spikehansley | 29.03.2014 14:39 | einmal Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-03-2014 01
Ran by Acer at 2014-03-29 14:25:46
Running from C:\Users\user\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader X (10.1.4) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.4 - Adobe Systems Incorporated)
Brother MFL-Pro Suite DCP-7055 (HKLM\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.0.0.0 - Brother Industries, Ltd.)
CD/DVD Drive Acoustic Silencer (HKLM\...\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}) (Version: 2.02.03 - ACER)
FreePDFReader (HKLM\...\FreePDFReader) (Version: - FreePDFConverter)
Google Chrome (HKLM\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.)
Google Chrome Frame (HKLM\...\{4F2EAFFD-6D9A-3804-A77B-5A450D3201F6}) (Version: 65.107.16494 - Google, Inc.)
Google Update Helper (Version: 1.3.23.9 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.5.6.1001 - Intel Corporation)
Join Air (HKLM\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.1 - ZTE Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office Outlook 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Outlook 2010 (HKLM\...\Office14.OUTLOOK) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 27.0.1 (x86 de) (HKLM\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
Nuance PaperPort 12 (HKLM\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
OpenOffice 4.0.1 (HKLM\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
PaperPort Image Printer (HKLM\...\{2BC2781A-F7F6-452E-95EB-018A522F1B2C}) (Version: 1.00.0000 - Nuance Communications, Inc.)
Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek)
REALTEK RTL8187B Wireless LAN Driver (HKLM\...\{895722FE-25FE-4854-95AC-B0C42F9DBEDA}) (Version: Package:1.00.0026 Driver:6.1116.1226.2007 - REALTEK Semiconductor Corp.)
ScanSoft PaperPort 11 (HKLM\...\{02570AE0-BEE0-4A6C-BE3F-D806E9F2EA17}) (Version: 11.2.0000 - Nuance Communications, Inc.)
Scansoft PDF Professional (Version: - ) Hidden
ACER Hardware Setup (HKLM\...\{2883F6F5-0509-43F3-868C-D50330DD9DD3}) (Version: 2.00.08 - )
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (HKLM\...\{90140000-001A-0000-0000-0000000FF1CE}_Office14.OUTLOOK_{C8694FF0-8203-483B-A07A-2BC40433167D}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (HKLM\...\{90140000-006E-0407-0000-0000000FF1CE}_Office14.OUTLOOK_{32E700B9-1A94-48B4-99E1-CB8BD5F7340A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.OUTLOOK_{007CC0F3-15DE-426D-95B5-B019FCEF58CE}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.OUTLOOK_{460FF681-BC66-4C38-99DF-7012E03F1EBA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (HKLM\...\{90140000-001F-0410-0000-0000000FF1CE}_Office14.OUTLOOK_{D1688F5A-9A61-42F0-B8D0-2C9DF315A141}) (Version: - Microsoft)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (HKLM\...\{90140000-001A-0000-0000-0000000FF1CE}_Office14.OUTLOOK_{BC6DFBFD-16DD-47E1-A7EF-2C062930FA4F}) (Version: - Microsoft)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (HKLM\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.OUTLOOK_{81CA2EFA-7250-4B1E-B3A6-E0595224E2CD}) (Version: - Microsoft)
==================== Restore Points =========================
27-03-2014 12:21:21 Windows Vista™ Service Pack 2
27-03-2014 12:31:24 Gerätetreiber-Paketinstallation: Intel IDE ATA/ATAPI-Controller
27-03-2014 13:24:01 Windows Update
27-03-2014 19:32:50 Windows Vista™ Service Pack 2
27-03-2014 20:51:17 Windows Update
28-03-2014 02:00:44 Windows Update
28-03-2014 06:00:35 Windows Update
28-03-2014 06:30:06 Windows Update
28-03-2014 07:18:37 Windows Update
28-03-2014 13:59:52 Windows Update
29-03-2014 06:02:19 Windows Update
==================== Hosts content: ==========================
2006-11-02 11:23 - 2014-03-27 06:58 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {0AD00EFB-CCD6-419F-8E82-2EDD0F65380D} - System32\Tasks\Fifth => C:\Users\user\AppData\Roaming\Fifth\Fifth.exe [2014-03-04] () <==== ATTENTION
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {21A83EEE-FD7F-4826-8885-AF59F42AB342} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-13] (Adobe Systems Incorporated)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {40EF26FE-84E8-4FE3-A39F-BEEC037F7932} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-02-24] (Google Inc.)
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {9E4C6F46-4FB7-42B2-A3E2-887BD19119BA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-02-24] (Google Inc.)
