07-29 13:25 - 61689856 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.46.0.msi 2014-07-29 09:54 - 2014-07-29 09:54 - 00108809 _____ () C:\Users\Michael\Downloads\no_gullingen.zip 2014-07-28 10:13 - 2014-07-28 10:13 - 00296888 _____ () C:\WINDOWS\Minidump\072814-61468-01.dmp 2014-07-28 10:13 - 2014-07-28 10:13 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-28 05:59 - 2014-07-28 05:59 - 00000000 ____D () C:\Users\Michael\Downloads\Wo Bleibt die Musik 2014-07-28 05:17 - 2014-07-28 05:58 - 126414632 _____ () C:\Users\Michael\Downloads\Wo Bleibt die Musik.rar 2014-07-27 13:25 - 2014-07-27 13:28 - 125274721 _____ () C:\Users\Michael\Downloads\Klangkarussell-Netzwerk-2014-VOiCE.rar 2014-07-27 13:25 - 2014-07-27 13:27 - 84846335 _____ () C:\Users\Michael\Downloads\Tom_Petty_And_The_Heartbreakers-Hypnotic_Eye-2014-404.rar 2014-07-27 13:18 - 2014-07-27 13:21 - 20921388 _____ () C:\Users\Michael\Downloads\031120132206.rar 2014-07-26 19:33 - 2014-07-27 06:11 - 00000000 ____D () C:\Users\Michael\Downloads\Midi_Hüttenmusikant 2014-07-26 19:07 - 2014-07-26 19:07 - 00046745 _____ () C:\Users\Michael\Downloads\xt Amoi seg ma uns.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00094136 _____ () C:\Users\Michael\Downloads\xt Atemlos.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00080784 _____ () C:\Users\Michael\Downloads\SRP021 S910.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT(1).zip 2014-07-26 19:01 - 2014-07-26 19:01 - 00062888 _____ () C:\Users\Michael\Downloads\klingande-jubel.mid 2014-07-26 18:59 - 2014-07-26 18:59 - 00019221 _____ () C:\Users\Michael\Downloads\one_republic-love_runs_out.mid 2014-07-26 18:58 - 2014-07-26 18:58 - 00032868 _____ () C:\Users\Michael\Downloads\golden_earing-twilight_zone.mid 2014-07-25 17:21 - 2014-07-25 17:23 - 111246046 _____ () C:\Users\Michael\Downloads\OneRepublic-Nature-%28Special_Edition%29-2014-MTD.rar 2014-07-25 15:07 - 2014-07-29 13:23 - 00000000 ____D () C:\Users\Michael\Downloads\tanja Kruse 2014-07-25 15:06 - 2014-07-25 15:11 - 13567374 _____ () C:\Users\Michael\Downloads\Vita0814.rar 2014-07-25 15:02 - 2014-07-25 15:02 - 03151820 _____ () C:\Users\Michael\Downloads\t_k_na_fa_hac.rar 2014-07-25 15:01 - 2014-07-25 15:03 - 12253886 _____ () C:\Users\Michael\Downloads\290320142142.rar 2014-07-25 14:25 - 2014-07-25 14:25 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog_-_axel_f.mid 2014-07-25 14:24 - 2014-07-25 14:24 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog-axel_f.mid 2014-07-25 07:56 - 2014-07-25 07:56 - 00003164 _____ () C:\WINDOWS\System32\Tasks\StartMenuAutoupdate 2014-07-25 07:56 - 2014-07-25 07:56 - 00001279 _____ () C:\Users\Public\Desktop\Start Menu 8.lnk 2014-07-25 07:56 - 2014-07-25 07:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu 8 2014-07-22 18:26 - 2014-07-22 18:26 - 00000000 ____D () C:\WINDOWS\SysWOW64\Hotspot Shield 2014-07-21 21:10 - 2014-08-06 09:20 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-07-21 18:50 - 2014-07-21 18:50 - 00000000 ____D () C:\Users\Michael\AppData\Local\Intel_Corporation 2014-07-20 12:52 - 2014-07-20 12:52 - 00030891 _____ () C:\Users\Michael\Downloads\peterburgsky-donnaklara.zip 2014-07-20 09:28 - 2014-07-20 09:43 - 47978285 _____ () C:\Users\Michael\Downloads\01belle30.rar 2014-07-17 19:00 - 2014-07-17 19:01 - 69767374 _____ () C:\Users\Michael\Downloads\32pfl4308k_12_fus_deu.zip 2014-07-17 10:04 - 2014-07-17 13:41 - 00000000 ____D () C:\Users\Michael\Downloads\Garmin Topo Österreich V4_3086_imgUL-sql 2014-07-17 09:47 - 2014-07-17 09:49 - 06094554 _____ () C:\Users\Michael\Downloads\3222_gmapUL.part01(1).rar 2014-07-17 09:40 - 2014-07-17 10:04 - 363182599 _____ () C:\Users\Michael\Downloads\_3086_imgUL-sql.rar_ 2014-07-17 09:31 - 2014-07-17 09:31 - 00000000 ____D () C:\Users\Michael\Downloads\188 2014-07-17 09:30 - 2014-07-17 09:30 - 03704534 _____ () C:\Users\Michael\Downloads\188.rar 2014-07-17 09:21 - 2014-07-17 09:21 - 00001140 _____ () C:\Users\Public\Desktop\Hotspot Shield.lnk 2014-07-17 09:21 - 2014-07-17 09:21 - 00000176 _____ () C:\Users\Michael\Downloads\hotspotshield-setup_540.exe 2014-07-17 08:55 - 2014-05-17 04:35 - 00044744 _____ (AnchorFree Inc.) C:\WINDOWS\system32\Drivers\hssdrv6.sys 2014-07-17 08:54 - 2014-07-17 08:55 - 00000000 ____D () C:\ProgramData\Hotspot Shield 2014-07-17 08:54 - 2014-07-17 08:55 - 00000000 ____D () C:\Program Files (x86)\Hotspot Shield 2014-07-17 08:54 - 2014-07-17 08:54 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Hotspot Shield 2014-07-17 08:54 - 2014-07-17 08:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield 2014-07-17 08:53 - 2014-07-17 08:53 - 07787136 _____ () C:\Users\Michael\Downloads\HSS-3.42-install-e-550-plain.exe 2014-07-17 07:15 - 2014-07-17 07:15 - 00000000 ____D () C:\Users\Michael\Downloads\Sam_Smith-In_The_Lonely_Hour 2014-07-17 07:04 - 2014-07-17 07:04 - 00001799 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-07-17 07:04 - 2014-07-17 07:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-07-17 07:03 - 2014-07-17 07:04 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-07-17 07:03 - 2014-07-17 07:04 - 00000000 ____D () C:\Program Files\iTunes 2014-07-17 07:03 - 2014-07-17 07:03 - 00000000 ____D () C:\Program Files\iPod 2014-07-16 11:23 - 2014-07-16 11:23 - 00000000 ____D () C:\Users\Michael\Downloads\Onerepublic-Native 2014-07-16 11:15 - 2014-07-16 11:17 - 129360596 _____ () C:\Users\Michael\Downloads\Onerepublic-Native-2013-OMA.rar 2014-07-16 11:00 - 2014-07-16 11:00 - 02426602 _____ () C:\Users\Michael\Desktop\Lenker_0882.MOV 2014-07-16 10:59 - 2014-07-16 10:59 - 00670852 _____ () C:\Users\Michael\Desktop\Sitz.MOV 2014-07-16 10:04 - 2014-08-06 10:07 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-07-16 10:03 - 2014-07-16 10:04 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers 2014-07-16 10:02 - 2014-07-16 10:02 - 00000000 ____D () C:\Program Files\Common Files\Common Desktop Agent 2014-07-16 10:01 - 2014-07-16 10:04 - 00000000 ____D () C:\Program Files (x86)\SamsungPrinterLiveUpdate 2014-07-16 10:00 - 2014-07-16 10:04 - 00000000 ____D () C:\Program Files (x86)\Samsung 2014-07-16 10:00 - 2013-12-27 11:33 - 00226424 _____ () C:\WINDOWS\system32\SBuySupplies.exe 2014-07-16 10:00 - 2013-12-27 11:33 - 00158040 _____ (SS) C:\WINDOWS\system32\ssj2mci.exe 2014-07-16 10:00 - 2013-12-27 11:33 - 00089600 _____ (SS) C:\WINDOWS\system32\ssj2mci.dll 2014-07-16 10:00 - 2013-12-27 11:33 - 00034304 _____ () C:\WINDOWS\system32\ssj2mlm.dll 2014-07-16 10:00 - 2013-12-27 11:33 - 00000359 _____ () C:\WINDOWS\system32\ssj2mlm.smt 2014-07-16 10:00 - 2013-12-06 10:24 - 00101518 ____N () C:\WINDOWS\ssj2mLTR.prn 2014-07-16 10:00 - 2013-12-06 10:23 - 00107317 ____N () C:\WINDOWS\ssj2mA4.prn 2014-07-16 10:00 - 2013-07-05 08:20 - 00094208 ____N () C:\WINDOWS\SysWOW64\ssdevm.dll 2014-07-16 10:00 - 2013-07-05 08:20 - 00091136 ____N () C:\WINDOWS\system32\ssdevm64.dll 2014-07-15 10:55 - 2014-07-15 10:56 - 94166931 _____ () C:\Users\Michael\Downloads\Marquess-Favoritas-ES-2014-VOiCE.rar 2014-07-13 17:00 - 2014-07-13 17:01 - 00000862 _____ () C:\Users\Michael\Downloads\garmin alpenvereinskarten.nzb 2014-07-13 16:50 - 2014-07-13 16:50 - 07315296 _____ (IObit ) C:\Users\Michael\Downloads\startmenu-setup.exe 2014-07-13 12:03 - 2014-07-13 11:28 - 01104896 _____ () C:\Users\Michael\Desktop\michalt.db 2014-07-13 11:39 - 2014-07-29 13:26 - 00000946 _____ () C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk 2014-07-13 11:35 - 2014-07-13 11:36 - 61681664 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.44.0.msi 2014-07-13 09:08 - 2014-07-13 09:10 - 05083103 _____ () C:\Users\Michael\Downloads\Hartmann-Sechs.rar 2014-07-13 09:00 - 2014-07-13 09:00 - 00632784 _____ () C:\Users\Michael\Downloads\FRITZ.Box Fon WLAN 7390 (UI) 84.06.03_13.07.14_0859.export 2014-07-12 19:46 - 2014-07-12 19:46 - 04849874 _____ () C:\Users\Michael\Downloads\lkblijb3.rar 2014-07-12 19:14 - 2014-07-12 19:16 - 10233600 _____ () C:\Users\Michael\Downloads\c2gd7DhVt.rar 2014-07-12 18:33 - 2014-07-12 18:35 - 01144832 _____ () C:\Users\Michael\Desktop\test.db 2014-07-12 16:02 - 2014-07-12 16:04 - 10462813 _____ () C:\Users\Michael\Downloads\160520141214.rar 2014-07-12 16:02 - 2014-07-12 16:03 - 03237196 _____ () C:\Users\Michael\Downloads\ja-bo-bob.rar 2014-07-10 11:06 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll 2014-07-10 11:01 - 2014-07-10 11:01 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2014-07-10 08:52 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe 2014-07-10 08:52 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe 2014-07-10 08:52 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-07-10 08:52 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2014-07-10 08:51 - 2014-07-01 00:45 - 00688128 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2014-07-10 08:51 - 2014-06-28 09:48 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2014-07-10 08:51 - 2014-06-28 09:07 - 00385536 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2014-07-10 08:51 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-07-10 08:51 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-07-10 08:51 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-07-10 08:51 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2014-07-10 08:51 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-07-10 08:51 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-07-10 08:51 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2014-07-10 08:51 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2014-07-10 08:51 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-07-10 08:51 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-07-10 08:51 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-07-10 08:51 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-07-10 08:51 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-07-10 08:51 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-07-10 08:51 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-07-10 08:51 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2014-07-10 08:51 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-07-10 08:51 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-07-10 08:51 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-07-10 08:51 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-07-10 08:51 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-07-10 08:51 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-07-10 08:51 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-07-10 08:51 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-07-10 08:51 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-07-10 08:51 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-07-10 08:51 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-07-10 08:51 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll 2014-07-10 08:51 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll 2014-07-10 08:51 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2014-07-10 08:51 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2014-07-10 08:51 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2014-07-10 08:51 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2014-07-10 08:51 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2014-07-10 08:51 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2014-07-10 08:50 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2014-07-10 08:50 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2014-07-10 08:50 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2014-07-10 08:50 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2014-07-10 08:50 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-10 08:50 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2014-07-10 08:50 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2014-07-10 08:50 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-10 08:50 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2014-07-10 08:50 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2014-07-10 08:50 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2014-07-10 08:50 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2014-07-10 08:50 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-07-10 08:50 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2014-07-10 08:50 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-07-10 08:42 - 2014-07-10 08:42 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe 2014-07-09 11:39 - 2014-07-09 11:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SqliteBrowser3 2014-07-09 11:39 - 2014-07-09 11:39 - 00000000 ____D () C:\Program Files (x86)\SqliteBrowser3 2014-07-09 11:37 - 2014-07-09 11:38 - 10911328 _____ () C:\Users\Michael\Downloads\sqlitebrowser-3.2.0-win32.exe 2014-07-08 13:49 - 2014-07-08 13:49 - 00000000 ____D () C:\Users\Michael\Downloads\Lindsey_Stirling-Shatter_Me 2014-07-08 13:46 - 2014-07-08 13:48 - 102889698 _____ () C:\Users\Michael\Downloads\Lindsey_Stirling-Shatter_Me-2014-C4.rar 2014-07-08 13:45 - 2014-07-08 13:47 - 151930634 _____ () C:\Users\Michael\Downloads\Blue_Man_Group-The_Complex_Rock_Tour_Live_%28DVD%29-2004-CannaPower.rar 2014-07-08 12:46 - 2014-07-08 13:07 - 315621376 _____ () C:\Users\Michael\Downloads\_3222_gmapUL.part04.rar_ 2014-07-08 12:11 - 2014-07-08 12:32 - 315621376 _____ () C:\Users\Michael\Downloads\3222_gmapUL.part01.rar 2014-07-08 04:10 - 2014-07-09 11:35 - 00344064 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\Datenbank1.accdb 2014-07-07 18:47 - 2014-07-07 18:47 - 06598344 _____ () C:\Users\Michael\Downloads\HPPSdr.exe 2014-07-07 18:46 - 2014-07-07 18:48 - 122606512 _____ () C:\Users\Michael\Downloads\OJ6500_E710a-f_1315.exe 2014-07-07 15:56 - 2014-07-07 15:56 - 00000000 ____D () C:\AirPrint 2014-07-07 07:48 - 2014-07-07 07:48 - 01027470 _____ () C:\Users\Michael\Downloads\AirPrint Activator iOS5_4f2668dc9fdad.zip ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-06 20:18 - 2014-08-05 11:40 - 00033590 _____ () C:\Users\Michael\Downloads\FRST.txt 2014-08-06 20:17 - 2014-08-05 11:40 - 00000000 ____D () C:\FRST 2014-08-06 20:12 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\mkoelbl@online.de.pst 2014-08-06 20:12 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\mike1k@gmx.de.pst 2014-08-06 20:12 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\homeshopper66@online.de.pst 2014-08-06 20:12 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\hdampff@gmx.de.pst 2014-08-06 20:12 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\FTF-Hunter@online.de.pst 2014-08-06 20:12 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\FTF-Hunter@gmx.de.pst 2014-08-06 20:12 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\bayanbua@gmx.de.pst 2014-08-06 20:12 - 2013-02-09 23:55 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\Outlook-Dateien 2014-08-06 20:12 - 2009-06-28 12:04 - 588678144 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\Outlook.pst 2014-08-06 20:07 - 2013-11-30 20:51 - 00003950 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{A0BF6906-8E67-4F48-9A06-BFACF99DFEAA} 2014-08-06 20:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-08-06 19:34 - 2013-02-17 08:44 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-08-06 19:30 - 2013-07-09 19:43 - 00001136 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-06 19:29 - 2013-07-09 19:43 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-06 18:20 - 2013-02-08 14:30 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-587935961-2775860875-2407296441-1002 2014-08-06 17:55 - 2012-11-02 05:43 - 00000000 ____D () C:\ProgramData\Temp 2014-08-06 17:43 - 2014-08-06 17:43 - 02194385 _____ () C:\Users\Michael\Desktop\Lenker_neu3.MOV 2014-08-06 17:43 - 2013-02-10 02:35 - 01159168 ___SH () C:\Users\Michael\Desktop\Thumbs.db 2014-08-06 17:42 - 2014-08-06 17:42 - 02977434 _____ () C:\Users\Michael\Desktop\Lenker_neu2.MOV 2014-08-06 17:42 - 2014-08-06 17:42 - 00971867 _____ () C:\Users\Michael\Desktop\Lenker_neu1.MOV 2014-08-06 17:34 - 2013-06-29 10:28 - 00014750 _____ () C:\missing.ini 2014-08-06 17:27 - 2013-05-25 19:22 - 00004208 _____ () C:\WINDOWS\System32\Tasks\Software Updater 2014-08-06 17:25 - 2013-02-07 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\Packages 2014-08-06 13:53 - 2014-02-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\FileAdvisor 2014-08-06 13:52 - 2014-02-11 14:52 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor 2014-08-06 12:41 - 2013-11-06 14:57 - 01516906 _____ () C:\WINDOWS\WindowsUpdate.log 2014-08-06 10:07 - 2014-07-16 10:04 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-08-06 09:43 - 2014-08-06 09:43 - 00001457 _____ () C:\Users\Michael\AppData\Local\recently-used.xbel 2014-08-06 09:43 - 2014-03-21 19:22 - 00000000 ____D () C:\Users\Michael\AppData\Local\gtk-2.0 2014-08-06 09:43 - 2013-02-09 21:20 - 00000000 ____D () C:\Users\Michael\.gimp-2.8 2014-08-06 09:39 - 2014-08-06 09:24 - 976158128 _____ (Adobe Systems Incorporated) C:\Users\Michael\Downloads\Lightroom_5_LS11_win_5_6.exe 2014-08-06 09:28 - 2014-05-29 17:33 - 00000000 ____D () C:\Users\Michael\AppData\Local\Adobe 2014-08-06 09:25 - 2014-08-06 09:25 - 00000303 _____ () C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Heimnetzgruppe.lnk 2014-08-06 09:21 - 2013-05-25 19:22 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-06 09:21 - 2013-02-07 23:47 - 00000000 ____D () C:\Users\Michael 2014-08-06 09:20 - 2014-07-21 21:10 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-06 09:20 - 2014-06-25 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-06 09:20 - 2014-06-25 21:07 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-06 09:14 - 2014-01-17 19:33 - 00000324 _____ () C:\WINDOWS\Tasks\AutoKMS.job 2014-08-06 09:14 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-08-06 09:14 - 2013-04-22 12:00 - 00008192 _____ () C:\WINDOWS\SysWOW64\WDPABKP.dat 2014-08-06 08:32 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-08-06 06:21 - 2014-05-26 14:09 - 00000000 ____D () C:\Program Files (x86)\KETTLER 2014-08-05 11:45 - 2014-08-05 11:45 - 00086969 _____ () C:\Users\Michael\Desktop\FRST-ALT.txt 2014-08-05 11:45 - 2014-08-05 11:45 - 00082200 _____ () C:\Users\Michael\Desktop\Addition_ALT.txt 2014-08-05 11:44 - 2014-08-05 11:43 - 00082200 _____ () C:\Users\Michael\Downloads\Addition.txt 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\system32\NV 2014-08-05 11:38 - 2014-08-05 11:37 - 02094080 _____ (Farbar) C:\Users\Michael\Downloads\FRST64.exe 2014-08-05 11:38 - 2013-02-09 20:07 - 00000000 ____D () C:\Temp 2014-08-05 11:38 - 2012-11-23 04:45 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-08-05 11:37 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Help 2014-08-05 11:17 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-08-05 10:07 - 2013-08-22 16:46 - 00395073 _____ () C:\WINDOWS\setupact.log 2014-08-05 10:06 - 2014-08-05 10:06 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp 2014-08-05 09:58 - 2014-06-26 14:25 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\BitLord 2014-08-05 09:26 - 2013-09-30 06:14 - 00731054 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-08-05 09:26 - 2013-09-30 05:56 - 01036102 _____ () C:\WINDOWS\system32\perfh007.dat 2014-08-05 09:26 - 2013-09-30 05:56 - 00239366 _____ () C:\WINDOWS\system32\perfc007.dat 2014-08-05 09:22 - 2014-05-09 06:38 - 00000000 ____D () C:\Users\Michael\Desktop\kabat 2014-08-05 08:33 - 2014-08-05 08:15 - 520324935 _____ () C:\Users\Michael\Downloads\Demo_Flakstad.exe 2014-08-05 08:08 - 2014-08-05 08:08 - 00053507 _____ () C:\Users\Michael\Downloads\route_1325.gpx 2014-08-05 04:08 - 2014-08-05 04:08 - 00064602 _____ () C:\Users\Michael\Downloads\IT_Stelvio2013_Control.rar 2014-08-05 03:43 - 2014-08-05 03:43 - 00031250 _____ () C:\Users\Michael\Downloads\NO_Gullingen.rlv 2014-08-05 03:38 - 2014-08-05 03:35 - 183717406 _____ () C:\Users\Michael\Downloads\Demo_Furka2011.exe 2014-08-04 15:36 - 2014-08-04 15:36 - 00961405 _____ () C:\Users\Michael\Downloads\GpsiesTrack.gpx 2014-08-04 15:36 - 2014-08-04 15:36 - 00074226 _____ () C:\Users\Michael\Downloads\Innradtour09Obernberg-Erlau.gpx 2014-08-04 15:21 - 2013-02-10 01:38 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\gsak8 2014-08-04 15:14 - 2013-02-10 01:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Nitro PDF 2014-08-04 15:13 - 2013-02-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin 2014-08-04 15:13 - 2013-02-09 20:40 - 00000000 ____D () C:\Program Files (x86)\Garmin 2014-08-04 15:05 - 2013-02-09 19:41 - 00000000 ____D () C:\GSAK8 2014-08-04 12:59 - 2013-11-06 20:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\Deployment 2014-08-03 17:38 - 2014-08-03 17:38 - 00490166 _____ () C:\Users\Michael\Downloads\09-Movie&Show.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00352614 _____ () C:\Users\Michael\Downloads\Arabic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00269690 _____ () C:\Users\Michael\Downloads\12-Ethnic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00265411 _____ () C:\Users\Michael\Downloads\Turkish&Greek.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00263102 _____ () C:\Users\Michael\Downloads\06-Country.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00610081 _____ () C:\Users\Michael\Downloads\01-Pop&Rock.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00564588 _____ () C:\Users\Michael\Downloads\05-R&B.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00541643 _____ () C:\Users\Michael\Downloads\02-Ballad.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00524065 _____ () C:\Users\Michael\Downloads\03-Dance.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00394653 _____ () C:\Users\Michael\Downloads\07-Latin.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00347569 _____ () C:\Users\Michael\Downloads\04-Swing&Jazz.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00310825 _____ () C:\Users\Michael\Downloads\10-Entertainer.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00165856 _____ () C:\Users\Michael\Downloads\08-Ballroom.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00161112 _____ () C:\Users\Michael\Downloads\11-World.zip 2014-08-03 11:47 - 2013-02-10 10:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-03 11:43 - 2014-01-27 11:29 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\vlc 2014-08-03 09:29 - 2014-08-03 09:28 - 02252800 _____ () C:\Users\Michael\Downloads\Google.rar.part 2014-08-02 14:38 - 2014-01-25 20:26 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0 2014-08-01 09:27 - 2013-05-25 19:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-29 20:17 - 2014-06-26 13:01 - 00002527 _____ () C:\Users\Public\Desktop\KETTLER WORLD TOURS 2.0.lnk 2014-07-29 20:15 - 2014-07-29 20:14 - 32040040 _____ (KETTLER) C:\Users\Michael\AVM_Driver\Pictures\Documents\KWT20Update20132.exe 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 ____D () C:\Users\Michael\Downloads\bosch 2014-07-29 18:59 - 2014-07-29 18:54 - 14162083 _____ () C:\Users\Michael\Downloads\Geoc0314.rar 2014-07-29 18:59 - 2014-07-29 18:52 - 19768581 _____ () C:\Users\Michael\Downloads\160720141227.rar 2014-07-29 16:40 - 2013-11-01 11:05 - 00000000 ____D () C:\Users\Michael\Desktop\ebook 2014-07-29 16:37 - 2013-11-01 11:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\calibre-cache 2014-07-29 13:26 - 2014-07-13 11:39 - 00000946 _____ () C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk 2014-07-29 13:26 - 2013-11-01 11:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management 2014-07-29 13:26 - 2013-11-01 11:05 - 00000000 ____D () C:\Program Files\Calibre2 2014-07-29 13:25 - 2014-07-29 13:24 - 61689856 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.46.0.msi 2014-07-29 13:23 - 2014-07-25 15:07 - 00000000 ____D () C:\Users\Michael\Downloads\tanja Kruse 2014-07-29 11:34 - 2013-02-10 20:56 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2014-07-29 09:54 - 2014-07-29 09:54 - 00108809 _____ () C:\Users\Michael\Downloads\no_gullingen.zip 2014-07-28 10:13 - 2014-07-28 10:13 - 00296888 _____ () C:\WINDOWS\Minidump\072814-61468-01.dmp 2014-07-28 10:13 - 2014-07-28 10:13 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-28 10:13 - 2013-08-22 16:44 - 05244208 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-07-28 10:12 - 2013-02-25 11:04 - 744034049 _____ () C:\WINDOWS\MEMORY.DMP 2014-07-28 06:05 - 2013-02-10 00:17 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\Steuerfälle 2014-07-28 05:59 - 2014-07-28 05:59 - 00000000 ____D () C:\Users\Michael\Downloads\Wo Bleibt die Musik 2014-07-28 05:58 - 2014-07-28 05:17 - 126414632 _____ () C:\Users\Michael\Downloads\Wo Bleibt die Musik.rar 2014-07-27 13:28 - 2014-07-27 13:25 - 125274721 _____ () C:\Users\Michael\Downloads\Klangkarussell-Netzwerk-2014-VOiCE.rar 2014-07-27 13:27 - 2014-07-27 13:25 - 84846335 _____ () C:\Users\Michael\Downloads\Tom_Petty_And_The_Heartbreakers-Hypnotic_Eye-2014-404.rar 2014-07-27 13:21 - 2014-07-27 13:18 - 20921388 _____ () C:\Users\Michael\Downloads\031120132206.rar 2014-07-27 06:11 - 2014-07-26 19:33 - 00000000 ____D () C:\Users\Michael\Downloads\Midi_Hüttenmusikant 2014-07-27 05:58 - 2013-02-10 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\Google 2014-07-26 19:24 - 2013-04-07 17:58 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-26 19:24 - 2013-04-07 17:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-07-26 19:07 - 2014-07-26 19:07 - 00046745 _____ () C:\Users\Michael\Downloads\xt Amoi seg ma uns.