Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   lrcnta + srptm, graue Felder (https://www.trojaner-board.de/158379-lrcnta-srptm-graue-felder.html)

Snoosel 07.09.2014 12:52

lrcnta + srptm, graue Felder
 
Hallo,
es öffnen sich seit gestern
2 graue Felder grauen Feld (lrcnta + srptm), beim weggeklicken :twak:erscheinen sie sie im Sekundentakt.
Arbeiten am Rechner ist unmöglich.
Ich muß dazu sagen, dass ich jetzt von meinem Rechner schreibe, das Problem ist auf dem Rechner meines Mannes.

Kann mir jemand helfen?

Schöne Grüße Ute

cosinus 07.09.2014 13:08

Hallo und :hallo:

Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten!
Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht!




Zudem bitte auch ein Log mit Farbars Tool machen:

Scan mit Farbar's Recovery Scan Tool (FRST)

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Snoosel 07.09.2014 17:45

Hallo Cosinus,

schon beim Runterladen des Farbar's Recovery Scan Tool´s reagiert das Programm nicht mehr. Wir kommen bis zum Scan, dann ist Feierabend. Der Balken bleibt stehen bei: Scanning Registry: HKCU/Software/Classes/CLSID.

das Virenprogramm läßt den download zu

Das Virenprogramm G-Data hat einen Virus gefunden. Keine Ahnung welchen, mein Mann hat ihn sofort gelöscht.

Nach langem experimentieren sind weitere Probleme entstanden.
Weder Farbar's Recovery Scan Tool noch Malwarebytes Anti-Malware können ihren Job machen. Beide Programme reagieren mit der Zeit nicht mehr und sind dann verschwunden.
Puhhh, habt Ihr noch eine Möglichkeit?
Gruß Ute

cosinus 07.09.2014 17:50

GDATA komplett deaktivieren, dann mit FRST nochmal probieren

Snoosel 07.09.2014 18:30

Nach nochmaligen Versuchen Malwarebytes zu aktivieren (mit G-Data aus) kommt das graue Feld:
Malewarebytes Anti-Maleware funktioniert nicht mehr. Das Programm wird aufgrund eines Problems nicht richtig ausgeführt. Das Programm wird geschlossen und Sie werden benachrichtigt, wenn eine Lösung verfügbar ist.

Und nix geht mehr.

cosinus 07.09.2014 21:48

Wir sind immer noch bei FRST, nicht bei malwarebytes

Snoosel 07.09.2014 21:57

Sorry,
bei FRST ist es so wie mit G-Data und ohne, ich komme bis "Scan" und dann bleibt das Programm (eigentlich der ganze Rechner) stehen. Nichts tut sich. Erst wenn der Task-Manager das Programm beendet läuft der Rechner wieder.

cosinus 07.09.2014 22:21

In Windows mit einem anderen Benutzerkonto anmelden und von da aus erneut FRST runterladen und starten. Falls kein anderes Benutzerkonto da ist, musst du eins mit Adminrechten erstellen über die Systemsteuerung/Benutzerkonten

Snoosel 08.09.2014 08:53

Guten Morgen,
Benutzerkonto geändert, MS Windows sagt, Windows-Sidebar funktioniert nicht mehr.
Er hängt sich auf, Task-Manager anschließend auch. Anzeige: "Keine Rückmeldung"

Seit 1 Std. schon

cosinus 08.09.2014 08:56

Und weiter? Was ist jetzt mit FRST?

Snoosel 08.09.2014 10:58

ich komme nicht soweit. FRST wird gestartet und bleibt stehen bei: Scanning Registry: HKCU/Software/Classes/CLSID.

cosinus 08.09.2014 10:59

Welches Windows hast du da eigentlich? Vista? 7? 8? 8.1?

Snoosel 08.09.2014 11:21

Obwohl die Administrationsrechte geändert sind.

Zitat:

Zitat von cosinus (Beitrag 1355936)
Welches Windows hast du da eigentlich? Vista? 7? 8? 8.1?

wo kann ich das erfahren?

Hab über Tune Up nachgesehen.
Vista Home Premium 64 bit.
Version 6.0.6002 Service Pack 2


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-09-2014 01
Ran by Ute (administrator) on MANOPOST-PC on 08-09-2014 12:14:52
Running from C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A1IGUS3K
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(AOL LLC) C:\Program Files (x86)\Common Files\aol\acs\AOLacsd.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files (x86)\LPT\srpts.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\LPT\srptsl.exe
() J:\Tobit Radio.fx\Server\rfx-server.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\loggingserver.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\AVKBap64.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(AOL, LLC.) C:\Program Files (x86)\AOL 9.0 VR\waol.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GDKBFltExe32.exe
(America Online, Inc.) C:\Program Files (x86)\Common Files\aol\1231342872\ee\aolsoftware.exe
(AOL, LLC.) C:\Program Files (x86)\AOL 9.0 VR\shellmon.exe
(TuneUp Software) C:\Windows\System32\TuneUpDefragService.exe
() C:\Program Files (x86)\LPT\srptm.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe
(America Online Inc) C:\Program Files (x86)\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe
(Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Farbar) C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A1IGUS3K\FRST64[1].exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [ITSecMng] => C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [83336 2009-07-22] (TOSHIBA CORPORATION)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe
HKU\.DEFAULT\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
HKU\.DEFAULT\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-243317379-2889874547-3061927781-1001\...\Run: [AOL Fast Start] => C:\Program Files (x86)\AOL 9.0 VR\AOL.EXE [50480 2007-06-21] (AOL, LLC.)
AppInit_DLLs: C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil64.dll => C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil64.dll File Not Found
AppInit_DLLs-x32: C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil.dll => "C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil.dll" File Not Found
IFEO: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\bip_camera1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\browser7.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\btassist1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\coverdes.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\discspeed.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\drivespeed.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\eccenter1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\excel.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\express.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\frontpg.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\groove.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\hpwucli.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\infopath.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\infotool.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\lifecam.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mobiletrans.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\msaccess.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\msoxmled.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mspub.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mstore.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mypc backup.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nero.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neroburnrights.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerohome.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neromediahome.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerorescueagent.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neroscoutoptions.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerostartsmart.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerovision.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\offdiag.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\ois.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\onenote.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\osa.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\outlook.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\photosnap.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\photosnapviewer.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\powerpnt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\pptview.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\recode.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\setupx.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\showtime.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\skype.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\soundtrax.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\tosbtmng.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\tosbtproc1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\uninst.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\usrguide.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\waveedit.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\winword.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\wirelessftp1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\wlangui.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\zune.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt1" -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt2" -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt3" -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt4" -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt5" -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt6" -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt7" -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt8" -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/cpm-redir/ie-9.html
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.t-online.de/cpm-redir/ie-9.html
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.t-online.de/cpm-redir/ie-9.html
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.t-online.de/cpm-redir/ie-9.html
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.sweet-page.com/?type=hp&ts=1408538863&from=cor&uid=395049983_1052451_7047A004
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1408538863&from=cor&uid=395049983_1052451_7047A004
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1408538863&from=cor&uid=395049983_1052451_7047A004&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1408538863&from=cor&uid=395049983_1052451_7047A004&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKLM-x32 - AOL Deutschland Toolbar Search Class - {66a449dc-6b1d-4187-a4f1-b335d3da5365} -  No File
URLSearchHook: HKLM-x32 - AOL Deutschland Toolbar Search Class - {66a449dc-6b1d-4187-a4f1-b335d3da5365} - C:\Program Files (x86)\AOL Deutschland Toolbar\aoldetb.dll (AOL Inc.)
URLSearchHook: HKLM-x32 - (No Name) - {b106b661-3e1b-4015-af5c-195e909f35c6} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1408538863&from=cor&uid=395049983_1052451_7047A004&q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1408538863&from=cor&uid=395049983_1052451_7047A004&q={searchTerms}
SearchScopes: HKLM - {D6E4D59A-E5FE-4C8D-8347-B99B76E656E5} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
SearchScopes: HKLM - {F137222E-6DE9-44E9-8EF2-CC5A8D3833BB} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880NHL4NpXhO1w6Yb0c1W9-FhgkQWK4Ehfdcz3I3UPArKQFSZNlsdq5hyma9cy00L27XTCH8NP7vFjk0yFgGduK9dBuoGkYUY0-22LRv-4czOZ-p-bZAf0CeOHjuDAscDUZ6_hKRoRcEYt0oaxLZu2rTwuPYGxxcvT1FlCb8enA,,&q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880NHL4NpXhO1w6Yb0c1W9-FhgkQWK4Ehfdcz3I3UPArKQFSZNlsdq5hyma9cy00L27XTCH8NP7vFjk0yFgGduK9dBuoGkYUY0-22LRv-4czOZ-p-bZAf0CeOHjuDAscDUZ6_hKRoRcEYt0oaxLZu2rTwuPYGxxcvT1FlCb8enA,,&q={searchTerms}
SearchScopes: HKLM-x32 - {2059CF48-25F3-40d7-9D37-24A3142FD20B} URL = hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=3379&q={searchTerms}&rp=&s_it=tb50-ie-aolde-chromesbox-de-de
SearchScopes: HKLM-x32 - {D6E4D59A-E5FE-4C8D-8347-B99B76E656E5} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
SearchScopes: HKCU - DefaultScope {83CB6700-9424-4FE4-B1F4-F9BC555167F3} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {6C7BD9C4-A466-46C4-82C4-CC66701D1395} URL = hxxp://rover.ebay.com/rover/1/707-1403-276402/4?mpre=hxxp://search.ebay.de/search/search.dll?shortcut=4&query={sear chTerms}
SearchScopes: HKCU - {83CB6700-9424-4FE4-B1F4-F9BC555167F3} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {E6396811-2413-44EC-A69B-A788B0E124FC} URL = hxxp://suche.t-online.de/fastcgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&d ia=suche&context=wiki-tab&tpc=internet&ptl=std&classification=wikitab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {F048D832-4CD6-4A55-AAC4-45E3EE19F9B4} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag= interactivemesuche21&index=blended&linkCode=ur2&camp=1638&creative=6742
BHO: SafeFinder SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: AOL Deutschland Toolbar Loader -> {2d3b1910-86c2-4d4b-b1db-124b3ea35bef} -> C:\Program Files (x86)\AOL Deutschland Toolbar\aoldetb.dll (AOL Inc.)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: AVG Security Toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Secure Search\18.1.9.799\AVG Secure Search_toolbar.dll (AVG Secure Search)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - SafeFinder Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - AOL Deutschland Toolbar - {567d4d94-8077-4682-b887-945f3d644116} - C:\Program Files (x86)\AOL Deutschland Toolbar\aoldetb.dll (AOL Inc.)
Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\18.1.9.799\AVG Secure Search_toolbar.dll (AVG Secure Search)
DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: HKLM-x32 {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: HKLM-x32 {477E2667-7E7A-4737-BFF5-121D68EF7816} hxxp://musikdownloads.aol.de/imcdms-static/code/AOL%20Download%20Assistent.ocx
DPF: HKLM-x32 {74E4A24D-5224-4F05-8A41-99445E0FC22B} hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: HKLM-x32 {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} -  No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.5.0 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.0 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @funwebproducts.com/Plugin -> C:\Program Files (x86)\FunWebProducts\Installr\1.bin\NPFunWeb.dll No File
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF Plugin-x32: @viewpoint.com/VMP -> C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-03-21]
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\18.1.9.799
FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\18.1.9.799 [2014-08-26]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-03-07]
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\faststartff@gmail.com
FF Extension: Fast Start - C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\faststartff@gmail.com [2014-08-20]