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries
Task: {DA86A1CC-0754-4E6E-B031-E5586BB7FC35} - System32\Tasks\OMESupervisor => C:\Users\user\AppData\Local\omesuperv.exe <==== ATTENTION
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {F1F2DCC3-ECFD-47FF-8747-06A77F91AA38} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - ACER => C:\Program Files\Windows Calendar\WinCal.exe [2008-01-21] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-03-11 21:15 - 2009-08-31 10:43 - 00132608 _____ () C:\Program Files\Join Air\UIExec.exe
2014-03-15 21:21 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
2014-03-11 21:15 - 2009-08-31 10:43 - 00241664 _____ () C:\Program Files\Join Air\AssistantServices.exe
2014-03-27 13:31 - 2009-12-23 17:32 - 00058880 _____ () C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/29/2014 02:25:22 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/29/2014 01:31:04 PM) (Source: LoadPerf) (User: )
Description: 扨湩怀¶က16
Error: (03/29/2014 01:27:15 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/29/2014 09:56:57 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/29/2014 09:18:54 AM) (Source: LoadPerf) (User: )
Description: 扨湩怀¶က16
Error: (03/29/2014 09:14:59 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/29/2014 08:53:44 AM) (Source: LoadPerf) (User: )
Description: 扨湩怀¶က16
Error: (03/29/2014 08:48:06 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/29/2014 07:49:43 AM) (Source: LoadPerf) (User: )
Description: 扨湩怀¶က16
Error: (03/29/2014 07:48:26 AM) (Source: LoadPerf) (User: )
Description: 扨湩怀¶က16
System errors:
=============
Microsoft Office Sessions:
=========================
Error: (03/29/2014 02:25:22 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/29/2014 01:31:04 PM) (Source: LoadPerf)(User: )
Description: 扨湩怀¶က16
Error: (03/29/2014 01:27:15 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/29/2014 09:56:57 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/29/2014 09:18:54 AM) (Source: LoadPerf)(User: )
Description: 扨湩怀¶က16
Error: (03/29/2014 09:14:59 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/29/2014 08:53:44 AM) (Source: LoadPerf)(User: )
Description: 扨湩怀¶က16
Error: (03/29/2014 08:48:06 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/29/2014 07:49:43 AM) (Source: LoadPerf)(User: )
Description: 扨湩怀¶က16
Error: (03/29/2014 07:48:26 AM) (Source: LoadPerf)(User: )
Description: 扨湩怀¶က16
CodeIntegrity Errors:
===================================
Date: 2014-03-29 14:25:24.024
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-29 14:25:23.930
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-29 14:25:23.837
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-29 14:25:23.759
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-29 14:25:23.649
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-29 14:25:23.571
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-29 14:25:23.462
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-29 14:25:23.369
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-27 20:32:45.168
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-27 20:32:45.075
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 39%
Total physical RAM: 1915.25 MB
Available physical RAM: 1162.29 MB
Total Pagefile: 4071.81 MB
Available Pagefile: 3363.34 MB
Total Virtual: 2047.88 MB
Available Virtual: 1894.95 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:228.95 GB) (Free:188.87 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:213.65 GB) (Free:182.96 GB) NTFS
Drive e: (RECOVERY) (Fixed) (Total:23.17 GB) (Free:23.07 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: BBD4AC46)
Partition: GPT Partition Type.
==================== End Of Log ============================
zweimal
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by user (administrator) on ACER-PC on 29-03-2014 14:25:17
Running from C:\Users\user\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\Join Air\UIExec.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\Brother\BrStMonW.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(ACER) C:\Program Files\ACER\TOSCDSPD\TOSCDSPD.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
() C:\Program Files\Join Air\AssistantServices.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Brother Industries, Ltd.) C:\Program Files\Browny02\BrYNSvc.exe
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCtrlCntr.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCcUxSys.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NDSTray.exe] - NDSTray.exe
HKLM\...\Run: [UIExec] - C:\Program Files\Join Air\UIExec.exe [132608 2009-08-31] ()
HKLM\...\Run: [PPort12reminder] - C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe [328992 2007-08-31] (Nuance Communications, Inc.)
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] - C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [ControlCenter4] - C:\Program Files\ControlCenter4\BrCcBoot.exe [139264 2010-10-26] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] - C:\Program Files\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [SSBkgdUpdate] - C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM\...\Run: [IndexSearch] - C:\Program Files\Nuance\PaperPort\IndexSearch.exe [46368 2008-07-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PPort11reminder] - C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe [328992 2007-08-31] (Nuance Communications, Inc.)
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-12-23] (Intel Corporation)
HKU\S-1-5-21-3372144804-2533914639-1054969159-1000\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3372144804-2533914639-1054969159-1000\...\Run: [TOSCDSPD] - C:\Program Files\ACER\TOSCDSPD\toscdspd.exe [430080 2008-04-24] (ACER)
HKU\S-1-5-21-3372144804-2533914639-1054969159-1000\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {08BD8B7C-6EDF-4F08-ABA9-7F9CC9DE4D42} URL = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=4c3a222c-6862-4f84-b021-6864cc3a0544&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {1B0644E5-C15F-4AEF-8C10-472C93242465} URL = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=4c3a222c-6862-4f84-b021-6864cc3a0544&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {3BC3ABF4-4751-4BE8-92E4-A42397EF76FB} URL = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=4c3a222c-6862-4f84-b021-6864cc3a0544&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {8455DAAD-5A91-4CD3-B8D7-EA4B09AA41F2} URL = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=4c3a222c-6862-4f84-b021-6864cc3a0544&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {8C151852-D48F-4A5A-98DE-31893ADCE34A} URL = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=4c3a222c-6862-4f84-b021-6864cc3a0544&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {E04011E0-4782-41BC-A17E-FD55BCA1D569} URL = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=4c3a222c-6862-4f84-b021-6864cc3a0544&pid=fotofreeware&mode=bounce&k=0
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: ChromeFrame BHO - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome Frame\Application\27.0.1453.110\npchrome_frame.dll (Google Inc.)
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome Frame\Application\27.0.1453.110\npchrome_frame.dll (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.1.2.1
FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default
FF user.js: detected! => C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\user.js
FF DefaultSearchEngine: Conduit Search
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: bebomedia.com/OfferMosquitoIEHelper - C:\Users\user\AppData\Local\ext_offermosquito\npOfferMosquitoIEHelper.dll No File
FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\searchplugins\de2b94fc-51e4-4a40-b737-711ad7e33c69.xml
FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\searchplugins\{272BDC81-5292-4FAE-9491-FBA3FF104A82}.xml
FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\searchplugins\{300E9015-F74C-4ACC-B898-FD12C8BDDF8D}.xml
FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\searchplugins\{763C485D-1C65-4092-8959-0BD7FEAC0A8E}.xml
FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\searchplugins\{B468D502-C186-4DA0-A4ED-B672D23E7675}.xml
FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\searchplugins\{E0B9B3B0-212D-4AEE-BBF0-16360D253EB3}.xml
FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\searchplugins\{F612F2A0-0E1E-4266-8F32-5E822EDEAC20}.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Amazon-Icon - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\Extensions\amazon-icon@giga.de [2014-03-15]
FF Extension: FireJump - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\Extensions\firejump@firejump.net [2014-03-15]
FF Extension: Bitdefender QuickScan - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2014-03-26]
FF Extension: OfferMosquito - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cjxsd530.default\Extensions\om@offermosquito.com.xpi [2014-02-28]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
Chrome:
=======
CHR HomePage: hxxp://www.trovigo.com/?gd=&ctid=CT3324415&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPE2FF63DE-B413-42D5-B448-ADCB8CE5CAA4&SSPV=
CHR Extension: (Google Docs) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-24]
CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-24]
CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-24]
CHR Extension: (Google-Suche) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-24]
CHR Extension: (Amazon-Icon) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg [2014-03-26]
CHR Extension: (Google Wallet) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-25]
CHR Extension: (Google Mail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-24]
CHR HKLM\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\user\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx [2014-03-15]
========================== Services (Whitelisted) =================
R3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.)
