|
Plagegeister aller Art und deren Bekämpfung: lenovo g700 surkfeepita und winspeed deinstallierenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
04.09.2014, 21:20 | #1 |
| lenovo g700 surkfeepita und winspeed deinstallieren Ich hier ein Lenovo g700 Notebook mit Windows 8 und emsisoft Schutz. Jetzt habe ich bemerkt, dass ich bei Google immer automatisch Werbung von surkfeepita bekomme. Habe dies bei meinen Programmen deinstalliert. Trotzdem kommt die Werbeeinschaltung. Auch habe ich bei meinen Programmen ein Programm winspeed entdeckt, dass sich nicht deinstallieren lässt. Hoffe da kann mir jemand weiterhelfen, wie ich dies deinstallieren kann, bzw. wie dies auch mit emsisoft passieren konnte. Meine Firewall Amor läuft immer im Lernmodus, sonst gehen keine Updates von Windows 8 Vielen Dank |
04.09.2014, 22:21 | #2 |
/// TB-Ausbilder | lenovo g700 surkfeepita und winspeed deinstallieren Hallo !
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
04.09.2014, 22:55 | #3 |
| lenovo g700 surkfeepita und winspeed deinstallieren Danke für die Antwort:
__________________Hier die Ergebnisse der Dateien FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2014 02 Ran by harald (administrator) on LAPTOP on 04-09-2014 23:50:50 Running from C:\Users\harald\Downloads\x Platform: Windows 8.1 Enterprise (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (Emsisoft GmbH) C:\Program Files (x86)\Online Armor\oacat.exe (Emsisoft GmbH) C:\Program Files (x86)\Online Armor\oasrv.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files (x86)\TrialReset\TrialReset.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (MAFIA) C:\Program Files\LicenseProxy\LicenseProxy.exe (Emsisoft GmbH) C:\Program Files (x86)\Online Armor\oaui.exe (Emsisoft GmbH) C:\Program Files (x86)\Online Armor\oahlp.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2014-07-22] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2014-07-22] (Lenovo(beijing) Limited) HKLM\...\Run: [LicenseProxy] => C:\Program Files\LicenseProxy\LicenseProxy.exe [298496 2013-06-28] (MAFIA) HKLM\...\Run: [@OnlineArmor GUI] => C:\Program Files (x86)\Online Armor\oaui.exe [7558464 2013-10-11] (Emsisoft GmbH) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2777840 2013-08-14] (Synaptics Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation) HKLM-x32\...\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft anti-malware\a2guard.exe [4857256 2014-08-14] (Emsisoft GmbH) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3477640 2012-09-23] (Adobe Systems Inc.) HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [273544 2014-08-28] (RealNetworks, Inc.) AppInit_DLLs: C:\PROGRA~3\WinSpeed\WINSPE~1.DLL => C:\ProgramData\WinSpeed\WinSpeed_x64.dll [4304896 2014-08-20] () AppInit_DLLs-x32: c:\programdata\winspeed\winspeed.dll => "c:\programdata\winspeed\winspeed.dll" File Not Found ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.at/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.at.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x45052BA204A5CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKCU - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: surfkeePita -> {AAEB3734-F79C-B310-1448-14ECC679F6D9} -> C:\ProgramData\surfkeePita\UZaFWpjX.x64.dll () BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: surfkeePita -> {AAEB3734-F79C-B310-1448-14ECC679F6D9} -> C:\ProgramData\surfkeePita\UZaFWpjX.dll () BHO-x32: Adobe Acrobat Create PDF Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.138 FireFox: ======== FF ProfilePath: C:\Users\harald\AppData\Roaming\Mozilla\Firefox\Profiles\x9wwz94a.default FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=12.0.1.647 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprjplug;version=12.0.1.647 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=12.0.1.652 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprphtml5videoshim;version=12.0.1.652 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpjplug;version=12.0.1.647 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DeAl2dEaliT - C:\Users\harald\AppData\Roaming\Mozilla\Firefox\Profiles\x9wwz94a.default\Extensions\ftq9nau@pdd-yrbt.net [2014-08-21] FF Extension: suaRFkeePit - C:\Users\harald\AppData\Roaming\Mozilla\Firefox\Profiles\x9wwz94a.default\Extensions\o6yaua@owmn.net [2014-09-03] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-08-18] FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2014-08-28] FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2012-09-23] CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2014-08-28] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4754256 2014-08-14] (Emsisoft GmbH) S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-08-08] (Broadcom Corporation.) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-21] (Intel Corporation) S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation) S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation) S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation) R2 OAcat; C:\Program Files (x86)\Online Armor\OAcat.exe [584864 2013-10-11] (Emsisoft GmbH) R2 PSI_SVC_2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (arvato digital services llc) S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation) S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation) R2 SvcOnlineArmor; C:\Program Files (x86)\Online Armor\oasrv.exe [4457688 2013-10-11] (Emsisoft GmbH) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) R2 AutoTrialReset; C:\Program Files (x86)\TrialReset\TrialReset -runservice [X] S2 f1f78e38; "C:\Windows\system32\rundll32.exe" "c:\programdata\winspeed\winspeedSvc.dll",service ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH) R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH) R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH) R1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [23088 2014-05-12] (Emsisoft GmbH) R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-08-08] (Broadcom Corporation.) R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation) R1 OADevice; C:\Windows\SysWow64\Drivers\OADriver.sys [64720 2013-10-11] () R1 oahlpXX; C:\Windows\syswow64\drivers\oahlp64.sys [62008 2013-10-11] () R1 OAmon; C:\Windows\SysWOW64\Drivers\OAmon.sys [52360 2013-10-11] (Emsisoft) R3 OAnet; C:\Windows\system32\DRIVERS\oanet.sys [35368 2013-10-11] (Emsisoft) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-14] (Synaptics Incorporated) S3 usbrndis6; C:\Windows\System32\drivers\usb80236.sys [20992 2013-08-22] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-04 23:50 - 2014-09-04 23:50 - 00000000 ____D () C:\FRST 2014-09-04 23:38 - 2014-09-04 23:50 - 00000000 ____D () C:\Users\harald\Downloads\x 2014-09-03 19:21 - 2014-09-03 19:21 - 00000000 ____D () C:\ProgramData\surfkeePita 2014-08-28 00:47 - 2014-08-28 00:47 - 00003338 _____ () C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4162614285-2887739644-64261045-1001 2014-08-28 00:47 - 2014-08-28 00:47 - 00003282 _____ () C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4162614285-2887739644-64261045-1001 2014-08-28 00:45 - 2014-08-28 00:45 - 00001964 _____ () C:\Users\Public\Desktop\Kostenlose Angebote.lnk 2014-08-28 00:45 - 2014-08-28 00:45 - 00001370 _____ () C:\Users\Public\Desktop\RealPlayer.lnk 2014-08-28 00:44 - 2014-08-28 00:47 - 00000000 ____D () C:\ProgramData\Real 2014-08-28 00:44 - 2014-08-28 00:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real 2014-08-28 00:44 - 2014-08-28 00:45 - 00000000 ____D () C:\Program Files (x86)\Real 2014-08-28 00:44 - 2014-08-28 00:44 - 00272896 _____ (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll 2014-08-28 00:44 - 2014-08-28 00:44 - 00198848 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll 2014-08-28 00:44 - 2014-08-28 00:44 - 00006656 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll 2014-08-28 00:44 - 2014-08-28 00:44 - 00005632 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll 2014-08-28 