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00094136 _____ () C:\Users\Michael\Downloads\xt Atemlos.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00080784 _____ () C:\Users\Michael\Downloads\SRP021 S910.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT(1).zip 2014-07-26 19:01 - 2014-07-26 19:01 - 00062888 _____ () C:\Users\Michael\Downloads\klingande-jubel.mid 2014-07-26 18:59 - 2014-07-26 18:59 - 00019221 _____ () C:\Users\Michael\Downloads\one_republic-love_runs_out.mid 2014-07-26 18:58 - 2014-07-26 18:58 - 00032868 _____ () C:\Users\Michael\Downloads\golden_earing-twilight_zone.mid 2014-07-25 17:23 - 2014-07-25 17:21 - 111246046 _____ () C:\Users\Michael\Downloads\OneRepublic-Nature-%28Special_Edition%29-2014-MTD.rar 2014-07-25 15:50 - 2014-08-05 10:07 - 01715224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2014-07-25 15:50 - 2014-08-05 10:07 - 01291280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2014-07-25 15:50 - 2014-04-19 16:27 - 01283136 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2014-07-25 15:50 - 2014-04-19 16:27 - 01126480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2014-07-25 15:11 - 2014-07-25 15:06 - 13567374 _____ () C:\Users\Michael\Downloads\Vita0814.rar 2014-07-25 15:03 - 2014-07-25 15:01 - 12253886 _____ () C:\Users\Michael\Downloads\290320142142.rar 2014-07-25 15:02 - 2014-07-25 15:02 - 03151820 _____ () C:\Users\Michael\Downloads\t_k_na_fa_hac.rar 2014-07-25 14:38 - 2014-07-03 20:03 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys 2014-07-25 14:25 - 2014-07-25 14:25 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog_-_axel_f.mid 2014-07-25 14:24 - 2014-07-25 14:24 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog-axel_f.mid 2014-07-25 07:56 - 2014-07-25 07:56 - 00003164 _____ () C:\WINDOWS\System32\Tasks\StartMenuAutoupdate 2014-07-25 07:56 - 2014-07-25 07:56 - 00001279 _____ () C:\Users\Public\Desktop\Start Menu 8.lnk 2014-07-25 07:56 - 2014-07-25 07:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu 8 2014-07-25 07:54 - 2014-02-02 19:48 - 00165659 _____ () C:\MyXML.xml 2014-07-24 17:24 - 2013-04-07 17:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-22 19:26 - 2013-12-09 10:58 - 00000000 ____D () C:\Users\Michael\Desktop\Apple + Tools 2014-07-22 18:27 - 2013-09-29 21:04 - 00423222 _____ () C:\WINDOWS\PFRO.log 2014-07-22 18:26 - 2014-07-22 18:26 - 00000000 ____D () C:\WINDOWS\SysWOW64\Hotspot Shield 2014-07-21 18:50 - 2014-07-21 18:50 - 00000000 ____D () C:\Users\Michael\AppData\Local\Intel_Corporation 2014-07-20 18:57 - 2013-02-25 11:31 - 00043008 ___SH () C:\Users\Michael\Thumbs.db 2014-07-20 12:52 - 2014-07-20 12:52 - 00030891 _____ () C:\Users\Michael\Downloads\peterburgsky-donnaklara.zip 2014-07-20 09:43 - 2014-07-20 09:28 - 47978285 _____ () C:\Users\Michael\Downloads\01belle30.rar 2014-07-17 19:01 - 2014-07-17 19:00 - 69767374 _____ () C:\Users\Michael\Downloads\32pfl4308k_12_fus_deu.zip 2014-07-17 13:41 - 2014-07-17 10:04 - 00000000 ____D () C:\Users\Michael\Downloads\Garmin Topo Österreich V4_3086_imgUL-sql 2014-07-17 13:38 - 2013-02-09 18:54 - 00000000 ___RD () C:\Garmin 2014-07-17 10:04 - 2014-07-17 09:40 - 363182599 _____ () C:\Users\Michael\Downloads\_3086_imgUL-sql.rar_ 2014-07-17 09:49 - 2014-07-17 09:47 - 06094554 _____ () C:\Users\Michael\Downloads\3222_gmapUL.part01(1).rar 2014-07-17 09:31 - 2014-07-17 09:31 - 00000000 ____D () C:\Users\Michael\Downloads\188 2014-07-17 09:30 - 2014-07-17 09:30 - 03704534 _____ () C:\Users\Michael\Downloads\188.rar 2014-07-17 09:21 - 2014-07-17 09:21 - 00001140 _____ () C:\Users\Public\Desktop\Hotspot Shield.lnk 2014-07-17 09:21 - 2014-07-17 09:21 - 00000176 _____ () C:\Users\Michael\Downloads\hotspotshield-setup_540.exe 2014-07-17 08:55 - 2014-07-17 08:54 - 00000000 ____D () C:\ProgramData\Hotspot Shield 2014-07-17 08:55 - 2014-07-17 08:54 - 00000000 ____D () C:\Program Files (x86)\Hotspot Shield 2014-07-17 08:54 - 2014-07-17 08:54 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Hotspot Shield 2014-07-17 08:54 - 2014-07-17 08:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield 2014-07-17 08:53 - 2014-07-17 08:53 - 07787136 _____ () C:\Users\Michael\Downloads\HSS-3.42-install-e-550-plain.exe 2014-07-17 07:15 - 2014-07-17 07:15 - 00000000 ____D () C:\Users\Michael\Downloads\Sam_Smith-In_The_Lonely_Hour 2014-07-17 07:04 - 2014-07-17 07:04 - 00001799 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-07-17 07:04 - 2014-07-17 07:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-07-17 07:04 - 2014-07-17 07:03 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-07-17 07:04 - 2014-07-17 07:03 - 00000000 ____D () C:\Program Files\iTunes 2014-07-17 07:04 - 2013-02-18 19:51 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-07-17 07:03 - 2014-07-17 07:03 - 00000000 ____D () C:\Program Files\iPod 2014-07-16 13:23 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-07-16 11:23 - 2014-07-16 11:23 - 00000000 ____D () C:\Users\Michael\Downloads\Onerepublic-Native 2014-07-16 11:17 - 2014-07-16 11:15 - 129360596 _____ () C:\Users\Michael\Downloads\Onerepublic-Native-2013-OMA.rar 2014-07-16 11:00 - 2014-07-16 11:00 - 02426602 _____ () C:\Users\Michael\Desktop\Lenker_0882.MOV 2014-07-16 10:59 - 2014-07-16 10:59 - 00670852 _____ () C:\Users\Michael\Desktop\Sitz.MOV 2014-07-16 10:04 - 2014-07-16 10:03 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers 2014-07-16 10:04 - 2014-07-16 10:01 - 00000000 ____D () C:\Program Files (x86)\SamsungPrinterLiveUpdate 2014-07-16 10:04 - 2014-07-16 10:00 - 00000000 ____D () C:\Program Files (x86)\Samsung 2014-07-16 10:03 - 2013-02-10 01:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Samsung 2014-07-16 10:02 - 2014-07-16 10:02 - 00000000 ____D () C:\Program Files\Common Files\Common Desktop Agent 2014-07-16 10:02 - 2013-02-09 20:20 - 00000000 ____D () C:\ProgramData\Samsung 2014-07-15 10:56 - 2014-07-15 10:55 - 94166931 _____ () C:\Users\Michael\Downloads\Marquess-Favoritas-ES-2014-VOiCE.rar 2014-07-13 17:01 - 2014-07-13 17:00 - 00000862 _____ () C:\Users\Michael\Downloads\garmin alpenvereinskarten.nzb 2014-07-13 16:50 - 2014-07-13 16:50 - 07315296 _____ (IObit ) C:\Users\Michael\Downloads\startmenu-setup.exe 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore 2014-07-13 16:25 - 2013-02-17 08:44 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2014-07-13 14:41 - 2013-02-09 23:47 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\FinePrint-Dateien 2014-07-13 11:36 - 2014-07-13 11:35 - 61681664 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.44.0.msi 2014-07-13 11:28 - 2014-07-13 12:03 - 01104896 _____ () C:\Users\Michael\Desktop\michalt.db 2014-07-13 09:10 - 2014-07-13 09:08 - 05083103 _____ () C:\Users\Michael\Downloads\Hartmann-Sechs.rar 2014-07-13 09:00 - 2014-07-13 09:00 - 00632784 _____ () C:\Users\Michael\Downloads\FRITZ.Box Fon WLAN 7390 (UI) 84.06.03_13.07.14_0859.export 2014-07-12 19:46 - 2014-07-12 19:46 - 04849874 _____ () C:\Users\Michael\Downloads\lkblijb3.rar 2014-07-12 19:28 - 2014-01-17 18:51 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-07-12 19:28 - 2013-02-09 17:16 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-07-12 19:16 - 2014-07-12 19:14 - 10233600 _____ () C:\Users\Michael\Downloads\c2gd7DhVt.rar 2014-07-12 18:35 - 2014-07-12 18:33 - 01144832 _____ () C:\Users\Michael\Desktop\test.db 2014-07-12 16:04 - 2014-07-12 16:02 - 10462813 _____ () C:\Users\Michael\Downloads\160520141214.rar 2014-07-12 16:03 - 2014-07-12 16:02 - 03237196 _____ () C:\Users\Michael\Downloads\ja-bo-bob.rar 2014-07-10 11:32 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2014-07-10 11:31 - 2013-07-20 10:40 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-07-10 11:28 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-07-10 11:28 - 2013-02-11 11:03 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-07-10 11:03 - 2013-09-30 05:59 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 11:01 - 2014-07-10 11:01 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2014-07-10 08:42 - 2014-07-10 08:42 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe 2014-07-09 11:39 - 2014-07-09 11:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SqliteBrowser3 2014-07-09 11:39 - 2014-07-09 11:39 - 00000000 ____D () C:\Program Files (x86)\SqliteBrowser3 2014-07-09 11:38 - 2014-07-09 11:37 - 10911328 _____ () C:\Users\Michael\Downloads\sqlitebrowser-3.2.0-win32.exe 2014-07-09 11:35 - 2014-07-08 04:10 - 00344064 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\Datenbank1.accdb 2014-07-08 13:49 - 2014-07-08 13:49 - 00000000 ____D () C:\Users\Michael\Downloads\Lindsey_Stirling-Shatter_Me 2014-07-08 13:48 - 2014-07-08 13:46 - 102889698 _____ () C:\Users\Michael\Downloads\Lindsey_Stirling-Shatter_Me-2014-C4.rar 2014-07-08 13:47 - 2014-07-08 13:45 - 151930634 _____ () C:\Users\Michael\Downloads\Blue_Man_Group-The_Complex_Rock_Tour_Live_%28DVD%29-2004-CannaPower.rar 2014-07-08 13:07 - 2014-07-08 12:46 - 315621376 _____ () C:\Users\Michael\Downloads\_3222_gmapUL.part04.rar_ 2014-07-08 12:32 - 2014-07-08 12:11 - 315621376 _____ () C:\Users\Michael\Downloads\3222_gmapUL.part01.rar 2014-07-07 18:48 - 2014-07-07 18:46 - 122606512 _____ () C:\Users\Michael\Downloads\OJ6500_E710a-f_1315.exe 2014-07-07 18:47 - 2014-07-07 18:47 - 06598344 _____ () C:\Users\Michael\Downloads\HPPSdr.exe 2014-07-07 18:47 - 2013-02-09 20:44 - 00000000 ____D () C:\Program Files (x86)\HP 2014-07-07 15:56 - 2014-07-07 15:56 - 00000000 ____D () C:\AirPrint 2014-07-07 12:31 - 2014-05-26 15:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2014-07-07 07:48 - 2014-07-07 07:48 - 01027470 _____ () C:\Users\Michael\Downloads\AirPrint Activator iOS5_4f2668dc9fdad.zip Files to move or delete: ==================== C:\ProgramData\JonDoFox.paf.exe C:\Users\Michael\AutoRun.exe C:\Users\Michael\setup.exe C:\Users\Michael\Setup_AR.exe Some content of TEMP: ==================== C:\Users\Michael\AppData\Local\Temp\avgnt.exe C:\Users\Michael\AppData\Local\Temp\bassmod.dll C:\Users\Michael\AppData\Local\Temp\Creative Cloud Helper.exe C:\Users\Michael\AppData\Local\Temp\EasyLogin_setup_DE.exe C:\Users\Michael\AppData\Local\Temp\install_flashplayer13x32au_mssa_aaa_aih(1).exe C:\Users\Michael\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Michael\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Michael\AppData\Local\Temp\Offercast_AVIRAV7_.exe C:\Users\Michael\AppData\Local\Temp\photosync_setup_en_212.exe C:\Users\Michael\AppData\Local\Temp\photosync_setup_en_221.exe C:\Users\Michael\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Michael\AppData\Local\Temp\repair.exe C:\Users\Michael\AppData\Local\Temp\sqlite3.exe C:\Users\Michael\AppData\Local\Temp\tunesgo_full1368.exe C:\Users\Michael\AppData\Local\Temp\vlc-2.1.4-win64.exe C:\Users\Michael\AppData\Local\Temp\vlc-2.1.5-win64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-06 10:12 ==================== End Of Log ============================ |
07.08.2014, 16:49 | #7 |
/// the machine /// TB-Ausbilder | C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werden hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.08.2014, 20:44 | #8 |
| C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werden Hi ich bekomme bei Start von combofix folgende Fehlermeldung: combofix is not meant to run in compatibility mode antivir etc ist alles ausgeschaltet |
08.08.2014, 16:29 | #9 |
/// the machine /// TB-Ausbilder | C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werden Mein Fehler Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.08.2014, 17:42 | #10 |
| C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werden sorry - hat ein wenig gedauert :-( Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 08.08.2014 Suchlauf-Zeit: 20:43:26 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.08.08.05 Rootkit Datenbank: v2014.08.04.01 Lizenz: Premium Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Michael Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 392793 Verstrichene Zeit: 21 Std, 17 Min, 42 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 2 PUP.Optional.Babylon.A, HKU\S-1-5-21-587935961-2775860875-2407296441-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Löschen bei Neustart, [0025289c95e691a55456d0956b9710f0], PUP.Optional.AdPeak.A, HKLM\SOFTWARE\LevelQualityWatcher, In Quarantäne, [27fea51f1c5f3cfa3bd59050c73b0cf4], Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 4 PUP.Optional.Adpeak, C:\Program Files\Level Quality Watcher, In Quarantäne, [3de84a7a9eddd462f41fa9216f939e62], PUP.Optional.SystemSpeedup, C:\Users\Michael\AppData\Roaming\systweak\ssd, In Quarantäne, [5ec721a36615de585301ccff0df57789], PUP.Optional.HomeTab.A, C:\Program Files (x86)\HomeTab, In Quarantäne, [e83d2f95413aae88ed9d6669a35f46ba], PUP.Optional.DownTango.A, C:\Program Files (x86)\Red Sky\DownTango, In Quarantäne, [44e14d77116af145b3420acac33fa060], Dateien: 1 PUP.Optional.SystemSpeedup, C:\Users\Michael\AppData\Roaming\systweak\ssd\SSDPTstub.exe, In Quarantäne, [5ec721a36615de585301ccff0df57789], Physische Sektoren: 0 (No malicious items detected) (end) AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.304 - Bericht erstellt am 09/08/2014 um 18:19:58 # Aktualisiert 08/08/2014 von Xplode # Betriebssystem : Windows 8.1 (64 bits) # Benutzername : Michael - MICHILAPTOP # Gestartet von : C:\Users\Michael\Desktop\adwcleaner_3.304.exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : hshld [#] Dienst Gelöscht : hsstrayservice Dienst Gelöscht : hsswd [#] Dienst Gelöscht : SystemStoreService ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\blekko toolbars Ordner Gelöscht : C:\ProgramData\hotspot shield Ordner Gelöscht : C:\ProgramData\Iminent Ordner Gelöscht : C:\ProgramData\ParetoLogic Ordner Gelöscht : C:\ProgramData\QuickSet Ordner Gelöscht : C:\ProgramData\Search Protection Ordner Gelöscht : C:\ProgramData\WPM Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hotspot shield Ordner Gelöscht : C:\Program Files (x86)\adawaretb Ordner Gelöscht : C:\Program Files (x86)\Advanced System Protector Ordner Gelöscht : C:\Program Files (x86)\BrowseSmart Ordner Gelöscht : C:\Program Files (x86)\Conduit Ordner Gelöscht : C:\Program Files (x86)\hotspot shield Ordner Gelöscht : C:\Program Files (x86)\Iminent Ordner Gelöscht : C:\Program Files (x86)\Mobogenie Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro Ordner Gelöscht : C:\Program Files (x86)\ParetoLogic Ordner Gelöscht : C:\Program Files (x86)\Red Sky Ordner Gelöscht : C:\Program Files (x86)\SoftwareUpdater Ordner Gelöscht : C:\Program Files (x86)\sweetpacks bundle uninstaller Ordner Gelöscht : C:\Program Files (x86)\System Speedup Ordner Gelöscht : C:\Program Files (x86)\Toolbar Cleaner Ordner Gelöscht : C:\Program Files (x86)\Uniblue Ordner Gelöscht : C:\Program Files (x86)\Common Files\Umbrella Ordner Gelöscht : C:\WINDOWS\SysWOW64\hotspot shield Ordner Gelöscht : C:\Users\Michael\AppData\Local\Conduit Ordner Gelöscht : C:\Users\Michael\AppData\Local\Mobogenie Ordner Gelöscht : C:\Users\Michael\AppData\Local\PackageAware Ordner Gelöscht : C:\Users\Michael\AppData\Local\Software_Updater Ordner Gelöscht : C:\Users\Michael\AppData\Local\SoftwareUpdater Ordner Gelöscht : C:\Users\Michael\AppData\Local\Temp\hotspot shield Ordner Gelöscht : C:\Users\Michael\AppData\Local\Temp\OCS Ordner Gelöscht : C:\Users\Michael\AppData\LocalLow\adawaretb Ordner Gelöscht : C:\Users\Michael\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Michael\AppData\LocalLow\SimplyTech Ordner Gelöscht : C:\Users\Michael\AppData\Roaming\aartemis Ordner Gelöscht : C:\Users\Michael\AppData\Roaming\DesktopIconForAmazon Ordner Gelöscht : C:\Users\Michael\AppData\Roaming\DriverCure Ordner Gelöscht : C:\Users\Michael\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Michael\AppData\Roaming\hotspot shield Ordner Gelöscht : C:\Users\Michael\AppData\Roaming\Iminent Ordner Gelöscht : C:\Users\Michael\AppData\Roaming\OCS Ordner Gelöscht : C:\Users\Michael\AppData\Roaming\ParetoLogic Ordner Gelöscht : C:\Users\Michael\AppData\Roaming\Systweak Ordner Gelöscht : C:\Users\Michael\AppData\Roaming\Uniblue Ordner Gelöscht : C:\Users\wangzhisong\AppData\Local\Mobogenie Ordner Gelöscht : C:\Users\Michael\AppData\Local\Software Ordner Gelöscht : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\tgdaq8o1.default-1363975082672\Extensions\{33E0DAA6-3AF3-D8B5-6752-10E949C61516} Datei Gelöscht : C:\END Datei Gelöscht : C:\Program Files (x86)\Uninstall.exe Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe Datei Gelöscht : C:\Users\Michael\daemonprocess.txt Datei Gelöscht : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\user.js Datei Gelöscht : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\tgdaq8o1.default-1363975082672\user.js ***** [ Tasks ] ***** Task Gelöscht : Freemium1ClickMaint Task Gelöscht : Software Updater Ui Task Gelöscht : Software Updater ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [webbooster@iminent.com] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\Complitly.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateBrowseSmart_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateBrowseSmart_RASMANCS Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtection] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02C9C7B0-C7C8-4AAC-A9E4-55295BF60F8F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0398B101-6DA7-473F-A290-17D2FBC88CC0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0CC36196-8589-4B80-A771-D659411D7F90} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{143D96F9-EB64-48B3-B192-91C2C41A1F43} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{14F7D91F-F669-45C9-9F42-BACBFDB86EAD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{187A6488-6E71-4A2A-B118-7BEFBFE58257} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26C9BBE4-6D45-4AB6-A5B4-E068C9F5EF6D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2D065204-A024-4C39-8A38-EE7078EC7ACF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30F5476C-677B-4DB0-B397-51F5BFD86840} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3223F2FB-D9B9-45FC-9D66-CD717FFA4EE5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{351798B1-C1D2-45AB-92B4-4D6C2D6AB5AF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3AEA1BEF-6195-46F4-ACA2-0ED14F7EFA1B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3D7F9AC3-BAC3-4E51-81D7-D121D79E550A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4498C5E9-93C6-4142-B6BE-F0C6DC48B77A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{479BF2D6-E362-4A99-B1AB-BC764D7B97AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{492A108F-51D0-4BD8-899D-AD4AB2893064} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4B6D6E60-FBD2-4E79-BF4B-886BC98F1797} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{60893E02-2E5B-43F9-A93A-BAD60C2DF6EF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6D39931F-451E-4BDD-BAF4-37FB96DBBA5D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{76C684D2-C35D-4284-976A-D862F53ADB81} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{796D822A-C3F9-4A97-BAAB-42FE7628EA63} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{79EF3691-EC1A-4705-A01A-D2E36EC11758} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82F41418-8E64-47EB-A7F1-4702A974D289} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{85D920CE-63A7-46DC-8992-41D1D2E07FAD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{895ED5E8-ABB4-40C3-A0CA-2571964268E2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8AAC123A-1959-4A45-BFC5-E2D50783098A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A07956CD-81F8-4A03-B524-5D87E690DC83} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B5E3B26B-6E5C-4865-A63D-58D04B10E245} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B84D2DC5-42B2-4E5E-BF61-7B48152FF8EF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B89D5309-0367-4494-A92F-3D4C94F88307} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C014EBF8-8854-448B-B5A4-557C4090EDCE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C31191DB-2F64-464C-B97C-6AC81ACB7AAC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C342C7A7-F622-4EF3-8B7F-ABB9FBE73F14} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C4765B07-BC2F-477B-925C-B2BF24887823} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C875C0A1-09E3-48D5-9F8E-BD337796FD14} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD126DA6-FF5B-4181-AC13-54A62240D2FA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D8F01233-2DE6-4EE7-8988-37263F00651B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DD438708-AAB4-422D-A322-B619589F5680} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E812AE43-7799-4E67-8CF8-4104297A2D16} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F0BAAEC7-9AE0-49FF-9C4B-86E774FF397F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F92193FD-2243-4401-9ACC-49FF30885898} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD21B8A2-910B-45AC-9C10-45E6A8B84984} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522072280} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7697BC38-D0FA-454B-AC75-968B4CCABFCE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B0DE3308-5D5A-470D-81B9-634FC078393B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522072280} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7697BC38-D0FA-454B-AC75-968B4CCABFCE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ACA608DB-A210-4253-B799-3FD24E9A7BF5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36} Schlüssel Gelöscht : HKCU\Software\anchorfree Schlüssel Gelöscht : HKCU\Software\Complitly Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\distromatic Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\ParetoLogic Schlüssel Gelöscht : HKCU\Software\simplytech Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\SweetIM Schlüssel Gelöscht : HKCU\Software\systweak Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKCU\Software\AppDataLow\AskBarDis Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\adawarebp Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Schlüssel Gelöscht : HKLM\Software\aartemisSoftware Schlüssel Gelöscht : HKLM\Software\adawaretb Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\hotspotshield Schlüssel Gelöscht : HKLM\Software\ParetoLogic Schlüssel Gelöscht : HKLM\Software\SimplyGen Schlüssel Gelöscht : HKLM\Software\supWPM Schlüssel Gelöscht : HKLM\Software\SweetIM Schlüssel Gelöscht : HKLM\Software\systweak Schlüssel Gelöscht : HKLM\Software\Toolbar Cleaner Schlüssel Gelöscht : HKLM\Software\Uniblue Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{29C7E8BE-FBD9-4D91-BC4F-B470C718D554} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hotspotshield Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Tarma Installer Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\EB8E7C929DBF19D4CBF44B077C815D45 Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\EB8E7C929DBF19D4CBF44B077C815D45 ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 -\\ Mozilla Firefox v31.0 (x86 de) [ Datei : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\prefs.js ] Zeile gelöscht : user_pref("keyword.URL", "hxxp://www.sm.de/?q="); [ Datei : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\tgdaq8o1.default-1363975082672\prefs.js ] Zeile gelöscht : user_pref("browser.search.defaultenginename", "Web Search"); Zeile gelöscht : user_pref("browser.search.defaultengine", "Web Search"); Zeile gelöscht : user_pref("browser.search.order.1", "Web Search"); ************************* AdwCleaner[R0].txt - [15745 octets] - [09/08/2014 18:16:56] AdwCleaner[S0].txt - [14591 octets] - [09/08/2014 18:19:58] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14652 octets] ########## --- --- --- Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 8.1 x64 Ran by Michael on 09.08.2014 at 18:26:30,52 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2C67950C-8251-481E-B96D-A28F2062192E} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{2C67950C-8251-481E-B96D-A28F2062192E} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" Successfully deleted: [Folder] "C:\ProgramData\simplitec" Successfully deleted: [Folder] "C:\Users\Michael\AppData\Roaming\getrighttogo" Successfully deleted: [Folder] "C:\Users\Michael\AppData\Roaming\simplitec" Successfully deleted: [Folder] "C:\Program Files (x86)\conduit" Successfully deleted: [Folder] "C:\Program Files (x86)\simplitec" Successfully deleted: [Empty Folder] C:\Users\Michael\appdata\local\{1039DCFC-0151-4DD2-A4E3-5048491E4201} Successfully deleted: [Empty Folder] C:\Users\Michael\appdata\local\{3830DE7D-4421-4440-88C7-BCB408295A19} Successfully deleted: [Empty Folder] C:\Users\Michael\appdata\local\{67A3C21E-989F-4ED0-B2AE-18840E842582} Successfully deleted: [Empty Folder] C:\Users\Michael\appdata\local\{7FD9A45F-2C77-4A42-BA3D-48D4C0F1EC65} Successfully deleted: [Empty Folder] C:\Users\Michael\appdata\local\{A6767227-8EC8-4DB0-A312-BDC328A976E2} Successfully deleted: [Empty Folder] C:\Users\Michael\appdata\local\{BB401EB0-70BA-4306-ACFA-A31C9AB25741} Successfully deleted: [Empty Folder] C:\Users\Michael\appdata\local\{C3E2F063-9B60-4975-93ED-B53E903FA4C5} ~~~ FireFox Emptied folder: C:\Users\Michael\AppData\Roaming\mozilla\firefox\profiles\2kdf8z5s.default-1375768414006\minidumps [4 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 09.08.2014 at 18:31:51,06 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-08-2014 01 Ran by Michael (administrator) on MICHILAPTOP on 09-08-2014 18:33:48 Running from C:\Users\Michael\Downloads Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe () C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe (Apple Inc.) C:\AirPrint\airprint.