R2 UI Assistant Service; C:\Program Files\Join Air\AssistantServices.exe [241664 2009-08-31] ()
S2 IAANTMON; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [X]
S2 PDFProFiltSrvPP; C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [X]
==================== Drivers (Whitelisted) ====================
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-03-27] (Malwarebytes Corporation)
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [47632 2013-04-29] (Panda Security, S.L.)
R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [290304 2007-12-26] (Realtek Semiconductor Corporation )
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\TOSHIB~1.TOS\AppData\Local\Temp\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-29 14:25 - 2014-03-29 14:25 - 00013632 _____ () C:\Users\user\Desktop\FRST.txt
2014-03-29 14:25 - 2014-03-29 14:25 - 00000000 ____D () C:\FRST
2014-03-29 14:24 - 2014-03-13 18:57 - 01145856 _____ (Farbar) C:\Users\user\Desktop\FRST.exe
2014-03-28 08:19 - 2014-03-28 08:21 - 00000000 ____D () C:\e60b5eb8aa7bcb42c3d84e89169f93
2014-03-28 08:01 - 2014-03-28 08:01 - 18733360 _____ (Microsoft Corporation) C:\Users\user\Downloads\IE9-WindowsVista-x86-deu.exe
2014-03-28 07:27 - 2014-03-28 07:27 - 00000000 ____D () C:\Users\user\AppData\Local\WindowsUpdate
2014-03-28 07:26 - 2014-03-28 07:27 - 04413904 _____ (Avira Operations GmbH & Co. KG) C:\Users\user\Downloads\avira_de_av___ws(1).exe
2014-03-28 07:26 - 2014-03-28 07:26 - 04413904 _____ (Avira Operations GmbH & Co. KG) C:\Users\user\Downloads\avira_de_av___ws.exe
2014-03-28 07:15 - 2013-04-16 16:46 - 00000413 _____ () C:\Users\user\Desktop\Reset_Windows_Update_History.bat
2014-03-27 20:53 - 2014-03-27 20:53 - 00000000 ____D () C:\Windows\system32\SPReview
2014-03-27 15:14 - 2013-12-18 07:13 - 00231584 _____ (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-03-27 15:09 - 2014-03-27 15:10 - 00258750 _____ () C:\Windows\msxml4-KB973685-enu.LOG
2014-03-27 14:29 - 2014-03-27 14:31 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-27 13:44 - 2014-03-27 13:46 - 00000000 ____D () C:\a36f62b2c58cedcf59e4f8a0
2014-03-27 13:34 - 2014-03-27 13:34 - 00000000 ____D () C:\Users\user\AppData\Roaming\Intel Corporation
2014-03-27 13:31 - 2009-12-17 10:25 - 00433176 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStor.sys
2014-03-27 13:20 - 2014-03-27 13:20 - 00000000 ____D () C:\Windows\system32\EventProviders
2014-03-27 13:20 - 2009-04-11 12:36 - 365230920 _____ (Microsoft Corporation) C:\Users\user\Desktop\Windows6.0-KB948465-X86.exe
2014-03-27 08:14 - 2014-03-27 08:15 - 00000000 ___SD () C:\32788R22FWJFW
2014-03-27 08:11 - 2014-03-27 08:11 - 00162010 _____ () C:\Users\user\Downloads\DIAG_MATS_NETWORK_global.DiagCab
2014-03-27 08:10 - 2014-03-27 08:10 - 00000776 _____ () C:\Windows\ie8_main.log
2014-03-27 07:19 - 2012-09-20 02:17 - 01005568 _____ (Microsoft Corporation) C:\Users\user\Desktop\dotNetFx45_Full_setup.exe
2014-03-27 07:09 - 2014-03-27 07:10 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files
2014-03-27 07:08 - 2014-02-25 16:01 - 257813336 _____ () C:\Users\user\Desktop\kis14.0.0.4651de-de.exe
2014-03-27 07:02 - 2014-03-27 07:02 - 00034750 _____ () C:\ComboFix.txt
2014-03-27 06:51 - 2014-03-27 08:15 - 00000000 ____D () C:\Windows\erdnt
2014-03-26 20:07 - 2014-03-27 06:41 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-26 20:06 - 2014-03-26 20:06 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-26 19:40 - 2014-03-26 19:40 - 00002140 _____ () C:\Users\user\Desktop\attach.txt
2014-03-26 19:10 - 2014-03-26 19:10 - 00000861 _____ () C:\AdwCleaner[S1].txt
2014-03-26 19:10 - 2014-03-26 19:10 - 00000800 _____ () C:\AdwCleaner[R1].txt
2014-03-26 10:18 - 2014-03-26 10:18 - 08326064 _____ (McAfee, Inc.) C:\Users\user\Downloads\SecurityScan_Release.exe
2014-03-26 09:58 - 2014-03-26 09:58 - 00000000 ____D () C:\Program Files\Panda Security
2014-03-26 09:58 - 2013-04-29 08:17 - 00047632 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\PSKMAD.sys
2014-03-26 09:57 - 2014-03-26 09:58 - 28413552 _____ (Panda Security ) C:\Users\user\Downloads\PandaCloudCleaner.exe
2014-03-26 09:51 - 2014-03-26 09:51 - 00185944 _____ (Лаборатория Касперского) C:\Users\user\Downloads\kss12.0.1.117abRU_EN_DE_FR_ES_IT_JA_PT_ZH_5623(1).exe
2014-03-26 09:45 - 2014-03-26 09:45 - 00185944 _____ (Лаборатория Касперского) C:\Users\user\Downloads\kss12.0.1.117abRU_EN_DE_FR_ES_IT_JA_PT_ZH_5623.exe
2014-03-26 09:43 - 2014-03-26 09:48 - 00000000 ____D () C:\Users\user\AppData\Roaming\QuickScan
2014-03-26 09:34 - 2014-03-26 09:35 - 00000000 ____D () C:\AdwCleaner
2014-03-26 09:31 - 2014-03-26 09:32 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\user\Downloads\spybot-2.2.25.exe
2014-03-26 09:28 - 2014-03-26 09:28 - 01950720 _____ () C:\Users\user\Downloads\adwcleaner_3.022.exe
2014-03-26 09:26 - 2014-03-26 09:31 - 138607664 _____ () C:\Users\user\Downloads\avira_free_antivirus_de_14.0.3.350.exe
2014-03-26 07:48 - 2014-03-26 10:18 - 00000424 _____ () C:\AVScanner.ini