00:04 - 2014-08-28 00:54 - 00000000 ____D () C:\Users\harald\AppData\Roaming\Real 2014-08-27 22:42 - 2014-08-23 02:42 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf 2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf 2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____D () C:\Program Files\Synaptics 2014-08-27 18:20 - 2014-08-27 18:22 - 00001404 _____ () C:\Windows\Synaptics.log 2014-08-27 18:20 - 2013-08-14 15:01 - 00722160 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll 2014-08-27 18:20 - 2013-08-14 15:01 - 00527600 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys 2014-08-27 18:20 - 2013-08-14 15:01 - 00421616 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo19.dll 2014-08-27 18:20 - 2013-08-14 15:01 - 00400112 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCom.dll 2014-08-27 18:20 - 2013-08-14 15:01 - 00251632 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2014-08-27 18:20 - 2013-08-14 15:01 - 00169712 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynTPCom.dll 2014-08-27 18:20 - 2013-08-14 15:01 - 00034544 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\Smb_driver_Intel.sys 2014-08-27 00:29 - 2014-08-27 00:30 - 00000000 ____D () C:\ProgramData\Protexis 2014-08-27 00:27 - 2014-08-27 00:26 - 00002467 _____ () C:\Users\Public\Desktop\Bitstream Font Navigator.lnk 2014-08-27 00:27 - 2014-08-27 00:24 - 00002847 _____ () C:\Users\Public\Desktop\Corel PHOTO-PAINT X7.lnk 2014-08-27 00:27 - 2014-08-27 00:24 - 00002840 _____ () C:\Users\Public\Desktop\Corel CAPTURE X7.lnk 2014-08-27 00:27 - 2014-08-27 00:24 - 00002371 _____ () C:\Users\Public\Desktop\Corel CONNECT X7.lnk 2014-08-27 00:27 - 2014-08-27 00:23 - 00002799 _____ () C:\Users\Public\Desktop\CorelDRAW X7.lnk 2014-08-27 00:24 - 2014-08-27 00:24 - 00000000 ____D () C:\Users\Public\Documents\Corel 2014-08-27 00:23 - 2014-08-27 00:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 2014-08-27 00:22 - 2014-09-04 00:44 - 00000000 ____D () C:\ProgramData\Corel 2014-08-27 00:22 - 2014-08-27 00:23 - 00000000 ____D () C:\Program Files (x86)\Corel 2014-08-27 00:13 - 2014-08-27 00:31 - 00000000 ____D () C:\ProgramData\CorelDRAW Graphics Suite X7 2014-08-26 23:46 - 2014-08-26 23:46 - 00000000 ____D () C:\Users\harald\Documents\Meine Paletten 2014-08-26 23:45 - 2014-08-26 23:45 - 00000000 ____D () C:\Users\harald\Documents\Corel 2014-08-26 23:43 - 2014-08-27 00:30 - 00000000 ____D () C:\Users\harald\AppData\Roaming\Corel 2014-08-26 23:43 - 2014-08-26 23:43 - 00000000 ____D () C:\ProgramData\Protexis64 2014-08-26 23:39 - 2014-08-26 23:39 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-26 23:37 - 2014-08-26 23:37 - 00000000 ____D () C:\Program Files\Common Files\Protexis 2014-08-26 23:23 - 2014-08-26 23:44 - 00000000 ____D () C:\ProgramData\CorelDRAW Graphics Suite X7 x64 2014-08-26 22:40 - 2014-08-26 22:40 - 00000000 _____ () C:\Windows\longfile.INI 2014-08-26 22:39 - 2014-08-26 22:39 - 00008198 _____ () C:\Windows\WT61US.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61UK.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61SD.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61OZ.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61KR.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61DE.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61CE.UWL 2014-08-26 22:39 - 1996-04-11 17:34 - 00965904 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSJT3032.DLL 2014-08-26 22:39 - 1996-03-15 18:47 - 00098356 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSJTER32.DLL 2014-08-26 22:39 - 1996-03-15 18:15 - 00033552 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSJINT32.DLL 2014-08-26 22:39 - 1995-09-24 11:02 - 00243472 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBAR2232.DLL 2014-08-26 22:39 - 1995-09-20 17:16 - 00245520 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSRD2X32.DLL 2014-08-26 22:39 - 1995-08-15 01:00 - 00144144 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSLT3032.DLL 2014-08-26 22:39 - 1995-08-07 06:33 - 00043008 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSOC95.DLL 2014-08-26 22:39 - 1995-07-20 01:00 - 01371436 ____R () C:\Windows\SysWOW64\VBAR2132.DLL 2014-08-26 22:39 - 1995-07-20 01:00 - 00816720 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBA32.DLL 2014-08-26 22:39 - 1995-07-20 01:00 - 00240912 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSPX3032.DLL 2014-08-26 22:39 - 1995-07-20 01:00 - 00220944 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSXL3032.DLL 2014-08-26 22:39 - 1995-07-20 01:00 - 00121104 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSTX3032.DLL 2014-08-26 22:39 - 1995-07-20 01:00 - 00025564 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBAEN32.OLB 2014-08-26 22:39 - 1995-07-20 01:00 - 00008976 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBAEN32.DLL 2014-08-26 22:39 - 1995-07-11 10:50 - 00398416 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBRUN300.DLL 2014-08-26 22:39 - 1995-06-15 01:00 - 00037376 ____R () C:\Windows\SysWOW64\VEN2132.OLB 2014-08-26 22:39 - 1995-05-12 01:00 - 00260368 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSXB3032.DLL 2014-08-26 22:39 - 1994-04-13 00:00 - 00095200 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBDB300.DLL 2014-08-26 22:39 - 1993-04-28 01:00 - 00013824 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBOA300.DLL 2014-08-26 22:37 - 1996-11-25 23:28 - 00345600 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\qtim32.dll 2014-08-26 22:37 - 1996-11-25 23:28 - 00229376 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\rpza32.qtc 2014-08-26 22:37 - 1996-11-25 23:28 - 00165888 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\smc32.qtc 2014-08-26 22:37 - 1996-11-25 23:28 - 00151040 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\cvid32.qtc 2014-08-26 22:37 - 1996-11-25 23:28 - 00128000 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\mc32.qtc 2014-08-26 22:37 - 1996-11-25 23:28 - 00103936 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\rle32.qtc 2014-08-26 22:37 - 1996-11-25 23:28 - 00083456 ____N (Intel(R) Corporation) C:\Windows\SysWOW64\iv32qt32.qtc 2014-08-26 22:37 - 1996-11-25 23:28 - 00038912 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\dhio32.qtc 2014-08-26 22:37 - 1996-11-25 23:28 - 00035840 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\navg32.qtc 2014-08-26 22:37 - 1996-11-25 23:28 - 00034816 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\jpeg32.qtc 2014-08-26 22:37 - 1996-11-25 23:28 - 00032768 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\cmgr32.dll 2014-08-26 22:37 - 1996-11-25 23:28 - 00024064 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\dci32.qtc 2014-08-26 22:37 - 1996-11-25 23:28 - 00020480 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\raw32.qtc 2014-08-26 22:36 - 1996-11-25 23:31 - 00088916 ____N () C:\Windows\twain.dll 2014-08-26 22:36 - 1996-10-29 23:01 - 00409600 ____N (Corel Corporation) C:\Windows\SysWOW64\scint70.dll 2014-08-26 22:36 - 1996-09-24 12:54 - 00033280 ____N () C:\Windows\SysWOW64\picbuttn.ocx 2014-08-26 22:36 - 1996-06-04 23:51 - 00721168 ____N (Microsoft Corporation) C:\Windows\SysWOW64\vb40032.dll 2014-08-26 22:36 - 1996-06-04 23:51 - 00330752 ____N (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.ocx 2014-08-26 22:36 - 1995-11-07 09:57 - 00006144 ____N (Corel Corporation) C:\Windows\SysWOW64\Drivers\crlscsi.sys 2014-08-26 22:36 - 1995-10-18 14:46 - 00000142 ____N () C:\Windows\SysWOW64\scanners.reg 2014-08-26 22:36 - 1995-09-15 11:51 - 00069632 ____N (Twain Working Group) C:\Windows\twunk_32.exe 2014-08-26 22:36 - 1995-09-15 11:51 - 00048560 ____N (Twain Working Group) C:\Windows\twunk_16.exe 2014-08-26 22:36 - 1995-08-15 01:00 - 00136704 ____N (Apex Software Corporation) C:\Windows\SysWOW64\grdkrn32.dll 2014-08-26 22:36 - 1995-07-26 01:00 - 00288256 ____N (Apex Software Corporation) C:\Windows\SysWOW64\dbgrid32.ocx 2014-08-26 22:36 - 1995-07-26 01:00 - 00263680 ____N (Microsoft Corporation) C:\Windows\SysWOW64\msrdo32.dll 2014-08-26 22:36 - 1995-07-26 01:00 - 00200704 ____N (Sheridan Software Systems, Inc.) C:\Windows\SysWOW64\threed32.ocx 2014-08-26 22:36 - 1995-07-26 01:00 - 00141824 ____N (Microsoft Corporation) C:\Windows\SysWOW64\dblist32.ocx 2014-08-26 22:36 - 1995-07-26 01:00 - 00136192 ____N (Microsoft Corporation) C:\Windows\SysWOW64\msrdc32.ocx 2014-08-26 22:36 - 1995-07-26 01:00 - 00129024 ____N (Sheridan Software Systems, Inc.) C:\Windows\SysWOW64\tabctl32.ocx 2014-08-26 22:36 - 1995-07-26 01:00 - 00081408 ____N (Microsoft Corporation) C:\Windows\SysWOW64\richtx32.ocx 2014-08-26 22:36 - 1995-05-22 14:05 - 00108032 ____N (Microsoft Corporation) C:\Windows\SysWOW64\mfcuia32.dll 2014-08-26 22:36 - 1995-05-19 15:44 - 00322832 ____N (Microsoft Corporation) C:\Windows\SysWOW64\mfc30.dll 2014-08-26 22:36 - 1995-05-19 14:49 - 00133904 ____N (Microsoft Corporation) C:\Windows\SysWOW64\mfcans32.dll 2014-08-26 22:35 - 2014-08-26 23:52 - 00000000 ____D () C:\Windows\COREL 2014-08-26 22:35 - 2014-08-26 22:35 - 00000000 ____D () C:\Corel 2014-08-23 19:15 - 2014-08-23 19:15 - 00001181 _____ () C:\Users\tn\Documents\info.dat 2014-08-23 19:15 - 2012-05-30 21:31 - 00024576 _____ (Hochl-it) C:\Users\tn\Documents\info.exe 2014-08-23 15:13 - 2014-08-23 15:13 - 00000000 ____D () C:\Program Files (x86)\deal2ddealit 2014-08-23 14:53 - 2014-08-25 21:37 - 02482176 _____ () C:\Users\tn\Documents\kassa.accdb 2014-08-23 14:52 - 2014-08-23 14:53 - 00000000 ____D () C:\Users\tn 2014-08-23 13:08 - 2014-08-23 13:08 - 06052529 _____ (Tim Kosse) C:\Users\harald\Downloads\FileZilla_3.9.0.3_win32-setup.exe 2014-08-21 21:18 - 2014-09-03 19:21 - 00000000 ____D () C:\ProgramData\5940d185bd756d33 2014-08-21 21:18 - 2014-08-23 15:13 - 00000000 ____D () C:\ProgramData\deal2ddealit 2014-08-21 21:04 - 2014-08-23 12:36 - 00000940 _____ () C:\EamClean.log 2014-08-20 06:22 - 2014-08-21 21:04 - 00000000 ____D () C:\ProgramData\WinSpeed 2014-08-18 20:31 - 2014-08-18 20:31 - 00000000 ____D () C:\Users\harald\AppData\Local\PDF Writer 2014-08-18 20:24 - 2014-08-18 20:24 - 00000000 ____D () C:\Users\harald\AppData\Roaming\PDF Writer 2014-08-18 20:24 - 2012-11-05 11:02 - 00218624 _____ (Bullzip) C:\Windows\system32\bzpdf.dll 2014-08-18 20:13 - 2014-08-18 20:15 - 00000000 ____D () C:\ProgramData\PDF Writer 2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip 2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\Program Files\Common Files\Bullzip 2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\Program Files\Bullzip 2014-08-18 20:13 - 2014-08-01 20:29 - 00147456 _____ (Bullzip) C:\Windows\SysWOW64\bzpdfc.dll 2014-08-18 20:13 - 2013-09-01 12:59 - 01103872 _____ () C:\Windows\SysWOW64\CBLCtlsU.ocx 2014-08-18 20:13 - 2013-07-13 12:15 - 00805376 _____ () C:\Windows\SysWOW64\EditCtlsU.ocx 2014-08-18 20:13 - 2013-07-12 22:57 - 00539648 _____ () C:\Windows\SysWOW64\LblCtlsU.ocx 2014-08-18 20:13 - 2013-04-05 13:55 - 00476160 _____ () C:\Windows\SysWOW64\TabStripCtlU.ocx 2014-08-18 20:13 - 2013-03-28 23:13 - 00645632 _____ () C:\Windows\SysWOW64\BtnCtlsU.ocx 2014-08-18 20:13 - 2013-03-03 14:37 - 01061888 _____ () C:\Windows\SysWOW64\ExLvwU.ocx 2014-08-18 20:13 - 2008-10-30 20:29 - 00227840 _____ (Bullzip) C:\Windows\SysWOW64\bzFlRdr.dll 2014-08-18 20:13 - 2008-07-09 20:29 - 00103424 _____ (Bullzip) C:\Windows\SysWOW64\bzDCT.dll 2014-08-18 20:13 - 1999-05-07 00:00 - 00140288 ____N (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.OCX 2014-08-18 16:36 - 2014-08-18 16:57 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-08-18 16:34 - 2014-08-18 16:57 - 00000000 ____D () C:\Users\harald\AppData\Local\Adobe 2014-08-18 16:33 - 2014-08-18 16:33 - 00002469 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk 2014-08-18 16:33 - 2014-08-18 16:33 - 00002230 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk 2014-08-18 16:33 - 2014-08-18 16:33 - 00002160 _____ () C:\Users\Public\Desktop\Adobe FormsCentral.lnk 2014-08-18 16:33 - 2014-08-18 16:33 - 00002069 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk 2014-08-18 16:33 - 2014-08-18 16:33 - 00002046 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk 2014-08-18 16:30 - 2014-08-18 16:57 - 00000000 ____D () C:\ProgramData\Adobe 2014-08-18 16:30 - 2014-08-18 16:30 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-08-18 16:25 - 2014-08-18 16:28 - 00000000 ____D () C:\Users\harald\Desktop\Adobe Acrobat XI 2014-08-18 15:58 - 2014-08-02 05:11 - 00918528 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll 2014-08-18 15:56 - 2014-08-07 00:38 - 00697856 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-18 15:56 - 2014-08-02 07:44 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-18 15:56 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-18 15:56 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-18 15:56 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-18 15:56 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-18 15:56 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-18 15:56 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-18 15:56 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-18 15:56 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-18 15:56 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-18 15:56 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-18 15:56 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-18 15:56 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-18 15:56 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-18 15:56 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-18 15:56 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-18 15:56 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-18 15:56 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-18 15:56 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-18 15:56 - 2014-07-25 13:43 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-18 15:56 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-18 15:56 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-18 15:56 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-18 15:56 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-18 15:56 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-18 15:56 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-18 15:56 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-18 15:56 - 2014-07-25 13:09 - 00291840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-18 15:56 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-18 15:56 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-18 15:56 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-18 15:56 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-18 15:56 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-18 15:56 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-18 15:56 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-18 15:56 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-18 15:56 - 2014-07-15 20:16 - 03048880 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe 2014-08-18 15:56 - 2014-07-15 10:29 - 03118080 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2014-08-18 15:56 - 2014-07-15 10:22 - 02861056 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll 2014-08-18 15:56 - 2014-07-15 10:03 - 02344448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2014-08-18 15:56 - 2014-07-12 06:17 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe 2014-08-18 15:56 - 2014-06-20 03:48 - 01273184 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-18 15:56 - 2014-06-20 01:52 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-18 15:56 - 2014-06-13 03:15 - 00517528 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2014-08-18 15:56 - 2014-06-13 03:14 - 01557848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-18 15:56 - 2014-06-13 02:10 - 00406400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2014-08-18 15:56 - 2014-06-06 13:34 - 02133504 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2014-08-18 15:52 - 2014-08-07 04:12 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-18 15:52 - 2014-08-02 05:56 - 01064448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-15 10:45 - 2014-08-15 10:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF 2014-08-15 10:45 - 2014-08-15 10:45 - 00000000 ____D () C:\Program Files (x86)\Acro Software 2014-08-15 10:45 - 2009-11-05 08:40 - 00085504 _____ () C:\Windows\system32\cpwmon64.dll 2014-08-15 10:35 - 2014-06-04 11:27 - 00114520 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-15 10:35 - 2014-06-04 07:31 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-15 10:35 - 2014-06-04 07:22 - 02790912 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-15 10:35 - 2014-06-04 06:43 - 00281088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-15 10:35 - 2014-06-04 06:38 - 03304448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-15 10:35 - 2014-06-04 04:15 - 02642944 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-15 10:35 - 2014-06-04 04:14 - 02318336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-04 23:50 - 2014-09-04 23:50 - 00000000 ____D () C:\FRST 2014-09-04 23:50 - 2014-09-04 23:38 - 00000000 ____D () C:\Users\harald\Downloads\x 2014-09-04 23:06 - 2014-06-23 10:32 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware 2014-09-04 23:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru 2014-09-04 22:15 - 2013-09-30 06:14 - 01686150 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-04 22:15 - 2013-09-30 05:58 - 00727930 _____ () C:\Windows\system32\perfh007.dat 2014-09-04 22:15 - 2013-09-30 05:58 - 00151586 _____ () C:\Windows\system32\perfc007.dat 2014-09-04 22:10 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-04 21:31 - 2014-07-30 22:55 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2014-09-04 21:27 - 2014-06-22 15:14 - 01264886 _____ () C:\Windows\WindowsUpdate.log 2014-09-04 21:02 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-09-04 15:34 - 2014-06-22 15:14 - 00000000 ____D () C:\Users\harald\AppData\Local\Packages 2014-09-04 11:15 - 2014-07-08 14:33 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{DC4EDA5E-B3C8-4505-80D9-A694042D1F7C} 2014-09-04 00:44 - 2014-08-27 00:22 - 00000000 ____D () C:\ProgramData\Corel 2014-09-03 19:21 - 2014-09-03 19:21 - 00000000 ____D () C:\ProgramData\surfkeePita 2014-09-03 19:21 - 2014-08-21 21:18 - 00000000 ____D () C:\ProgramData\5940d185bd756d33 2014-09-03 11:55 - 2014-06-22 15:20 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4162614285-2887739644-64261045-1001 2014-09-01 10:02 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness 2014-08-29 12:38 - 2013-08-22 16:44 - 00604560 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-28 16:24 - 2014-07-22 22:08 - 00000000 ____D () C:\Users\harald\AppData\Roaming\FileZilla 2014-08-28 00:54 - 2014-08-28 00:04 - 00000000 ____D () C:\Users\harald\AppData\Roaming\Real 2014-08-28 00:47 - 2014-08-28 00:47 - 00003338 _____ () C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4162614285-2887739644-64261045-1001 2014-08-28 00:47 - 2014-08-28 00:47 - 00003282 _____ () C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4162614285-2887739644-64261045-1001 2014-08-28 00:47 - 2014-08-28 00:44 - 00000000 ____D () C:\ProgramData\Real 2014-08-28 00:45 - 2014-08-28 00:45 - 00001964 _____ () C:\Users\Public\Desktop\Kostenlose Angebote.lnk 2014-08-28 00:45 - 2014-08-28 00:45 - 00001370 _____ () C:\Users\Public\Desktop\RealPlayer.lnk 2014-08-28 00:45 - 2014-08-28 00:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real 2014-08-28 00:45 - 2014-08-28 00:44 - 00000000 ____D () C:\Program Files (x86)\Real 2014-08-28 00:44 - 2014-08-28 00:44 - 00272896 _____ (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll 2014-08-28 00:44 - 2014-08-28 00:44 - 00198848 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll 2014-08-28 00:44 - 2014-08-28 00:44 - 00006656 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll 2014-08-28 00:44 - 2014-08-28 00:44 - 00005632 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll 2014-08-28 00:44 - 2012-09-23 20:43 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2014-08-28 00:44 - 2012-09-23 20:43 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2014-08-27 23:32 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp 2014-08-27 18:22 - 2014-08-27 18:20 - 00001404 _____ () C:\Windows\Synaptics.log 2014-08-27 18:22 - 2014-06-22 16:24 - 00021624 _____ () C:\Windows\DPINST.LOG 2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf 2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf 2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____D () C:\Program Files\Synaptics 2014-08-27 18:21 - 2013-08-22 16:46 - 00028779 _____ () C:\Windows\setupact.log 2014-08-27 00:31 - 2014-08-27 00:13 - 00000000 ____D () C:\ProgramData\CorelDRAW Graphics Suite X7 2014-08-27 00:30 - 2014-08-27 00:29 - 00000000 ____D () C:\ProgramData\Protexis 2014-08-27 00:30 - 2014-08-26 23:43 - 00000000 ____D () C:\Users\harald\AppData\Roaming\Corel 2014-08-27 00:29 - 2014-08-27 00:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 2014-08-27 00:26 - 2014-08-27 00:27 - 00002467 _____ () C:\Users\Public\Desktop\Bitstream Font Navigator.lnk 2014-08-27 00:24 - 2014-08-27 00:27 - 00002847 _____ () C:\Users\Public\Desktop\Corel PHOTO-PAINT X7.lnk 2014-08-27 00:24 - 2014-08-27 00:27 - 00002840 _____ () C:\Users\Public\Desktop\Corel CAPTURE X7.lnk 2014-08-27 00:24 - 2014-08-27 00:27 - 00002371 _____ () C:\Users\Public\Desktop\Corel CONNECT X7.lnk 2014-08-27 00:24 - 2014-08-27 00:24 - 00000000 ____D () C:\Users\Public\Documents\Corel 2014-08-27 00:23 - 2014-08-27 00:27 - 00002799 _____ () C:\Users\Public\Desktop\CorelDRAW X7.lnk 2014-08-27 00:23 - 2014-08-27 00:22 - 00000000 ____D () C:\Program Files (x86)\Corel 2014-08-27 00:01 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-08-26 23:52 - 2014-08-26 22:35 - 00000000 ____D () C:\Windows\COREL 2014-08-26 23:46 - 2014-08-26 23:46 - 00000000 ____D () C:\Users\harald\Documents\Meine Paletten 2014-08-26 23:45 - 2014-08-26 23:45 - 00000000 ____D () C:\Users\harald\Documents\Corel 2014-08-26 23:44 - 2014-08-26 23:23 - 00000000 ____D () C:\ProgramData\CorelDRAW Graphics Suite X7 x64 2014-08-26 23:43 - 2014-08-26 23:43 - 00000000 ____D () C:\ProgramData\Protexis64 2014-08-26 23:39 - 2014-08-26 23:39 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-26 23:37 - 2014-08-26 23:37 - 00000000 ____D () C:\Program Files\Common Files\Protexis 2014-08-26 22:40 - 2014-08-26 22:40 - 00000000 _____ () C:\Windows\longfile.INI 2014-08-26 22:39 - 2014-08-26 22:39 - 00008198 _____ () C:\Windows\WT61US.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61UK.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61SD.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61OZ.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61KR.