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17]
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\18.1.0.443\avg.crx [2014-05-01]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 ABBYY.Licensing.PDFTransformer.Classic.3.0; C:\Program Files (x86)\ABBYY PDF Transformer 3.0\NetworkLicenseServer.exe [759048 2010-02-01] (ABBYY)
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2250360 2014-07-30] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe [2683760 2014-05-20] (G Data Software AG)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [356352 2006-12-28] (AVM Berlin) [File not signed]
S4 Boonty Games; C:\Program Files (x86)\Common Files\BOONTY Shared\Service\Boonty.exe [69120 2009-01-28] (BOONTY) [File not signed]
S4 Browser7Maintenance; C:\Program Files (x86)\Browser 7 Maintenance Service\maintenanceservice.exe [112128 2014-08-26] (Deutsche Telekom AG) [File not signed]
R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [File not signed]
S4 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700536 2014-05-20] (G Data Software AG)
S3 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-06-02] (Hewlett-Packard) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2008-10-16] (Hewlett-Packard Co.) [File not signed]
S2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [135168 2008-03-25] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 LPTSystemUpdater; C:\Program Files (x86)\LPT\srpts.exe [32768 2014-08-27] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [69632 2006-11-08] (Hewlett-Packard) [File not signed]
S4 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-12-12] (Nero AG)
S4 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [88064 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Radio.fx; J:\Tobit Radio.fx\Server\rfx-server.exe [3673944 2011-11-18] ()
S4 ServiceLayer; C:\Program Files (x86)\Nokia\PC Connectivity Solution\ServiceLayer.exe [632832 2011-03-21] (Nokia) [File not signed]
R3 TuneUp.Defrag; C:\Windows\System32\TuneUpDefragService.exe [506696 2010-02-27] (TuneUp Software)
S3 TuneUp.ProgramStatisticsSvc; C:\Windows\System32\TUProgSt.exe [842056 2010-02-27] (TuneUp Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
R2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-20] (AVG Secure Search)
S2 scores; C:\Windows\score.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [103936 2013-04-23] (LG Electronics Inc.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2010-07-22] ()
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-08-20] (AVG Technologies)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2006-12-28] (AVM Berlin)
S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [34704 2010-02-05] (CSR, plc)
R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2006-12-28] (AVM GmbH)
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [55808 2014-09-01] (G Data Software AG)
R1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [20992 2014-07-06] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [142336 2014-09-01] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [64000 2014-07-06] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64000 2014-09-01] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-08-31] (G Data Software)
R3 HCW3x64; C:\Windows\System32\DRIVERS\HCW3x64.sys [1087872 2007-03-26] (Hauppauge Computer Works inc.)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [61440 2014-07-06] (G Data Software AG)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2010-07-22] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-08] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [166944 2008-06-06] (NVIDIA Corporation)
S3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1368960 2006-09-30] (Philips Semiconductors GmbH)
S3 Ps2; C:\Windows\System32\DRIVERS\PS2.sys [21504 2006-09-07] ()
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2014-08-20] ()
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-09-18] (TuneUp Software)
R1 {5eeb83d0-96ea-4249-942c-beead6847053}Gt64; C:\Windows\System32\drivers\{5eeb83d0-96ea-4249-942c-beead6847053}Gt64.sys [60056 2014-09-06] (StdLib)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-08 09:47 - 2014-09-08 09:47 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Adobe
2014-09-08 09:46 - 2014-09-08 11:00 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\TuneUp Software
2014-09-08 09:46 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\TuneUp Software
2014-09-08 09:45 - 2014-09-08 09:45 - 00000951 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\AOL
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Local\AOL
2014-09-08 09:44 - 2014-09-08 09:45 - 00000941 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-08 09:44 - 2014-09-08 09:44 - 00000936 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-09-08 09:42 - 2014-09-08 09:44 - 00000917 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2014-09-08 09:41 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\VirtualStore
2014-09-08 09:41 - 2014-09-08 09:44 - 00000000 ____D () C:\Users\Ute
2014-09-08 09:41 - 2014-09-08 09:41 - 00000020 ___SH () C:\Users\Ute\ntuser.ini
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Vorlagen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Startmenü
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Netzwerkumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Lokale Einstellungen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Eigene Dateien
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Druckumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Musik
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Bilder
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Verlauf
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Anwendungsdaten
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Anwendungsdaten
2014-09-08 09:41 - 2014-04-09 17:34 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Garmin
2014-09-08 09:41 - 2011-11-18 04:55 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Macromedia
2014-09-08 09:41 - 2010-11-16 00:09 - 00000000 ____D () C:\Users\Ute\AppData\Local\Microsoft Help
2014-09-08 09:41 - 2008-01-21 05:20 - 00000000 ___RD () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-09-08 09:41 - 2008-01-21 05:20 - 00000000 ___RD () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-09-08 08:03 - 2014-09-08 08:03 - 00003631 _____ () C:\Users\Manopost\Downloads\FRST.txt
2014-09-08 08:02 - 2014-09-08 08:03 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64(1).exe
2014-09-08 07:44 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-09-08 07:44 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-09-08 07:43 - 2014-09-08 07:43 - 01101648 _____ () C:\Users\Manopost\Downloads\HijackThis - CHIP-Installer.exe
2014-09-07 19:19 - 2014-09-07 19:19 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64.exe
2014-09-07 16:20 - 2014-09-08 10:59 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-07 16:19 - 2014-09-07 16:19 - 00000903 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-07 16:19 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-07 16:19 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-07 16:19 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-07 16:18 - 2014-09-07 16:19 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Manopost\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-07 15:00 - 2014-09-08 12:14 - 00000000 ____D () C:\FRST
2014-09-07 10:24 - 2014-09-07 10:24 - 00388152 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-07 10:23 - 2014-09-07 10:23 - 00185186 _____ () C:\Windows\PFRO.log
2014-09-06 23:41 - 2014-09-06 23:42 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup.exe
2014-09-06 23:27 - 2014-09-06 23:27 - 00000000 ____D () C:\Users\Manopost\Documents\PC Speed Maximizer
2014-09-06 23:27 - 2014-09-06 04:13 - 00060056 _____ (StdLib) C:\Windows\system32\Drivers\{5eeb83d0-96ea-4249-942c-beead6847053}Gt64.sys
2014-09-06 23:24 - 2014-09-07 16:25 - 00000000 ____D () C:\Program Files (x86)\LPT
2014-09-06 23:24 - 2014-09-06 23:24 - 00106712 _____ () C:\Users\Manopost\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-06 23:24 - 2014-09-06 23:24 - 00002379 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-09-06 23:22 - 2014-09-07 00:24 - 00000000 ____D () C:\Users\Manopost\AppData\Local\LPT
2014-09-06 23:22 - 2014-09-06 23:22 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Smartbar
2014-09-06 23:16 - 2014-09-06 23:57 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Gameo
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\Desktop\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000000 ___HD () C:\Users\Manopost\AppData\Roaming\GoldenGate
2014-09-06 21:50 - 2014-09-06 21:50 - 00602112 _____ (OldTimer Tools) C:\Users\Manopost\Desktop\OTL.exe