2014-03-25 13:51 - 2014-03-28 07:31 - 00000000 ____D () C:\ProgramData\Package Cache
2014-03-19 11:59 - 2014-03-19 11:59 - 00000000 ____D () C:\Users\user\AppData\Local\Scansoft
2014-03-17 12:51 - 2014-03-17 12:51 - 00000050 _____ () C:\Windows\system32\bridf08b.dat
2014-03-17 12:43 - 2014-03-17 12:43 - 00000000 ____D () C:\ProgramData\InstallShield
2014-03-15 23:10 - 2014-03-15 23:10 - 00000000 ____D () C:\Users\user\AppData\Roaming\Helper
2014-03-15 23:10 - 2014-03-15 23:10 - 00000000 ____D () C:\Users\user\AppData\Local\Temp4692faee989ebd3dc9e66fd91d2d8c4a
2014-03-15 23:04 - 2014-03-15 23:04 - 00000000 ____D () C:\Users\user\ChromeExtensions
2014-03-15 23:04 - 2014-03-15 23:04 - 00000000 ____D () C:\Users\user\AppData\Local\Temp980e3c1db7890a9aa6b2d0911b25867e
2014-03-15 23:04 - 2014-03-15 23:04 - 00000000 ____D () C:\Users\user\AppData\Local\{2BE34C9D-9174-4AD3-A478-E970F0DAF4E1}
2014-03-15 23:03 - 2014-03-15 23:03 - 01058296 _____ () C:\Users\user\Downloads\Windows-Live-Fotogalerie-lnstall.exe
2014-03-15 22:41 - 2014-03-15 22:41 - 01292648 _____ (Microsoft Corporation) C:\Users\user\Downloads\wlsetup-web.exe
2014-03-15 22:41 - 2014-03-15 22:41 - 00000000 ____D () C:\Users\user\AppData\Local\{2481AE9D-1E93-46DF-80EC-4A54C4325E39}
2014-03-15 22:10 - 2014-03-29 07:16 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-15 22:08 - 2014-03-26 08:01 - 00000000 ____D () C:\Users\user\AppData\Roaming\DesktopIconForAmazon
2014-03-15 22:08 - 2014-03-15 22:08 - 00000000 ____D () C:\Users\user\AppData\Roaming\Opera
2014-03-15 22:08 - 2014-03-15 22:08 - 00000000 ____D () C:\Users\user\AppData\Roaming\OCS
2014-03-15 22:08 - 2011-05-13 14:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\system32\dhRichClient3.dll
2014-03-15 22:08 - 2011-03-25 22:42 - 00338432 _____ () C:\Windows\system32\sqlite36_engine.dll
2014-03-15 22:03 - 2014-03-15 22:08 - 142608624 _____ (Microsoft Corporation) C:\Users\user\Downloads\wlsetup-all_de_16.4.3505.0912.exe
2014-03-15 21:59 - 2014-03-29 14:24 - 00000000 ____D () C:\Users\user\AppData\Roaming\Fifth
2014-03-15 21:59 - 2014-03-27 06:47 - 00000000 ____D () C:\Users\user\AppData\Roaming\Security System 2
2014-03-15 21:59 - 2014-03-27 06:37 - 00000000 ____D () C:\Users\user\AppData\Local\ext_offermosquito
2014-03-15 21:59 - 2014-03-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\SSync
2014-03-15 21:59 - 2014-03-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\Intermediate
2014-03-15 21:59 - 2014-03-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\DataMgr
2014-03-15 21:56 - 2014-03-15 21:56 - 00000000 ____D () C:\Users\user\AppData\Roaming\Common
2014-03-15 21:56 - 2014-03-15 21:56 - 00000000 ____D () C:\Program Files\Common Files\Windows Live
2014-03-15 21:52 - 2014-03-15 21:52 - 00001892 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-03-15 21:51 - 2014-03-15 21:51 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-15 21:51 - 2014-03-15 21:51 - 00000000 ____D () C:\Program Files\Adobe
2014-03-15 21:50 - 2014-03-19 12:00 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-15 21:44 - 2014-03-26 08:03 - 00000000 ____D () C:\Users\user\AppData\Roaming\PerformerSoft
2014-03-15 21:44 - 2014-03-15 21:44 - 05241504 _____ () C:\Users\user\Downloads\util_su_password_25675A.exe
2014-03-15 21:44 - 2014-03-15 21:44 - 00000864 _____ () C:\Users\user\Desktop\FreePDFReader.lnk
2014-03-15 21:44 - 2014-03-15 21:44 - 00000000 ____D () C:\Users\user\AppData\Roaming\FreePDFReader
2014-03-15 21:44 - 2014-03-15 21:44 - 00000000 ____D () C:\Program Files\FreePDFReader
2014-03-15 21:30 - 2014-03-15 21:30 - 00000000 ____D () C:\Users\user\AppData\Roaming\ControlCenter4
2014-03-15 21:29 - 2014-03-15 21:29 - 00000000 ____D () C:\Users\user\AppData\Roaming\FLEXnet
2014-03-15 21:27 - 2014-03-15 21:27 - 00001921 _____ () C:\Users\Public\Desktop\Brother Creative Center.lnk
2014-03-15 21:22 - 2014-03-15 21:22 - 00000000 ____D () C:\Brother
2014-03-15 21:21 - 2014-03-17 21:49 - 00000000 ____D () C:\Program Files\Brother
2014-03-15 21:21 - 2014-03-15 21:22 - 00000000 ____D () C:\Program Files\Browny02
2014-03-15 21:21 - 2014-03-15 21:21 - 00000000 ____D () C:\ProgramData\ControlCenter4
2014-03-15 21:21 - 2014-03-15 21:21 - 00000000 ____D () C:\Program Files\ControlCenter4
2014-03-15 21:21 - 2010-08-02 20:57 - 00217088 _____ (brother) C:\Windows\system32\NSSearch.dll
2014-03-15 21:21 - 2010-06-10 07:09 - 01475072 _____ (Brother Industries, Ltd.) C:\Windows\system32\BrWi209d.dll
2014-03-15 21:21 - 2010-06-07 12:18 - 00055808 _____ (Brother Industries, Ltd.) C:\Windows\system32\BrUsi09d.dll
2014-03-15 21:21 - 2010-05-10 09:45 - 00103736 _____ (Brother Industries Ltd) C:\Windows\system32\BRRBTOOL.EXE
2014-03-15 21:21 - 2010-04-02 06:33 - 00025299 _____ (Brother Industries, Ltd) C:\Windows\system32\BRLM03A.DLL
2014-03-15 21:21 - 2010-04-01 11:28 - 00217088 _____ (Brother Industries, Ltd.) C:\Windows\system32\BrJDec.dll
2014-03-15 21:21 - 2010-03-15 19:45 - 00073728 _____ (Brother Industries Ltd.) C:\Windows\system32\BrDctF2.dll