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61DE.UWL 2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61CE.UWL 2014-08-26 22:35 - 2014-08-26 22:35 - 00000000 ____D () C:\Corel 2014-08-25 21:37 - 2014-08-23 14:53 - 02482176 _____ () C:\Users\tn\Documents\kassa.accdb 2014-08-23 19:15 - 2014-08-23 19:15 - 00001181 _____ () C:\Users\tn\Documents\info.dat 2014-08-23 15:13 - 2014-08-23 15:13 - 00000000 ____D () C:\Program Files (x86)\deal2ddealit 2014-08-23 15:13 - 2014-08-21 21:18 - 00000000 ____D () C:\ProgramData\deal2ddealit 2014-08-23 14:53 - 2014-08-23 14:52 - 00000000 ____D () C:\Users\tn 2014-08-23 13:10 - 2014-07-22 22:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2014-08-23 13:10 - 2014-07-22 22:07 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-08-23 13:08 - 2014-08-23 13:08 - 06052529 _____ (Tim Kosse) C:\Users\harald\Downloads\FileZilla_3.9.0.3_win32-setup.exe 2014-08-23 12:36 - 2014-08-21 21:04 - 00000940 _____ () C:\EamClean.log 2014-08-23 10:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache 2014-08-23 02:42 - 2014-08-27 22:42 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-22 20:07 - 2014-06-22 15:15 - 00000000 ____D () C:\Users\harald\AppData\Roaming\Adobe 2014-08-22 09:11 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-22 09:10 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData 2014-08-22 09:09 - 2014-07-26 13:10 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-21 21:04 - 2014-08-20 06:22 - 00000000 ____D () C:\ProgramData\WinSpeed 2014-08-20 06:23 - 2014-07-30 22:49 - 00000000 ____D () C:\ProgramData\374311380 2014-08-18 20:31 - 2014-08-18 20:31 - 00000000 ____D () C:\Users\harald\AppData\Local\PDF Writer 2014-08-18 20:24 - 2014-08-18 20:24 - 00000000 ____D () C:\Users\harald\AppData\Roaming\PDF Writer 2014-08-18 20:15 - 2014-08-18 20:13 - 00000000 ____D () C:\ProgramData\PDF Writer 2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip 2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\Program Files\Common Files\Bullzip 2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\Program Files\Bullzip 2014-08-18 16:57 - 2014-08-18 16:36 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-08-18 16:57 - 2014-08-18 16:34 - 00000000 ____D () C:\Users\harald\AppData\Local\Adobe 2014-08-18 16:57 - 2014-08-18 16:30 - 00000000 ____D () C:\ProgramData\Adobe 2014-08-18 16:53 - 2014-07-10 22:09 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-08-18 16:53 - 2014-07-10 22:07 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-18 16:33 - 2014-08-18 16:33 - 00002469 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk 2014-08-18 16:33 - 2014-08-18 16:33 - 00002230 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk 2014-08-18 16:33 - 2014-08-18 16:33 - 00002160 _____ () C:\Users\Public\Desktop\Adobe FormsCentral.lnk 2014-08-18 16:33 - 2014-08-18 16:33 - 00002069 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk 2014-08-18 16:33 - 2014-08-18 16:33 - 00002046 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk 2014-08-18 16:30 - 2014-08-18 16:30 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-08-18 16:28 - 2014-08-18 16:25 - 00000000 ____D () C:\Users\harald\Desktop\Adobe Acrobat XI 2014-08-15 11:23 - 2014-07-10 21:23 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-15 11:21 - 2014-07-10 21:23 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-15 10:45 - 2014-08-15 10:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF 2014-08-15 10:45 - 2014-08-15 10:45 - 00000000 ____D () C:\Program Files (x86)\Acro Software 2014-08-15 09:02 - 2014-07-14 11:09 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-15 09:02 - 2014-07-14 11:08 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-15 09:02 - 2014-07-14 11:08 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-15 09:02 - 2013-08-22 13:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-15 09:02 - 2013-08-22 13:44 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-15 09:02 - 2013-08-22 13:22 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-15 09:02 - 2013-08-22 13:21 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-15 09:02 - 2013-08-22 13:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-15 09:02 - 2013-08-22 13:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-15 09:02 - 2013-08-22 12:32 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-15 09:02 - 2013-08-22 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-15 09:02 - 2013-08-22 05:55 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-15 09:02 - 2013-08-22 05:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-15 09:02 - 2013-08-22 05:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-15 09:02 - 2013-08-22 05:40 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-15 09:02 - 2013-08-22 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-07 04:12 - 2014-08-18 15:52 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-07 00:38 - 2014-08-18 15:56 - 00697856 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll Some content of TEMP: ==================== C:\Users\harald\AppData\Local\Temp\AskSLib.dll C:\Users\harald\AppData\Local\Temp\JDSetup130509647251693530.exe C:\Users\harald\AppData\Local\Temp\JDSetup130512265273593134.exe C:\Users\harald\AppData\Local\Temp\JDSetup130512271351440163.exe C:\Users\harald\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-27 00:44 ==================== End Of Log ============================ --- --- --- und Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-09-2014 02 Ran by harald at 2014-09-04 23:51:44 Running from C:\Users\harald\Downloads\x Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Emsisoft Anti-Malware (Enabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Emsisoft Anti-Malware (Enabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367} FW: Online Armor Firewall (Enabled) {BD3F5FCA-866B-1E2E-0A68-58900A751EA1} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.00 - Adobe Systems) Bullzip PDF Printer 9.2.0.1499 (HKLM\...\Bullzip PDF Printer_is1) (Version: 9.2.0.1499 - Bullzip) Color MF30-1 (HKLM\...\MFP-Printer Utility Color MF30-1 Installer) (Version: - ) Color MF30-1 Scanner (HKLM-x32\...\InstallShield_{53498E29-B8FE-4B33-BD35-EB8804A45D33}) (Version: - ) Color MF30-1 Scanner (Version: 1.00.0000 - ) Hidden Corel Graphics - Windows Shell Extension (HKLM-x32\...\_{8616305F-122C-4341-9C37-47A9CD322AB2}) (Version: 17.1.0.572 - Corel Corporation) Corel Graphics - Windows Shell Extension (x32 Version: 17.1.572 - Corel Corporation) Hidden Corel Graphics - Windows Shell Extension 64 Bit (Version: 17.1.572 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Capture (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Common (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Connect (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Custom Data (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - DE (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Draw (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Filters (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - FontNav (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - IPM Content (x32 Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - IPM T (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - PHOTO-PAINT (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Photozoom Plugin (x32 Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Redist (x32 Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Setup Files (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - VBA (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - VideoBrowser (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Writing Tools (x32 Version: 17.1 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 (HKLM-x32\...\_{C5D9CECB-A66F-473F-B406-5C8C2DCA4DF0}) (Version: 17.1.0.572 - Corel Corporation) CorelDRAW Graphics Suite X7 (x32 Version: 17.1 - Corel Corporation) Hidden CutePDF Writer 2.8 (HKLM\...\CutePDF Writer Installation) (Version: - ) Definition Update for Microsoft Office 2013 (KB2760587) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{0B79C91F-978F-4C2E-9FE4-D4B567808858}) (Version: - Microsoft) Emsisoft Anti-Malware (HKLM-x32\...