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\InstallServices64.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212048 2012-06-07] (Realtek Semiconductor) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [ACPW06DE] => C:\Program Files\ACD Systems\ACDSee Pro\6.0\ACDSeePro6InTouch2.exe [1231992 2012-11-14] (ACD Systems) HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-41 (the data entry has 36 more characters). HKLM\...\Run: [SBRegRebootCleaner] => C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] () HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Dolby PCEE4\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554408 2013-05-15] (Lavasoft) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [uni mouse driver] => "C:\Mouse driver\mouse_driver.exe" /hide HKLM-x32\...\Run: [uni mouse driver tilt] => "C:\Mouse driver\wh_exec.exe" HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [CloneCDTray] => C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-24] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoDriveAutoRun] 0x0000 HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Agent] => "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse] => "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [7 Taskbar Tweaker] => C:\Users\Michael\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe [283648 2013-04-30] (RaMMicHaeL) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [1&1_1&1 Upload-Manager] => C:\Program Files (x86)\1&1\1&1 Upload-Manager\DAVSRV.EXE [989264 2011-11-21] (1&1 Internet AG) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [Rainlendar2] => C:\Program Files\Rainlendar2\Rainlendar2.exe HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Policies\Explorer: [NoDriveAutoRun] 0x0000 HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation) AppInit_DLLs: , C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation) AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [146480 2014-07-02] (NVIDIA Corporation) Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: AcronisSyncError -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncInProgress -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncOk -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers-x32: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: CloudIcon_DOWNLOAD -> {C3DBFBE2-A521-4619-9F32-502318CB4EC2} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_ERROR -> {851C758E-C636-4045-B323-059931A3A331} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_INSYNC -> {580030D3-492E-45EA-A1C9-A0AC525BEB26} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_REFRESH -> {FEBF62C8-B6B3-43B7-BEC4-1A9CD61BDCD2} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_UPLOAD -> {EBED3602-8915-43F9-81F7-CAA6FC4F70D6} => No File ShellIconOverlayIdentifiers-x32: Offline Files -> {4E77131D-3629-431c-9818-C5679DC83E81} => No File ShellIconOverlayIdentifiers-x32: SharingPrivate -> {08244EE6-92F0-47f2-9FC9-929BAA2E7235} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: http=;ftp=;https=; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - {2C67950C-8251-481E-B96D-A28F2062192E} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS SearchScopes: HKLM - {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKCU - {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - No Name - {C7DDDD27-F303-42A5-B979-51559F7DC0F0} - No File Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006 FF SearchEngineOrder.1: SuchMaschine FF Homepage: web.de FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VLC Player\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\McAfee Security Scan\3.0.313\npMcAfeeMss.dll No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\searchplugins\search_engine.xml FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Garmin Communicator - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-07-26] FF Extension: ColorZilla - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2014-03-18] FF Extension: Personas Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\personas@christopher.beard.xpi [2013-08-06] FF Extension: Leet Key - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{3335F91D-2AEF-4097-B831-C96C60349822}.xpi [2014-03-18] FF Extension: Adblock Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-07] FF Extension: Greasemonkey - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-01-01] FF Extension: Hotspot Shield Extension - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afproxy@anchorfree.com [2014-07-17] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited) R2 AirPrint; C:\AirPrint\airprint.exe [234784 2014-07-07] (Apple Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-05] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-05] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227456 2013-01-28] (Qualcomm Atheros Commnucations) S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG) S4 BrcmCardReader; C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe [176640 2012-08-20] (Broadcom Corp.) [File not signed] S4 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2435728 2012-08-23] (Acer Incorporated) S4 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [468624 2012-08-23] (Acer Incorporated) S4 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658576 2012-08-22] (Acer Incorporated) R2 HPSLPSVC; C:\Users\Michael\AppData\Local\Temp\7zS57EE\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed] S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-11-12] (Nitro PDF Software) S4 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-08-23] (NTI Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [66872 2013-12-27] () R2 PnkBstrB; C:\WINDOWS\SysWOW64\PnkBstrB.exe [107832 2013-12-27] () S4 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2012-11-23] (Dritek System INC.) R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software) S4 StarMoney 8.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S4 Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [142960 2013-01-31] (Stardock Software, Inc) R2 StartMenuService; C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe [72992 2014-06-06] (IObit) R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2013-04-22] (Western Digital Technologies, Inc.) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270192 2013-03-21] (Western Digital Technologies, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) R2 WO_LiveService; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe [885096 2013-04-10] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-06-17] (Avira Operations GmbH & Co. KG) R3 avmaura; C:\Windows\System32\drivers\avmaura.sys [116480 2013-10-20] (AVM Berlin) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-28] (Qualcomm Atheros) S3 bthav; C:\Windows\system32\drivers\bthav.sys [40448 2008-07-10] (CSR, plc) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.) R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.) S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-06-28] (GFI Software) S3 GigasetGenericUSB_x64; C:\Windows\system32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2013-03-05] (Siemens Home and Office Communication Devices GmbH & Co. KG) R1 HssDRV6; C:\Windows\system32\DRIVERS\hssdrv6.sys [44744 2014-05-17] (AnchorFree Inc.) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) R2 LiveTunerPM; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerProcessMonitor64.sys [12824 2011-03-08] () R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-09] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-11-23] (Dritek System Inc.) R3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [1093256 2013-02-14] (Acronis) R1 ui11rdr; C:\Windows\System32\DRIVERS\ui11rdr.sys [199752 2011-11-21] (1&1 Internet AG) R1 UimBus; C:\Windows\System32\drivers\uimx64.sys [90960 2012-08-07] (Windows (R) 2000 DDK provider) R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633552 2012-08-07] (Paragon) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) R3 whfltr2k; C:\Windows\System32\drivers\whfltr2k.sys [10368 2009-09-16] () ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-09 18:33 - 2014-08-09 18:33 - 00000000 ____D () C:\Users\Michael\Downloads\FRST-OlderVersion 2014-08-09 18:31 - 2014-08-09 18:31 - 00002349 _____ () C:\Users\Michael\Desktop\JRT.txt 2014-08-09 18:26 - 2014-08-09 18:26 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-08-09 18:24 - 2014-08-09 18:24 - 00014761 _____ () C:\Users\Michael\Desktop\AdwCleaner[S0].txt 2014-08-09 18:16 - 2014-08-09 18:21 - 00000000 ____D () C:\AdwCleaner 2014-08-09 18:15 - 2014-08-09 18:15 - 00002046 _____ () C:\Users\Michael\Desktop\mbam.txt 2014-08-08 19:53 - 2014-08-08 19:53 - 01366203 _____ () C:\Users\Michael\Desktop\adwcleaner_3.304.exe 2014-08-08 19:53 - 2014-08-08 19:53 - 01016261 _____ (Thisisu) C:\Users\Michael\Desktop\JRT.exe 2014-08-08 19:51 - 2014-08-08 19:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michael\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-08 06:42 - 2014-08-08 06:42 - 00072062 _____ () C:\Users\Michael\Downloads\t1556858_Etappe-2-Der-Granat-landschaftlich-schoenster-Etappenausschnitt.gpx 2014-08-07 19:39 - 2014-08-07 19:40 - 05568206 _____ (Swearware) C:\Users\Michael\Downloads\ComboFix.exe 2014-08-06 20:21 - 2014-08-06 20:27 - 00085201 _____ () C:\Users\Michael\Desktop\FRST.txt 2014-08-06 17:43 - 2014-08-06 17:43 - 02194385 _____ () C:\Users\Michael\Desktop\Lenker_neu3.MOV 2014-08-06 17:42 - 2014-08-06 17:42 - 02977434 _____ () C:\Users\Michael\Desktop\Lenker_neu2.MOV 2014-08-06 17:42 - 2014-08-06 17:42 - 00971867 _____ () C:\Users\Michael\Desktop\Lenker_neu1.MOV 2014-08-06 09:43 - 2014-08-06 09:43 - 00001457 _____ () C:\Users\Michael\AppData\Local\recently-used.xbel 2014-08-06 09:25 - 2014-08-06 09:25 - 00000303 _____ () C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Heimnetzgruppe.lnk 2014-08-05 11:45 - 2014-08-05 11:45 - 00086969 _____ () C:\Users\Michael\Desktop\FRST-ALT.txt 2014-08-05 11:45 - 2014-08-05 11:45 - 00082200 _____ () C:\Users\Michael\Desktop\Addition_ALT.txt 2014-08-05 11:43 - 2014-08-05 11:44 - 00082200 _____ () C:\Users\Michael\Downloads\Addition.txt 2014-08-05 11:40 - 2014-08-09 18:33 - 00030616 _____ () C:\Users\Michael\Downloads\FRST.txt 2014-08-05 11:40 - 2014-08-09 18:33 - 00000000 ____D () C:\FRST 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\system32\NV 2014-08-05 11:37 - 2014-08-09 18:33 - 02093568 _____ (Farbar) C:\Users\Michael\Downloads\FRST64.exe 2014-08-05 11:37 - 2014-07-02 20:55 - 06783776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 03522392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 02559960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 01084704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00935368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2014-08-05 11:37 - 2014-07-02 20:55 - 00386520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00067072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00062808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2014-08-05 11:37 - 2014-07-02 12:14 - 03826628 _____ () C:\WINDOWS\system32\nvcoproc.bin 2014-08-05 11:15 - 2014-07-02 22:48 - 31512520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 24196896 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 22994208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 18626304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 17555104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 16122344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 15294296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 14498552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 13922752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 13835208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 12866008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys 2014-08-05 11:15 - 2014-07-02 22:48 - 11283344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 11222048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 04247000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 03989960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 03196816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 02814656 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 01890080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6434052.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 01539928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6434052.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00965312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00944928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00907096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00903624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00869152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00846832 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00354016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00305600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00166568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00146480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00032544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys 2014-08-05 11:15 - 2014-07-02 22:48 - 00026353 _____ () C:\WINDOWS\system32\nvinfo.pb 2014-08-05 10:07 - 2014-07-25 15:50 - 01715224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2014-08-05 10:07 - 2014-07-25 15:50 - 01291280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2014-08-05 10:06 - 2014-08-05 10:06 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp 2014-08-05 10:06 - 2014-03-31 18:42 - 00040392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys 2014-08-05 10:06 - 2014-03-31 18:42 - 00034760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll 2014-08-05 08:15 - 2014-08-05 08:33 - 520324935 _____ () C:\Users\Michael\Downloads\Demo_Flakstad.exe 2014-08-05 08:08 - 2014-08-05 08:08 - 00053507 _____ () C:\Users\Michael\Downloads\route_1325.gpx 2014-08-05 03:43 - 2014-08-05 03:43 - 00031250 _____ () C:\Users\Michael\Downloads\NO_Gullingen.rlv 2014-08-05 03:35 - 2014-08-05 03:38 - 183717406 _____ () C:\Users\Michael\Downloads\Demo_Furka2011.exe 2014-08-04 15:36 - 2014-08-04 15:36 - 00961405 _____ () C:\Users\Michael\Downloads\GpsiesTrack.gpx 2014-08-04 15:36 - 2014-08-04 15:36 - 00074226 _____ () C:\Users\Michael\Downloads\Innradtour09Obernberg-Erlau.gpx 2014-08-03 17:38 - 2014-08-03 17:38 - 00490166 _____ () C:\Users\Michael\Downloads\09-Movie&Show.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00352614 _____ () C:\Users\Michael\Downloads\Arabic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00269690 _____ () C:\Users\Michael\Downloads\12-Ethnic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00265411 _____ () C:\Users\Michael\Downloads\Turkish&Greek.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00263102 _____ () C:\Users\Michael\Downloads\06-Country.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00610081 _____ () C:\Users\Michael\Downloads\01-Pop&Rock.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00564588 _____ () C:\Users\Michael\Downloads\05-R&B.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00541643 _____ () C:\Users\Michael\Downloads\02-Ballad.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00524065 _____ () C:\Users\Michael\Downloads\03-Dance.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00394653 _____ () C:\Users\Michael\Downloads\07-Latin.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00347569 _____ () C:\Users\Michael\Downloads\04-Swing&Jazz.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00310825 _____ () C:\Users\Michael\Downloads\10-Entertainer.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00165856 _____ () C:\Users\Michael\Downloads\08-Ballroom.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00161112 _____ () C:\Users\Michael\Downloads\11-World.zip 2014-08-03 09:28 - 2014-08-03 09:29 - 02252800 _____ () C:\Users\Michael\Downloads\Google.rar.part 2014-07-29 20:14 - 2014-07-29 20:15 - 32040040 _____ (KETTLER) C:\Users\Michael\AVM_Driver\Pictures\Documents\KWT20Update20132.exe 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 ____D () C:\Users\Michael\Downloads\bosch 2014-07-29 13:24 - 2014-07-29 13:25 - 61689856 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.46.0.msi 2014-07-29 09:54 - 2014-07-29 09:54 - 00108809 _____ () C:\Users\Michael\Downloads\no_gullingen.zip 2014-07-28 10:13 - 2014-07-28 10:13 - 00296888 _____ () C:\WINDOWS\Minidump\072814-61468-01.dmp 2014-07-28 10:13 - 2014-07-28 10:13 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-28 05:59 - 2014-07-28 05:59 - 00000000 ____D () C:\Users\Michael\Downloads\Wo Bleibt die Musik 2014-07-26 19:33 - 2014-07-27 06:11 - 00000000 ____D () C:\Users\Michael\Downloads\Midi_Hüttenmusikant 2014-07-26 19:07 - 2014-07-26 19:07 - 00046745 _____ () C:\Users\Michael\Downloads\xt Amoi seg ma uns.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00094136 _____ () C:\Users\Michael\Downloads\xt Atemlos.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00080784 _____ () C:\Users\Michael\Downloads\SRP021 S910.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT(1).zip 2014-07-26 19:01 - 2014-07-26 19:01 - 00062888 _____ () C:\Users\Michael\Downloads\klingande-jubel.mid 2014-07-26 18:59 - 2014-07-26 18:59 - 00019221 _____ () C:\Users\Michael\Downloads\one_republic-love_runs_out.mid 2014-07-26 18:58 - 2014-07-26 18:58 - 00032868 _____ () C:\Users\Michael\Downloads\golden_earing-twilight_zone.mid 2014-07-25 15:07 - 2014-07-29 13:23 - 00000000 ____D () C:\Users\Michael\Downloads\tanja Kruse 2014-07-25 14:25 - 2014-07-25 14:25 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog_-_axel_f.mid 2014-07-25 14:24 - 2014-07-25 14:24 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog-axel_f.mid 2014-07-25 07:56 - 2014-07-25 07:56 - 00003164 _____ () C:\WINDOWS\System32\Tasks\StartMenuAutoupdate 2014-07-25 07:56 - 2014-07-25 07:56 - 00001279 _____ () C:\Users\Public\Desktop\Start Menu 8.lnk 2014-07-25 07:56 - 2014-07-25 07:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu 8 2014-07-21 21:10 - 2014-08-06 09:20 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-07-21 18:50 - 2014-07-21 18:50 - 00000000 ____D () C:\Users\Michael\AppData\Local\Intel_Corporation 2014-07-20 12:52 - 2014-07-20 12:52 - 00030891 _____ () C:\Users\Michael\Downloads\peterburgsky-donnaklara.zip 2014-07-20 09:28 - 2014-07-20 09:43 - 47978285 _____ () C:\Users\Michael\Downloads\01belle30.rar 2014-07-17 19:00 - 2014-07-17 19:01 - 69767374 _____ () C:\Users\Michael\Downloads\32pfl4308k_12_fus_deu.zip 2014-07-17 10:04 - 2014-07-17 13:41 - 00000000 ____D () C:\Users\Michael\Downloads\Garmin Topo Österreich V4_3086_imgUL-sql 2014-07-17 09:31 - 2014-07-17 09:31 - 00000000 ____D () C:\Users\Michael\Downloads\188 2014-07-17 09:30 - 2014-07-17 09:30 - 03704534 _____ () C:\Users\Michael\Downloads\188.rar 2014-07-17 09:21 - 2014-07-17 09:21 - 00001140 _____ () C:\Users\Public\Desktop\Hotspot Shield.lnk 2014-07-17 09:21 - 2014-07-17 09:21 - 00000176 _____ () C:\Users\Michael\Downloads\hotspotshield-setup_540.exe 2014-07-17 08:55 - 2014-05-17 04:35 - 00044744 _____ (AnchorFree Inc.) C:\WINDOWS\system32\Drivers\hssdrv6.sys 2014-07-17 08:53 - 2014-07-17 08:53 - 07787136 _____ () C:\Users\Michael\Downloads\HSS-3.42-install-e-550-plain.exe 2014-07-17 07:04 - 2014-07-17 07:04 - 00001799 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-07-17 07:04 - 2014-07-17 07:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-07-17 07:03 - 2014-07-17 07:04 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-07-17 07:03 - 2014-07-17 07:04 - 00000000 ____D () C:\Program Files\iTunes 2014-07-17 07:03 - 2014-07-17 07:03 - 00000000 ____D () C:\Program Files\iPod 2014-07-16 11:23 - 2014-07-16 11:23 - 00000000 ____D () C:\Users\Michael\Downloads\Onerepublic-Native 2014-07-16 11:00 - 2014-07-16 11:00 - 02426602 _____ () C:\Users\Michael\Desktop\Lenker_0882.MOV 2014-07-16 10:59 - 2014-07-16 10:59 - 00670852 _____ () C:\Users\Michael\Desktop\Sitz.MOV 2014-07-16 10:04 - 2014-08-08 19:49 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-07-16 10:03 - 2014-07-16 10:04 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers 2014-07-16 10:02 - 2014-07-16 10:02 - 00000000 ____D () C:\Program Files\Common Files\Common Desktop Agent 2014-07-16 10:01 - 2014-07-16 10:04 - 00000000 ____D () C:\Program Files (x86)\SamsungPrinterLiveUpdate 2014-07-16 10:00 - 2014-07-16 10:04 - 00000000 ____D () C:\Program Files (x86)\Samsung 2014-07-16 10:00 - 2013-12-27 11:33 - 00226424 _____ () C:\WINDOWS\system32\SBuySupplies.exe 2014-07-16 10:00 - 2013-12-27 11:33 - 00158040 _____ (SS) C:\WINDOWS\system32\ssj2mci.exe 2014-07-16 10:00 - 2013-12-27 11:33 - 00089600 _____ (SS) C:\WINDOWS\system32\ssj2mci.dll 2014-07-16 10:00 - 2013-12-27 11:33 - 00034304 _____ () C:\WINDOWS\system32\ssj2mlm.dll 2014-07-16 10:00 - 2013-12-27 11:33 - 00000359 _____ () C:\WINDOWS\system32\ssj2mlm.smt 2014-07-16 10:00 - 2013-12-06 10:24 - 00101518 ____N () C:\WINDOWS\ssj2mLTR.prn 2014-07-16 10:00 - 2013-12-06 10:23 - 00107317 ____N () C:\WINDOWS\ssj2mA4.prn 2014-07-16 10:00 - 2013-07-05 08:20 - 00094208 ____N () C:\WINDOWS\SysWOW64\ssdevm.dll 2014-07-16 10:00 - 2013-07-05 08:20 - 00091136 ____N () C:\WINDOWS\system32\ssdevm64.dll 2014-07-13 17:00 - 2014-07-13 17:01 - 00000862 _____ () C:\Users\Michael\Downloads\garmin alpenvereinskarten.nzb 2014-07-13 16:50 - 2014-07-13 16:50 - 07315296 _____ (IObit ) C:\Users\Michael\Downloads\startmenu-setup.exe 2014-07-13 12:03 - 2014-07-13 11:28 - 01104896 _____ () C:\Users\Michael\Desktop\michalt.db 2014-07-13 11:39 - 2014-07-29 13:26 - 00000946 _____ () C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk 2014-07-13 11:35 - 2014-07-13 11:36 - 61681664 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.44.0.msi 2014-07-13 09:00 - 2014-07-13 09:00 - 00632784 _____ () C:\Users\Michael\Downloads\FRITZ.Box Fon WLAN 7390 (UI) 84.06.03_13.07.14_0859.export 2014-07-12 18:33 - 2014-07-12 18:35 - 01144832 _____ () C:\Users\Michael\Desktop\test.db 2014-07-10 11:06 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll 2014-07-10 11:01 - 2014-07-10 11:01 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2014-07-10 08:52 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe 2014-07-10 08:52 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe 2014-07-10 08:52 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-07-10 08:52 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2014-07-10 08:51 - 2014-07-01 00:45 - 00688128 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2014-07-10 08:51 - 2014-06-28 09:48 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2014-07-10 08:51 - 2014-06-28 09:07 - 00385536 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2014-07-10 08:51 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-07-10 08:51 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-07-10 08:51 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-07-10 08:51 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2014-07-10 08:51 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-07-10 08:51 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-07-10 08:51 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2014-07-10 08:51 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2014-07-10 08:51 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-07-10 08:51 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-07-10 08:51 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-07-10 08:51 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-07-10 08:51 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-07-10 08:51 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-07-10 08:51 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-07-10 08:51 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2014-07-10 08:51 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-07-10 08:51 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-07-10 08:51 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-07-10 08:51 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-07-10 08:51 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-07-10 08:51 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-07-10 08:51 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-07-10 08:51 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-07-10 08:51 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-07-10 08:51 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-07-10 08:51 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-07-10 08:51 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll 2014-07-10 08:51 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll 2014-07-10 08:51 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2014-07-10 08:51 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2014-07-10 08:51 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2014-07-10 08:51 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2014-07-10 08:51 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2014-07-10 08:51 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2014-07-10 08:50 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2014-07-10 08:50 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2014-07-10 08:50 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2014-07-10 08:50 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2014-07-10 08:50 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-10 08:50 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2014-07-10 08:50 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2014-07-10 08:50 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-10 08:50 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2014-07-10 08:50 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2014-07-10 08:50 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2014-07-10 08:50 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2014-07-10 08:50 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-07-10 08:50 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2014-07-10 08:50 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-07-10 08:42 - 2014-07-10 08:42 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-09 18:34 - 2014-08-05 11:40 - 00030616 _____ () C:\Users\Michael\Downloads\FRST.txt 2014-08-09 18:34 - 2013-02-17 08:44 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-08-09 18:33 - 2014-08-09 18:33 - 00000000 ____D () C:\Users\Michael\Downloads\FRST-OlderVersion 2014-08-09 18:33 - 2014-08-05 11:40 - 00000000 ____D () C:\FRST 2014-08-09 18:33 - 2014-08-05 11:37 - 02093568 _____ (Farbar) C:\Users\Michael\Downloads\FRST64.exe 2014-08-09 18:33 - 2013-02-08 14:30 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-587935961-2775860875-2407296441-1002 2014-08-09 18:31 - 2014-08-09 18:31 - 00002349 _____ () C:\Users\Michael\Desktop\JRT.txt 2014-08-09 18:29 - 2013-07-09 19:43 - 00001136 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-09 18:26 - 2014-08-09 18:26 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-08-09 18:24 - 2014-08-09 18:24 - 00014761 _____ () C:\Users\Michael\Desktop\AdwCleaner[S0].txt 2014-08-09 18:23 - 2013-07-09 19:43 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-09 18:23 - 2013-04-22 12:00 - 00008192 _____ () C:\WINDOWS\SysWOW64\WDPABKP.dat 2014-08-09 18:22 - 2014-01-17 19:33 - 00000324 _____ () C:\WINDOWS\Tasks\AutoKMS.job 2014-08-09 18:22 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-08-09 18:21 - 2014-08-09 18:16 - 00000000 ____D () C:\AdwCleaner 2014-08-09 18:21 - 2013-09-29 21:04 - 00424994 _____ () C:\WINDOWS\PFRO.log 2014-08-09 18:20 - 2013-02-07 23:47 - 00000000 ____D () C:\Users\Michael 2014-08-09 18:15 - 2014-08-09 18:15 - 00002046 _____ () C:\Users\Michael\Desktop\mbam.txt 2014-08-09 18:13 - 2014-06-25 20:16 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-08-09 18:04 - 2013-11-06 14:54 - 00000000 ___DC () C:\WINDOWS\Panther 2014-08-09 18:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-08-09 17:29 - 2013-11-06 14:57 - 01891094 _____ () C:\WINDOWS\WindowsUpdate.log 2014-08-09 17:11 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-08-09 17:05 - 2013-11-30 20:51 - 00003950 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{A0BF6906-8E67-4F48-9A06-BFACF99DFEAA} 2014-08-09 17:05 - 2009-06-28 12:04 - 609248256 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\Outlook.pst 2014-08-09 17:03 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\mkoelbl@online.de.pst 2014-08-09 17:03 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\mike1k@gmx.de.pst 2014-08-09 17:03 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\homeshopper66@online.de.pst 2014-08-09 17:03 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\hdampff@gmx.de.pst 2014-08-09 17:03 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\FTF-Hunter@online.de.pst 2014-08-09 17:03 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\FTF-Hunter@gmx.de.pst 2014-08-09 17:03 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\bayanbua@gmx.de.pst 2014-08-09 17:03 - 2013-02-09 23:55 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\Outlook-Dateien 2014-08-08 20:42 - 2014-06-25 20:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-08 20:42 - 2014-06-25 20:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-08 20:42 - 2013-08-05 13:52 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-08 19:53 - 2014-08-08 19:53 - 01366203 _____ () C:\Users\Michael\Desktop\adwcleaner_3.304.exe 2014-08-08 19:53 - 2014-08-08 19:53 - 01016261 _____ (Thisisu) C:\Users\Michael\Desktop\JRT.exe 2014-08-08 19:52 - 2014-08-08 19:51 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michael\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-08 19:49 - 2014-07-16 10:04 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-08-08 11:12 - 2013-02-10 01:38 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\gsak8 2014-08-08 11:08 - 2013-02-09 19:41 - 00000000 ____D () C:\GSAK8 2014-08-08 10:49 - 2014-01-25 20:26 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0 2014-08-08 06:47 - 2014-07-09 11:39 - 00000000 ____D () C:\Program Files (x86)\SqliteBrowser3 2014-08-08 06:47 - 2013-06-29 10:28 - 00014786 _____ () C:\missing.ini 2014-08-08 06:42 - 2014-08-08 06:42 - 00072062 _____ () C:\Users\Michael\Downloads\t1556858_Etappe-2-Der-Granat-landschaftlich-schoenster-Etappenausschnitt.gpx 2014-08-08 06:38 - 2013-08-25 10:27 - 00000000 ____D () C:\totalcmd 2014-08-08 06:38 - 2013-02-10 01:38 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\GHISLER 2014-08-08 06:35 - 2014-04-11 08:39 - 00000000 ____D () C:\Program Files (x86)\Mopsos 2014-08-08 06:35 - 2014-03-23 13:37 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Mopsos 2014-08-08 06:34 - 2012-11-02 05:43 - 00000000 ____D () C:\ProgramData\Temp 2014-08-08 06:20 - 2013-02-07 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\Packages 2014-08-07 19:40 - 2014-08-07 19:39 - 05568206 _____ (Swearware) C:\Users\Michael\Downloads\ComboFix.exe 2014-08-07 13:54 - 2014-02-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\FileAdvisor 2014-08-07 13:52 - 2014-02-11 14:52 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor 2014-08-07 10:24 - 2013-02-10 02:35 - 01171456 ___SH () C:\Users\Michael\Desktop\Thumbs.db 2014-08-06 20:27 - 2014-08-06 20:21 - 00085201 _____ () C:\Users\Michael\Desktop\FRST.txt 2014-08-06 17:43 - 2014-08-06 17:43 - 02194385 _____ () C:\Users\Michael\Desktop\Lenker_neu3.MOV 2014-08-06 17:42 - 2014-08-06 17:42 - 02977434 _____ () C:\Users\Michael\Desktop\Lenker_neu2.MOV 2014-08-06 17:42 - 2014-08-06 17:42 - 00971867 _____ () C:\Users\Michael\Desktop\Lenker_neu1.MOV 2014-08-06 09:43 - 2014-08-06 09:43 - 00001457 _____ () C:\Users\Michael\AppData\Local\recently-used.xbel 2014-08-06 09:43 - 2014-03-21 19:22 - 00000000 ____D () C:\Users\Michael\AppData\Local\gtk-2.0 2014-08-06 09:43 - 2013-02-09 21:20 - 00000000 ____D () C:\Users\Michael\.gimp-2.8 2014-08-06 09:28 - 2014-05-29 17:33 - 00000000 ____D () C:\Users\Michael\AppData\Local\Adobe 2014-08-06 09:25 - 2014-08-06 09:25 - 00000303 _____ () C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Heimnetzgruppe.lnk 2014-08-06 09:21 - 2013-05-25 19:22 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-06 09:20 - 2014-07-21 21:10 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-06 09:20 - 2014-06-25 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-06 09:20 - 2014-06-25 21:07 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-06 06:21 - 2014-05-26 14:09 - 00000000 ____D () C:\Program Files (x86)\KETTLER 2014-08-05 11:45 - 2014-08-05 11:45 - 00086969 _____ () C:\Users\Michael\Desktop\FRST-ALT.txt 2014-08-05 11:45 - 2014-08-05 11:45 - 00082200 _____ () C:\Users\Michael\Desktop\Addition_ALT.txt 2014-08-05 11:44 - 2014-08-05 11:43 - 00082200 _____ () C:\Users\Michael\Downloads\Addition.txt 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\system32\NV 2014-08-05 11:38 - 2013-02-09 20:07 - 00000000 ____D () C:\Temp 2014-08-05 11:38 - 2012-11-23 04:45 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-08-05 11:37 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Help 2014-08-05 11:17 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-08-05 10:07 - 2013-08-22 16:46 - 00395073 _____ () C:\WINDOWS\setupact.log 2014-08-05 10:06 - 2014-08-05 10:06 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp 2014-08-05 09:58 - 2014-06-26 14:25 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\BitLord 2014-08-05 09:26 - 2013-09-30 06:14 - 00731054 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-08-05 09:26 - 2013-09-30 05:56 - 01036102 _____ () C:\WINDOWS\system32\perfh007.dat 2014-08-05 09:26 - 2013-09-30 05:56 - 00239366 _____ () C:\WINDOWS\system32\perfc007.dat 2014-08-05 09:22 - 2014-05-09 06:38 - 00000000 ____D () C:\Users\Michael\Desktop\kabat 2014-08-05 08:33 - 2014-08-05 08:15 - 520324935 _____ () C:\Users\Michael\Downloads\Demo_Flakstad.exe 2014-08-05 08:08 - 2014-08-05 08:08 - 00053507 _____ () C:\Users\Michael\Downloads\route_1325.gpx 2014-08-05 03:43 - 2014-08-05 03:43 - 00031250 _____ () C:\Users\Michael\Downloads\NO_Gullingen.rlv 2014-08-05 03:38 - 2014-08-05 03:35 - 183717406 _____ () C:\Users\Michael\Downloads\Demo_Furka2011.exe 2014-08-04 15:36 - 2014-08-04 15:36 - 00961405 _____ () C:\Users\Michael\Downloads\GpsiesTrack.gpx 2014-08-04 15:36 - 2014-08-04 15:36 - 00074226 _____ () C:\Users\Michael\Downloads\Innradtour09Obernberg-Erlau.gpx 2014-08-04 15:14 - 2013-02-10 01:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Nitro PDF 2014-08-04 15:13 - 2013-02-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin 2014-08-04 15:13 - 2013-02-09 20:40 - 00000000 ____D () C:\Program Files (x86)\Garmin 2014-08-04 12:59 - 2013-11-06 20:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\Deployment 2014-08-03 17:38 - 2014-08-03 17:38 - 00490166 _____ () C:\Users\Michael\Downloads\09-Movie&Show.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00352614 _____ () C:\Users\Michael\Downloads\Arabic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00269690 _____ () C:\Users\Michael\Downloads\12-Ethnic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00265411 _____ () C:\Users\Michael\Downloads\Turkish&Greek.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00263102 _____ () C:\Users\Michael\Downloads\06-Country.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00610081 _____ () C:\Users\Michael\Downloads\01-Pop&Rock.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00564588 _____ () C:\Users\Michael\Downloads\05-R&B.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00541643 _____ () C:\Users\Michael\Downloads\02-Ballad.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00524065 _____ () C:\Users\Michael\Downloads\03-Dance.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00394653 _____ () C:\Users\Michael\Downloads\07-Latin.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00347569 _____ () C:\Users\Michael\Downloads\04-Swing&Jazz.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00310825 _____ () C:\Users\Michael\Downloads\10-Entertainer.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00165856 _____ () C:\Users\Michael\Downloads\08-Ballroom.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00161112 _____ () C:\Users\Michael\Downloads\11-World.zip 2014-08-03 11:47 - 2013-02-10 10:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-03 11:43 - 2014-01-27 11:29 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\vlc 2014-08-03 09:29 - 2014-08-03 09:28 - 02252800 _____ () C:\Users\Michael\Downloads\Google.rar.part 2014-08-01 09:27 - 2013-05-25 19:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-29 20:17 - 2014-06-26 13:01 - 00002527 _____ () C:\Users\Public\Desktop\KETTLER WORLD TOURS 2.0.lnk 2014-07-29 20:15 - 2014-07-29 20:14 - 32040040 _____ (KETTLER) C:\Users\Michael\AVM_Driver\Pictures\Documents\KWT20Update20132.exe 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 ____D () C:\Users\Michael\Downloads\bosch 2014-07-29 16:40 - 2013-11-01 11:05 - 00000000 ____D () C:\Users\Michael\Desktop\ebook 2014-07-29 16:37 - 2013-11-01 11:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\calibre-cache 2014-07-29 13:26 - 2014-07-13 11:39 - 00000946 _____ () C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk 2014-07-29 13:26 - 2013-11-01 11:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management 2014-07-29 13:26 - 2013-11-01 11:05 - 00000000 ____D () C:\Program Files\Calibre2 2014-07-29 13:25 - 2014-07-29 13:24 - 61689856 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.46.0.msi 2014-07-29 13:23 - 2014-07-25 15:07 - 00000000 ____D () C:\Users\Michael\Downloads\tanja Kruse 2014-07-29 11:34 - 2013-02-10 20:56 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2014-07-29 09:54 - 2014-07-29 09:54 - 00108809 _____ () C:\Users\Michael\Downloads\no_gullingen.zip 2014-07-28 10:13 - 2014-07-28 10:13 - 00296888 _____ () C:\WINDOWS\Minidump\072814-61468-01.dmp 2014-07-28 10:13 - 2014-07-28 10:13 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-28 10:13 - 2013-08-22 16:44 - 05244208 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-07-28 10:12 - 2013-02-25 11:04 - 744034049 _____ () C:\WINDOWS\MEMORY.DMP 2014-07-28 06:05 - 2013-02-10 00:17 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\Steuerfälle 2014-07-28 05:59 - 2014-07-28 05:59 - 00000000 ____D () C:\Users\Michael\Downloads\Wo Bleibt die Musik 2014-07-27 06:11 - 2014-07-26 19:33 - 00000000 ____D () C:\Users\Michael\Downloads\Midi_Hüttenmusikant 2014-07-27 05:58 - 2013-02-10 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\Google 2014-07-26 19:24 - 2013-04-07 17:58 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-26 19:24 - 2013-04-07 17:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-07-26 19:07 - 2014-07-26 19:07 - 00046745 _____ () C:\Users\Michael\Downloads\xt Amoi seg ma uns.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00094136 _____ () C:\Users\Michael\Downloads\xt Atemlos.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00080784 _____ () C:\Users\Michael\Downloads\SRP021 S910.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT(1).zip 2014-07-26 19:01 - 2014-07-26 19:01 - 00062888 _____ () C:\Users\Michael\Downloads\klingande-jubel.mid 2014-07-26 18:59 - 2014-07-26 18:59 - 00019221 _____ () C:\Users\Michael\Downloads\one_republic-love_runs_out.mid 2014-07-26 18:58 - 2014-07-26 18:58 - 00032868 _____ () C:\Users\Michael\Downloads\golden_earing-twilight_zone.mid 2014-07-25 15:50 - 2014-08-05 10:07 - 01715224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2014-07-25 15:50 - 2014-08-05 10:07 - 01291280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2014-07-25 15:50 - 2014-04-19 16:27 - 01283136 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2014-07-25 15:50 - 2014-04-19 16:27 - 01126480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2014-07-25 14:38 - 2014-07-03 20:03 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys 2014-07-25 14:25 - 2014-07-25 14:25 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog_-_axel_f.mid 2014-07-25 14:24 - 2014-07-25 14:24 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog-axel_f.mid 2014-07-25 07:56 - 2014-07-25 07:56 - 00003164 _____ () C:\WINDOWS\System32\Tasks\StartMenuAutoupdate 2014-07-25 07:56 - 2014-07-25 07:56 - 00001279 _____ () C:\Users\Public\Desktop\Start Menu 8.lnk 2014-07-25 07:56 - 2014-07-25 07:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu 8 2014-07-25 07:54 - 2014-02-02 19:48 - 00165659 _____ () C:\MyXML.xml 2014-07-24 17:24 - 2013-04-07 17:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-22 19:26 - 2013-12-09 10:58 - 00000000 ____D () C:\Users\Michael\Desktop\Apple + Tools 2014-07-21 18:50 - 2014-07-21 18:50 - 00000000 ____D () C:\Users\Michael\AppData\Local\Intel_Corporation 2014-07-20 18:57 - 2013-02-25 11:31 - 00043008 ___SH () C:\Users\Michael\Thumbs.db 2014-07-20 12:52 - 2014-07-20 12:52 - 00030891 _____ () C:\Users\Michael\Downloads\peterburgsky-donnaklara.zip 2014-07-20 09:43 - 2014-07-20 09:28 - 47978285 _____ () C:\Users\Michael\Downloads\01belle30.rar 2014-07-17 19:01 - 2014-07-17 19:00 - 69767374 _____ () C:\Users\Michael\Downloads\32pfl4308k_12_fus_deu.zip 2014-07-17 13:41 - 2014-07-17 10:04 - 00000000 ____D () C:\Users\Michael\Downloads\Garmin Topo Österreich V4_3086_imgUL-sql 2014-07-17 13:38 - 2013-02-09 18:54 - 00000000 ___RD () C:\Garmin 2014-07-17 09:31 - 2014-07-17 09:31 - 00000000 ____D () C:\Users\Michael\Downloads\188 2014-07-17 09:30 - 2014-07-17 09:30 - 03704534 _____ () C:\Users\Michael\Downloads\188.rar 2014-07-17 09:21 - 2014-07-17 09:21 - 00001140 _____ () C:\Users\Public\Desktop\Hotspot Shield.lnk 2014-07-17 09:21 - 2014-07-17 09:21 - 00000176 _____ () C:\Users\Michael\Downloads\hotspotshield-setup_540.exe 2014-07-17 08:53 - 2014-07-17 08:53 - 07787136 _____ () C:\Users\Michael\Downloads\HSS-3.42-install-e-550-plain.exe 2014-07-17 07:04 - 2014-07-17 07:04 - 00001799 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-07-17 07:04 - 2014-07-17 07:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-07-17 07:04 - 2014-07-17 07:03 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-07-17 07:04 - 2014-07-17 07:03 - 00000000 ____D () C:\Program Files\iTunes 2014-07-17 07:04 - 2013-02-18 19:51 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-07-17 07:03 - 2014-07-17 07:03 - 00000000 ____D () C:\Program Files\iPod 2014-07-16 13:23 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-07-16 11:23 - 2014-07-16 11:23 - 00000000 ____D () C:\Users\Michael\Downloads\Onerepublic-Native 2014-07-16 11:00 - 2014-07-16 11:00 - 02426602 _____ () C:\Users\Michael\Desktop\Lenker_0882.MOV 2014-07-16 10:59 - 2014-07-16 10:59 - 00670852 _____ () C:\Users\Michael\Desktop\Sitz.MOV 2014-07-16 10:04 - 2014-07-16 10:03 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers 2014-07-16 10:04 - 2014-07-16 10:01 - 00000000 ____D () C:\Program Files (x86)\SamsungPrinterLiveUpdate 2014-07-16 10:04 - 2014-07-16 10:00 - 00000000 ____D () C:\Program Files (x86)\Samsung 2014-07-16 10:03 - 2013-02-10 01:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Samsung 2014-07-16 10:02 - 2014-07-16 10:02 - 00000000 ____D () C:\Program Files\Common Files\Common Desktop Agent 2014-07-16 10:02 - 2013-02-09 20:20 - 00000000 ____D () C:\ProgramData\Samsung 2014-07-13 17:01 - 2014-07-13 17:00 - 00000862 _____ () C:\Users\Michael\Downloads\garmin alpenvereinskarten.nzb 2014-07-13 16:50 - 2014-07-13 16:50 - 07315296 _____ (IObit ) C:\Users\Michael\Downloads\startmenu-setup.exe 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore 2014-07-13 16:25 - 2013-02-17 08:44 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2014-07-13 14:41 - 2013-02-09 23:47 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\FinePrint-Dateien 2014-07-13 11:36 - 2014-07-13 11:35 - 61681664 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.44.0.msi 2014-07-13 11:28 - 2014-07-13 12:03 - 01104896 _____ () C:\Users\Michael\Desktop\michalt.db 2014-07-13 09:00 - 2014-07-13 09:00 - 00632784 _____ () C:\Users\Michael\Downloads\FRITZ.Box Fon WLAN 7390 (UI) 84.06.03_13.07.14_0859.export 2014-07-12 19:28 - 2014-01-17 18:51 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-07-12 19:28 - 2013-02-09 17:16 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-07-12 18:35 - 2014-07-12 18:33 - 01144832 _____ () C:\Users\Michael\Desktop\test.db 2014-07-10 11:32 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2014-07-10 11:31 - 2013-07-20 10:40 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-07-10 11:28 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-07-10 11:28 - 2013-02-11 11:03 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-07-10 11:03 - 2013-09-30 05:59 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 11:01 - 2014-07-10 11:01 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2014-07-10 08:42 - 2014-07-10 08:42 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe Files to move or delete: ==================== C:\ProgramData\JonDoFox.paf.exe C:\Users\Michael\AutoRun.exe C:\Users\Michael\setup.exe C:\Users\Michael\Setup_AR.exe Some content of TEMP: ==================== C:\Users\Michael\AppData\Local\Temp\avgnt.exe C:\Users\Michael\AppData\Local\Temp\bassmod.dll C:\Users\Michael\AppData\Local\Temp\Creative Cloud Helper.exe C:\Users\Michael\AppData\Local\Temp\EasyLogin_setup_DE.exe C:\Users\Michael\AppData\Local\Temp\install_flashplayer13x32au_mssa_aaa_aih(1).exe C:\Users\Michael\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Michael\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Michael\AppData\Local\Temp\Offercast_AVIRAV7_.exe C:\Users\Michael\AppData\Local\Temp\photosync_setup_en_212.exe C:\Users\Michael\AppData\Local\Temp\photosync_setup_en_221.exe C:\Users\Michael\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Michael\AppData\Local\Temp\Quarantine.exe C:\Users\Michael\AppData\Local\Temp\repair.exe C:\Users\Michael\AppData\Local\Temp\sqlite3.exe C:\Users\Michael\AppData\Local\Temp\tunesgo_full1368.exe C:\Users\Michael\AppData\Local\Temp\vlc-2.1.4-win64.exe C:\Users\Michael\AppData\Local\Temp\vlc-2.1.5-win64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-09 17:13 ==================== End Of Log ============================ --- --- --- [/CODE] |