2014-09-06 16:11 - 2014-09-06 16:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Deployment
2014-09-01 23:00 - 2014-09-01 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA ANTIVIRUS
2014-08-28 21:52 - 2014-08-23 03:05 - 00304128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-28 21:52 - 2014-08-23 02:42 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 21:52 - 2014-08-23 01:38 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 10:03 - 2014-08-27 10:03 - 00000630 _____ () C:\Users\Manopost\Desktop\BLT14-15_209.exe - Verknüpfung.lnk
2014-08-27 09:52 - 2014-08-27 09:52 - 00724992 _____ (Maximilian Stangel) C:\Users\Manopost\Downloads\BLT14-15_209.exe
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\ProgramData\Avg_Update_0814tb
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\Program Files (x86)\AVG Security Toolbar
2014-08-26 18:52 - 2014-08-31 22:03 - 00000000 ___HD () C:\Users\Public\Temp
2014-08-26 18:49 - 2014-08-26 18:50 - 00000000 ____D () C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F
2014-08-26 14:15 - 2013-12-27 16:17 - 37650432 _____ () C:\Users\Manopost\Desktop\M2U00050.MPG
2014-08-26 13:28 - 2014-09-06 23:26 - 00000000 ____D () C:\Users\Manopost\Desktop\Tablet
2014-08-26 13:13 - 2014-08-26 13:13 - 00000000 ____D () C:\ProgramData\Telekom-Browser 7
2014-08-25 17:43 - 2014-09-07 01:20 - 00000000 ___RD () C:\Users\Manopost\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Program Files (x86)\Dropbox
2014-08-25 17:39 - 2014-09-06 22:46 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Dropbox
2014-08-25 07:52 - 2014-08-25 07:52 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Adobe
2014-08-22 15:27 - 2014-08-22 15:27 - 00000000 ____D () C:\ProgramData\Xerox
2014-08-22 14:28 - 2014-09-06 23:32 - 00000000 ____D () C:\Users\Manopost\Desktop\Neuer Ordner
2014-08-22 12:43 - 2014-08-22 12:45 - 00000000 ____D () C:\Users\Public\10F34257C92C4CB28669BE8F744057EF
2014-08-22 10:23 - 2014-08-22 10:24 - 00000000 ____D () C:\Users\Public\39203AE8A0DE4F819CFD816F114013DB
2014-08-22 10:23 - 2014-08-22 10:24 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\InetStat
2014-08-22 10:23 - 2014-08-22 10:23 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat
2014-08-22 10:00 - 2014-04-19 17:34 - 00000426 _____ () C:\AVScanner.ini
2014-08-22 09:12 - 2014-08-29 15:01 - 00004040 _____ () C:\Windows\System32\Tasks\LaunchSignup
2014-08-22 09:11 - 2014-08-31 15:59 - 00000000 ____D () C:\Program Files (x86)\videos MediaPlay-Air
2014-08-22 09:11 - 2014-08-22 09:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\globalUpdate
2014-08-22 09:11 - 2014-08-22 09:11 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-08-22 09:10 - 2014-09-07 18:16 - 00000000 ____D () C:\Program Files (x86)\ver1Re-markit
2014-08-22 09:10 - 2014-08-22 12:46 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\VOPackage
2014-08-22 09:10 - 2014-08-22 12:46 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-08-22 09:10 - 2014-08-22 09:12 - 00062602 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistMSI61B3.txt
2014-08-22 09:10 - 2014-08-22 09:12 - 00012036 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistUI61B3.txt
2014-08-20 14:49 - 2014-08-20 14:49 - 00016152 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-08-20 14:49 - 2014-08-20 14:49 - 00000000 ____D () C:\Users\Manopost\AppData\Local\SlimWare Utilities Inc
2014-08-20 14:48 - 2014-08-20 14:48 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-08-20 14:45 - 2014-08-20 15:13 - 00000732 _____ () C:\Users\Manopost\AppData\Local\d3d9caps64.dat
2014-08-20 14:44 - 2014-08-20 14:44 - 00796720 _____ ( ) C:\Users\Manopost\Downloads\nero_setup.exe
2014-08-17 18:20 - 2014-08-17 18:45 - 00001653 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fotostory 3 für Windows.lnk
2014-08-17 18:20 - 2014-08-17 18:20 - 00000000 ____D () C:\Program Files (x86)\Photo Story 3 for Windows
2014-08-17 18:18 - 2014-08-17 18:18 - 01101648 _____ () C:\Users\Manopost\Documents\Microsoft Photo Story - CHIP-Installer.exe
2014-08-17 13:33 - 2014-08-22 13:21 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo Video 1
2014-08-17 13:26 - 2014-08-22 14:59 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo 2
2014-08-17 11:21 - 2014-08-26 14:04 - 00000000 ____D () C:\Users\Manopost\Desktop\Meine Bilder
2014-08-17 08:49 - 2014-08-17 08:49 - 01058200 _____ (Adobe) C:\Users\Manopost\Downloads\install_flashplayer14x32au_mssa_awc_aih.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 01389200 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 00619664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 00171152 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00008848 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-17 08:36 - 2014-06-06 06:29 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-17 08:36 - 2014-06-06 06:28 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-17 08:32 - 2014-08-17 08:32 - 00001757 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2014-08-17 08:32 - 2014-08-17 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2014-08-17 00:05 - 2014-08-14 12:15 - 36898446 _____ () C:\Users\Manopost\Desktop\20140814_131447.mp4
2014-08-16 23:56 - 2014-08-20 19:35 - 00000000 ____D () C:\Users\Manopost\Desktop\Handy Tolo
2014-08-16 23:37 - 2014-06-14 02:56 - 00901568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-16 23:37 - 2014-06-14 02:51 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-16 23:37 - 2014-06-02 23:30 - 03137536 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-16 23:37 - 2014-06-02 23:30 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-16 23:37 - 2014-06-02 23:29 - 02280448 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-16 23:37 - 2014-06-02 23:29 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-08-16 23:37 - 2014-06-02 22:29 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-16 23:37 - 2014-06-02 12:31 - 02263552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-16 23:37 - 2014-06-02 12:31 - 00332800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-16 23:37 - 2014-06-02 12:30 - 01993728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-16 23:36 - 2014-07-24 21:28 - 17861120 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-16 23:36 - 2014-07-24 21:12 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-16 23:36 - 2014-07-24 21:10 - 10920960 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-16 23:36 - 2014-07-24 21:07 - 01384960 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-16 23:36 - 2014-07-24 21:06 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-16 23:36 - 2014-07-24 21:05 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-16 23:36 - 2014-07-24 21:05 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-08-16 23:36 - 2014-07-24 21:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 02155520 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-16 23:36 - 2014-07-24 21:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-16 23:36 - 2014-07-24 21:03 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-16 23:36 - 2014-07-24 21:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-16 23:36 - 2014-07-24 21:03 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-08-16 23:36 - 2014-07-24 21:03 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-08-16 23:36 - 2014-07-24 21:03 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-08-16 23:36 - 2014-07-24 21:02 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-16 23:36 - 2014-07-24 20:07 - 12356608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-16 23:36 - 2014-07-24 19:58 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-16 23:36 - 2014-07-24 19:57 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-16 23:36 - 2014-07-24 19:52 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-16 23:36 - 2014-07-24 19:51 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-16 23:36 - 2014-07-24 19:51 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-16 23:36 - 2014-07-24 19:50 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-08-16 23:36 - 2014-07-24 19:50 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 01802240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-16 23:36 - 2014-07-24 19:48 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-16 23:36 - 2014-07-24 19:48 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-08-16 23:36 - 2014-07-24 19:48 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-08-16 23:36 - 2014-07-24 19:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-16 23:36 - 2014-07-08 03:12 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-16 23:36 - 2014-07-08 02:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-16 23:06 - 2014-09-06 23:25 - 00000000 ____D () C:\Users\Manopost\Desktop\Kamera Tolo