\{BC30E5E7-047D-4232-A7E8-F2CB7CC7B2E0}_is1) (Version: 9.0 - Emsisoft GmbH) Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 8.0.2.4 - Lenovo) Energy Management (x32 Version: 8.0.2.4 - Lenovo) Hidden FileZilla Client 3.9.0.3 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.3 - Tim Kosse) Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3621 - Intel Corporation) Java 7 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.650 - Oracle) Java Auto Updater (x32 Version: 2.1.65.20 - Oracle, Inc.) Hidden JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) Microsoft Access MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft DCF MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Excel MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Groove MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft InfoPath MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Lync MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office 64-bit Components 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Korrekturhilfen 2013 - Deutsch (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM UX MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - English (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - Italiano (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft OneNote MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Outlook MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft PowerPoint MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Publisher MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual Basic for Applications 7.1 (x86) (x32 Version: 7.1.00.00 - Microsoft Corporation) Hidden Microsoft Visual Basic for Applications 7.1 (x86) English (x32 Version: 7.1.0.0 - Microsoft Corporation) Hidden Microsoft Visual Basic for Applications 7.1 (x86) German (x32 Version: 7.1.0.0 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 (HKLM-x32\...\{89ca2a32-2b52-4595-8dfd-6fe4757958d0}) (Version: 11.0.51108 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2012 Finalizer (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - Module linguistique Français (Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - DEU-Sprachpaket (Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - Language Pack ITA (Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - Paquete de idioma ESN (Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - 한국어 언어 팩 (Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - 日本語 Language Pack (Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support (Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x64 主控支援 - 繁體中文語言套件 (Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x64 托管支持 - 简体中文语言包 (Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - DEU-Sprachpaket (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - Language Pack ITA (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - Module linguistique Français (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - Paquete de idioma ESN (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - 한국어 언어 팩 (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - 日本語 Language Pack (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x86 主控支援 - 繁體中文語言套件 (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Visual Studio Tools for Applications 2012 x86 托管支持 - 简体中文语言包 (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden Microsoft Word MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) Mozilla Thunderbird 24.6.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.7 - Notepad++ Team) Online Armor 7.0 (HKLM-x32\...\OnlineArmor_is1) (Version: 7.0 - Emsisoft GmbH) Outils de vérification linguistique 2013 de Microsoft Office*- Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (Version: 11.0.51108 - Microsoft Corporation) Hidden Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - PTB (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM-x32\...\RealPlayer 12.0) (Version: - RealNetworks) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (x32 Version: - Microsoft) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.9.1 - Synaptics Incorporated) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.29480 - TeamViewer) Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-0018-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-001B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2881070) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{35E5FACD-A5AA-46AD-93C7-F6D7969044E7}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2881070) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{35E5FACD-A5AA-46AD-93C7-F6D7969044E7}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2881070) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{35E5FACD-A5AA-46AD-93C7-F6D7969044E7}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2881083) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4FC38705-B045-4DAC-A0B0-C573D31B8CD5}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760249) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{8C07AD38-38EB-4332-BCB3-F55A77C927DF}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760344) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{A7610F07-E844-4444-8E1D-D5BC8AD0B4C5}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760544) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{45B7D395-EB9B-414F-9E46-5849B42326E2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2768012) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{66421820-D3CA-450A-898C-78D7E40108E6}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{1644D7F6-90EE-4252-8884-18E4E330529D}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 32-Bit Edition (HKLM-x32\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{1644D7F6-90EE-4252-8884-18E4E330529D}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2826040) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{B7EA8070-C37F-4617-82F4-52CF3304595A}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2837644) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{9BC5FF1D-9626-44D7-BC7F-EB44BD8BDB9F}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{AD7045B8-1D75-4B4C-8120-12F045D206C7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{AD7045B8-1D75-4B4C-8120-12F045D206C7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880457) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{D27F6360-AE1E-4C8C-8ECD-C0375E20B923}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{5D6439FF-D651-4B13-B52E-2508AB9DE19D}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{5D6439FF-D651-4B13-B52E-2508AB9DE19D}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880478) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7C5CEE0F-6823-4BB7-A28F-76FEC14EB6AC}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881009) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7A3EF4FF-A9C8-4F7E-8020-A45F7D319387}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{01B80B63-C638-4004-9148-75B8C8518B1E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition (HKLM-x32\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{01B80B63-C638-4004-9148-75B8C8518B1E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition (HKLM-x32\...\{90150000-0090-0407-0000-0000000FF1CE}_Office15.PROPLUS_{01B80B63-C638-4004-9148-75B8C8518B1E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883036) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{B8E73381-09B1-4895-ACD0-34385B0F526D}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883049) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{1C6260FD-A280-49FE-89D0-CCEC647FBD8E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883052) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{3F3A95FF-9F40-4B19-8227-53DF683B4CF9}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883052) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{3F3A95FF-9F40-4B19-8227-53DF683B4CF9}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-0407-0000-0000000FF1CE}_Office15.PROPLUS_{0F5FFEB6-2F66-4592-8A34-CC85FF318951}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-0409-0000-0000000FF1CE}_Office15.PROPLUS_{DA288EB3-648C-433C-88AC-71AEAAFAACF7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-040C-0000-0000000FF1CE}_Office15.PROPLUS_{51865C36-97D4-4210-A33E-50BCC8CDDF72}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-0410-0000-0000000FF1CE}_Office15.PROPLUS_{D533D4E6-5056-487A-8F18-7FA51AF0E283}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883062) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{EE35EB6C-7768-433F-B9A0-73C97699A08C}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883062) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EE35EB6C-7768-433F-B9A0-73C97699A08C}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-00BA-0407-0000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{CA0F0611-10FB-47D4-A642-E3BABCC73393}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{CA0F0611-10FB-47D4-A642-E3BABCC73393}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 32-Bit Edition (HKLM-x32\...