10.08.2014, 06:18 | #11 |
/// the machine /// TB-Ausbilder | C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werdenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Dazu FRST öffnen, Haken setzen bei Addition und scannen. Poste bitte beide Logfiles. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.08.2014, 17:25 | #12 |
| C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werdenCode:
ATTFilter Results of screen317's Security Check version 0.99.86 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Lavasoft Ad-Aware Windows Defender Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Ad-Aware CCleaner Java 7 Update 51 Java version out of Date! Adobe Flash Player 14.0.0.145 Adobe Reader XI Mozilla Firefox (31.0) ````````Process Check: objlist.exe by Laurent```````` Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! Avira Antivir avguard.exe Ad-Aware Antivirus AdAwareService.exe Ad-Aware Antivirus SBAMSvc.exe StarMoney 9.0 ouservice StarMoneyOnlineUpdate.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=aec02e679e16b94c89fe59245f2341d4 # engine=19581 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-08-10 05:06:18 # local_time=2014-08-10 07:06:18 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 99 89618 4675220 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 6494157 13526552 0 0 # scanned=562 # found=0 # cleaned=0 # scan_time=36464 ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=aec02e679e16b94c89fe59245f2341d4 # engine=19587 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-08-11 02:35:28 # local_time=2014-08-11 04:35:28 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 99 123768 4709370 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 6528307 13560702 0 0 # scanned=642273 # found=26 # cleaned=0 # scan_time=33994 sh=88BDD2B699F8BBADB6347A5EB0E4B86140B102A5 ft=1 fh=a0d134eb3d731e7a vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\$Recycle.Bin\S-1-5-21-587935961-2775860875-2407296441-1002\$R6P8WCD.exe" sh=6394E27A1A0F10FD54B6B3208F9315DC9EE58813 ft=1 fh=d8db3b390de6315b vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\$Recycle.Bin\S-1-5-21-587935961-2775860875-2407296441-1002\$RKNCYD7.exe" sh=FF2F81E8DFCD46D824251CBEB75905D80DED06C9 ft=1 fh=7ab661430676d238 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\$Recycle.Bin\S-1-5-21-587935961-2775860875-2407296441-1002\$RRR1XMU.exe" sh=6DEADCD179072E282D72AEB671997925DA02DCB6 ft=1 fh=4828b5a97b0ea8d5 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\$Recycle.Bin\S-1-5-21-587935961-2775860875-2407296441-1002\$RVKDGMG.exe" sh=14C1DC5CB0CF73A42866AEA0A07B0A754C84F6B9 ft=1 fh=7b8fdf4e16867ebd vn="Variante von Win32/Toolbar.Visicom.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\adawareDx.dll.vir" sh=632FB41B95FBFF1B14048B2DC0512520DD794583 ft=1 fh=7b1f3132515a2652 vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\adawaretb.dll.vir" sh=6E6B9D9B42A510193E815990C05C757BBC9DE99E ft=1 fh=601943b04511081d vn="Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\dtUser.exe.vir" sh=855094147DCCD2BC4969CB0FEDCA7BC8331B9415 ft=1 fh=aaf524e0b1926a0a vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareSafeBrowsing.exe" sh=9832E303AF1F020C6DD37DB8D8E7A0FF40979142 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\1T0ZE1RQ\intext_adv_m[1].js" sh=B683C210045A4133B80E4ECC0C23BC3196B66514 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\7JG10CFA\bpo_serp_m[1].js" sh=723041AFAA11FE75C1E748C4BCD3D15B4F61145F ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\7T6MXE64\icm_m[1].js" sh=928B3A0AAB8E65FB9E3A586D99E80AD24A68A831 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\84Z8OC9A\corticas_m[1].js" sh=066D67D3C0F4110A52C2843171BCB750FA7A6E6B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\84Z8OC9A\intext_5_m[1].js" sh=CC9B5D471D8C379CBAA0E63FE16033287F90F82D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\84Z8OC9A\jollywallet_m[1].js" sh=09E41DAB84A351A234F471879A1C5FC682957ABA ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\H678FC35\revizer_p_dynamic_m[1].js" sh=B8B5897BC3983B6CE75447868BDAE3EB1441E61C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\K27LRO6E\ibario_pops_m[1].js" sh=57F74C3FAF6723290F6FA3341542A17948A76BCD ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\K27LRO6E\revizer_ws_dynamic_m[1].js" sh=C403B988AF2EFC2B9DD070F5C5A3070244B7DEE2 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\R9X6H22A\dealply_m[1].js" sh=BFD0F29067CAE71544784708FE5554D6518AD6AD ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\R9X6H22A\superfish_no_coupons_m[1].js" sh=BD99029E3E064DE3BDC009BED86CE5F9F6556130 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\U71LIA11\ciuvo_m[1].js" sh=B4853CCBF4F400FB3A12155815CFFD0D74C8EEAC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Microsoft\Windows\INetCache\IE\U71LIA11\noproblemppc_m[1].js" sh=CCD90EE6E9B1ADFF9657E8F2C126BC6CB5C2EB24 ft=1 fh=91473923cd86549e vn="Variante von Win32/SProtector.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Temp\is-794MT.tmp\OptProCrash.dll" sh=ED0D9B8B9FD42BF9314F605438EF3135E4801638 ft=1 fh=bff9a8118895e117 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Temp\is1832903999\447677562_stp.EXE" sh=FC5698CC842074F05ADDDD305699E6C0C13633AA ft=1 fh=61fe7620fd1abc15 vn="Win32/Mobogenie.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Temp\is1832903999\447677778_stp\Mobogenie_Setup_2.1.25_501.exe" sh=A707761067E38FACE204049CAEF58BFCEBC1F8B3 ft=1 fh=273a117abdd03601 vn="Win32/Distromatic.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michael\AppData\Local\Temp\is2099814586\245536398_stp\distro-meta-installer.exe" sh=A87B7647DC34B5B6186209377786E946B677C574 ft=1 fh=c2834f18f25710d9 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Michael\AppData\Local\Temp\{8F57B5D5-150B-419C-BF9A-12A51BC3546B}\setup.exe" |
11.08.2014, 21:20 | #13 |
/// the machine /// TB-Ausbilder | C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werden Frisches FRST log und Antwort auf meine Frage fehlt
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.08.2014, 17:57 | #14 |
| C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werden Fehlermeldung kommt nun nicht mehr beim Hochfahren/Neustart des Systems FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-08-2014 01 Ran by Michael (administrator) on MICHILAPTOP on 12-08-2014 17:18:45 Running from C:\Users\Michael\Downloads Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe () C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe (Apple Inc.) C:\AirPrint\airprint.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\InstallServices64.exe (IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe (GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212048 2012-06-07] (Realtek Semiconductor) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [ACPW06DE] => C:\Program Files\ACD Systems\ACDSee Pro\6.0\ACDSeePro6InTouch2.exe [1231992 2012-11-14] (ACD Systems) HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-41 (the data entry has 36 more characters). HKLM\...\Run: [SBRegRebootCleaner] => C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] () HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Dolby PCEE4\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554408 2013-05-15] (Lavasoft) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [uni mouse driver] => "C:\Mouse driver\mouse_driver.exe" /hide HKLM-x32\...\Run: [uni mouse driver tilt] => "C:\Mouse driver\wh_exec.exe" HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [CloneCDTray] => C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoDriveAutoRun] 0x0000 HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Agent] => "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse] => "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [7 Taskbar Tweaker] => C:\Users\Michael\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe [283648 2013-04-30] (RaMMicHaeL) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [1&1_1&1 Upload-Manager] => C:\Program Files (x86)\1&1\1&1 Upload-Manager\DAVSRV.EXE [989264 2011-11-21] (1&1 Internet AG) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Run: [Rainlendar2] => C:\Program Files\Rainlendar2\Rainlendar2.exe HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Policies\Explorer: [NoDriveAutoRun] 0x0000 HKU\S-1-5-21-587935961-2775860875-2407296441-1002\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation) AppInit_DLLs: , C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation) AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [146480 2014-07-02] (NVIDIA Corporation) Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: AcronisSyncError -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncInProgress -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncOk -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google) ShellIconOverlayIdentifiers-x32: CloudIcon_DOWNLOAD -> {C3DBFBE2-A521-4619-9F32-502318CB4EC2} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_ERROR -> {851C758E-C636-4045-B323-059931A3A331} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_INSYNC -> {580030D3-492E-45EA-A1C9-A0AC525BEB26} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_REFRESH -> {FEBF62C8-B6B3-43B7-BEC4-1A9CD61BDCD2} => No File ShellIconOverlayIdentifiers-x32: CloudIcon_UPLOAD -> {EBED3602-8915-43F9-81F7-CAA6FC4F70D6} => No File ShellIconOverlayIdentifiers-x32: Offline Files -> {4E77131D-3629-431c-9818-C5679DC83E81} => No File ShellIconOverlayIdentifiers-x32: SharingPrivate -> {08244EE6-92F0-47f2-9FC9-929BAA2E7235} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: http=;ftp=;https=; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - {2C67950C-8251-481E-B96D-A28F2062192E} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS SearchScopes: HKLM - {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKCU - {EB26B7B1-333E-4940-B489-AB24FCB89F8E} URL = hxxp://www.sm.de/?q={searchTerms} BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - No Name - {C7DDDD27-F303-42A5-B979-51559F7DC0F0} - No File Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006 FF SearchEngineOrder.1: SuchMaschine FF Homepage: web.de FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VLC Player\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\McAfee Security Scan\3.0.313\npMcAfeeMss.dll No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\searchplugins\search_engine.xml FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Garmin Communicator - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-07-26] FF Extension: ColorZilla - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2014-03-18] FF Extension: Personas Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\personas@christopher.beard.xpi [2013-08-06] FF Extension: Leet Key - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{3335F91D-2AEF-4097-B831-C96C60349822}.xpi [2014-03-18] FF Extension: Adblock Plus - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-07] FF Extension: Greasemonkey - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\2kdf8z5s.default-1375768414006\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-01-01] FF Extension: Hotspot Shield Extension - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afproxy@anchorfree.com [2014-07-17] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited) R2 AirPrint; C:\AirPrint\airprint.exe [234784 2014-07-07] (Apple Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-05] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-05] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227456 2013-01-28] (Qualcomm Atheros Commnucations) S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG) S4 BrcmCardReader; C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe [176640 2012-08-20] (Broadcom Corp.) [File not signed] S4 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2435728 2012-08-23] (Acer Incorporated) S4 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [468624 2012-08-23] (Acer Incorporated) S4 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658576 2012-08-22] (Acer Incorporated) R2 HPSLPSVC; C:\Users\Michael\AppData\Local\Temp\7zS57EE\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed] S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-11-12] (Nitro PDF Software) S4 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-08-23] (NTI Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [66872 2013-12-27] () R2 PnkBstrB; C:\WINDOWS\SysWOW64\PnkBstrB.exe [107832 2013-12-27] () S4 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2012-11-23] (Dritek System INC.) R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software) S4 StarMoney 8.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH) S4 Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [142960 2013-01-31] (Stardock Software, Inc) R2 StartMenuService; C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe [72992 2014-06-06] (IObit) R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2013-04-22] (Western Digital Technologies, Inc.) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270192 2013-03-21] (Western Digital Technologies, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) R2 WO_LiveService; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe [885096 2013-04-10] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-06-17] (Avira Operations GmbH & Co. KG) R3 avmaura; C:\Windows\System32\drivers\avmaura.sys [116480 2013-10-20] (AVM Berlin) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-28] (Qualcomm Atheros) S3 bthav; C:\Windows\system32\drivers\bthav.sys [40448 2008-07-10] (CSR, plc) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.) R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.) S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-06-28] (GFI Software) S3 GigasetGenericUSB_x64; C:\Windows\system32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2013-03-05] (Siemens Home and Office Communication Devices GmbH & Co. KG) [File not signed] R1 HssDRV6; C:\Windows\system32\DRIVERS\hssdrv6.sys [44744 2014-05-17] (AnchorFree Inc.) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) R2 LiveTunerPM; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerProcessMonitor64.sys [12824 2011-03-08] () R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-11] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-11-23] (Dritek System Inc.) R3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [1093256 2013-02-14] (Acronis) R1 ui11rdr; C:\Windows\System32\DRIVERS\ui11rdr.sys [199752 2011-11-21] (1&1 Internet AG) R1 UimBus; C:\Windows\System32\drivers\uimx64.sys [90960 2012-08-07] (Windows (R) 2000 DDK provider) R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633552 2012-08-07] (Paragon) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) R3 whfltr2k; C:\Windows\System32\drivers\whfltr2k.sys [10368 2009-09-16] () ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-11 19:10 - 2014-08-11 19:10 - 00001799 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-08-11 19:10 - 2014-08-11 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-08-11 19:08 - 2014-08-11 19:10 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-08-11 19:08 - 2014-08-11 19:10 - 00000000 ____D () C:\Program Files\iTunes 2014-08-11 19:08 - 2014-08-11 19:08 - 00000000 ____D () C:\Program Files\iPod 2014-08-10 08:53 - 2014-08-10 08:52 - 02347384 _____ (ESET) C:\Users\Michael\Desktop\esetsmartinstaller_deu.exe 2014-08-10 08:52 - 2014-08-10 08:52 - 02347384 _____ (ESET) C:\Users\Michael\Downloads\esetsmartinstaller_deu.exe 2014-08-10 08:51 - 2014-08-10 08:51 - 00854410 _____ () C:\Users\Michael\Desktop\SecurityCheck.exe 2014-08-09 18:36 - 2014-08-09 18:36 - 00076623 _____ () C:\Users\Michael\Desktop\FRST_neu.txt 2014-08-09 18:33 - 2014-08-11 18:25 - 00000000 ____D () C:\Users\Michael\Downloads\FRST-OlderVersion 2014-08-09 18:31 - 2014-08-09 18:31 - 00002349 _____ () C:\Users\Michael\Desktop\JRT.txt 2014-08-09 18:26 - 2014-08-09 18:26 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-08-09 18:24 - 2014-08-09 18:24 - 00014761 _____ () C:\Users\Michael\Desktop\AdwCleaner[S0].txt 2014-08-09 18:16 - 2014-08-09 18:21 - 00000000 ____D () C:\AdwCleaner 2014-08-09 18:15 - 2014-08-09 18:15 - 00002046 _____ () C:\Users\Michael\Desktop\mbam.txt 2014-08-08 19:53 - 2014-08-08 19:53 - 01366203 _____ () C:\Users\Michael\Desktop\adwcleaner_3.304.exe 2014-08-08 19:53 - 2014-08-08 19:53 - 01016261 _____ (Thisisu) C:\Users\Michael\Desktop\JRT.exe 2014-08-08 19:51 - 2014-08-08 19:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michael\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-08 06:42 - 2014-08-08 06:42 - 00072062 _____ () C:\Users\Michael\Downloads\t1556858_Etappe-2-Der-Granat-landschaftlich-schoenster-Etappenausschnitt.gpx 2014-08-06 20:21 - 2014-08-06 20:27 - 00085201 _____ () C:\Users\Michael\Desktop\FRST.txt 2014-08-06 17:43 - 2014-08-06 17:43 - 02194385 _____ () C:\Users\Michael\Desktop\Lenker_neu3.MOV 2014-08-06 17:42 - 2014-08-06 17:42 - 02977434 _____ () C:\Users\Michael\Desktop\Lenker_neu2.MOV 2014-08-06 17:42 - 2014-08-06 17:42 - 00971867 _____ () C:\Users\Michael\Desktop\Lenker_neu1.MOV 2014-08-06 09:43 - 2014-08-06 09:43 - 00001457 _____ () C:\Users\Michael\AppData\Local\recently-used.xbel 2014-08-06 09:25 - 2014-08-06 09:25 - 00000303 _____ () C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Heimnetzgruppe.lnk 2014-08-05 11:45 - 2014-08-05 11:45 - 00086969 _____ () C:\Users\Michael\Desktop\FRST-ALT.txt 2014-08-05 11:45 - 2014-08-05 11:45 - 00082200 _____ () C:\Users\Michael\Desktop\Addition_ALT.txt 2014-08-05 11:43 - 2014-08-12 17:12 - 00090278 _____ () C:\Users\Michael\Downloads\Addition.txt 2014-08-05 11:40 - 2014-08-12 17:19 - 00029777 _____ () C:\Users\Michael\Downloads\FRST.txt 2014-08-05 11:40 - 2014-08-12 17:18 - 00000000 ____D () C:\FRST 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\system32\NV 2014-08-05 11:37 - 2014-08-11 18:25 - 02099712 _____ (Farbar) C:\Users\Michael\Downloads\FRST64.exe 2014-08-05 11:37 - 2014-07-02 20:55 - 06783776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 03522392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 02559960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 01084704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00935368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2014-08-05 11:37 - 2014-07-02 20:55 - 00386520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00067072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00062808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2014-08-05 11:37 - 2014-07-02 12:14 - 03826628 _____ () C:\WINDOWS\system32\nvcoproc.bin 2014-08-05 11:15 - 2014-07-02 22:48 - 31512520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 24196896 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 22994208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 18626304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 17555104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 16122344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 15294296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 14498552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 13922752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 13835208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 12866008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys 2014-08-05 11:15 - 2014-07-02 22:48 - 11283344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 11222048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 04247000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 03989960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 03196816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 02814656 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 01890080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6434052.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 01539928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6434052.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00965312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00944928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00907096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00903624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00869152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00846832 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00354016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00305600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00166568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00146480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00032544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys 2014-08-05 11:15 - 2014-07-02 22:48 - 00026353 _____ () C:\WINDOWS\system32\nvinfo.pb 2014-08-05 10:07 - 2014-07-25 15:50 - 01715224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2014-08-05 10:07 - 2014-07-25 15:50 - 01291280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2014-08-05 10:06 - 2014-08-05 10:06 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp 2014-08-05 10:06 - 2014-03-31 18:42 - 00040392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys 2014-08-05 10:06 - 2014-03-31 18:42 - 00034760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll 2014-08-05 08:15 - 2014-08-05 08:33 - 520324935 _____ () C:\Users\Michael\Downloads\Demo_Flakstad.exe 2014-08-05 08:08 - 2014-08-05 08:08 - 00053507 _____ () C:\Users\Michael\Downloads\route_1325.gpx 2014-08-05 03:43 - 2014-08-05 03:43 - 00031250 _____ () C:\Users\Michael\Downloads\NO_Gullingen.rlv 2014-08-05 03:35 - 2014-08-05 03:38 - 183717406 _____ () C:\Users\Michael\Downloads\Demo_Furka2011.exe 2014-08-04 15:36 - 2014-08-04 15:36 - 00961405 _____ () C:\Users\Michael\Downloads\GpsiesTrack.gpx 2014-08-04 15:36 - 2014-08-04 15:36 - 00074226 _____ () C:\Users\Michael\Downloads\Innradtour09Obernberg-Erlau.gpx 2014-08-03 17:38 - 2014-08-03 17:38 - 00490166 _____ () C:\Users\Michael\Downloads\09-Movie&Show.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00352614 _____ () C:\Users\Michael\Downloads\Arabic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00269690 _____ () C:\Users\Michael\Downloads\12-Ethnic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00265411 _____ () C:\Users\Michael\Downloads\Turkish&Greek.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00263102 _____ () C:\Users\Michael\Downloads\06-Country.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00610081 _____ () C:\Users\Michael\Downloads\01-Pop&Rock.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00564588 _____ () C:\Users\Michael\Downloads\05-R&B.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00541643 _____ () C:\Users\Michael\Downloads\02-Ballad.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00524065 _____ () C:\Users\Michael\Downloads\03-Dance.