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-08 12:14 - 2014-09-07 15:00 - 00000000 ____D () C:\FRST
2014-09-08 12:12 - 2010-11-02 18:19 - 01084488 _____ () C:\Windows\WindowsUpdate.log
2014-09-08 11:55 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-08 11:55 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-08 11:35 - 2012-07-19 18:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-08 11:00 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\TuneUp Software
2014-09-08 10:59 - 2014-09-07 16:20 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-08 09:55 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-08 09:54 - 2006-11-02 17:42 - 00032514 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-08 09:47 - 2014-09-08 09:47 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Adobe
2014-09-08 09:46 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\TuneUp Software
2014-09-08 09:46 - 2014-09-08 09:41 - 00000000 ____D () C:\Users\Ute\AppData\Local\VirtualStore
2014-09-08 09:45 - 2014-09-08 09:45 - 00000951 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\AOL
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Local\AOL
2014-09-08 09:45 - 2014-09-08 09:44 - 00000941 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-08 09:44 - 2014-09-08 09:44 - 00000936 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-09-08 09:44 - 2014-09-08 09:42 - 00000917 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2014-09-08 09:44 - 2014-09-08 09:41 - 00000000 ____D () C:\Users\Ute
2014-09-08 09:41 - 2014-09-08 09:41 - 00000020 ___SH () C:\Users\Ute\ntuser.ini
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Vorlagen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Startmenü
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Netzwerkumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Lokale Einstellungen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Eigene Dateien
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Druckumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Musik
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Bilder
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Verlauf
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Anwendungsdaten
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Anwendungsdaten
2014-09-08 08:03 - 2014-09-08 08:03 - 00003631 _____ () C:\Users\Manopost\Downloads\FRST.txt
2014-09-08 08:03 - 2014-09-08 08:02 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64(1).exe
2014-09-08 07:52 - 2009-02-04 12:45 - 00000069 _____ () C:\Windows\NeroDigital.ini
2014-09-08 07:43 - 2014-09-08 07:43 - 01101648 _____ () C:\Users\Manopost\Downloads\HijackThis - CHIP-Installer.exe
2014-09-08 06:31 - 2013-09-17 15:45 - 00000425 _____ () C:\Windows\BRWMARK.INI
2014-09-07 21:28 - 2011-06-11 10:44 - 00003714 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{7D2327BF-DAC5-43D7-8EB3-6EA0AF4A749D}
2014-09-07 19:19 - 2014-09-07 19:19 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64.exe
2014-09-07 18:29 - 2009-01-28 11:48 - 00000108 _____ () C:\Users\Manopost\AppData\Roaming\default.pls
2014-09-07 18:16 - 2014-08-22 09:10 - 00000000 ____D () C:\Program Files (x86)\ver1Re-markit
2014-09-07 16:25 - 2014-09-06 23:24 - 00000000 ____D () C:\Program Files (x86)\LPT
2014-09-07 16:19 - 2014-09-07 16:19 - 00000903 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-07 16:19 - 2014-09-07 16:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Manopost\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-07 11:08 - 2010-11-15 00:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-09-07 11:08 - 2010-11-15 00:52 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-07 10:24 - 2014-09-07 10:24 - 00388152 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-07 10:23 - 2014-09-07 10:23 - 00185186 _____ () C:\Windows\PFRO.log
2014-09-07 01:20 - 2014-08-25 17:43 - 00000000 ___RD () C:\Users\Manopost\Dropbox
2014-09-07 00:24 - 2014-09-06 23:22 - 00000000 ____D () C:\Users\Manopost\AppData\Local\LPT
2014-09-07 00:16 - 2009-01-10 16:50 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-06 23:57 - 2014-09-06 23:16 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Gameo
2014-09-06 23:42 - 2014-09-06 23:41 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup.exe
2014-09-06 23:35 - 2013-12-03 13:32 - 00000000 ___RD () C:\Users\Manopost\Documents\Fugen-T-Poster
2014-09-06 23:34 - 2014-01-02 12:23 - 00000000 ____D () C:\Users\Manopost\Desktop\2014
2014-09-06 23:33 - 2014-01-02 15:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Bayrischer Wald
2014-09-06 23:32 - 2014-08-22 14:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Neuer Ordner
2014-09-06 23:27 - 2014-09-06 23:27 - 00000000 ____D () C:\Users\Manopost\Documents\PC Speed Maximizer
2014-09-06 23:27 - 2013-01-21 16:39 - 00000000 ____D () C:\Users\Manopost\Desktop\Bilder1
2014-09-06 23:26 - 2014-08-26 13:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Tablet
2014-09-06 23:25 - 2014-08-16 23:06 - 00000000 ____D () C:\Users\Manopost\Desktop\Kamera Tolo
2014-09-06 23:24 - 2014-09-06 23:24 - 00106712 _____ () C:\Users\Manopost\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-06 23:24 - 2014-09-06 23:24 - 00002379 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-09-06 23:22 - 2014-09-06 23:22 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Smartbar
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\Desktop\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000000 ___HD () C:\Users\Manopost\AppData\Roaming\GoldenGate
2014-09-06 22:51 - 2006-11-02 15:33 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-09-06 22:50 - 2009-01-07 16:56 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-09-06 22:50 - 2006-11-02 17:15 - 00000000 ____D () C:\Windows\WindowsMobile
2014-09-06 22:46 - 2014-08-25 17:39 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Dropbox
2014-09-06 22:41 - 2013-04-11 17:22 - 00000000 ____D () C:\Program Files\Google
2014-09-06 22:40 - 2013-09-17 15:40 - 00000000 ____D () C:\ProgramData\InstallShield
2014-09-06 22:39 - 2013-09-17 15:42 - 00000000 ____D () C:\Program Files (x86)\Brother
2014-09-06 21:50 - 2014-09-06 21:50 - 00602112 _____ (OldTimer Tools) C:\Users\Manopost\Desktop\OTL.exe
2014-09-06 16:12 - 2009-01-10 16:51 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Google
2014-09-06 16:11 - 2014-09-06 16:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Deployment
2014-09-06 16:11 - 2010-06-03 12:57 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Apps\2.0
2014-09-06 15:57 - 2009-01-10 16:51 - 00000000 ____D () C:\ProgramData\Google
2014-09-06 15:36 - 2011-06-13 13:08 - 00003292 _____ () C:\Windows\System32\Tasks\{4231AEF2-8460-496A-9460-D6D1F6493ADF}
2014-09-06 04:13 - 2014-09-06 23:27 - 00060056 _____ (StdLib) C:\Windows\system32\Drivers\{5eeb83d0-96ea-4249-942c-beead6847053}Gt64.sys
2014-09-02 16:07 - 2008-09-13 07:16 - 00699062 _____ () C:\Windows\system32\perfh007.dat
2014-09-02 16:07 - 2008-09-13 07:16 - 00156416 _____ () C:\Windows\system32\perfc007.dat
2014-09-02 16:07 - 2006-11-02 14:46 - 01638136 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-01 23:00 - 2014-09-01 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA ANTIVIRUS
2014-09-01 23:00 - 2014-04-12 12:28 - 00001794 _____ () C:\Users\Public\Desktop\G DATA ANTIVIRUS.lnk
2014-09-01 23:00 - 2009-10-03 14:49 - 00055808 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2014-09-01 23:00 - 2009-06-20 14:57 - 00142336 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2014-09-01 23:00 - 2009-06-20 14:56 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys
2014-08-31 23:00 - 2014-02-28 00:00 - 00018160 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys
2014-08-31 23:00 - 2009-07-28 16:34 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2014-08-31 22:03 - 2014-08-26 18:52 - 00000000 ___HD () C:\Users\Public\Temp
2014-08-31 15:59 - 2014-08-22 09:11 - 00000000 ____D () C:\Program Files (x86)\videos MediaPlay-Air
2014-08-29 15:01 - 2014-08-22 09:12 - 00004040 _____ () C:\Windows\System32\Tasks\LaunchSignup
2014-08-29 15:01 - 2009-01-08 19:24 - 00003784 _____ () C:\Windows\System32\Tasks\HP-Online-Aktualisierungsprogramm
2014-08-29 15:00 - 2014-04-06 16:26 - 00003558 _____ () C:\Windows\System32\Tasks\GarminUpdaterTask
2014-08-27 10:03 - 2014-08-27 10:03 - 00000630 _____ () C:\Users\Manopost\Desktop\BLT14-15_209.exe - Verknüpfung.lnk
2014-08-27 09:52 - 2014-08-27 09:52 - 00724992 _____ (Maximilian Stangel) C:\Users\Manopost\Downloads\BLT14-15_209.exe
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\ProgramData\Avg_Update_0814tb
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\Program Files (x86)\AVG Security Toolbar
2014-08-27 07:33 - 2014-07-28 19:59 - 00000000 ____D () C:\Program Files (x86)\Browser 7 Maintenance Service
2014-08-26 18:50 - 2014-08-26 18:49 - 00000000 ____D () C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F
2014-08-26 14:04 - 2014-08-17 11:21 - 00000000 ____D () C:\Users\Manopost\Desktop\Meine Bilder
2014-08-26 13:43 - 2009-01-09 17:08 - 00112128 _____ () C:\Users\Manopost\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-08-26 13:13 - 2014-08-26 13:13 - 00000000 ____D () C:\ProgramData\Telekom-Browser 7
2014-08-26 13:13 - 2014-07-28 19:59 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Deutsche Telekom AG
2014-08-26 07:51 - 2012-03-02 20:45 - 00000000 ____D () C:\Program Files (x86)\AVG Secure Search
2014-08-25 17:43 - 2009-01-07 16:52 - 00000000 ____D () C:\Users\Manopost
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Program Files (x86)\Dropbox
2014-08-25 07:52 - 2014-08-25 07:52 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Adobe
2014-08-24 10:30 - 2012-07-19 18:26 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-24 10:30 - 2012-04-08 10:43 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-24 10:30 - 2011-05-14 09:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-23 03:05 - 2014-08-28 21:52 - 00304128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:42 - 2014-08-28 21:52 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 01:38 - 2014-08-28 21:52 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 15:27 - 2014-08-22 15:27 - 00000000 ____D () C:\ProgramData\Xerox
2014-08-22 14:59 - 2014-08-17 13:26 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo 2
2014-08-22 13:21 - 2014-08-17 13:33 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo Video 1
2014-08-22 12:46 - 2014-08-22 09:10 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\VOPackage
2014-08-22 12:46 - 2014-08-22 09:10 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-08-22 12:45 - 2014-08-22 12:43 - 00000000 ____D () C:\Users\Public\10F34257C92C4CB28669BE8F744057EF
2014-08-22 10:24 - 2014-08-22 10:23 - 00000000 ____D () C:\Users\Public\39203AE8A0DE4F819CFD816F114013DB
2014-08-22 10:24 - 2014-08-22 10:23 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\InetStat
2014-08-22 10:23 - 2014-08-22 10:23 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat
2014-08-22 10:20 - 2009-01-28 10:44 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Ahead
2014-08-22 09:57 - 2009-02-02 23:48 - 00000000 __SHD () C:\found.000
2014-08-22 09:36 - 2012-12-16 14:45 - 00000111 _____ () C:\.dir
2014-08-22 09:32 - 2014-07-31 19:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-08-22 09:24 - 2014-01-03 19:18 - 00000008 __RSH () C:\Users\Manopost\ntuser.pol
2014-08-22 09:24 - 2009-11-23 14:04 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-08-22 09:16 - 2006-11-02 15:34 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-08-22 09:12 - 2014-08-22 09:10 - 00062602 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistMSI61B3.txt
2014-08-22 09:12 - 2014-08-22 09:10 - 00012036 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistUI61B3.txt
2014-08-22 09:11 - 2014-08-22 09:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\globalUpdate
2014-08-22 09:11 - 2014-08-22 09:11 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-08-20 19:35 - 2014-08-16 23:56 - 00000000 ____D () C:\Users\Manopost\Desktop\Handy Tolo
2014-08-20 19:28 - 2012-09-05 19:54 - 00050976 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-08-20 17:31 - 2010-08-01 13:11 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Skype
2014-08-20 15:13 - 2014-08-20 14:45 - 00000732 _____ () C:\Users\Manopost\AppData\Local\d3d9caps64.dat
2014-08-20 14:49 - 2014-08-20 14:49 - 00016152 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-08-20 14:49 - 2014-08-20 14:49 - 00000000 ____D () C:\Users\Manopost\AppData\Local\SlimWare Utilities Inc
2014-08-20 14:48 - 2014-08-20 14:48 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-08-20 14:44 - 2014-08-20 14:44 - 00796720 _____ ( ) C:\Users\Manopost\Downloads\nero_setup.exe
2014-08-17 18:45 - 2014-08-17 18:20 - 00001653 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fotostory 3 für Windows.lnk
2014-08-17 18:20 - 2014-08-17 18:20 - 00000000 ____D () C:\Program Files (x86)\Photo Story 3 for Windows
2014-08-17 18:18 - 2014-08-17 18:18 - 01101648 _____ () C:\Users\Manopost\Documents\Microsoft Photo Story - CHIP-Installer.exe
2014-08-17 11:36 - 2013-07-04 09:21 - 00000855 _____ () C:\Users\Manopost\Desktop\Bluetooth-Informationsaustausch.lnk
2014-08-17 09:51 - 2006-11-02 15:33 - 00000000 ____D () C:\Windows\rescache
2014-08-17 08:49 - 2014-08-17 08:49 - 01058200 _____ (Adobe) C:\Users\Manopost\Downloads\install_flashplayer14x32au_mssa_awc_aih.exe
2014-08-17 08:48 - 2013-08-15 20:56 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-17 08:44 - 2006-11-02 14:35 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-08-17 08:33 - 2014-02-19 16:41 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-17 08:32 - 2014-08-17 08:32 - 00001757 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2014-08-17 08:32 - 2014-08-17 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2014-08-17 08:32 - 2014-02-19 16:42 - 00000000 ____D () C:\ProgramData\Garmin
2014-08-17 08:32 - 2014-02-19 16:41 - 00000000 ____D () C:\Program Files (x86)\Garmin
2014-08-14 12:15 - 2014-08-17 00:05 - 36898446 _____ () C:\Users\Manopost\Desktop\20140814_131447.mp4