2014-03-15 21:21 - 2010-02-05 11:42 - 00180224 _____ (Brother Industries, Ltd.) C:\Windows\system32\BroSNMP.dll
2014-03-15 21:21 - 2009-01-15 19:20 - 00003072 _____ (Brother Industries Ltd.) C:\Windows\system32\BrDctF2S.dll
2014-03-15 21:21 - 2007-12-13 22:16 - 00005632 _____ (Brother Industries Ltd.) C:\Windows\system32\BrDctF2L.dll
2014-03-15 21:21 - 2005-01-17 08:10 - 00045056 _____ () C:\Windows\system32\BRTCPCON.DLL
2014-03-15 21:21 - 2004-08-09 08:00 - 00000114 _____ () C:\Windows\system32\BRLMW03A.INI
2014-03-15 21:21 - 2004-08-09 07:42 - 00077824 _____ (Brother Industries, Ltd.) C:\Windows\system32\BRLMW03A.DLL
2014-03-15 21:21 - 1999-10-26 17:00 - 00000050 _____ () C:\Windows\system32\BRADM10A.DAT
2014-03-15 21:19 - 2014-03-15 21:19 - 00000000 ____D () C:\ProgramData\zeon
2014-03-15 21:18 - 2014-03-15 21:18 - 00000000 ____D () C:\Users\user\AppData\Roaming\Nuance
2014-03-15 21:17 - 2014-03-17 12:41 - 00000000 ____D () C:\ProgramData\ScanSoft
2014-03-15 21:16 - 2014-03-17 12:45 - 00000000 ____D () C:\Program Files\Nuance
2014-03-15 21:16 - 2014-03-17 12:41 - 00000000 ____D () C:\Program Files\Common Files\ScanSoft Shared
2014-03-15 21:16 - 2014-03-15 21:19 - 00000000 ____D () C:\ProgramData\Nuance
2014-03-15 21:16 - 2014-03-15 21:16 - 00000000 ____D () C:\ProgramData\FLEXnet
2014-03-15 21:15 - 2014-03-15 21:26 - 00000000 ____D () C:\ProgramData\Brother
2014-03-15 21:15 - 2014-03-15 21:15 - 00000000 ____D () C:\Program Files\MSXML 4.0
2014-03-15 18:35 - 2014-03-15 18:35 - 00003584 _____ () C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-13 14:19 - 2014-03-13 14:19 - 00008565 _____ () C:\Users\user\Desktop\versuch.odt
2014-03-13 14:10 - 2014-03-13 14:10 - 00000360 _____ () C:\Users\user\Desktop\IBK - Verknüpfung.lnk
2014-03-13 14:10 - 2014-03-13 14:10 - 00000360 _____ () C:\Users\user\Desktop\DSK - Verknüpfung.lnk
2014-03-11 21:18 - 2009-08-19 15:52 - 00000625 _____ () C:\NetworkCfg.xml
2014-03-11 21:16 - 2014-03-11 21:17 - 00013810 _____ () C:\Windows\ZTEInstallInfo.log
2014-03-11 21:16 - 2009-04-22 16:35 - 00009728 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\massfilter.sys
2014-03-11 21:16 - 2009-03-10 15:38 - 00110080 _____ (ZTE Corporation) C:\Windows\system32\Drivers\ZTEusbnet.sys
2014-03-11 21:16 - 2009-02-02 18:14 - 00105344 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbnmea.sys
2014-03-11 21:16 - 2009-02-02 18:14 - 00104960 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbser6k.sys
2014-03-11 21:16 - 2009-02-02 18:14 - 00104960 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbmdm6k.sys
2014-03-11 21:15 - 2014-03-11 21:18 - 00000000 ____D () C:\Program Files\Join Air
2014-03-11 21:15 - 2014-03-11 21:15 - 00001483 _____ () C:\Users\Public\Desktop\Join Air.lnk
2014-03-11 21:15 - 2014-03-11 21:15 - 00000000 ____D () C:\Windows\system32\SupportAppCB
2014-03-06 10:02 - 2014-03-06 15:00 - 00018764 _____ () C:\Users\user\Desktop\für Max Josef - Versuch.odt
2014-03-04 14:10 - 2014-03-15 21:53 - 00000000 ____D () C:\Users\user\AppData\Roaming\Adobe
2014-03-04 14:10 - 2014-03-04 14:10 - 00000000 ____D () C:\Users\user\AppData\Roaming\Macromedia
2014-03-04 14:10 - 2014-03-04 14:10 - 00000000 ____D () C:\Users\user\AppData\Local\Macromedia
2014-03-04 14:09 - 2014-03-29 13:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-04 14:09 - 2014-03-15 21:53 - 00000000 ____D () C:\Users\user\AppData\Local\Adobe
2014-03-04 14:09 - 2014-03-13 12:54 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-04 14:09 - 2014-03-13 12:54 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-04 14:09 - 2014-03-04 14:09 - 00000000 ____D () C:\Windows\system32\Macromed
2014-03-04 14:09 - 2014-03-04 14:09 - 00000000 ____D () C:\ProgramData\McAfee
2014-03-04 14:02 - 2014-03-04 14:02 - 00000000 ____D () C:\Users\user\AppData\Roaming\Mozilla
2014-03-04 14:02 - 2014-03-04 14:02 - 00000000 ____D () C:\Users\user\AppData\Local\Mozilla
2014-03-04 14:01 - 2014-03-04 14:01 - 00000846 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-03-04 14:01 - 2014-03-04 14:01 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-04 14:01 - 2014-03-04 14:01 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-03-04 14:01 - 2014-03-04 14:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2014-03-29 14:25 - 2014-03-29 14:25 - 00013632 _____ () C:\Users\user\Desktop\FRST.txt
2014-03-29 14:25 - 2014-03-29 14:25 - 00000000 ____D () C:\FRST
2014-03-29 14:24 - 2014-03-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\Fifth
2014-03-29 14:24 - 2014-02-24 21:33 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-29 14:24 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-29 14:24 - 2006-11-02 13:47 - 00004192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-29 14:24 - 2006-11-02 13:47 - 00004192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-29 13:55 - 2008-01-21 02:35 - 01232828 _____ () C:\Windows\WindowsUpdate.log