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00394653 _____ () C:\Users\Michael\Downloads\07-Latin.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00347569 _____ () C:\Users\Michael\Downloads\04-Swing&Jazz.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00310825 _____ () C:\Users\Michael\Downloads\10-Entertainer.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00165856 _____ () C:\Users\Michael\Downloads\08-Ballroom.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00161112 _____ () C:\Users\Michael\Downloads\11-World.zip 2014-08-03 09:28 - 2014-08-03 09:29 - 02252800 _____ () C:\Users\Michael\Downloads\Google.rar.part 2014-07-29 20:14 - 2014-07-29 20:15 - 32040040 _____ (KETTLER) C:\Users\Michael\AVM_Driver\Pictures\Documents\KWT20Update20132.exe 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 ____D () C:\Users\Michael\Downloads\bosch 2014-07-29 13:24 - 2014-07-29 13:25 - 61689856 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.46.0.msi 2014-07-29 09:54 - 2014-07-29 09:54 - 00108809 _____ () C:\Users\Michael\Downloads\no_gullingen.zip 2014-07-28 10:13 - 2014-07-28 10:13 - 00296888 _____ () C:\WINDOWS\Minidump\072814-61468-01.dmp 2014-07-28 10:13 - 2014-07-28 10:13 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-28 05:59 - 2014-07-28 05:59 - 00000000 ____D () C:\Users\Michael\Downloads\Wo Bleibt die Musik 2014-07-26 19:33 - 2014-07-27 06:11 - 00000000 ____D () C:\Users\Michael\Downloads\Midi_Hüttenmusikant 2014-07-26 19:07 - 2014-07-26 19:07 - 00046745 _____ () C:\Users\Michael\Downloads\xt Amoi seg ma uns.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00094136 _____ () C:\Users\Michael\Downloads\xt Atemlos.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00080784 _____ () C:\Users\Michael\Downloads\SRP021 S910.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT(1).zip 2014-07-26 19:01 - 2014-07-26 19:01 - 00062888 _____ () C:\Users\Michael\Downloads\klingande-jubel.mid 2014-07-26 18:59 - 2014-07-26 18:59 - 00019221 _____ () C:\Users\Michael\Downloads\one_republic-love_runs_out.mid 2014-07-26 18:58 - 2014-07-26 18:58 - 00032868 _____ () C:\Users\Michael\Downloads\golden_earing-twilight_zone.mid 2014-07-25 15:07 - 2014-07-29 13:23 - 00000000 ____D () C:\Users\Michael\Downloads\tanja Kruse 2014-07-25 14:25 - 2014-07-25 14:25 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog_-_axel_f.mid 2014-07-25 14:24 - 2014-07-25 14:24 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog-axel_f.mid 2014-07-25 07:56 - 2014-07-25 07:56 - 00003164 _____ () C:\WINDOWS\System32\Tasks\StartMenuAutoupdate 2014-07-25 07:56 - 2014-07-25 07:56 - 00001279 _____ () C:\Users\Public\Desktop\Start Menu 8.lnk 2014-07-25 07:56 - 2014-07-25 07:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu 8 2014-07-21 21:10 - 2014-08-06 09:20 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-07-21 18:50 - 2014-07-21 18:50 - 00000000 ____D () C:\Users\Michael\AppData\Local\Intel_Corporation 2014-07-20 12:52 - 2014-07-20 12:52 - 00030891 _____ () C:\Users\Michael\Downloads\peterburgsky-donnaklara.zip 2014-07-20 09:28 - 2014-07-20 09:43 - 47978285 _____ () C:\Users\Michael\Downloads\01belle30.rar 2014-07-17 19:00 - 2014-07-17 19:01 - 69767374 _____ () C:\Users\Michael\Downloads\32pfl4308k_12_fus_deu.zip 2014-07-17 10:04 - 2014-07-17 13:41 - 00000000 ____D () C:\Users\Michael\Downloads\Garmin Topo Österreich V4_3086_imgUL-sql 2014-07-17 09:30 - 2014-07-17 09:30 - 03704534 _____ () C:\Users\Michael\Downloads\188.rar 2014-07-17 09:21 - 2014-07-17 09:21 - 00001140 _____ () C:\Users\Public\Desktop\Hotspot Shield.lnk 2014-07-17 09:21 - 2014-07-17 09:21 - 00000176 _____ () C:\Users\Michael\Downloads\hotspotshield-setup_540.exe 2014-07-17 08:55 - 2014-05-17 04:35 - 00044744 _____ (AnchorFree Inc.) C:\WINDOWS\system32\Drivers\hssdrv6.sys 2014-07-17 08:53 - 2014-07-17 08:53 - 07787136 _____ () C:\Users\Michael\Downloads\HSS-3.42-install-e-550-plain.exe 2014-07-16 11:23 - 2014-07-16 11:23 - 00000000 ____D () C:\Users\Michael\Downloads\Onerepublic-Native 2014-07-16 11:00 - 2014-07-16 11:00 - 02426602 _____ () C:\Users\Michael\Desktop\Lenker_0882.MOV 2014-07-16 10:59 - 2014-07-16 10:59 - 00670852 _____ () C:\Users\Michael\Desktop\Sitz.MOV 2014-07-16 10:04 - 2014-08-11 18:58 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-07-16 10:03 - 2014-07-16 10:04 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers 2014-07-16 10:02 - 2014-07-16 10:02 - 00000000 ____D () C:\Program Files\Common Files\Common Desktop Agent 2014-07-16 10:01 - 2014-07-16 10:04 - 00000000 ____D () C:\Program Files (x86)\SamsungPrinterLiveUpdate 2014-07-16 10:00 - 2014-07-16 10:04 - 00000000 ____D () C:\Program Files (x86)\Samsung 2014-07-16 10:00 - 2013-12-27 11:33 - 00226424 _____ () C:\WINDOWS\system32\SBuySupplies.exe 2014-07-16 10:00 - 2013-12-27 11:33 - 00158040 _____ (SS) C:\WINDOWS\system32\ssj2mci.exe 2014-07-16 10:00 - 2013-12-27 11:33 - 00089600 _____ (SS) C:\WINDOWS\system32\ssj2mci.dll 2014-07-16 10:00 - 2013-12-27 11:33 - 00034304 _____ () C:\WINDOWS\system32\ssj2mlm.dll 2014-07-16 10:00 - 2013-12-27 11:33 - 00000359 _____ () C:\WINDOWS\system32\ssj2mlm.smt 2014-07-16 10:00 - 2013-12-06 10:24 - 00101518 ____N () C:\WINDOWS\ssj2mLTR.prn 2014-07-16 10:00 - 2013-12-06 10:23 - 00107317 ____N () C:\WINDOWS\ssj2mA4.prn 2014-07-16 10:00 - 2013-07-05 08:20 - 00094208 ____N () C:\WINDOWS\SysWOW64\ssdevm.dll 2014-07-16 10:00 - 2013-07-05 08:20 - 00091136 ____N () C:\WINDOWS\system32\ssdevm64.dll 2014-07-13 17:00 - 2014-07-13 17:01 - 00000862 _____ () C:\Users\Michael\Downloads\garmin alpenvereinskarten.nzb 2014-07-13 16:50 - 2014-07-13 16:50 - 07315296 _____ (IObit ) C:\Users\Michael\Downloads\startmenu-setup.exe 2014-07-13 12:03 - 2014-07-13 11:28 - 01104896 _____ () C:\Users\Michael\Desktop\michalt.db 2014-07-13 11:39 - 2014-07-29 13:26 - 00000946 _____ () C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk 2014-07-13 11:35 - 2014-07-13 11:36 - 61681664 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.44.0.msi 2014-07-13 09:00 - 2014-07-13 09:00 - 00632784 _____ () C:\Users\Michael\Downloads\FRITZ.Box Fon WLAN 7390 (UI) 84.06.03_13.07.14_0859.export ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-12 17:19 - 2014-08-05 11:40 - 00029777 _____ () C:\Users\Michael\Downloads\FRST.txt 2014-08-12 17:18 - 2014-08-05 11:40 - 00000000 ____D () C:\FRST 2014-08-12 17:17 - 2013-11-06 14:57 - 02096530 _____ () C:\WINDOWS\WindowsUpdate.log 2014-08-12 17:12 - 2014-08-05 11:43 - 00090278 _____ () C:\Users\Michael\Downloads\Addition.txt 2014-08-12 17:10 - 2013-11-30 20:51 - 00003950 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{A0BF6906-8E67-4F48-9A06-BFACF99DFEAA} 2014-08-12 17:06 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-08-11 19:26 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\mkoelbl@online.de.pst 2014-08-11 19:26 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\mike1k@gmx.de.pst 2014-08-11 19:26 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\homeshopper66@online.de.pst 2014-08-11 19:26 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\hdampff@gmx.de.pst 2014-08-11 19:26 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\FTF-Hunter@online.de.pst 2014-08-11 19:26 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\FTF-Hunter@gmx.de.pst 2014-08-11 19:26 - 2013-12-05 19:51 - 00271360 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\bayanbua@gmx.de.pst 2014-08-11 19:26 - 2013-02-09 23:55 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\Outlook-Dateien 2014-08-11 19:26 - 2009-06-28 12:04 - 609248256 _____ () C:\Users\Michael\AVM_Driver\Pictures\Documents\Outlook.pst 2014-08-11 19:18 - 2013-02-08 14:30 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-587935961-2775860875-2407296441-1002 2014-08-11 19:14 - 2014-06-25 20:16 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-08-11 19:14 - 2013-04-22 12:00 - 00008192 _____ () C:\WINDOWS\SysWOW64\WDPABKP.dat 2014-08-11 19:13 - 2014-01-17 19:33 - 00000324 _____ () C:\WINDOWS\Tasks\AutoKMS.job 2014-08-11 19:13 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-08-11 19:13 - 2013-07-09 19:43 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-11 19:12 - 2013-09-29 21:04 - 00425828 _____ () C:\WINDOWS\PFRO.log 2014-08-11 19:10 - 2014-08-11 19:10 - 00001799 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-08-11 19:10 - 2014-08-11 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-08-11 19:10 - 2014-08-11 19:08 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-08-11 19:10 - 2014-08-11 19:08 - 00000000 ____D () C:\Program Files\iTunes 2014-08-11 19:10 - 2013-02-18 19:51 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-08-11 19:08 - 2014-08-11 19:08 - 00000000 ____D () C:\Program Files\iPod 2014-08-11 18:58 - 2014-07-16 10:04 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-08-11 18:34 - 2013-02-17 08:44 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-08-11 18:29 - 2013-07-09 19:43 - 00001136 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-11 18:25 - 2014-08-09 18:33 - 00000000 ____D () C:\Users\Michael\Downloads\FRST-OlderVersion 2014-08-11 18:25 - 2014-08-05 11:37 - 02099712 _____ (Farbar) C:\Users\Michael\Downloads\FRST64.exe 2014-08-11 02:39 - 2013-02-07 23:47 - 00000000 ____D () C:\Users\Michael\AppData\Local\Packages 2014-08-10 08:52 - 2014-08-10 08:53 - 02347384 _____ (ESET) C:\Users\Michael\Desktop\esetsmartinstaller_deu.exe 2014-08-10 08:52 - 2014-08-10 08:52 - 02347384 _____ (ESET) C:\Users\Michael\Downloads\esetsmartinstaller_deu.exe 2014-08-10 08:51 - 2014-08-10 08:51 - 00854410 _____ () C:\Users\Michael\Desktop\SecurityCheck.exe 2014-08-10 07:18 - 2013-05-25 19:22 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-10 07:17 - 2014-01-17 17:27 - 00271360 _____ () C:\WINDOWS\system32\C 2014-08-10 07:12 - 2013-06-29 10:28 - 00014822 _____ () C:\missing.ini 2014-08-10 07:10 - 2014-06-13 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KETTLER 2014-08-10 07:09 - 2013-02-18 14:08 - 00000000 ____D () C:\Program Files (x86)\Gigaset QuickSync 2014-08-10 07:05 - 2012-11-02 05:43 - 00000000 ____D () C:\ProgramData\Temp 2014-08-09 19:30 - 2013-10-05 18:30 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\TV-Browser 2014-08-09 18:50 - 2013-11-06 20:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\Deployment 2014-08-09 18:44 - 2013-02-10 01:38 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\gsak8 2014-08-09 18:44 - 2013-02-09 19:41 - 00000000 ____D () C:\GSAK8 2014-08-09 18:36 - 2014-08-09 18:36 - 00076623 _____ () C:\Users\Michael\Desktop\FRST_neu.txt 2014-08-09 18:31 - 2014-08-09 18:31 - 00002349 _____ () C:\Users\Michael\Desktop\JRT.txt 2014-08-09 18:26 - 2014-08-09 18:26 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-08-09 18:24 - 2014-08-09 18:24 - 00014761 _____ () C:\Users\Michael\Desktop\AdwCleaner[S0].txt 2014-08-09 18:21 - 2014-08-09 18:16 - 00000000 ____D () C:\AdwCleaner 2014-08-09 18:20 - 2013-02-07 23:47 - 00000000 ____D () C:\Users\Michael 2014-08-09 18:15 - 2014-08-09 18:15 - 00002046 _____ () C:\Users\Michael\Desktop\mbam.txt 2014-08-09 18:04 - 2013-11-06 14:54 - 00000000 ___DC () C:\WINDOWS\Panther 2014-08-09 17:11 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-08-08 20:42 - 2014-06-25 20:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-08 20:42 - 2014-06-25 20:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-08 20:42 - 2013-08-05 13:52 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-08 19:53 - 2014-08-08 19:53 - 01366203 _____ () C:\Users\Michael\Desktop\adwcleaner_3.304.exe 2014-08-08 19:53 - 2014-08-08 19:53 - 01016261 _____ (Thisisu) C:\Users\Michael\Desktop\JRT.exe 2014-08-08 19:52 - 2014-08-08 19:51 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michael\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-08 10:49 - 2014-01-25 20:26 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0 2014-08-08 06:47 - 2014-07-09 11:39 - 00000000 ____D () C:\Program Files (x86)\SqliteBrowser3 2014-08-08 06:42 - 2014-08-08 06:42 - 00072062 _____ () C:\Users\Michael\Downloads\t1556858_Etappe-2-Der-Granat-landschaftlich-schoenster-Etappenausschnitt.gpx 2014-08-08 06:38 - 2013-08-25 10:27 - 00000000 ____D () C:\totalcmd 2014-08-08 06:38 - 2013-02-10 01:38 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\GHISLER 2014-08-08 06:35 - 2014-04-11 08:39 - 00000000 ____D () C:\Program Files (x86)\Mopsos 2014-08-08 06:35 - 2014-03-23 13:37 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Mopsos 2014-08-07 13:54 - 2014-02-21 10:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\FileAdvisor 2014-08-07 13:52 - 2014-02-11 14:52 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor 2014-08-07 10:24 - 2013-02-10 02:35 - 01171456 ___SH () C:\Users\Michael\Desktop\Thumbs.db 2014-08-06 20:27 - 2014-08-06 20:21 - 00085201 _____ () C:\Users\Michael\Desktop\FRST.txt 2014-08-06 17:43 - 2014-08-06 17:43 - 02194385 _____ () C:\Users\Michael\Desktop\Lenker_neu3.MOV 2014-08-06 17:42 - 2014-08-06 17:42 - 02977434 _____ () C:\Users\Michael\Desktop\Lenker_neu2.MOV 2014-08-06 17:42 - 2014-08-06 17:42 - 00971867 _____ () C:\Users\Michael\Desktop\Lenker_neu1.MOV 2014-08-06 09:43 - 2014-08-06 09:43 - 00001457 _____ () C:\Users\Michael\AppData\Local\recently-used.xbel 2014-08-06 09:43 - 2014-03-21 19:22 - 00000000 ____D () C:\Users\Michael\AppData\Local\gtk-2.0 2014-08-06 09:43 - 2013-02-09 21:20 - 00000000 ____D () C:\Users\Michael\.gimp-2.8 2014-08-06 09:28 - 2014-05-29 17:33 - 00000000 ____D () C:\Users\Michael\AppData\Local\Adobe 2014-08-06 09:25 - 2014-08-06 09:25 - 00000303 _____ () C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Heimnetzgruppe.lnk 2014-08-06 09:20 - 2014-07-21 21:10 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-06 09:20 - 2014-06-25 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-06 09:20 - 2014-06-25 21:07 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-06 06:21 - 2014-05-26 14:09 - 00000000 ____D () C:\Program Files (x86)\KETTLER 2014-08-05 11:45 - 2014-08-05 11:45 - 00086969 _____ () C:\Users\Michael\Desktop\FRST-ALT.txt 2014-08-05 11:45 - 2014-08-05 11:45 - 00082200 _____ () C:\Users\Michael\Desktop\Addition_ALT.txt 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV 2014-08-05 11:38 - 2014-08-05 11:38 - 00000000 ____D () C:\WINDOWS\system32\NV 2014-08-05 11:38 - 2013-02-09 20:07 - 00000000 ____D () C:\Temp 2014-08-05 11:38 - 2012-11-23 04:45 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-08-05 11:37 - 2013-11-06 14:56 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-08-05 11:37 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Help 2014-08-05 11:17 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-08-05 10:07 - 2013-08-22 16:46 - 00395073 _____ () C:\WINDOWS\setupact.log 2014-08-05 10:06 - 2014-08-05 10:06 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp 2014-08-05 09:58 - 2014-06-26 14:25 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\BitLord 2014-08-05 09:26 - 2013-09-30 06:14 - 00731054 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-08-05 09:26 - 2013-09-30 05:56 - 01036102 _____ () C:\WINDOWS\system32\perfh007.dat 2014-08-05 09:26 - 2013-09-30 05:56 - 00239366 _____ () C:\WINDOWS\system32\perfc007.dat 2014-08-05 09:22 - 2014-05-09 06:38 - 00000000 ____D () C:\Users\Michael\Desktop\kabat 2014-08-05 08:33 - 2014-08-05 08:15 - 520324935 _____ () C:\Users\Michael\Downloads\Demo_Flakstad.exe 2014-08-05 08:08 - 2014-08-05 08:08 - 00053507 _____ () C:\Users\Michael\Downloads\route_1325.gpx 2014-08-05 03:43 - 2014-08-05 03:43 - 00031250 _____ () C:\Users\Michael\Downloads\NO_Gullingen.rlv 2014-08-05 03:38 - 2014-08-05 03:35 - 183717406 _____ () C:\Users\Michael\Downloads\Demo_Furka2011.exe 2014-08-04 15:36 - 2014-08-04 15:36 - 00961405 _____ () C:\Users\Michael\Downloads\GpsiesTrack.gpx 2014-08-04 15:36 - 2014-08-04 15:36 - 00074226 _____ () C:\Users\Michael\Downloads\Innradtour09Obernberg-Erlau.gpx 2014-08-04 15:14 - 2013-02-10 01:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Nitro PDF 2014-08-04 15:13 - 2013-02-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin 2014-08-04 15:13 - 2013-02-09 20:40 - 00000000 ____D () C:\Program Files (x86)\Garmin 2014-08-03 17:38 - 2014-08-03 17:38 - 00490166 _____ () C:\Users\Michael\Downloads\09-Movie&Show.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00352614 _____ () C:\Users\Michael\Downloads\Arabic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00269690 _____ () C:\Users\Michael\Downloads\12-Ethnic.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00265411 _____ () C:\Users\Michael\Downloads\Turkish&Greek.zip 2014-08-03 17:38 - 2014-08-03 17:38 - 00263102 _____ () C:\Users\Michael\Downloads\06-Country.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00610081 _____ () C:\Users\Michael\Downloads\01-Pop&Rock.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00564588 _____ () C:\Users\Michael\Downloads\05-R&B.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00541643 _____ () C:\Users\Michael\Downloads\02-Ballad.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00524065 _____ () C:\Users\Michael\Downloads\03-Dance.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00394653 _____ () C:\Users\Michael\Downloads\07-Latin.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00347569 _____ () C:\Users\Michael\Downloads\04-Swing&Jazz.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00310825 _____ () C:\Users\Michael\Downloads\10-Entertainer.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00165856 _____ () C:\Users\Michael\Downloads\08-Ballroom.zip 2014-08-03 17:37 - 2014-08-03 17:37 - 00161112 _____ () C:\Users\Michael\Downloads\11-World.zip 2014-08-03 11:47 - 2013-02-10 10:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-03 11:43 - 2014-01-27 11:29 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\vlc 2014-08-03 09:29 - 2014-08-03 09:28 - 02252800 _____ () C:\Users\Michael\Downloads\Google.rar.part 2014-08-01 09:27 - 2013-05-25 19:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-29 20:17 - 2014-06-26 13:01 - 00002527 _____ () C:\Users\Public\Desktop\KETTLER WORLD TOURS 2.0.lnk 2014-07-29 20:15 - 2014-07-29 20:14 - 32040040 _____ (KETTLER) C:\Users\Michael\AVM_Driver\Pictures\Documents\KWT20Update20132.exe 2014-07-29 19:38 - 2014-07-29 19:38 - 00000000 ____D () C:\Users\Michael\Downloads\bosch 2014-07-29 16:40 - 2013-11-01 11:05 - 00000000 ____D () C:\Users\Michael\Desktop\ebook 2014-07-29 16:37 - 2013-11-01 11:06 - 00000000 ____D () C:\Users\Michael\AppData\Local\calibre-cache 2014-07-29 13:26 - 2014-07-13 11:39 - 00000946 _____ () C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk 2014-07-29 13:26 - 2013-11-01 11:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management 2014-07-29 13:26 - 2013-11-01 11:05 - 00000000 ____D () C:\Program Files\Calibre2 2014-07-29 13:25 - 2014-07-29 13:24 - 61689856 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.46.0.msi 2014-07-29 13:23 - 2014-07-25 15:07 - 00000000 ____D () C:\Users\Michael\Downloads\tanja Kruse 2014-07-29 11:34 - 2013-02-10 20:56 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2014-07-29 09:54 - 2014-07-29 09:54 - 00108809 _____ () C:\Users\Michael\Downloads\no_gullingen.zip 2014-07-28 10:13 - 2014-07-28 10:13 - 00296888 _____ () C:\WINDOWS\Minidump\072814-61468-01.dmp 2014-07-28 10:13 - 2014-07-28 10:13 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-28 10:13 - 2013-08-22 16:44 - 05244208 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-07-28 10:12 - 2013-02-25 11:04 - 744034049 _____ () C:\WINDOWS\MEMORY.DMP 2014-07-28 06:05 - 2013-02-10 00:17 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\Steuerfälle 2014-07-28 05:59 - 2014-07-28 05:59 - 00000000 ____D () C:\Users\Michael\Downloads\Wo Bleibt die Musik 2014-07-27 06:11 - 2014-07-26 19:33 - 00000000 ____D () C:\Users\Michael\Downloads\Midi_Hüttenmusikant 2014-07-27 05:58 - 2013-02-10 00:28 - 00000000 ____D () C:\Users\Michael\AppData\Local\Google 2014-07-26 19:24 - 2013-04-07 17:58 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-26 19:24 - 2013-04-07 17:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-07-26 19:07 - 2014-07-26 19:07 - 00046745 _____ () C:\Users\Michael\Downloads\xt Amoi seg ma uns.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00094136 _____ () C:\Users\Michael\Downloads\xt Atemlos.MID 2014-07-26 19:06 - 2014-07-26 19:06 - 00080784 _____ () C:\Users\Michael\Downloads\SRP021 S910.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT.zip 2014-07-26 19:06 - 2014-07-26 19:06 - 00028190 _____ () C:\Users\Michael\Downloads\01552-SNG_XT(1).zip 2014-07-26 19:01 - 2014-07-26 19:01 - 00062888 _____ () C:\Users\Michael\Downloads\klingande-jubel.mid 2014-07-26 18:59 - 2014-07-26 18:59 - 00019221 _____ () C:\Users\Michael\Downloads\one_republic-love_runs_out.mid 2014-07-26 18:58 - 2014-07-26 18:58 - 00032868 _____ () C:\Users\Michael\Downloads\golden_earing-twilight_zone.mid 2014-07-25 15:50 - 2014-08-05 10:07 - 01715224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2014-07-25 15:50 - 2014-08-05 10:07 - 01291280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2014-07-25 15:50 - 2014-04-19 16:27 - 01283136 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2014-07-25 15:50 - 2014-04-19 16:27 - 01126480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2014-07-25 14:38 - 2014-07-03 20:03 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys 2014-07-25 14:25 - 2014-07-25 14:25 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog_-_axel_f.mid 2014-07-25 14:24 - 2014-07-25 14:24 - 00033748 _____ () C:\Users\Michael\Downloads\crazy_frog-axel_f.mid 2014-07-25 07:56 - 2014-07-25 07:56 - 00003164 _____ () C:\WINDOWS\System32\Tasks\StartMenuAutoupdate 2014-07-25 07:56 - 2014-07-25 07:56 - 00001279 _____ () C:\Users\Public\Desktop\Start Menu 8.lnk 2014-07-25 07:56 - 2014-07-25 07:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Menu 8 2014-07-25 07:54 - 2014-02-02 19:48 - 00165659 _____ () C:\MyXML.xml 2014-07-24 17:24 - 2013-04-07 17:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-22 19:26 - 2013-12-09 10:58 - 00000000 ____D () C:\Users\Michael\Desktop\Apple + Tools 2014-07-21 18:50 - 2014-07-21 18:50 - 00000000 ____D () C:\Users\Michael\AppData\Local\Intel_Corporation 2014-07-20 18:57 - 2013-02-25 11:31 - 00043008 ___SH () C:\Users\Michael\Thumbs.db 2014-07-20 12:52 - 2014-07-20 12:52 - 00030891 _____ () C:\Users\Michael\Downloads\peterburgsky-donnaklara.zip 2014-07-20 09:43 - 2014-07-20 09:28 - 47978285 _____ () C:\Users\Michael\Downloads\01belle30.rar 2014-07-17 19:01 - 2014-07-17 19:00 - 69767374 _____ () C:\Users\Michael\Downloads\32pfl4308k_12_fus_deu.zip 2014-07-17 13:41 - 2014-07-17 10:04 - 00000000 ____D () C:\Users\Michael\Downloads\Garmin Topo Österreich V4_3086_imgUL-sql 2014-07-17 13:38 - 2013-02-09 18:54 - 00000000 ___RD () C:\Garmin 2014-07-17 09:30 - 2014-07-17 09:30 - 03704534 _____ () C:\Users\Michael\Downloads\188.rar 2014-07-17 09:21 - 2014-07-17 09:21 - 00001140 _____ () C:\Users\Public\Desktop\Hotspot Shield.lnk 2014-07-17 09:21 - 2014-07-17 09:21 - 00000176 _____ () C:\Users\Michael\Downloads\hotspotshield-setup_540.exe 2014-07-17 08:53 - 2014-07-17 08:53 - 07787136 _____ () C:\Users\Michael\Downloads\HSS-3.42-install-e-550-plain.exe 2014-07-16 13:23 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-07-16 11:23 - 2014-07-16 11:23 - 00000000 ____D () C:\Users\Michael\Downloads\Onerepublic-Native 2014-07-16 11:00 - 2014-07-16 11:00 - 02426602 _____ () C:\Users\Michael\Desktop\Lenker_0882.MOV 2014-07-16 10:59 - 2014-07-16 10:59 - 00670852 _____ () C:\Users\Michael\Desktop\Sitz.MOV 2014-07-16 10:04 - 2014-07-16 10:03 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers 2014-07-16 10:04 - 2014-07-16 10:01 - 00000000 ____D () C:\Program Files (x86)\SamsungPrinterLiveUpdate 2014-07-16 10:04 - 2014-07-16 10:00 - 00000000 ____D () C:\Program Files (x86)\Samsung 2014-07-16 10:03 - 2013-02-10 01:39 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Samsung 2014-07-16 10:02 - 2014-07-16 10:02 - 00000000 ____D () C:\Program Files\Common Files\Common Desktop Agent 2014-07-16 10:02 - 2013-02-09 20:20 - 00000000 ____D () C:\ProgramData\Samsung 2014-07-13 17:01 - 2014-07-13 17:00 - 00000862 _____ () C:\Users\Michael\Downloads\garmin alpenvereinskarten.nzb 2014-07-13 16:50 - 2014-07-13 16:50 - 07315296 _____ (IObit ) C:\Users\Michael\Downloads\startmenu-setup.exe 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-13 16:40 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore 2014-07-13 16:25 - 2013-02-17 08:44 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2014-07-13 14:41 - 2013-02-09 23:47 - 00000000 ____D () C:\Users\Michael\AVM_Driver\Pictures\Documents\FinePrint-Dateien 2014-07-13 11:36 - 2014-07-13 11:35 - 61681664 _____ () C:\Users\Michael\Downloads\calibre-64bit-1.44.0.msi 2014-07-13 11:28 - 2014-07-13 12:03 - 01104896 _____ () C:\Users\Michael\Desktop\michalt.db 2014-07-13 09:00 - 2014-07-13 09:00 - 00632784 _____ () C:\Users\Michael\Downloads\FRITZ.Box Fon WLAN 7390 (UI) 84.06.03_13.07.14_0859.export Files to move or delete: ==================== C:\ProgramData\JonDoFox.paf.exe C:\Users\Michael\AutoRun.exe C:\Users\Michael\setup.exe C:\Users\Michael\Setup_AR.exe Some content of TEMP: ==================== C:\Users\Michael\AppData\Local\Temp\avgnt.exe C:\Users\Michael\AppData\Local\Temp\bassmod.dll C:\Users\Michael\AppData\Local\Temp\Creative Cloud Helper.exe C:\Users\Michael\AppData\Local\Temp\EasyLogin_setup_DE.exe C:\Users\Michael\AppData\Local\Temp\install_flashplayer13x32au_mssa_aaa_aih(1).exe C:\Users\Michael\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Michael\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Michael\AppData\Local\Temp\Offercast_AVIRAV7_.exe C:\Users\Michael\AppData\Local\Temp\photosync_setup_en_212.exe C:\Users\Michael\AppData\Local\Temp\photosync_setup_en_221.exe C:\Users\Michael\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Michael\AppData\Local\Temp\Quarantine.exe C:\Users\Michael\AppData\Local\Temp\repair.exe C:\Users\Michael\AppData\Local\Temp\sqlite3.exe C:\Users\Michael\AppData\Local\Temp\tunesgo_full1368.exe C:\Users\Michael\AppData\Local\Temp\vlc-2.1.4-win64.exe C:\Users\Michael\AppData\Local\Temp\vlc-2.1.5-win64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-10 21:06 ==================== End Of Log ============================ |