Files to move or delete:
====================
C:\Users\Manopost\DivXInstaller7.exe
C:\Users\Manopost\googleupdatesetup.exe
C:\Users\Manopost\Nero-8.3.13.0_all_update.exe
C:\Users\Manopost\pcfresh.exe
C:\Users\Manopost\PowerPointViewer.exe


Some content of TEMP:
====================
C:\Users\Manopost\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmphpm47v.dll
C:\Users\Manopost\AppData\Local\Temp\ICReinstall_google-chrome_setup (1).exe
C:\Users\Manopost\AppData\Local\Temp\_isA52C.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-08 10:11

==================== End Of Log ============================

--- --- ---

--- --- ---

Snoosel 08.09.2014 11:22

Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-09-2014 01
Ran by Ute at 2014-09-08 12:15:59
Running from C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A1IGUS3K
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: G DATA ANTIVIRUS (Disabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0}
AS: G DATA ANTIVIRUS (Disabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
 Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
64 Bit HP CIO Components Installer (Version: 1.0.0 - Hewlett-Packard) Hidden
ABBYY PDF Transformer 3.0 (HKLM-x32\...\ABBYY PDF Transformer 3.0) (Version: 3.00.317.68010 - ABBYY)
ABBYY PDF Transformer 3.0 (Version: 3.00.317.68010 - ABBYY) Hidden
Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0.1 - Microsoft Corporation) Hidden
Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.179 - Adobe Systems Incorporated)
Adobe Reader X (10.1.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.8.638 - Adobe Systems, Inc.)
AGEIA PhysX v7.01.12 (HKLM-x32\...\{E2BE1618-AF5F-4F7D-8484-42E080EDF609}) (Version: 7.01.12 - AGEIA Technologies, Inc.)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
AOL Deinstallation (HKLM-x32\...\AOL Deinstallation) (Version:  - )
AOL Deutschland Toolbar (HKLM-x32\...\AOL Deutschland Toolbar) (Version:  - )
Apple Application Support (HKLM-x32\...\{3FA365DF-2D68-45ED-8F83-8C8A33E65143}) (Version: 1.1.0 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ATI Catalyst Install Manager (HKLM\...\{9EA8213A-9080-C41F-2F85-8FF98374AB9F}) (Version: 3.0.678.0 - ATI Technologies, Inc.)
AVG Security Toolbar (HKLM-x32\...\AVG Secure Search) (Version: 18.1.9.799 - AVG Technologies)
AVM FRITZ!Box Dokumentation (HKLM-x32\...\AVMFBox) (Version:  - AVM Berlin)
AVM FRITZ!Box Druckeranschluss (HKLM-x32\...\AVMFBoxPrinter) (Version:  - AVM Berlin)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Big Fish Games Client (HKLM-x32\...\BFGC) (Version: 1.4.0.11 - )
Bing Bar (HKLM-x32\...\{B4089055-D468-45A4-A6BA-5A138DD715FC}) (Version: 7.0.850.0 - Microsoft Corporation)
Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v7.00.05 - TOSHIBA CORPORATION)
Browser 7 der Telekom 31.0.19 (x86 de) (HKLM-x32\...\Browser 7 der Telekom 31.0.19 (x86 de)) (Version: 31.0.19 - Deutsche Telekom AG)
Browser 7 Maintenance Service (HKLM-x32\...\Browser7MaintenanceService) (Version: 29.0.40 - Deutsche Telekom AG)
BufferChm (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2008.0514.2139.36863 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization Chinese Standard (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Chinese Traditional (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Czech (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Danish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Dutch (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Finnish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization French (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization German (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Greek (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Hungarian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Italian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Japanese (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Korean (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Norwegian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Polish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Portuguese (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Russian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Spanish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Swedish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Thai (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Turkish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Czech (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Danish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Dutch (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help English (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Finnish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help French (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help German (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Greek (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Italian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Japanese (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Korean (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Polish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Russian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Spanish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Swedish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Thai (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Turkish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
ccc-core-static (x32 Version: 2008.0514.2139.36863 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2008.0514.2139.36863 - ATI) Hidden
Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.22 - Cliqz.com)
Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Copy (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
Destination Component (x32 Version: 090.000.091.086 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 110.0.180.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
DivX Converter (HKLM-x32\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 7.1.0 - DivX, Inc.)
DivX Plus DirectShow Filters (HKLM-x32\...\DivX Plus DirectShow Filters) (Version:  - DivX, Inc.)
DivX-Setup (HKLM-x32\...\DivX Setup.divx.com) (Version: 2.5.0.8 - DivX, LLC)
Download Updater (AOL Inc.) (HKLM-x32\...\SoftwareUpdUtility) (Version:  - AOL Inc.) <==== ATTENTION
Elevated Installer (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Favorit (HKLM-x32\...\koega) (Version:  - )
Fax (x32 Version: 120.0.194.000 - Hewlett-Packard) Hidden
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
G DATA ANTIVIRUS (HKLM-x32\...\{B9FC0A7D-FA1D-4347-ABED-AD8AD5305633}) (Version: 25.0.2.1 - G DATA Software AG)
Garmin Express (HKLM-x32\...\{b43ffffb-1adc-4bcb-b277-7844ebff94da}) (Version: 3.2.17.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
GEAR driver installer for AMD64 and Intel EM64T (HKLM\...\{50CBBEC7-1010-41C5-8718-A1A6FEDD9C3A}) (Version: 2.003.1 - GEAR Software, Inc.)
Hewlett-Packard Active Check for Health Check (x32 Version: 1.1.15.2 - Hewlett-Packard) Hidden
Hewlett-Packard Asset Agent for Health Check (x32 Version: 2.0.63.2 - HP) Hidden
HP Active Support Library (x32 Version: 3.1.6.1 - Hewlett-Packard) Hidden
HP Customer Experience Enhancements (HKLM-x32\...\{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}) (Version: 5.6.0.2510 - Hewlett-Packard)
HP Customer Feedback (x32 Version: 1.0.0 - Hewlett-Packard) Hidden
HP Customer Participation Program 9.0 (HKLM\...\HPExtendedCapabilities) (Version: 9.0 - HP)
HP Imaging Device Functions 9.0 (HKLM\...\HP Imaging Device Functions) (Version: 9.0 - HP)
HP Picasso Media Center Add-In (x32 Version: 1.0.0 - HP) Hidden
HP Recovery Manager RSS (x32 Version: 84.0.0.7 - Hewlet Packard Company) Hidden
HP Update (HKLM-x32\...\{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}) (Version: 4.000.010.008 - Hewlett-Packard)
HP_Network_UserGuide (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
HPSSupply (HKLM-x32\...\{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}) (Version: 2.2.0.0000 - Ihr Firmenname)
Java Auto Updater (x32 Version: 2.0.7.1 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle)
Java(TM) 7 Update 5 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417005FF}) (Version: 7.0.50 - Oracle)
Java(TM) SE Runtime Environment 6 Update 1 (HKLM-x32\...\{3248F0A8-6813-11D6-A77B-00B0D0160010}) (Version: 1.6.0.10 - Sun Microsystems, Inc.)
Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
king.com (remove only) (HKLM-x32\...\king.com) (Version:  - Midasplayer Ltd (king.com))
LG United Mobile Driver (HKLM-x32\...\{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}) (Version: 3.10.1.0 - LG Electronics)
LPT System Updater Service (HKLM-x32\...\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}) (Version: 1.0.0.0 - LPT) <==== ATTENTION
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Marco Polo Mobile Navigator 2 (HKLM-x32\...\{5F65ECEE-EB1D-4C85-8D8C-9C7CE2DBB1D6}) (Version:  - )
MarketResearch (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Corporation (Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft Corporation (x32 Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft VC9 runtime libraries (x32 Version: 2.0.0 - AOL Inc.) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Works (HKLM-x32\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation)
MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 24.2.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.2.0 (x86 de)) (Version: 24.2.0 - Mozilla)
MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NAVIGON Fresh 3.5.1 (HKLM-x32\...\NAVIGON Fresh) (Version: 3.5.1 - NAVIGON)
Nero 8 (HKLM-x32\...\{1CA7ACD6-B21B-4240-AA05-4FC55F6E1031}) (Version: 8.3.465 - Nero AG)
neroxml (x32 Version: 1.0.0 - Nero AG) Hidden
NewFreeScreensaver nfsHDWaterfall03 (HKLM-x32\...\nfsHDWaterfall03 New Free Screensaver_is1) (Version:  - )
Nokia Connectivity Cable Driver (HKLM-x32\...\{25CFEF55-A945-41FC-86ED-76469F31DF37}) (Version: 7.1.41.0 - Nokia)
Nokia Music Player (HKLM-x32\...\{4FCB1267-7380-4EBA-9A6C-69809C6E8227}) (Version: 2.5.11021 - Nokia Music Player)
Nokia_Multimedia_Common_Components_2_5 (HKLM-x32\...\{25F61E72-AAA4-4607-95D2-1E5139C98FFB}) (Version: 2.7.69 - Nokia)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Optimierte Multimedia-Tastatur-Lösung (HKLM-x32\...\KBD) (Version:  - Hewlett-Packard)
PanoStandAlone (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
PaperPort Image Printer 64-bit (HKLM\...\{ABA4FAF1-6389-45F9-92CE-3914A4E5C471}) (Version: 1.00.0000 - Nuance Communications, Inc.)
PC Connectivity Solution (HKLM-x32\...\{4B28C077-9958-45F1-8BB4-CBF90A69AD4E}) (Version: 11.4.15.0 - Nokia)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 6.5.2926 - CyberLink Corp.)
PowerDirector (x32 Version: 6.5.2926 - CyberLink Corp.) Hidden
Primo (x32 Version: 1.00.0000 - Your Company Name) Hidden
Python 2.5.2 (HKLM-x32\...\{6B976ADF-8AE8-434E-B282-A06C7F624D2F}) (Version: 2.5.2150 - Python Software Foundation)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5657 - Realtek Semiconductor Corp.)
RTC Client API v1.2 (HKLM-x32\...\{44CDBD1B-89FB-4E02-8319-2A4C550F664A}) (Version: 1.2.0000 - Microsoft)
Runtime (x32 Version: 1.00.0000 - Your Company Name) Hidden
SafeFinder Smartbar (HKLM-x32\...\{1898B668-CCF5-429F-A86F-9837E5439D77}) (Version: 11.114.72.19232 - Linkury Ltd.) <==== ATTENTION
Skins (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.9.9216 - Skype Technologies S.A.)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Sony USB Driver (HKLM-x32\...\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}) (Version: 2.00 - Sony Corporation)
Spielefieber Patiencen für Vista    (HKLM-x32\...\Spielefieber Patiencen für Vista) (Version:  - KlickMedia)
Status (x32 Version: 110.0.180.000 - Hewlett-Packard) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Top Ten Solitaire (HKLM-x32\...\{51790747-4141-2516-5286-723025870322}) (Version: 1.0 - Bluefish Games)
TrayApp (x32 Version: 110.0.180.000 - Hewlett-Packard) Hidden
TuneUp Utilities 2009 (HKLM-x32\...\{55A29068-F2CE-456C-9148-C869879E2357}) (Version: 8.0.3310.3 - TuneUp Software)
TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.340 - TuneUp Software)
TuneUp Utilities 2014 (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.171 - TuneUp Software) Hidden
UnloadSupport (x32 Version: 9.0.0 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2883097) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{B2260BC9-D561-46EE-B33D-739CF760A2A9}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
Viewpoint Media Player (HKLM-x32\...\ViewpointMediaPlayer) (Version:  - )
VR-NetWorld (HKLM-x32\...\{8815F011-43AF-4F50-BBD8-D78ED3D6F5B9}) (Version:  - )
WDR RadioRecorder (HKLM-x32\...\Tobit Radio.fx Server 1) (Version:  - Tobit.Software)
Windows 7 Upgrade Advisor (HKLM-x32\...\{9A4D182C-35C7-4791-8484-4304EBC9101A}) (Version: 2.0.5000.0 - Microsoft Corporation)
Windows Live Call (x32 Version: 14.0.8064.0206 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 14.0.8098.930 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 14.0.8093.805 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 14.0.8081.709 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 14.0.8091.0730 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live Writer (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0) (HKLM\...\FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D) (Version: 08/22/2008 7.0.0.0 - Nokia)
Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Wondershare MobileTrans ( Version 4.2.0 ) (HKLM-x32\...\{18CDCEAA-A9E4-4A4C-AC0E-C15E87C30EA5}_is1) (Version: 4.2.0 - Wondershare)
Xvid 1.1.2 final uninstall (HKLM-x32\...\Xvid_is1) (Version: 1.1 - Xvid team (Koepi))
Zoo Tycoon: Complete Collection (HKLM-x32\...\Zoo Tycoon 1.0) (Version:  - )
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)
Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 14:34 - 2006-09-18 23:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {279F157C-71B0-48BD-869F-5517150C523D} - System32\Tasks\HP Health Check Scheduler => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-02] (Hewlett-Packard)
Task: {28D5FA8E-3458-4145-A83A-4C217971EE93} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2007-03-11] (Hewlett-Packard Co.)
Task: {36094E77-3C21-421B-8EAB-76A357083F9B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-24] (Adobe Systems Incorporated)
Task: {376BB1C6-EE4E-4BEC-B4FE-84F31A30F5B1} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {468EF5B9-5FB1-4743-B57F-2607EADD3A6C} - System32\Tasks\HP Health Check => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-02] (Hewlett-Packard)
Task: {4C1210EF-7F37-4352-A913-6973F45DEBA2} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {4F0D940C-AD4F-4AE6-AF83-44F78476290D} - System32\Tasks\ScanSoft Background Update => C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
Task: {50B63E3C-8429-4B61-9671-2F1989927645} - System32\Tasks\Automatische Wartung => C:\Program Files (x86)\TuneUp Utilities 2009\OneClickStarter.exe [2009-11-16] (TuneUp Software GmbH)
Task: {5EE7DBA1-E02B-449D-A55F-76653BBFC245} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated)
Task: {5F5E9998-8B9C-481E-94C4-CA2EB746A438} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-18] (Sun Microsystems, Inc.)
Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {83D434E6-D58F-4458-8579-F63D1022BFEF} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {A4B635A8-CB6E-4CC9-A4C2-ED29C5B288AD} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe [2014-08-07] ()
Task: {ADFA917F-CC05-4250-BF79-23261ED49A92} - System32\Tasks\Desktop Messenger => C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Task: {B000A09E-317B-407D-BA22-B7FEDB6F3186} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2014-07-16] (TuneUp Software)
Task: {CDBEB6A4-BC55-4040-88D6-844C74525DBE} - System32\Tasks\{4231AEF2-8460-496A-9460-D6D1F6493ADF} => Chrome.exe hxxp://ui.skype.com/ui/0/5.3.0.116/de/abandoninstall?source=lightinstaller&amp;page=tsDownload&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;ienotdefaultbrowser2
Task: {E6C229EB-FEFD-4A53-A5C9-7AE2CDBC5A82} - System32\Tasks\RecoveryCD => C:\Program Files (x86)\Hewlett-Packard\SDP\RemEngine.exe [2008-06-12] ()
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2014-08-27 18:43 - 2014-08-27 18:43 - 00032768 _____ () C:\Program Files (x86)\LPT\srpts.exe
2014-08-27 18:43 - 2014-08-27 18:52 - 00034816 _____ () C:\Program Files (x86)\LPT\srptsl.exe
2011-01-22 19:58 - 2011-11-18 15:51 - 03673944 _____ () J:\Tobit Radio.fx\Server\rfx-server.exe
2014-07-16 10:24 - 2014-07-16 10:24 - 00699704 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll
2014-08-20 19:29 - 2014-08-20 19:28 - 00159768 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\loggingserver.exe
2014-05-20 03:38 - 2014-05-20 03:38 - 00340088 ____N () C:\Program Files (x86)\Common Files\G Data\AVKProxy\PktIcpt2x64.dll
2008-09-12 21:49 - 2008-05-15 00:04 - 00116736 _____ () C:\Windows\system32\atitmm64.dll
2014-08-27 18:43 - 2014-08-27 18:52 - 00023040 _____ () C:\Program Files (x86)\LPT\srptm.exe
2014-08-27 18:43 - 2014-08-27 18:52 - 00042496 _____ () C:\Program Files (x86)\LPT\srptc.dll
2014-08-27 18:42 - 2014-08-27 18:50 - 00018944 _____ () C:\Program Files (x86)\LPT\Smartbar.Common.dll
2014-08-27 18:43 - 2014-08-27 18:52 - 00070144 _____ () C:\Program Files (x86)\LPT\srut.dll
2014-08-20 19:29 - 2014-08-20 19:28 - 00519704 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\log4cplusU.dll
2004-01-09 22:02 - 2004-01-09 22:02 - 00045056 _____ () C:\Program Files (x86)\AOL 9.0 VR\zlib.dll
2002-04-22 23:08 - 2002-04-22 23:08 - 00053248 _____ () C:\Program Files (x86)\AOL 9.0 VR\xmlparse.dll
2002-04-22 23:08 - 2002-04-22 23:08 - 00081920 _____ () C:\Program Files (x86)\AOL 9.0 VR\xmltok.dll
2007-05-24 10:01 - 2007-05-24 10:01 - 00090112 _____ () C:\Program Files (x86)\AOL 9.0 VR\Components\Tier2Svc.dll
2007-05-24 10:01 - 2007-05-24 10:01 - 00061440 _____ () C:\Program Files (x86)\AOL 9.0 VR\Components\DataSvcs.dll
2009-01-07 17:42 - 2007-05-24 04:49 - 00131072 _____ () c:\program files (x86)\common files\aol\1231342872\ee\services\proxyprovider\ver1_0_0_1\proxyprovider.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Manopost:zylomtest
AlternateDataStreams: C:\Users\Manopost:zylomtr{000HQ7FF-AD7A-3FG7-DNQC-2227NIQAQVVE}
AlternateDataStreams: C:\Users\Manopost:zylomtr{000HQ7FF-AD7A-3FG7-FCUD-28A45N46SVT9}
AlternateDataStreams: C:\ProgramData\TEMP:2B1EA607
AlternateDataStreams: C:\ProgramData\TEMP:8AD1F2E0
AlternateDataStreams: C:\ProgramData\TEMP:957E9765
AlternateDataStreams: C:\ProgramData\TEMP:BD36345D
AlternateDataStreams: C:\ProgramData\TEMP:F0D7EE30