\{90150000-00A1-0407-0000-0000000FF1CE}_Office15.PROPLUS_{CA0F0611-10FB-47D4-A642-E3BABCC73393}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{1BCA67A6-5329-48D0-A088-C097AC7A14BD}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 32-Bit Edition (HKLM-x32\...\{90150000-001A-0407-0000-0000000FF1CE}_Office15.PROPLUS_{1BCA67A6-5329-48D0-A088-C097AC7A14BD}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2883051) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{01923A0F-BA34-4A75-8D43-97F536E44D95}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2883051) 32-Bit Edition (HKLM-x32\...\{90150000-0018-0407-0000-0000000FF1CE}_Office15.PROPLUS_{01923A0F-BA34-4A75-8D43-97F536E44D95}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7500AD77-83C6-400B-8B2F-F8E401A7B697}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 32-Bit Edition (HKLM-x32\...\{90150000-0019-0407-0000-0000000FF1CE}_Office15.PROPLUS_{7500AD77-83C6-400B-8B2F-F8E401A7B697}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{25C61889-2E44-4BE1-9E96-9364BFDCF501}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{25C61889-2E44-4BE1-9E96-9364BFDCF501}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2878319) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{A7CD05CC-CA85-428C-91FD-74A908D126E1}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-001A-0407-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-001B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version: - Microsoft) Windows-Treiberpaket - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (HKLM\...\71BC3FD63F450BA0A957AAECBDB4A000C4F2BE42) (Version: 06/15/2012 8.1.0.1 - Lenovo) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (HKLM\...\8A223E56FB1ED4F697B54E5BF96F1EB63B512684) (Version: 06/19/2012 10.13.29.733 - Lenovo) WinRAR 5.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH) WinSpeed (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{f1f78e38}) (Version: - 24soft) <==== ATTENTION Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (Version: 11.0.51108 - Microsoft Corporation) Hidden Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x86) - RUS (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-4162614285-2887739644-64261045-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation) ==================== Restore Points ========================= 18-08-2014 14:29:35 Installed Adobe Acrobat XI Pro. 22-08-2014 07:09:14 Windows Update 26-08-2014 21:38:21 Microsoft Visual Studio Tools for Applications 2012 03-09-2014 06:41:34 Geplanter Prüfpunkt ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2014-08-18 16:42 - 00000916 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {2AB4B245-1EB0-4CD3-8970-8F43AD55F11B} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4162614285-2887739644-64261045-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2011-03-29] (RealNetworks, Inc.) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {379C9638-D709-4244-B560-A43805D64571} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {3A730463-D125-4F30-8404-4F89B7DDD3FA} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {444D8AB4-2001-4E7A-9A09-2FE7E1893D16} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4162614285-2887739644-64261045-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2011-03-29] (RealNetworks, Inc.) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {4B389D58-B37C-4000-822B-E314BB1FBABA} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {4B63DAD8-630E-4B6A-8687-3CE0B3CE803D} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe Task: {4C07F044-59E2-4A9A-AFEE-4014381DDF99} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {4F61FA1A-A31C-4B68-9F36-5EF5E641EA2E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {9E5FBC22-451B-4B62-A82A-41BA9B9F08FD} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A7395B5C-5140-4862-934F-8A8C654F86E3} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-08-15] (Microsoft Corporation) Task: {A9E91544-9F2B-4F4E-A73C-4AD3B0200EF1} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D0B6ED53-6F80-49C3-A3D7-72C7298A2C37} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {DF9569C7-627B-4BA6-9E65-FFAFEB2CAE0A} - System32\Tasks\AutoKMSCustom => C:\Windows\AutoKMS\AutoKMS.exe [2014-06-22] () Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE ==================== Loaded Modules (whitelisted) ============= 2014-05-12 11:49 - 2014-05-12 11:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2010-04-26 19:04 - 2010-04-26 19:04 - 00015360 _____ () C:\Windows\System32\KOBJUTAL.dll 2010-01-27 13:59 - 2010-01-27 13:59 - 00015360 _____ () C:\Windows\System32\KOBJUJAL.dll 2007-11-15 13:57 - 2007-11-15 13:57 - 00017408 _____ () C:\Windows\System32\KOBJUAAL.dll 2010-01-27 14:26 - 2010-01-27 14:26 - 00015360 _____ () C:\Windows\System32\KOBJUWAL.DLL 2014-08-15 10:45 - 2009-11-05 08:40 - 00085504 _____ () C:\Windows\System32\cpwmon64.dll 2014-07-31 00:16 - 2011-01-24 14:40 - 00041472 _____ () C:\Windows\system32\spool\PRTPROCS\x64\KOBJUAAP.DLL 2010-12-22 11:15 - 2010-12-22 11:15 - 00468992 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAC.DLL 2010-12-22 11:14 - 2010-12-22 11:14 - 03540992 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAU.DLL 2010-12-22 11:15 - 2010-12-22 11:15 - 03424768 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAR.DLL 2010-12-22 11:15 - 2010-12-22 11:15 - 00187904 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAS.DLL 2010-04-26 19:04 - 2010-04-26 19:04 - 00648704 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAO.DLL 2010-12-22 11:15 - 2010-12-22 11:15 - 02368512 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAD.DLL 2011-01-24 13:50 - 2011-01-24 13:50 - 00419840 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAC.DLL 2011-01-24 13:49 - 2011-01-24 13:49 - 03385344 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAU.DLL 2011-01-24 13:51 - 2011-01-24 13:51 - 03424768 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAR.DLL 2011-01-24 13:51 - 2011-01-24 13:51 - 00188416 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAS.DLL 2010-01-27 13:59 - 2010-01-27 13:59 - 00648704 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAO.DLL 2011-01-24 13:51 - 2011-01-24 13:51 - 03372544 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAD.DLL 2011-01-24 14:40 - 2011-01-24 14:40 - 00442368 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUAAC.DLL 2011-01-24 14:39 - 2011-01-24 14:39 - 00188416 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUAAS.DLL 2011-01-25 16:26 - 2011-01-25 16:26 - 01828352 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUWAC.DLL 2011-01-25 16:23 - 2011-01-25 16:23 - 00187392 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUWAS.DLL 2014-07-08 21:05 - 2014-06-24 04:53 - 00600576 _____ () C:\Program Files (x86)\TrialReset\TrialReset.exe 2014-08-20 06:22 - 2014-08-20 06:22 - 04304896 _____ () C:\ProgramData\WinSpeed\WinSpeed_x64.dll 2014-05-01 21:29 - 2014-05-01 21:29 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2010-01-19 02:49 - 2010-01-19 02:49 - 00805888 _____ () C:\Windows\system32\M30-1WDV.dll 2014-07-26 13:17 - 2014-08-18 15:51 - 00746536 _____ () C:\Program Files (x86)\Emsisoft Anti-Malware\fw32.dll 2014-09-03 19:21 - 2014-09-03 19:21 - 00619008 _____ () C:\ProgramData\surfkeePita\UZaFWpjX.dll 2012-09-23 20:43 - 2012-09-23 20:43 - 00010240 _____ () C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\locale\de_de\acrotray.deu 2014-01-23 15:55 - 2014-01-23 15:55 - 01030312 _____ () C:\Program Files (x86)\Microsoft Office\Office15\ADDINS\UmOutlookAddin.dll 2014-01-23 15:55 - 2014-01-23 15:55 - 00321704 _____ () C:\Program Files (x86)\Microsoft Office\Office15\msfad.