2014-03-29 13:55 - 2006-11-02 14:01 - 00023928 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-29 13:54 - 2014-03-04 14:09 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-29 13:51 - 2014-02-24 21:33 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-29 09:56 - 2014-02-13 09:43 - 00058672 _____ () C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-29 09:30 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\rescache
2014-03-29 09:14 - 2006-11-02 13:47 - 00264488 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-29 09:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\de-DE
2014-03-29 09:11 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\system32\XPSViewer
2014-03-29 09:11 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Movie Maker
2014-03-29 07:36 - 2014-02-24 21:13 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-29 07:16 - 2014-03-15 22:10 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-28 08:21 - 2014-03-28 08:19 - 00000000 ____D () C:\e60b5eb8aa7bcb42c3d84e89169f93
2014-03-28 08:01 - 2014-03-28 08:01 - 18733360 _____ (Microsoft Corporation) C:\Users\user\Downloads\IE9-WindowsVista-x86-deu.exe
2014-03-28 07:31 - 2014-03-25 13:51 - 00000000 ____D () C:\ProgramData\Package Cache
2014-03-28 07:27 - 2014-03-28 07:27 - 00000000 ____D () C:\Users\user\AppData\Local\WindowsUpdate
2014-03-28 07:27 - 2014-03-28 07:26 - 04413904 _____ (Avira Operations GmbH & Co. KG) C:\Users\user\Downloads\avira_de_av___ws(1).exe
2014-03-28 07:26 - 2014-03-28 07:26 - 04413904 _____ (Avira Operations GmbH & Co. KG) C:\Users\user\Downloads\avira_de_av___ws.exe
2014-03-28 07:15 - 2006-11-02 13:52 - 00102487 _____ () C:\Windows\setupact.log
2014-03-28 03:35 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-03-28 03:14 - 2008-01-21 03:47 - 00022120 _____ () C:\Windows\PFRO.log
2014-03-28 03:03 - 2014-02-24 21:15 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-03-27 21:12 - 2008-01-21 08:15 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE
2014-03-27 21:12 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-03-27 21:12 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Photo Gallery
2014-03-27 21:12 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Journal
2014-03-27 21:12 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Defender
2014-03-27 21:12 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Collaboration
2014-03-27 21:12 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Calendar
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\zh-TW
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\zh-CN
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\uk-UA
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\th-TH
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sv-SE
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\SLUI
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sl-SI
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sk-SK
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ru-RU
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ro-RO
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pt-PT
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pt-BR
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pl-PL
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\nl-NL
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\nb-NO
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\lv-LV
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\lt-LT
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ko-KR
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ja-JP
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\it-IT
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\hu-HU
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\hr-HR
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\he-IL
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\fr-FR
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\fi-FI
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\et-EE
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\el-GR
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\bg-BG
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ar-SA
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\IME
2014-03-27 21:12 - 2006-11-02 12:18 - 00000000 ____D () C:\Program Files\Common Files\System
2014-03-27 20:53 - 2014-03-27 20:53 - 00000000 ____D () C:\Windows\system32\SPReview
2014-03-27 15:10 - 2014-03-27 15:09 - 00258750 _____ () C:\Windows\msxml4-KB973685-enu.LOG
2014-03-27 15:03 - 2014-02-13 09:43 - 00000000 ____D () C:\Users\user
2014-03-27 14:31 - 2014-03-27 14:29 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-27 13:46 - 2014-03-27 13:44 - 00000000 ____D () C:\a36f62b2c58cedcf59e4f8a0
2014-03-27 13:34 - 2014-03-27 13:34 - 00000000 ____D () C:\Users\user\AppData\Roaming\Intel Corporation
2014-03-27 13:33 - 2014-02-13 10:02 - 00000000 ____D () C:\Program Files\Intel
2014-03-27 13:33 - 2014-02-13 09:58 - 00000000 ____D () C:\Windows\system32\Lang
2014-03-27 13:20 - 2014-03-27 13:20 - 00000000 ____D () C:\Windows\system32\EventProviders