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: KBD => C:\HP\KBD\KbdStub.EXE                                                                                                                                                                                                                                                   
MSCONFIG\startupreg: Wondershare Helper Compact.exe => "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"                                                                                                                                                                               
MSCONFIG\startupreg: WSHelperSetup.exe => "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"                                                                                                                                                                               

==================== Faulty Device Manager Devices =============

Name: isatap.{A615081A-DB1C-42C8-8B6A-0E4FEC46738B}
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: isatap.{1AFC8298-E6C4-448F-A08D-F0585C2E35D5}
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (09/08/2014 00:16:02 PM) (Source: VSS) (EventID: 12292) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422] ist ein Fehler aufgetreten.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien abfragen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 13
  Snapshotkontext: 13
  Ausführungskontext: Coordinator

Error: (09/08/2014 00:16:02 PM) (Source: VSS) (EventID: 40) (User: )
Description: Volumeschattenkopie-Dienst-Fehler: Der Dienst "Microsoft-Softwareschattenkopie-Anbieter"
(SWPRV) ist deaktiviert. Aktivieren Sie den Dienst, und wiederholen Sie den Vorgang.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien abfragen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 13
  Snapshotkontext: 13
  Ausführungskontext: Coordinator

Error: (09/08/2014 00:12:38 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts auf dem Volume (Prozess = C:\Windows\system32\msiexec.exe /V; Beschreibung = Installed Microsoft Fix it 50212; Hr = 0x8004230f).

Error: (09/08/2014 00:12:38 PM) (Source: VSS) (EventID: 12292) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422] ist ein Fehler aufgetreten.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien löschen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 0
  Snapshotkontext: 0
  Ausführungskontext: Coordinator

Error: (09/08/2014 00:12:38 PM) (Source: VSS) (EventID: 40) (User: )
Description: Volumeschattenkopie-Dienst-Fehler: Der Dienst "Microsoft-Softwareschattenkopie-Anbieter"
(SWPRV) ist deaktiviert. Aktivieren Sie den Dienst, und wiederholen Sie den Vorgang.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien löschen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 0
  Snapshotkontext: 0
  Ausführungskontext: Coordinator

Error: (09/08/2014 00:12:38 PM) (Source: VSS) (EventID: 12292) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422] ist ein Fehler aufgetreten.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien abfragen
  Schattenkopien löschen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 0
  Snapshotkontext: 0
  Ausführungskontext: Coordinator
  Ausführungskontext: Coordinator

Error: (09/08/2014 00:12:38 PM) (Source: VSS) (EventID: 40) (User: )
Description: Volumeschattenkopie-Dienst-Fehler: Der Dienst "Microsoft-Softwareschattenkopie-Anbieter"
(SWPRV) ist deaktiviert. Aktivieren Sie den Dienst, und wiederholen Sie den Vorgang.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien abfragen
  Schattenkopien löschen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 0
  Snapshotkontext: 0
  Ausführungskontext: Coordinator
  Ausführungskontext: Coordinator

Error: (09/08/2014 00:12:38 PM) (Source: VSS) (EventID: 12292) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422] ist ein Fehler aufgetreten.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Überprüfen, ob das Volume vom Anbieter unterstützt wird
  Volume einem Schattenkopiesatz hinzufügen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {00000000-0000-0000-0000-000000000000}
  Snapshotkontext: 4194317
  Ausführungskontext: Coordinator
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Volumename: \\?\Volume{cc3cf33a-b60c-11dd-934c-806e6f6e6963}\
  Ausführungskontext: Coordinator

Error: (09/08/2014 00:12:38 PM) (Source: VSS) (EventID: 40) (User: )
Description: Volumeschattenkopie-Dienst-Fehler: Der Dienst "Microsoft-Softwareschattenkopie-Anbieter"
(SWPRV) ist deaktiviert. Aktivieren Sie den Dienst, und wiederholen Sie den Vorgang.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Überprüfen, ob das Volume vom Anbieter unterstützt wird
  Volume einem Schattenkopiesatz hinzufügen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {00000000-0000-0000-0000-000000000000}
  Snapshotkontext: 4194317
  Ausführungskontext: Coordinator
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Volumename: \\?\Volume{cc3cf33a-b60c-11dd-934c-806e6f6e6963}\
  Ausführungskontext: Coordinator

Error: (09/08/2014 00:12:30 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts auf dem Volume (Prozess = C:\Windows\system32\msiexec.exe /V; Beschreibung = Installed Microsoft Fix it 50212; Hr = 0x8004230f).


System errors:
=============
Error: (09/08/2014 09:58:48 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: HP CUE DeviceDiscovery Service%%2147500037

Error: (09/08/2014 09:57:25 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt

Error: (09/08/2014 09:57:15 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: HP CUE DeviceDiscovery Service

Error: (09/08/2014 09:57:14 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Windows-BilderfassungShellhardwareerkennung%%1058

Error: (09/08/2014 09:57:14 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: scores%%2

Error: (09/08/2014 09:43:10 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: HP CUE DeviceDiscovery Service%%2147500037

Error: (09/08/2014 09:43:10 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt

Error: (09/08/2014 09:42:29 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: HP CUE DeviceDiscovery Service

Error: (09/08/2014 09:42:28 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Windows-BilderfassungShellhardwareerkennung%%1058

Error: (09/08/2014 09:42:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: scores%%2


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2014-09-08 12:15:49.418
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-08 12:15:48.685
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-08 12:15:47.920
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-08 12:15:47.125
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-08 12:15:46.220
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-08 12:15:45.440
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-08 12:15:44.660
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-08 12:15:43.864
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-08 12:15:11.098
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-08 12:15:10.318
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Processor: AMD Phenom(tm) 9650 Quad-Core Processor
Percentage of memory in use: 58%
Total physical RAM: 4093.58 MB
Available physical RAM: 1704.81 MB
Total Pagefile: 8387.68 MB
Available Pagefile: 5739.36 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (HP) (Fixed) (Total:582.63 GB) (Free:326.83 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (FACTORY_IMAGE) (Fixed) (Total:13.54 GB) (Free:1.86 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive j: (HP Pocket Media Drive) (Fixed) (Total:149.04 GB) (Free:126.5 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 596.2 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=582.6 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=13.5 GB) - (Type=07 NTFS)

========================================================
Disk: 5 (MBR Code: Windows XP) (Size: 149.1 GB) (Disk ID: 2BD35C77)
Partition 1: (Not Active) - (Size=149 GB) - (Type=OF Extended)