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (09/04/2014 09:01:39 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm OUTLOOK.EXE, Version 15.0.4615.1000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 137c Startzeit: 01cfc8727e3cd7e8 Endzeit: 23 Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE Berichts-ID: df3566dd-3465-11e4-8297-9cd21eec58b2 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (09/04/2014 08:45:08 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm OUTLOOK.EXE, Version 15.0.4615.1000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2624 Startzeit: 01cfc86ed9a0f864 Endzeit: 36 Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE Berichts-ID: 8a2212d9-3463-11e4-8297-9cd21eec58b2 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (09/04/2014 08:45:06 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm MSPUB.EXE, Version 15.0.4629.1000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2574 Startzeit: 01cfc7c8a0d17e85 Endzeit: 52 Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office15\MSPUB.EXE Berichts-ID: 927a5d66-3463-11e4-8297-9cd21eec58b2 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (09/04/2014 08:44:52 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm iexplore.exe, Version 11.0.9600.17239 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1294 Startzeit: 01cfc75a72708ed1 Endzeit: 786 Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe Berichts-ID: 5c02a7f3-3463-11e4-8297-9cd21eec58b2 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (09/04/2014 08:42:17 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm IEXPLORE.EXE, Version 11.0.9600.17239 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1004 Startzeit: 01cfc75a72bcdb09 Endzeit: 666 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: 2a620dc1-3463-11e4-8297-9cd21eec58b2 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (09/04/2014 08:33:54 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm OUTLOOK.EXE, Version 15.0.4615.1000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 20c4 Startzeit: 01cfc7a81d565edb Endzeit: 859 Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE Berichts-ID: b17d48af-3461-11e4-8297-9cd21eec58b2 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (09/03/2014 08:47:43 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (09/01/2014 11:33:17 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT-AUTORITÄT) Description: There was an error with the Windows Location Provider database Error: (09/01/2014 08:09:15 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (08/29/2014 01:00:14 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. System errors: ============= Error: (09/04/2014 11:26:27 AM) (Source: DCOM) (EventID: 10010) (User: laptop) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (09/04/2014 11:22:18 AM) (Source: DCOM) (EventID: 10010) (User: laptop) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (09/04/2014 11:21:47 AM) (Source: DCOM) (EventID: 10010) (User: laptop) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (09/03/2014 10:17:57 AM) (Source: DCOM) (EventID: 10010) (User: laptop) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (09/03/2014 07:54:41 AM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden. Error: (09/03/2014 00:35:41 AM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden. Error: (09/03/2014 00:35:40 AM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden. Error: (09/03/2014 00:35:40 AM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden. Error: (09/03/2014 00:35:40 AM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden. Error: (09/03/2014 00:35:40 AM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden. Microsoft Office Sessions: ========================= Error: (09/04/2014 09:01:39 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: OUTLOOK.EXE15.0.4615.1000137c01cfc8727e3cd7e823C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXEdf3566dd-3465-11e4-8297-9cd21eec58b2 Error: (09/04/2014 08:45:08 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: OUTLOOK.EXE15.0.4615.1000262401cfc86ed9a0f86436C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE8a2212d9-3463-11e4-8297-9cd21eec58b2 Error: (09/04/2014 08:45:06 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: MSPUB.EXE15.0.4629.1000257401cfc7c8a0d17e8552C:\Program Files (x86)\Microsoft Office\Office15\MSPUB.EXE927a5d66-3463-11e4-8297-9cd21eec58b2 Error: (09/04/2014 08:44:52 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: iexplore.exe11.0.9600.17239129401cfc75a72708ed1786C:\Program Files\Internet Explorer\iexplore.exe5c02a7f3-3463-11e4-8297-9cd21eec58b2 Error: (09/04/2014 08:42:17 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: IEXPLORE.EXE11.0.9600.17239100401cfc75a72bcdb09666C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE2a620dc1-3463-11e4-8297-9cd21eec58b2 Error: (09/04/2014 08:33:54 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: OUTLOOK.EXE15.0.4615.100020c401cfc7a81d565edb859C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXEb17d48af-3461-11e4-8297-9cd21eec58b2 Error: (09/03/2014 08:47:43 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"c:\program files (x86)\microsoft office\Office15\lync.exe.Manifestc:\program files (x86)\microsoft office\Office15\UccApi.DLL1 Error: (09/01/2014 11:33:17 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT-AUTORITÄT) Description: -2147024883 Error: (09/01/2014 08:09:15 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"c:\program files (x86)\microsoft office\Office15\lync.exe.Manifestc:\program files (x86)\microsoft office\Office15\UccApi.DLL1 Error: (08/29/2014 01:00:14 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"c:\program files (x86)\microsoft office\Office15\lync.exe.Manifestc:\program files (x86)\microsoft office\Office15\UccApi.DLL1 ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU 2020M @ 2.40GHz Percentage of memory in use: 59% Total physical RAM: 3975.27 MB Available physical RAM: 1597.4 MB Total Pagefile: 6535.27 MB Available Pagefile: 3211.91 MB Total Virtual: 131072 MB Available Virtual: 131071.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:232.36 GB) (Free:189.92 GB) NTFS Drive d: () (Fixed) (Total:232.88 GB) (Free:63.17 GB) NTFS Drive e: (WI_WIG_010) (CDROM) (Total:0.08 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: D9FA2484) Partition: GPT Partition Type. ==================== End Of Log ============================ Danke Geändert von haiflosse (04.09.2014 um 23:03 Uhr) |
05.09.2014, 07:36 | #4 | |
/// TB-Ausbilder | lenovo g700 surkfeepita und winspeed deinstallierenZitat:
Ausserdem ist das Betriebsystem nicht Original. Supportstopp Lesestoff: Das Thema wird erst nach Entfernung fortgeführt. Da dies eine Neuinstallation von Windows voraussetzt, ist der Support beendet. Cracks und Keygens Den Kopierschutz von Software zu umgehen ist nach geltendem Recht illegal. Die Logfiles deuten stark darauf hin, dass du nicht legal erworbene Software einsetzt. Zudem sind Cracks und Patches aus dubioser Quelle sehr oft mit Schädlingen versehen, womit man sich also fast vorsätzlich infiziert. Wir haben uns hier auf dem Board darauf geeinigt, dass wir an dieser Stelle nicht weiter bereinigen, da wir ein solches Vorgehen nicht unterstützen. Hinzu kommt, dass wir dich in unserer Anleitung und auch in diesem Wichtig-Thema unmissverständlich darauf hingewiesen haben, wie wir damit umgehen werden. Saubere, gute Software hat seinen Preis und die Softwarefirmen leben von diesen Einnahmen.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
Themen zu lenovo g700 surkfeepita und winspeed deinstallieren |
automatisch, deinstalliere, deinstallieren, ebook, emsisoft, entdeck, entdeckt, firewall, google, keine updates, lenovo, modus, notebook, passieren, programme, programmen, speed, updates, weiterhelfen, werbung, windows, windows 8 |