2014-03-27 08:15 - 2014-03-27 08:14 - 00000000 ___SD () C:\32788R22FWJFW
2014-03-27 08:15 - 2014-03-27 06:51 - 00000000 ____D () C:\Windows\erdnt
2014-03-27 08:11 - 2014-03-27 08:11 - 00162010 _____ () C:\Users\user\Downloads\DIAG_MATS_NETWORK_global.DiagCab
2014-03-27 08:10 - 2014-03-27 08:10 - 00000776 _____ () C:\Windows\ie8_main.log
2014-03-27 07:10 - 2014-03-27 07:09 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files
2014-03-27 07:02 - 2014-03-27 07:02 - 00034750 _____ () C:\ComboFix.txt
2014-03-27 07:02 - 2006-11-02 12:18 - 00000000 __RHD () C:\Users\Default
2014-03-27 07:02 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public
2014-03-27 06:58 - 2006-11-02 11:23 - 00000215 _____ () C:\Windows\system.ini
2014-03-27 06:47 - 2014-03-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\Security System 2
2014-03-27 06:41 - 2014-03-26 20:07 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-27 06:37 - 2014-03-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Local\ext_offermosquito
2014-03-27 06:37 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\Performance
2014-03-26 20:06 - 2014-03-26 20:06 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-26 19:40 - 2014-03-26 19:40 - 00002140 _____ () C:\Users\user\Desktop\attach.txt
2014-03-26 19:10 - 2014-03-26 19:10 - 00000861 _____ () C:\AdwCleaner[S1].txt
2014-03-26 19:10 - 2014-03-26 19:10 - 00000800 _____ () C:\AdwCleaner[R1].txt
2014-03-26 10:18 - 2014-03-26 10:18 - 08326064 _____ (McAfee, Inc.) C:\Users\user\Downloads\SecurityScan_Release.exe
2014-03-26 10:18 - 2014-03-26 07:48 - 00000424 _____ () C:\AVScanner.ini
2014-03-26 09:58 - 2014-03-26 09:58 - 00000000 ____D () C:\Program Files\Panda Security
2014-03-26 09:58 - 2014-03-26 09:57 - 28413552 _____ (Panda Security ) C:\Users\user\Downloads\PandaCloudCleaner.exe
2014-03-26 09:51 - 2014-03-26 09:51 - 00185944 _____ (Лаборатория Касперского) C:\Users\user\Downloads\kss12.0.1.117abRU_EN_DE_FR_ES_IT_JA_PT_ZH_5623(1).exe
2014-03-26 09:48 - 2014-03-26 09:43 - 00000000 ____D () C:\Users\user\AppData\Roaming\QuickScan
2014-03-26 09:45 - 2014-03-26 09:45 - 00185944 _____ (Лаборатория Касперского) C:\Users\user\Downloads\kss12.0.1.117abRU_EN_DE_FR_ES_IT_JA_PT_ZH_5623.exe
2014-03-26 09:41 - 2014-02-13 09:43 - 00000680 _____ () C:\Users\user\AppData\Local\d3d9caps.dat
2014-03-26 09:35 - 2014-03-26 09:34 - 00000000 ____D () C:\AdwCleaner
2014-03-26 09:32 - 2014-03-26 09:31 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\user\Downloads\spybot-2.2.25.exe
2014-03-26 09:31 - 2014-03-26 09:26 - 138607664 _____ () C:\Users\user\Downloads\avira_free_antivirus_de_14.0.3.350.exe
2014-03-26 09:28 - 2014-03-26 09:28 - 01950720 _____ () C:\Users\user\Downloads\adwcleaner_3.022.exe
2014-03-26 08:03 - 2014-03-15 21:44 - 00000000 ____D () C:\Users\user\AppData\Roaming\PerformerSoft
2014-03-26 08:01 - 2014-03-15 22:08 - 00000000 ____D () C:\Users\user\AppData\Roaming\DesktopIconForAmazon
2014-03-21 13:47 - 2014-02-24 21:16 - 00002721 _____ () C:\Users\user\Desktop\Microsoft Outlook 2010.lnk
2014-03-20 10:43 - 2014-02-24 21:34 - 00001963 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-19 12:00 - 2014-03-15 21:50 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-19 11:59 - 2014-03-19 11:59 - 00000000 ____D () C:\Users\user\AppData\Local\Scansoft
2014-03-17 21:49 - 2014-03-15 21:21 - 00000000 ____D () C:\Program Files\Brother
2014-03-17 21:49 - 2014-02-13 09:59 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-03-17 12:51 - 2014-03-17 12:51 - 00000050 _____ () C:\Windows\system32\bridf08b.dat
2014-03-17 12:45 - 2014-03-15 21:16 - 00000000 ____D () C:\Program Files\Nuance
2014-03-17 12:43 - 2014-03-17 12:43 - 00000000 ____D () C:\ProgramData\InstallShield
2014-03-17 12:41 - 2014-03-15 21:17 - 00000000 ____D () C:\ProgramData\ScanSoft
2014-03-17 12:41 - 2014-03-15 21:16 - 00000000 ____D () C:\Program Files\Common Files\ScanSoft Shared
2014-03-17 12:41 - 2014-02-13 10:01 - 00000000 ____D () C:\Program Files\Common Files\InstallShield
2014-03-15 23:10 - 2014-03-15 23:10 - 00000000 ____D () C:\Users\user\AppData\Roaming\Helper
2014-03-15 23:10 - 2014-03-15 23:10 - 00000000 ____D () C:\Users\user\AppData\Local\Temp4692faee989ebd3dc9e66fd91d2d8c4a
2014-03-15 23:04 - 2014-03-15 23:04 - 00000000 ____D () C:\Users\user\ChromeExtensions
2014-03-15 23:04 - 2014-03-15 23:04 - 00000000 ____D () C:\Users\user\AppData\Local\Temp980e3c1db7890a9aa6b2d0911b25867e
2014-03-15 23:04 - 2014-03-15 23:04 - 00000000 ____D () C:\Users\user\AppData\Local\{2BE34C9D-9174-4AD3-A478-E970F0DAF4E1}
2014-03-15 23:03 - 2014-03-15 23:03 - 01058296 _____ () C:\Users\user\Downloads\Windows-Live-Fotogalerie-lnstall.exe
2014-03-15 22:41 - 2014-03-15 22:41 - 01292648 _____ (Microsoft Corporation) C:\Users\user\Downloads\wlsetup-web.exe
2014-03-15 22:41 - 2014-03-15 22:41 - 00000000 ____D () C:\Users\user\AppData\Local\{2481AE9D-1E93-46DF-80EC-4A54C4325E39}
2014-03-15 22:08 - 2014-03-15 22:08 - 00000000 ____D () C:\Users\user\AppData\Roaming\Opera