12.08.2014, 17:57 | #15 |
| C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werdenCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-08-2014 01 Ran by Michael at 2014-08-12 17:19:42 Running from C:\Users\Michael\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Lavasoft Ad-Aware (Enabled - Up to date) {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Lavasoft Ad-Aware (Enabled - Up to date) {5BB89C30-6480-BC7C-9F17-199BD76F557A} FW: Lavasoft Ad-Aware (Disabled) {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) clear.fi SDK - Video 2 (x32 Version: 2.1.1925 - CyberLink Corp.) Hidden clear.fi SDK- Movie 2 (x32 Version: 2.1.2008 - CyberLink Corp.) Hidden 1&1 EasyLogin (HKLM-x32\...\1&1 EasyLogin) (Version: - ) 1&1 Upload-Manager (HKLM-x32\...\1&1 Upload-Manager) (Version: 2.0.676 - 1&1 Internet AG) 7+ Taskbar Tweaker v4.2.4 (HKCU\...\7 Taskbar Tweaker) (Version: 4.2.4 - RaMMicHaeL) AAVUpdateManager (HKLM-x32\...\{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}) (Version: 18.00.0000 - Wolters Kluwer Deutschland GmbH) ACDSee Pro 6 (HKLM\...\{CAF674E0-808C-4CF4-8868-A755EBABA228}) (Version: 6.1.197 - ACD Systems International Inc.) Acer Backup Manager (HKLM-x32\...\InstallShield_{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}) (Version: 4.0.0.0059 - NTI Corporation) Acer Device Fast-lane (HKLM\...\{3F62D2FD-13C1-49A2-8B5D-47623D9460D7}) (Version: 1.00.3007 - Acer Incorporated) Acer Instant Update Service (HKLM\...\{8215A318-CC27-435E-B3EA-2E3443C8998C}) (Version: 1.00.3013 - Acer Incorporated) Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.3006 - Acer Incorporated) Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.3011 - Acer Incorporated) AcerCloud (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 2.01.3115 - Acer Incorporated) AcerCloud Docs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.00.3201 - Acer Incorporated) Ad-Aware Antivirus (HKLM-x32\...\{944167EA-7F89-4705-8DCD-1D63B53141B0}) (Version: 10.5.3.4405 - Lavasoft) Ad-Aware Browsing Protection (HKLM-x32\...\Ad-Aware Browsing Protection) (Version: 1.0.1.106 - Lavasoft) Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.6 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.2.6 - Adobe Systems Incorporated) Hidden Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Ashampoo Burning Studio 12 v.12.0.5 (HKLM-x32\...\{91B33C97-93EB-244C-F687-71D85E45A206}_is1) (Version: 12.0.5 - Ashampoo GmbH & Co. KG) Ashampoo GetBack Photo v.1.0.1 (HKLM-x32\...\Ashampoo GetBack Photo_is1) (Version: 1.0.1 - Ashampoo GmbH & Co. KG) Ashampoo WinOptimizer 10 v.10.2.0 (HKLM-x32\...\{4209F371-88D4-AB00-ED2B-D6520C84D9D5}_is1) (Version: 10.02.00 - Ashampoo GmbH & Co. KG) Atheros Outlook Addin 2010 (HKCU\...\C74B42DAD40776B5A47FF77AE67D68DC289ADFC1) (Version: 1.0.0.0 - Microsoft) Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team) Avira (HKLM-x32\...\{9590977b-7b6f-467e-a11a-efa1fae804da}) (Version: 1.1.18.30000 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.18.30000 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.6.552 - Avira) Backup Manager v4 (x32 Version: 4.0.0.0059 - NTI Corporation) Hidden Benutzerhandbuch anzeigen (HKLM-x32\...\View User Guide) (Version: 3.60.43.0 - ) Bing Maps 3D (HKLM\...\{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}) (Version: 4.0.903.16005 - Microsoft Corporation) BitLord 2.1 (HKLM-x32\...\BitLord) (Version: 2.1.0-74 - House of Life) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Broadcom Card Reader Driver Installer (HKLM\...\{F0A7DF2F-0BE0-470F-B137-D7A19F977189}) (Version: 15.4.7.1 - Broadcom Corporation) CacheStats (HKLM-x32\...\{85118178-54A5-4107-85A3-F23FD4AD239B}) (Version: 3.0.10 - LogicWeave) calibre 64bit (HKLM\...\{C7530E59-3196-4EFD-A7EE-C0BFD80026BC}) (Version: 1.46.0 - Kovid Goyal) CCleaner (HKLM-x32\...\CCleaner) (Version: 2.32 - Piriform) CheckDrive (HKLM-x32\...\{B83513EC-2E4D-4621-816D-4CCF397BE702}_is1) (Version: 4.4 - Abelssoft) CloneCD (HKLM-x32\...\CloneCD) (Version: - SlySoft) CloneDVD2 (HKLM-x32\...\CloneDVD2) (Version: 2.9.3.0 - Elaborate Bytes) Common Desktop Agent (Version: 1.62.0 - OEM) Hidden Content Manager 2 (HKLM-x32\...\Content Manager 2) (Version: 3.18.0.342250 - NNG Llc.) Cross+A (Deutsch) (HKLM-x32\...\Cross+A (Deutsch)) (Version: 8.28.0.1056 - Sergey Kutasov, Ilya Morozov) CyberLink MediaEspresso 6.5 (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.3103_44819 - CyberLink Corp.) CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3103_44819 - CyberLink Corp.) Hidden Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{043645C8-48EC-458F-B9BD-9C8F15CEF6F7}) (Version: - Microsoft) Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D1C35197-B856-45E2-BA67-5ABB6B0CA9C2}) (Version: - Microsoft) DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.8000.13 - Dolby Laboratories Inc) eBay Worldwide (HKLM-x32\...\{A694AF57-9891-4D62-824C-7E55A1361A14}) (Version: 2.3.0630 - OEM) ETDWare PS/2-X64 11.6.9.001_WHQL (HKLM\...\Elantech) (Version: 11.6.9.001 - ELAN Microelectronic Corp.) Exif-Viewer 2.51 (HKLM-x32\...\Exif-Viewer) (Version: 2.51 - Ralf Bibinger) File Type Advisor 1.4 (HKLM-x32\...\File Type Advisor_is1) (Version: - filetypeadvisor.com) FinePrint (HKLM\...\FinePrint) (Version: 6.25 - FinePrint Software, LLC) Free M4a to MP3 Converter 8.1 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com) Free YouTube Download version 3.2.2.430 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.2.430 - DVDVideoSoft Ltd.) Freizeitkarte_ESP (Ausgabe 14.05) (HKLM-x32\...\Freizeitkarte_ESP) (Version: - ) Garmin BaseCamp (HKLM-x32\...\{CBB4288D-2D32-43BB-8FCE-3F102E385956}) (Version: 4.3.5 - Garmin Ltd or its subsidiaries) Garmin MapSource (HKLM-x32\...\{68C17A81-81E1-458C-8555-3131C4D7A8DF}) (Version: 6.16.1 - Garmin Ltd or its subsidiaries) Garmin TOPO Deutschland v3 (HKLM-x32\...\{AE255C55-E0CF-4591-AA86-CAA19AA32C53}) (Version: 3.0.0.0 - Garmin Ltd or its subsidiaries) Garmin TOPO Österreich v2 (HKLM-x32\...\{7AA38575-25A1-4C2F-B40B-2188EB73FF0E}) (Version: 2.0.0.0 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries) GeoGebra 4.4 (HKLM-x32\...\GeoGebra 4.4) (Version: 4.4.10.0 - International GeoGebra Institute) GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team) GMapTool 0.8.67 (HKLM-x32\...\{1873789F-59D5-4002-8A2F-60A827B78F98}_is1) (Version: - AP) Google Apps Migration For Microsoft Outlook® 2.3.12.34 (HKLM\...\{14379BD8-7185-4C13-92DC-576677F9F8C6}) (Version: 2.3.12.34 - Google, Inc.) Google Drive (HKLM-x32\...\{75939021-3B68-419D-8DC1-E9823BFF9658}) (Version: 1.16.7009.9618 - Google, Inc.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden GSAK 8.4.1.55 (HKLM-x32\...\GSAK_is1) (Version: - CWE computer services) HP Officejet 6500 E710a-f - Grundlegende Software für das Gerät (HKLM\...\{F28BD099-9FC0-4A03-A605-E069B8D17D47}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.) Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.3004 - Acer Incorporated) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3316 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.0.1207 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.36 - Irfan Skiljan) Island-Topo für MapSource (HKLM-x32\...\Island-Topo_is1) (Version: - ) iTunes (HKLM\...\{77DE5105-D05E-448C-96CB-7FA381903753}) (Version: 11.3.1.2 - Apple Inc.) Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) KETTLER WORLD TOURS 2.0.1.22 (HKLM-x32\...\{6efe54e6-5d12-457e-b056-d86f8576b3a7}) (Version: 2.0.1.22 - KETTLER) KETTLER WORLD TOURS 2.0.1.32 (HKLM-x32\...\{4b200421-edfe-402f-b07c-0e8f03351efb}) (Version: 2.0.1.32 - KETTLER) KML-Konverter-Tool 1.607 (HKLM-x32\...\Kml-Konverter-Tool-1607) (Version: - Neumann) KWT Database Utility (HKLM-x32\...\{79eefa84-1157-4a2b-bf8c-8c8af2ddabca}) (Version: 1.0.2.4 - WWS) KWT Database Utility (Version: 1.0.2.4 - WWS) Hidden KWT Video Allgäu (x32 Version: 1.0.0.0 - KETTLER) Hidden Laplink PCmover Professional (HKLM-x32\...\{A519B6CE-9EDF-451A-B626-C3F8D2C9BFC2}) (Version: 8.00.631.0 - Laplink Software, Inc.) Launch Manager (HKLM-x32\...\LManager) (Version: 7.0.5 - Acer Inc.) LifeScan USB Device Driver vSL2.0 (Driver Removal) (HKLM-x32\...\LFSVCOMM&10C4&85A7) (Version: - LifeScan Inc) Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.3004 - Acer Incorporated) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Master Unit (HKLM-x32\...\Master Unit) (Version: - ) Messgerätetreiber für die OneTouch® Software v1.10.0.0 (HKLM-x32\...\InstallShield_{A2C173E1-FB29-4B31-8ED6-CBEE8025E00A}) (Version: 1.10.0.0 - LifeScan) Meter Drivers for OneTouch(R) Software (x32 Version: 1.10.0.0 - LifeScan) Hidden Meter Drivers for OneTouch(R) Software (x32 Version: 1.9.1.0 - LifeScan) Hidden Microsoft Access MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft AutoRoute 2013 (HKLM-x32\...\{C82185E8-C27B-4EF4-2013-3333BC2C2B6D}) (Version: 19.0.21.0500 - Microsoft Corporation) Microsoft DCF MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Excel MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Groove MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft InfoPath MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Lync MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office 32-bit Components 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM UX MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft OneNote MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Outlook MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft PowerPoint MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Publisher MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{86CE1746-9EFF-3C9C-8755-81EA8903AC34}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2005 Tools for Office Runtime (x32 Version: 8.0.60940.0 - Microsoft Corporation) Hidden Microsoft Word MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden MOBackup - Datensicherung für Outlook (Vollversion) (HKLM-x32\...\MOBackup-DatensicherungfürOutlook) (Version: 7.91 - Heiko Schröder) Mobipocket Reader 6.2 (HKLM-x32\...\{342126E1-173C-4585-BFBE-3EBDD20E3E9E}) (Version: 6.2.608 - Mobipocket.com) Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MyWinLocker (Version: 4.0.14.35 - Egis Technology Inc.) Hidden MyWinLocker 4 (x32 Version: 4.0.14.35 - Egis Technology Inc.) Hidden MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.24 - Egis Technology Inc.) MyWinLocker Suite (x32 Version: 4.0.14.24 - Egis Technology Inc.) Hidden Namo WebEditor 8 Testversion (HKLM-x32\...\{25B9FEB3-2E4C-4D66-A3C4-921FAE9A63DA}) (Version: 8.0 - Namo Interactive, Inc.) Naviextras Toolbox Prerequesities (HKLM-x32\...\{537575D6-3B96-474C-BD8F-DFF667363DBD}) (Version: 1.0.0 - NNG Llc.) Nitro Pro 9 (HKLM\...\{00DF846D-B284-4F46-8E6E-D5423C2B5C57}) (Version: 9.0.4.5 - Nitro) Notepad++ (HKLM-x32\...\Notepad++) (Version: 5.8.2 - ) NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9008 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.9008 - NTI Corporation) Hidden NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.157.1165 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Optimus Update 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden NVIDIA Update 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 15.3.33 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.23 (Version: 1.2.23 - NVIDIA Corporation) Hidden Office Addin (HKLM-x32\...\{6D2BBE1D-E600-4695-BA37-0B0E605542CC}) (Version: 2.01.3200 - Acer) Office Addin 2003 (HKLM-x32\...\{1FCC073B-CC01-4443-AD20-E559F66E6E83}) (Version: 2.01.3200 - Acer) OneTouch-Software (HKLM-x32\...\{82FEBE5D-61EC-4365-A213-2B278780945E}) (Version: - ) OpenText (HKLM-x32\...\{A517D5EF-2BEA-4B7A-9691-03EFB97A4C19}) (Version: 1.4.3 - Michael P. Bedesem) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Paragon Festplatten Manager™ 12 Professional (HKLM-x32\...\{1E104AF0-EA49-11DE-AC07-005056C00008}) (Version: 90.00.0003 - Paragon Software) Pflanzen gegen Zombies (HKLM-x32\...\Pflanzen gegen Zombies) (Version: - PopCap Games) PhotoSync (HKLM\...\{7D69D25B-03CD-4FD3-9E05-7069B8CB88F4}) (Version: 2.1.2 - touchbyte GmbH) Picture Resizer 2.0 (HKLM-x32\...\{D1A85247-63B6-4F20-910E-58377D1B7430}_is1) (Version: - Patrik Abend) PixelNet Software 4.12.2 (HKLM-x32\...\PixelNet Software) (Version: 4.12.2 - ORWO Net) PL-2303 USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.3.0 - Prolific Technology INC) POIbase 1.062 (HKLM-x32\...\POIbase_is1) (Version: - POIbase) Polar WebLink 2.4.14 (HKLM-x32\...\{20614F5A-1D52-49AF-BF2B-010A820BA48F}) (Version: 02.49.0005 - Polar Electro Oy) PSR Style Database / Midi Database V4.4 (HKLM-x32\...\PSR Style Database/Midi Database_is1) (Version: - ) PSRUTI (remove only) (HKLM-x32\...\PSRUTI) (Version: - ) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.220 - Qualcomm Atheros Communications) Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 11.41 - Qualcomm Atheros) QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) RCH65 Spoiler Downloader (HKLM-x32\...\{51CE71F2-00FD-4A74-9577-79BC8F2E6E58}) (Version: 1.0.27 - RCH65) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6657 - Realtek Semiconductor Corp.) Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.03.60.00(23.07.2013) - Samsung Electronics Co., Ltd.) Samsung Easy Wireless Setup (HKLM-x32\...\Easy Wireless Setup) (Version: 3.60.47.0 - Samsung Electronics Co., Ltd.) Samsung M2020 Series (HKLM-x32\...\Samsung M2020 Series) (Version: 1.10 (12.02.2014) - Samsung Electronics Co., Ltd.) Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden Sibelius 7.0.0.23 (HKLM\...\Sibelius 7.0.0.23_is1) (Version: 7.0.0.23 - Avid) StarMoney (x32 Version: 4.0.0.203 - StarFinanz) Hidden StarMoney 8.0 (HKLM-x32\...\{69ED1411-962B-4B09-B4A4-E0266203593A}) (Version: 8.0 - Star Finanz GmbH) StarMoney 9.0 (HKLM-x32\...\{4D021042-CA84-4F6F-BE41-D3567E6A7C3A}) (Version: 9.0 - Star Finanz GmbH) Start Menu 8 (HKLM-x32\...\IObit_StartMenu8_is1) (Version: 1.5.0.0 - IObit) Start8 (HKLM-x32\...\{F9FADF71-8E4E-4482-B95C-0F7A9F1B68AF}_is1) (Version: 1.11 - Stardock Corperation) StartIsBack (HKLM-x32\...\StartIsBack) (Version: - startisback.com) Steuer-Spar-Erklärung 2012 (HKLM-x32\...\{CCD2BAD2-0919-40CB-80CC-E9538B0E4C2E}) (Version: 17.11 - Wolters Kluwer Deutschland GmbH) Steuer-Spar-Erklärung 2013 (HKLM-x32\...\{AEB61F7A-4BBA-4292-A096-7893E09034A4}) (Version: 18.09 - Wolters Kluwer Deutschland GmbH) SteuerSparErklärung 2014 (HKLM-x32\...\{A463EB06-22A6-47F5-9593-E52B291EF13E}) (Version: 19.11.90 - Akademische Arbeitsgemeinschaft) System Requirements Lab for Intel (HKLM-x32\...\{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}) (Version: 4.5.13.0 - Husdawg, LLC) Texas Hold'em Poker 3D - Deluxe Edition 1.0 (HKLM-x32\...\{E26DEDC7-1A99-4F8C-9615-6DB112E6495B}_is1) (Version: Texas Hold'em Poker 3D - Deluxe Edition - Play + Smile Marketing GmbH) TOPO Czech 3 PRO (HKLM-x32\...\{4F50C25D-9236-42EE-86A4-F0BC39A543AE}) (Version: 3.00 - Picodas Praha, spol. s r.o.) Topomap Benelux (HKLM-x32\...\{5140C97D-FE5A-41BF-AF03-5C7350B42F7C}) (Version: 1.00 - Garmin Belux - Sailtron) True Image 2013 (HKLM-x32\...\{59F3D2AC-5F1F-4A93-8F23-6FD4F029D9A9}Visible) (Version: 16.0.5551 - Acronis) True Image 2013 (x32 Version: 16.0.5551 - Acronis) Hidden True Image 2013 Plus Pack (HKLM-x32\...\{C408E706-94A7-454C-8B52-538AA6CBD0FB}) (Version: 16.0.5551 - Acronis) Turbo Lister 2 (HKLM-x32\...\{8927E07C-97F7-4A54-88FB-D976F50DD46E}) (Version: 2.00.0000 - eBay Inc.) TV-Browser 3.3.2 (HKLM-x32\...\tvbrowser) (Version: 3.3.2 - TV-Browser Team) Tyros Registration Memory Editor - 1 (HKCU\...\3b826b783ab170b8) (Version: 1.5.9.1 - Tyros Utility) UltraISO Premium V9.53 (HKLM-x32\...\UltraISO_is1) (Version: - ) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{FEF4C57D-0975-4D3C-ACC7-DCD038C3788F}) (Version: - Microsoft) Update for Microsoft Excel 2010 (KB2837600) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{17815BC8-062D-49BE-B40C-B54149C85CE3}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0018-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-001B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{84B191B5-5319-463A-A305-8C4D53B1D20A}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{DB0B0CDF-77EC-47B0-94E2-4738573A1E58}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817396) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{1AA82E2E-7DB7-4C70-910C-BBB657A6B3A5}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2850074) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{CE9A9D7C-B6FB-4F6C-8BDE-9A1ADBBAC1EE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2553092) (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E636FE63-842B-4F4B-9884-DA189ACC0B91}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2553092) (HKLM\...\{90140000-0044-0407-1000-0000000FF1CE}_Office14.PROPLUS_{E636FE63-842B-4F4B-9884-DA189ACC0B91}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825635) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{6E760BBA-B83F-4C2D-918F-5F91EF6C9861}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{90140000-0044-0407-1000-0000000FF1CE}_Office14.PROPLUS_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{D1F3B526-7EB2-4701-92DB-0784988D78DE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837606) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{52BEF8AE-9324-40A1-9A92-E5A8FB63A475}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUS_{8F699D53-05FB-488E-B7D3-E4E47257BE5D}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{324703B5-6765-489D-9B9B-B082D34F882E}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUS_{4B9B2BAF-EE1F-4B60-A4D9-17B7BEEB13A1}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760344) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EF77B4A6-DFEC-4010-A87D-9B6BF87FABEC}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760544) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{62857CDD-2985-4939-91BA-19ED0B0031A5}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2768012) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{0814662C-FD28-4DE0-ACE5-EE50D1D6C8FB}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{E79EFFDB-192A-4D9E-A2DB-C0F774E6EC32}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{E79EFFDB-192A-4D9E-A2DB-C0F774E6EC32}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2826040) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C4AEA56A-0759-4D08-9FAB-31A92137D0B8}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2837644) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D692E9FF-84BF-4F44-A0EA-D58ECE0D538E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863843) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{290D80DE-03AB-47EC-9402-108AF4CE4F66}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880457) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EC2AF602-2730-4B05-9438-06CDE43153F2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880464) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{88B29AA5-71EE-4692-91E2-E89407F0B783}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880478) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8116ED50-F1E7-49E1-9D8D-421497D34B0F}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880987) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6F540E80-4BB2-413F-9648-52031AA237B7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880987) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{6F540E80-4BB2-413F-9648-52031AA237B7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880987) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6F540E80-4BB2-413F-9648-52031AA237B7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0090-0407-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881074) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{9A479F9C-C1EC-4833-A115-A8B7A60480BD}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0407-1000-0000000FF1CE}_Office15.PROPLUS_{00BBBFFE-8889-4953-956A-77DDE975A947}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0409-1000-0000000FF1CE}_Office15.PROPLUS_{3A12DFA2-3FF5-450E-BDB1-A742551A5D1A}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}_Office15.PROPLUS_{EA8072E8-E3CF-46DF-A5DE-9F5975344327}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0410-1000-0000000FF1CE}_Office15.PROPLUS_{BF0D921F-E77E-4E03-BE71-46D9D2C7A36A}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881086) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{ED3A8E98-FDD4-493F-A0EC-141821573EC2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881086) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{ED3A8E98-FDD4-493F-A0EC-141821573EC2}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00BA-0407-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-00A1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{DDDC32A5-9528-4771-B91A-97A8E1D7957B}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-001A-0407-1000-0000000FF1CE}_Office14.PROPLUS_{6164E0E5-C903-488C-93AF-1B7AF7EBC331}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{34A169EC-990A-4DAE-AC65-9F981158B7DB}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 64-Bit Edition (HKLM\...\{90150000-001A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{34A169EC-990A-4DAE-AC65-9F981158B7DB}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A20A650C-F820-4CE4-AEA5-EC140192FAFB}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0018-0407-1000-0000000FF1CE}_Office14.PROPLUS_{FD360122-6829-4497-97C1-1BF578EF695B}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2881075) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C8955821-EDAC-4E65-BEF3-C9C0A049517A}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2881075) 64-Bit Edition (HKLM\...\{90150000-0018-0407-1000-0000000FF1CE}_Office15.PROPLUS_{C8955821-EDAC-4E65-BEF3-C9C0A049517A}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C07147B9-CC0B-4CC1-A107-A705889A54F2}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 64-Bit Edition (HKLM\...\{90150000-0019-0407-1000-0000000FF1CE}_Office15.PROPLUS_{C07147B9-CC0B-4CC1-A107-A705889A54F2}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F6F342A1-530B-4D48-A468-1E3F70928984}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2837587) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{C950A55F-82E3-4CC8-8FA2-E8A2A0F651F3}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2880529) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{89FDC8D9-FB84-4EFE-950D-AF4EECC3B64C}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2878319) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BC51FE30-3A56-4802-8D9E-E9BC05B56B49}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881080) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{F96FE9BB-CD90-472B-852E-156342618C54}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881080) 64-Bit Edition (HKLM\...\{90150000-001A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{F96FE9BB-CD90-472B-852E-156342618C54}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881080) 64-Bit Edition (HKLM\...\{90150000-001B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{F96FE9BB-CD90-472B-852E-156342618C54}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881080) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{F96FE9BB-CD90-472B-852E-156342618C54}) (Version: - Microsoft) Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN) WD Quick View (HKLM-x32\...\{124310E8-7C49-4C33-B4F2-3CF43F3830B7}) (Version: 2.0.1.2 - Western Digital Technologies, Inc.) WD SmartWare (HKLM\...\{DD178D9D-89DD-4F15-9E56-57C85D1EDF36}) (Version: 2.0.1.2 - Western Digital Technologies, Inc.) WD SmartWare Installer (HKLM-x32\...\{bfb9000e-e7d4-490f-a873-ec2c9cab3b3d}) (Version: 2.0.1.2 - Western Digital Technologies, Inc.) Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin) Windows Driver Package - Silicon Laboratories (silabenm) Ports (12/10/2012 6.6.1.0) (HKLM\...\D680DEE0F68D64EC53D0C5769879D15D387054CC) (Version: 12/10/2012 6.6.1.0 - Silicon Laboratories) WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) XnView 2.04 (HKLM-x32\...\XnView_is1) (Version: 2.04 - Gougelet Pierre-e) Your Uninstaller! 7 (HKLM-x32\...\YU2010_is1) (Version: 7.5.2013.2 - URSoft, Inc.) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{1082C812-D727-45CD-A31C-DAAC84FF09D0}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\RTFfilter.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{1701D2CE-B30E-4a76-AC65-25231D7F1529}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\HTMLfilter.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{1C473E52-3450-4A11-9683-EFEFA78B589E}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\EMFFilter.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{36116392-F445-4775-BA72-A90A4B18B4CF}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\PDFImport\PDFImport.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{51044162-9C29-430D-A48B-F0E97325F8E2}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\PPImport.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{5D096382-CEC5-4695-86CD-8C725D4514D2}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\SVGFilter.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{7070ED46-4C64-4D92-9511-0239B25B56E1}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\RAWImport\RAWImport.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{8D3E633C-DC8D-4446-88D5-FA149B562F36}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\PSDFilter.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{CB58FF31-2539-11D0-BDEE-0020AFE14B84}\localserver32 -> C:\PROGRA~1\MAGIX\WEBDES~1\WEBDES~1.EXE No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{CB58FF32-2539-11D0-BDEE-0020AFE14B84}\localserver32 -> C:\PROGRA~1\MAGIX\WEBDES~1\WEBDES~1.EXE No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{CBAA4D0A-9F10-41AF-B61F-2C6241CE8930}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\ODPImport.dll No File CustomCLSID: HKU\S-1-5-21-587935961-2775860875-2407296441-1002_Classes\CLSID\{F0A2F714-AAAB-40F9-AA86-54C74DD28A38}\InprocServer32 -> C:\Program Files\MAGIX\Web Designer 9 Premium\Filters\TIFFImport.dll No File ==================== Restore Points ========================= 24-07-2014 15:21:28 Windows Update 29-07-2014 18:15:28 KETTLER WORLD TOURS 2.0.1.32 05-08-2014 08:07:18 DirectX wurde installiert 10-08-2014 05:10:03 KETTLER WORLD TOURS 2.0 DEMO ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-07-26 07:26 - 2014-05-11 12:30 - 00001168 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 activation.acronis.com 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com 127.0.0.1 na1r.services.adobe.com 127.0.0.1 hlrcv.stage.adobe.com ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {01C2174F-0C01-4A56-B2BD-80874329EAF5} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {09D863F1-9C7B-447E-B232-5C9CAFEBE7B1} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {0AD7725D-3AB6-4C3C-B3E8-DF14CDFE900C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-09] (Google Inc.) Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {0DBC845C-AB33-4307-8534-8797BA5D3714} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {1C4E3FB9-5228-412C-837C-4FA3D9046B07} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {20251B22-540C-4B67-BAF0-C652B58BDEFE} - System32\Tasks\StartMenuAutoupdate => C:\Program Files (x86)\IObit\Start Menu 8\AutoUpdate.exe [2014-06-06] (IObit) Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {27949D9D-ABF9-436E-A568-6B88DBF87C2B} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2012-07-04] (CyberLink) Task: {2B7952E5-022C-4509-8747-24400CED2043} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-07-10] (Microsoft Corporation) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3764ACD2-537D-4A2A-B876-701C956B9C2B} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2012-08-30] () Task: {38F15E6B-D90D-47F6-BAAC-35CC0F28C426} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {3AE1903A-C82E-47BC-A828-CC02EF6A1C1D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-09] (Google Inc.) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {40A2A512-7EFC-491F-9522-0DBD1F61B4E1} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {4A8F5D9D-69E0-4E64-A8B0-066E8926AEB8} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {4D02C09C-7EC1-4366-89F4-A63219B60ED6} - System32\Tasks\iuBrowserIEAgent => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe [2012-08-23] () Task: {5684C451-228C-495B-A04D-4C0C76463363} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {5BBAFF37-BCB3-4604-B881-A930CDAF627A} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {69AC89AD-0274-4668-8047-BEEAA6D194B4} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2012-07-12] (Egis Technology Inc.) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {82B33C67-F329-458D-B9FC-BD1FEDEC1E40} - System32\Tasks\iuEmailOutlookAgent => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe [2012-08-23] () Task: {82EE0DCA-A3FB-4502-9AEE-DD18DC024CFF} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [2012-08-22] (Acer Incorporated) Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {8D71B8DF-2A46-4C7B-90D9-CCFC5BFDBD95} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2012-07-12] (Egis Technology Inc.) Task: {8EDF7391-BE15-4370-B355-5C3530024276} - System32\Tasks\APM_off => C:\hdparm\hdparm.exe Task: {93DBF3D0-A9EF-47B6-915D-705848D179CC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {C1B8B2DB-D4E2-4F80-A1F4-158C8E292165} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe [2013-06-13] (Lavasoft Limited) Task: {C2DE7166-6278-4412-95BB-517B6FFE6079} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe Task: {C3130A3A-D06F-4FF9-9880-0CC78D104382} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {CBCC905B-2F9E-4C65-8190-66BCC485E24D} - System32\Tasks\FileAdvisorCheck => C:\Program Files (x86)\File Type Advisor\file-type-advisor.exe [2013-09-05] (filetypeadvisor.com ) Task: {CDADAF36-53C4-4392-937A-458825AB781A} - System32\Tasks\Western Digital\SmartWare\____Volume_9a21b32e_ee89_47be_9a71_2867908abcfb______Volume_494b1ee2_a5ee_11e2_bec8_b888e3ac2d28__ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [2013-04-22] (Western Digital Technologies, Inc.) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {DDADEDBD-2B56-4634-9D9F-F4CED38F85BA} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2012-06-22] () Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {E85B317E-DAC0-49D6-BCCB-2A3D8A855D36} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-13] (Adobe Systems Incorporated) Task: {FA580E20-87EA-4D5E-A5DD-3A04BEC1E4F9} - System32\Tasks\FileAdvisorUpdate => C:\Program Files (x86)\File Type Advisor\fileadvisor.exe [2013-09-04] (File Type Advisor) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\AutoKMS.job => C:\WINDOWS\AutoKMS\AutoKMS.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-08-05 11:15 - 2014-07-02 22:48 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2014-08-05 11:37 - 2014-07-02 20:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-10-26 11:20 - 2012-09-18 15:27 - 00192512 _____ () C:\WINDOWS\System32\zlhp1020.dll 2014-07-16 10:00 - 2013-12-27 11:33 - 00034304 _____ () C:\WINDOWS\System32\ssj2mlm.dll 2013-10-20 13:05 - 2012-09-18 15:27 - 00065024 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\pphp1020.dll 2013-10-20 13:04 - 2012-09-18 15:27 - 03162624 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\suhp1020.dll 2013-10-20 13:04 - 2012-09-18 15:27 - 01236992 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\gchp1020.dll 2008-10-24 16:35 - 2008-10-24 16:35 - 00128296 _____ () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2013-12-27 20:41 - 2013-12-27 20:41 - 00066872 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2013-12-27 20:41 - 2013-12-27 20:41 - 00107832 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe 2013-07-31 20:22 - 2013-04-10 15:28 - 00885096 _____ () C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe 2013-10-04 00:42 - 2013-10-04 00:42 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-03-09 09:58 - 2012-03-09 09:58 - 00462712 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe 2012-03-09 09:58 - 2012-03-09 09:58 - 00057208 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll 2012-08-23 00:04 - 2012-08-23 00:04 - 00044176 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe 2012-08-23 00:04 - 2012-08-23 00:04 - 00025232 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2014-07-31 08:49 - 2011-01-13 11:44 - 00232800 _____ () C:\Program Files (x86)\StarMoney 9.0\ouservice\PATCHW32.dll 2013-05-15 11:09 - 2014-06-06 13:07 - 00348960 _____ () C:\Program Files (x86)\IObit\Start Menu 8\madExcept_.bpl 2013-05-15 11:09 - 2014-06-06 13:07 - 00183584 _____ () C:\Program Files (x86)\IObit\Start Menu 8\madBasic_.bpl 2013-05-15 11:09 - 2014-06-06 13:07 - 00050976 _____ () C:\Program Files (x86)\IObit\Start Menu 8\madDisAsm_.bpl 2013-10-20 14:04 - 2014-06-06 13:08 - 00041248 _____ () C:\Program Files (x86)\IObit\Start Menu 8\winkey.dll 2013-02-28 13:38 - 2014-06-20 06:08 - 00192376 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libBase64.dll 2013-02-28 13:38 - 2014-06-20 06:08 - 00180088 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libMachoUniv.dll 2013-05-25 19:27 - 2014-08-01 09:27 - 03800688 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-08-05 11:15 - 2014-07-02 22:48 - 00013272 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Windows:EFBA2313AE7FEED3 AlternateDataStreams: C:\ProgramData\Temp:1CE11B51 AlternateDataStreams: C:\ProgramData\Temp:BEACE4C8 AlternateDataStreams: C:\ProgramData\Temp:BF31A799 AlternateDataStreams: C:\ProgramData\Temp:C9633DEB ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: AcrSch2Svc => 2 MSCONFIG\Services: Ad-Aware Service => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: afcdpsrv => 3 MSCONFIG\Services: Apple Mobile Device => 2 MSCONFIG\Services: AtherosSvc => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: BrcmCardReader => 2 MSCONFIG\Services: CCDMonitorService => 2 MSCONFIG\Services: cphs => 3 MSCONFIG\Services: DeviceFastLaneService => 3 MSCONFIG\Services: DsiWMIService => 2 MSCONFIG\Services: EgisTec Ticket Service => 3 MSCONFIG\Services: ePowerSvc => 3 MSCONFIG\Services: ETDService => 2 MSCONFIG\Services: FLEXnet Licensing Service => 3 MSCONFIG\Services: IDriverT => 3 MSCONFIG\Services: Intel(R) Capability Licensing Service Interface => 2 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: jhi_service => 2 MSCONFIG\Services: LMS => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: NitroDriverReadSpool8 => 2 MSCONFIG\Services: nlsX86cc => 2 MSCONFIG\Services: NTI IScheduleSvc => 2 MSCONFIG\Services: nvsvc => 2 MSCONFIG\Services: nvUpdatusService => 3 MSCONFIG\Services: RfButtonDriverService => 2 MSCONFIG\Services: SBAMSvc => 2 MSCONFIG\Services: SDScannerService => 3 MSCONFIG\Services: SDUpdateService => 3 MSCONFIG\Services: SDWSCService => 3 MSCONFIG\Services: Start8 => 2 MSCONFIG\Services: StrartMenuService => 2 MSCONFIG\Services: UNS => 2 MSCONFIG\Services: WDBackup => 2 MSCONFIG\Services: WDDriveService => 2 MSCONFIG\Services: WDRulesService => 2 HKLM\...\StartupApproved\StartupFolder: => "Google Calendar Sync.lnk" HKLM\...\StartupApproved\Run: => "BCSSync" HKLM\...\StartupApproved\Run: => "RtHDVCpl" HKLM\...\StartupApproved\Run: => "ACPW06DE" HKLM\...\StartupApproved\Run: => "SpywareTerminatorShield" HKLM\...\StartupApproved\Run: => "SpywareTerminatorUpdater" HKLM\...\StartupApproved\Run32: => "APSDaemon" HKLM\...\StartupApproved\Run32: => "avgnt" HKLM\...\StartupApproved\Run32: => "Dolby Home Theater v4" HKLM\...\StartupApproved\Run32: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "QuickTime Task" HKLM\...\StartupApproved\Run32: => "BCSSync" HKLM\...\StartupApproved\Run32: => "HP Software Update" HKLM\...\StartupApproved\Run32: => "HTC Sync Loader" HKLM\...\StartupApproved\Run32: => "Ad-Aware Browsing Protection" HKLM\...\StartupApproved\Run32: => "SDTray" HKLM\...\StartupApproved\Run32: => "WD Quick View" HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe" HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKLM\...\StartupApproved\Run32: => "Avira Systray" HKLM\...\StartupApproved\Run32: => "CloneCDTray" HKCU\...\StartupApproved\StartupFolder: => "jAnrufmonitor 5.0.lnk" HKCU\...\StartupApproved\StartupFolder: => "OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk" HKCU\...\StartupApproved\StartupFolder: => "An OneNote senden.lnk" HKCU\...\StartupApproved\Run: => "Password Guard v3" HKCU\...\StartupApproved\Run: => "7 Taskbar Tweaker" HKCU\...\StartupApproved\Run: => "1&1_1&1 Upload-Manager" HKCU\...\StartupApproved\Run: => "Spotify Web Helper" HKCU\...\StartupApproved\Run: => "iCloudServices" HKCU\...\StartupApproved\Run: => "Wondershare Helper Compact" ==================== Faulty Device Manager Devices ============= Name: AVM USB-Fernanschluss Description: AVM USB-Fernanschluss Class Guid: {59e75f1d-160e-4aba-bb5c-1c179b8e9b7a} Manufacturer: AVM Berlin Service: avmaura Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: AVM USB-Fernanschluss Description: AVM USB-Fernanschluss Class Guid: {59e75f1d-160e-4aba-bb5c-1c179b8e9b7a} Manufacturer: AVM Berlin Service: avmaura Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver ==================== Event log errors: ========================= Application errors: ================== Error: (08/11/2014 07:15:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Avira.OE.ServiceHost.exe, Version: 1.1.18.30000, Zeitstempel: 0x53d0d678 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.3.9600.17055, Zeitstempel: 0x532943a3 Ausnahmecode: 0xe0434352 Fehleroffset: 0x00011d4d ID des fehlerhaften Prozesses: 0x12b8 Startzeit der fehlerhaften Anwendung: 0xAvira.OE.ServiceHost.exe0 Pfad der fehlerhaften Anwendung: Avira.OE.ServiceHost.exe1 Pfad des fehlerhaften Moduls: Avira.OE.ServiceHost.exe2 Berichtskennung: Avira.OE.ServiceHost.exe3 Vollständiger Name des fehlerhaften Pakets: Avira.OE.ServiceHost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Avira.OE.ServiceHost.exe5 Error: (08/11/2014 07:15:23 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(CatalogPart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetCastedExportedValue[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/11/2014 07:15:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Avira.OE.ServiceHost.exe, Version: 1.1.18.30000, Zeitstempel: 0x53d0d678 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.3.9600.17055, Zeitstempel: 0x532943a3 Ausnahmecode: 0xe0434352 Fehleroffset: 0x00011d4d ID des fehlerhaften Prozesses: 0x1360 Startzeit der fehlerhaften Anwendung: 0xAvira.OE.ServiceHost.exe0 Pfad der fehlerhaften Anwendung: Avira.OE.ServiceHost.exe1 Pfad des fehlerhaften Moduls: Avira.OE.ServiceHost.exe2 Berichtskennung: Avira.OE.ServiceHost.exe3 Vollständiger Name des fehlerhaften Pakets: Avira.OE.ServiceHost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Avira.OE.ServiceHost.exe5 Error: (08/11/2014 07:15:12 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(CatalogPart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetCastedExportedValue[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/11/2014 07:14:56 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: rdyboost4 Error: (08/11/2014 07:14:50 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll4 Error: (08/11/2014 07:14:32 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Avira.OE.ServiceHost.exe, Version: 1.1.18.30000, Zeitstempel: 0x53d0d678 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.3.9600.17055, Zeitstempel: 0x532943a3 Ausnahmecode: 0xe0434352 Fehleroffset: 0x00011d4d ID des fehlerhaften Prozesses: 0x5a8 Startzeit der fehlerhaften Anwendung: 0xAvira.OE.ServiceHost.exe0 Pfad der fehlerhaften Anwendung: Avira.OE.ServiceHost.exe1 Pfad des fehlerhaften Moduls: Avira.OE.ServiceHost.exe2 Berichtskennung: Avira.OE.ServiceHost.exe3 Vollständiger Name des fehlerhaften Pakets: Avira.OE.ServiceHost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Avira.OE.ServiceHost.exe5 Error: (08/11/2014 07:14:26 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(CatalogPart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetCastedExportedValue[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/11/2014 07:04:16 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Client application bug: DNSServiceResolve(90:b9:31:38:9e:aa@fe80::92b9:31ff:fe38:9eaa._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network. Error: (08/11/2014 07:01:16 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 24 System errors: ============= Error: (08/11/2014 07:15:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. Error: (08/11/2014 07:15:12 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/11/2014 07:14:59 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (08/11/2014 07:14:33 PM) (Source: DCOM) (EventID: 10016) (User: MichiLaptop) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}MichiLaptopMichaelS-1-5-21-587935961-2775860875-2407296441-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (08/11/2014 07:14:33 PM) (Source: DCOM) (EventID: 10016) (User: MichiLaptop) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}MichiLaptopMichaelS-1-5-21-587935961-2775860875-2407296441-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (08/11/2014 07:14:33 PM) (Source: DCOM) (EventID: 10016) (User: MichiLaptop) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}MichiLaptopMichaelS-1-5-21-587935961-2775860875-2407296441-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (08/11/2014 07:14:33 PM) (Source: DCOM) (EventID: 10016) (User: MichiLaptop) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}MichiLaptopMichaelS-1-5-21-587935961-2775860875-2407296441-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (08/11/2014 07:12:38 PM) (Source: avmaura) (EventID: 4012) (User: ) Description: AURA Error: (08/11/2014 07:12:38 PM) (Source: avmaura) (EventID: 4012) (User: ) Description: AURA Error: (08/10/2014 09:07:56 PM) (Source: DCOM) (EventID: 10010) (User: MichiLaptop) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Microsoft Office Sessions: ========================= Error: (08/11/2014 07:15:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Avira.OE.ServiceHost.exe1.1.18.3000053d0d678KERNELBASE.dll6.3.9600.17055532943a3e043435200011d4d12b801cfb587d5a2c226C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exeC:\WINDOWS\SYSTEM32\KERNELBASE.dll13b378b9-217b-11e4-bf78-b888e3ac2d28 Error: (08/11/2014 07:15:23 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(CatalogPart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetCastedExportedValue[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/11/2014 07:15:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Avira.OE.ServiceHost.exe1.1.18.3000053d0d678KERNELBASE.dll6.3.9600.17055532943a3e043435200011d4d136001cfb587cdff8140C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exeC:\WINDOWS\SYSTEM32\KERNELBASE.dll0d4d5200-217b-11e4-bf78-b888e3ac2d28 Error: (08/11/2014 07:15:12 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(CatalogPart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetCastedExportedValue[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/11/2014 07:14:56 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: rdyboost4 Error: (08/11/2014 07:14:50 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll4 Error: (08/11/2014 07:14:32 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Avira.OE.ServiceHost.exe1.1.18.3000053d0d678KERNELBASE.dll6.3.9600.17055532943a3e043435200011d4d5a801cfb587ab47020dC:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exeC:\WINDOWS\SYSTEM32\KERNELBASE.dllf53db32b-217a-11e4-bf78-b888e3ac2d28 Error: (08/11/2014 07:14:26 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(CatalogPart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetCastedExportedValue[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/11/2014 07:04:16 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Client application bug: DNSServiceResolve(90:b9:31:38:9e:aa@fe80::92b9:31ff:fe38:9eaa._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network. Error: (08/11/2014 07:01:16 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 24 CodeIntegrity Errors: =================================== Date: 2014-03-14 13:56:03.164 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:51.743 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:51.527 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:51.413 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.759 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.622 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.478 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.349 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.216 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-14 13:55:50.126 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Percentage of memory in use: 26% Total physical RAM: 8007.27 MB Available physical RAM: 5881.98 MB Total Pagefile: 10507.27 MB Available Pagefile: 7399.25 MB Total Virtual: 131072 MB Available Virtual: 131071.83 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:678.85 GB) (Free:206.97 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 699 GB) (Disk ID: 821BE156) Partition: GPT Partition Type. ==================== End Of Log ============================ |
Themen zu C:\Windows\System32\cmd. exe Fehlermeldung bat=exe konnte nicht gefunden werden |
anhang, bat, bräuchte, c:\windows, exe, fehlermeldung, gefunde, hilfe, js/toolbar.crossrider.b, konnte, pup.optional.adpeak, pup.optional.adpeak.a, pup.optional.babylon.a, pup.optional.downtango.a, pup.optional.hometab.a, pup.optional.systemspeedup, system, system32, win32/downloadsponsor.a, win32/sprotector.e, win32/toolbar.conduit, win32/toolbar.visicom.a, win32/toolbar.visicom.b, win32/toolbar.visicom.c, windows |