2014-03-15 22:08 - 2014-03-15 22:08 - 00000000 ____D () C:\Users\user\AppData\Roaming\OCS
2014-03-15 22:08 - 2014-03-15 22:03 - 142608624 _____ (Microsoft Corporation) C:\Users\user\Downloads\wlsetup-all_de_16.4.3505.0912.exe
2014-03-15 21:59 - 2014-03-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\SSync
2014-03-15 21:59 - 2014-03-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\Intermediate
2014-03-15 21:59 - 2014-03-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\DataMgr
2014-03-15 21:58 - 2014-02-24 21:33 - 00000000 ____D () C:\Users\user\AppData\Local\Google
2014-03-15 21:58 - 2014-02-24 21:33 - 00000000 ____D () C:\Program Files\Google
2014-03-15 21:56 - 2014-03-15 21:56 - 00000000 ____D () C:\Users\user\AppData\Roaming\Common
2014-03-15 21:56 - 2014-03-15 21:56 - 00000000 ____D () C:\Program Files\Common Files\Windows Live
2014-03-15 21:53 - 2014-03-04 14:10 - 00000000 ____D () C:\Users\user\AppData\Roaming\Adobe
2014-03-15 21:53 - 2014-03-04 14:09 - 00000000 ____D () C:\Users\user\AppData\Local\Adobe
2014-03-15 21:52 - 2014-03-15 21:52 - 00001892 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-03-15 21:51 - 2014-03-15 21:51 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-15 21:51 - 2014-03-15 21:51 - 00000000 ____D () C:\Program Files\Adobe
2014-03-15 21:44 - 2014-03-15 21:44 - 05241504 _____ () C:\Users\user\Downloads\util_su_password_25675A.exe
2014-03-15 21:44 - 2014-03-15 21:44 - 00000864 _____ () C:\Users\user\Desktop\FreePDFReader.lnk
2014-03-15 21:44 - 2014-03-15 21:44 - 00000000 ____D () C:\Users\user\AppData\Roaming\FreePDFReader
2014-03-15 21:44 - 2014-03-15 21:44 - 00000000 ____D () C:\Program Files\FreePDFReader
2014-03-15 21:30 - 2014-03-15 21:30 - 00000000 ____D () C:\Users\user\AppData\Roaming\ControlCenter4
2014-03-15 21:29 - 2014-03-15 21:29 - 00000000 ____D () C:\Users\user\AppData\Roaming\FLEXnet
2014-03-15 21:27 - 2014-03-15 21:27 - 00001921 _____ () C:\Users\Public\Desktop\Brother Creative Center.lnk
2014-03-15 21:26 - 2014-03-15 21:15 - 00000000 ____D () C:\ProgramData\Brother
2014-03-15 21:26 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\twain_32
2014-03-15 21:22 - 2014-03-15 21:22 - 00000000 ____D () C:\Brother
2014-03-15 21:22 - 2014-03-15 21:21 - 00000000 ____D () C:\Program Files\Browny02
2014-03-15 21:21 - 2014-03-15 21:21 - 00000000 ____D () C:\ProgramData\ControlCenter4
2014-03-15 21:21 - 2014-03-15 21:21 - 00000000 ____D () C:\Program Files\ControlCenter4
2014-03-15 21:19 - 2014-03-15 21:19 - 00000000 ____D () C:\ProgramData\zeon
2014-03-15 21:19 - 2014-03-15 21:16 - 00000000 ____D () C:\ProgramData\Nuance
2014-03-15 21:18 - 2014-03-15 21:18 - 00000000 ____D () C:\Users\user\AppData\Roaming\Nuance
2014-03-15 21:16 - 2014-03-15 21:16 - 00000000 ____D () C:\ProgramData\FLEXnet
2014-03-15 21:15 - 2014-03-15 21:15 - 00000000 ____D () C:\Program Files\MSXML 4.0
2014-03-15 18:35 - 2014-03-15 18:35 - 00003584 _____ () C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-13 18:57 - 2014-03-29 14:24 - 01145856 _____ (Farbar) C:\Users\user\Desktop\FRST.exe
2014-03-13 14:19 - 2014-03-13 14:19 - 00008565 _____ () C:\Users\user\Desktop\versuch.odt
2014-03-13 14:10 - 2014-03-13 14:10 - 00000360 _____ () C:\Users\user\Desktop\IBK - Verknüpfung.lnk
2014-03-13 14:10 - 2014-03-13 14:10 - 00000360 _____ () C:\Users\user\Desktop\DSK - Verknüpfung.lnk
2014-03-13 12:54 - 2014-03-04 14:09 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-13 12:54 - 2014-03-04 14:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-11 21:18 - 2014-03-11 21:15 - 00000000 ____D () C:\Program Files\Join Air
2014-03-11 21:17 - 2014-03-11 21:16 - 00013810 _____ () C:\Windows\ZTEInstallInfo.log
2014-03-11 21:15 - 2014-03-11 21:15 - 00001483 _____ () C:\Users\Public\Desktop\Join Air.lnk
2014-03-11 21:15 - 2014-03-11 21:15 - 00000000 ____D () C:\Windows\system32\SupportAppCB
2014-03-06 15:00 - 2014-03-06 10:02 - 00018764 _____ () C:\Users\user\Desktop\für Max Josef - Versuch.odt
2014-03-04 14:10 - 2014-03-04 14:10 - 00000000 ____D () C:\Users\user\AppData\Roaming\Macromedia
2014-03-04 14:10 - 2014-03-04 14:10 - 00000000 ____D () C:\Users\user\AppData\Local\Macromedia
2014-03-04 14:09 - 2014-03-04 14:09 - 00000000 ____D () C:\Windows\system32\Macromed
2014-03-04 14:09 - 2014-03-04 14:09 - 00000000 ____D () C:\ProgramData\McAfee
2014-03-04 14:02 - 2014-03-04 14:02 - 00000000 ____D () C:\Users\user\AppData\Roaming\Mozilla
2014-03-04 14:02 - 2014-03-04 14:02 - 00000000 ____D () C:\Users\user\AppData\Local\Mozilla
2014-03-04 14:01 - 2014-03-04 14:01 - 00000846 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-03-04 14:01 - 2014-03-04 14:01 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-04 14:01 - 2014-03-04 14:01 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-03-04 14:01 - 2014-03-04 14:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-03-02 14:03 - 2006-11-02 11:24 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-29 13:31
==================== End Of Log ============================ --- --- ---
--- --- --- |