==================== End Of Log ============================


Snoosel 08.09.2014 11:23


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-09-2014 01
Ran by Ute (administrator) on MANOPOST-PC on 08-09-2014 12:14:52
Running from C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A1IGUS3K
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(AOL LLC) C:\Program Files (x86)\Common Files\aol\acs\AOLacsd.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files (x86)\LPT\srpts.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\LPT\srptsl.exe
() J:\Tobit Radio.fx\Server\rfx-server.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\loggingserver.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\AVKBap64.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(AOL, LLC.) C:\Program Files (x86)\AOL 9.0 VR\waol.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GDKBFltExe32.exe
(America Online, Inc.) C:\Program Files (x86)\Common Files\aol\1231342872\ee\aolsoftware.exe
(AOL, LLC.) C:\Program Files (x86)\AOL 9.0 VR\shellmon.exe
(TuneUp Software) C:\Windows\System32\TuneUpDefragService.exe
() C:\Program Files (x86)\LPT\srptm.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe
(America Online Inc) C:\Program Files (x86)\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe
(Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Farbar) C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A1IGUS3K\FRST64[1].exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [ITSecMng] => C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [83336 2009-07-22] (TOSHIBA CORPORATION)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe
HKU\.DEFAULT\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
HKU\.DEFAULT\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-243317379-2889874547-3061927781-1001\...\Run: [AOL Fast Start] => C:\Program Files (x86)\AOL 9.0 VR\AOL.EXE [50480 2007-06-21] (AOL, LLC.)
AppInit_DLLs: C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil64.dll => C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil64.dll File Not Found
AppInit_DLLs-x32: C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil.dll => "C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil.dll" File Not Found
IFEO: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\bip_camera1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\browser7.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\btassist1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\coverdes.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\discspeed.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\drivespeed.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\eccenter1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\excel.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\express.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\frontpg.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\groove.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\hpwucli.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\infopath.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\infotool.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\lifecam.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mobiletrans.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\msaccess.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\msoxmled.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mspub.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mstore.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mypc backup.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nero.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neroburnrights.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerohome.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neromediahome.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerorescueagent.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neroscoutoptions.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerostartsmart.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerovision.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\offdiag.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\ois.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\onenote.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\osa.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\outlook.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\photosnap.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\photosnapviewer.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\powerpnt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\pptview.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\recode.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\setupx.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\showtime.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\skype.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\soundtrax.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\tosbtmng.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\tosbtproc1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\uninst.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\usrguide.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\waveedit.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\winword.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\wirelessftp1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\wlangui.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\zune.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt1" -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt2" -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt3" -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt4" -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt5" -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt6" -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt7" -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt8" -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/cpm-redir/ie-9.html
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.t-online.de/cpm-redir/ie-9.html
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.t-online.de/cpm-redir/ie-9.html
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.t-online.de/cpm-redir/ie-9.html
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.sweet-page.com/?type=hp&ts=1408538863&from=cor&uid=395049983_1052451_7047A004
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1408538863&from=cor&uid=395049983_1052451_7047A004
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1408538863&from=cor&uid=395049983_1052451_7047A004&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1408538863&from=cor&uid=395049983_1052451_7047A004&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKLM-x32 - AOL Deutschland Toolbar Search Class - {66a449dc-6b1d-4187-a4f1-b335d3da5365} -  No File
URLSearchHook: HKLM-x32 - AOL Deutschland Toolbar Search Class - {66a449dc-6b1d-4187-a4f1-b335d3da5365} - C:\Program Files (x86)\AOL Deutschland Toolbar\aoldetb.dll (AOL Inc.)
URLSearchHook: HKLM-x32 - (No Name) - {b106b661-3e1b-4015-af5c-195e909f35c6} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1408538863&from=cor&uid=395049983_1052451_7047A004&q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1408538863&from=cor&uid=395049983_1052451_7047A004&q={searchTerms}
SearchScopes: HKLM - {D6E4D59A-E5FE-4C8D-8347-B99B76E656E5} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
SearchScopes: HKLM - {F137222E-6DE9-44E9-8EF2-CC5A8D3833BB} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880NHL4NpXhO1w6Yb0c1W9-FhgkQWK4Ehfdcz3I3UPArKQFSZNlsdq5hyma9cy00L27XTCH8NP7vFjk0yFgGduK9dBuoGkYUY0-22LRv-4czOZ-p-bZAf0CeOHjuDAscDUZ6_hKRoRcEYt0oaxLZu2rTwuPYGxxcvT1FlCb8enA,,&q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWx880NHL4NpXhO1w6Yb0c1W9-FhgkQWK4Ehfdcz3I3UPArKQFSZNlsdq5hyma9cy00L27XTCH8NP7vFjk0yFgGduK9dBuoGkYUY0-22LRv-4czOZ-p-bZAf0CeOHjuDAscDUZ6_hKRoRcEYt0oaxLZu2rTwuPYGxxcvT1FlCb8enA,,&q={searchTerms}
SearchScopes: HKLM-x32 - {2059CF48-25F3-40d7-9D37-24A3142FD20B} URL = hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=3379&q={searchTerms}&rp=&s_it=tb50-ie-aolde-chromesbox-de-de
SearchScopes: HKLM-x32 - {D6E4D59A-E5FE-4C8D-8347-B99B76E656E5} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
SearchScopes: HKCU - DefaultScope {83CB6700-9424-4FE4-B1F4-F9BC555167F3} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {6C7BD9C4-A466-46C4-82C4-CC66701D1395} URL = hxxp://rover.ebay.com/rover/1/707-1403-276402/4?mpre=hxxp://search.ebay.de/search/search.dll?shortcut=4&query={sear chTerms}
SearchScopes: HKCU - {83CB6700-9424-4FE4-B1F4-F9BC555167F3} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {E6396811-2413-44EC-A69B-A788B0E124FC} URL = hxxp://suche.t-online.de/fastcgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&d ia=suche&context=wiki-tab&tpc=internet&ptl=std&classification=wikitab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {F048D832-4CD6-4A55-AAC4-45E3EE19F9B4} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag= interactivemesuche21&index=blended&linkCode=ur2&camp=1638&creative=6742
BHO: SafeFinder SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: AOL Deutschland Toolbar Loader -> {2d3b1910-86c2-4d4b-b1db-124b3ea35bef} -> C:\Program Files (x86)\AOL Deutschland Toolbar\aoldetb.dll (AOL Inc.)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: AVG Security Toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Secure Search\18.1.9.799\AVG Secure Search_toolbar.dll (AVG Secure Search)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - SafeFinder Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - AOL Deutschland Toolbar - {567d4d94-8077-4682-b887-945f3d644116} - C:\Program Files (x86)\AOL Deutschland Toolbar\aoldetb.dll (AOL Inc.)
Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\18.1.9.799\AVG Secure Search_toolbar.dll (AVG Secure Search)
DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: HKLM-x32 {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: HKLM-x32 {477E2667-7E7A-4737-BFF5-121D68EF7816} hxxp://musikdownloads.aol.de/imcdms-static/code/AOL%20Download%20Assistent.ocx
DPF: HKLM-x32 {74E4A24D-5224-4F05-8A41-99445E0FC22B} hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: HKLM-x32 {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} -  No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.5.0 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.0 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @funwebproducts.com/Plugin -> C:\Program Files (x86)\FunWebProducts\Installr\1.bin\NPFunWeb.dll No File
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF Plugin-x32: @viewpoint.com/VMP -> C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-03-21]
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\18.1.9.799
FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\18.1.9.799 [2014-08-26]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-03-07]
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\faststartff@gmail.com
FF Extension: Fast Start - C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\faststartff@gmail.com [2014-08-20]

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17]
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\18.1.0.443\avg.crx [2014-05-01]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 ABBYY.Licensing.PDFTransformer.Classic.3.0; C:\Program Files (x86)\ABBYY PDF Transformer 3.0\NetworkLicenseServer.exe [759048 2010-02-01] (ABBYY)
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2250360 2014-07-30] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe [2683760 2014-05-20] (G Data Software AG)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [356352 2006-12-28] (AVM Berlin) [File not signed]
S4 Boonty Games; C:\Program Files (x86)\Common Files\BOONTY Shared\Service\Boonty.exe [69120 2009-01-28] (BOONTY) [File not signed]
S4 Browser7Maintenance; C:\Program Files (x86)\Browser 7 Maintenance Service\maintenanceservice.exe [112128 2014-08-26] (Deutsche Telekom AG) [File not signed]
R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [File not signed]
S4 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700536 2014-05-20] (G Data Software AG)
S3 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-06-02] (Hewlett-Packard) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2008-10-16] (Hewlett-Packard Co.) [File not signed]
S2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [135168 2008-03-25] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 LPTSystemUpdater; C:\Program Files (x86)\LPT\srpts.exe [32768 2014-08-27] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [69632 2006-11-08] (Hewlett-Packard) [File not signed]
S4 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-12-12] (Nero AG)
S4 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [88064 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Radio.fx; J:\Tobit Radio.fx\Server\rfx-server.exe [3673944 2011-11-18] ()
S4 ServiceLayer; C:\Program Files (x86)\Nokia\PC Connectivity Solution\ServiceLayer.exe [632832 2011-03-21] (Nokia) [File not signed]
R3 TuneUp.Defrag; C:\Windows\System32\TuneUpDefragService.exe [506696 2010-02-27] (TuneUp Software)
S3 TuneUp.ProgramStatisticsSvc; C:\Windows\System32\TUProgSt.exe [842056 2010-02-27] (TuneUp Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
R2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-20] (AVG Secure Search)
S2 scores; C:\Windows\score.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [103936 2013-04-23] (LG Electronics Inc.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2010-07-22] ()
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-08-20] (AVG Technologies)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2006-12-28] (AVM Berlin)
S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [34704 2010-02-05] (CSR, plc)
R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2006-12-28] (AVM GmbH)
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [55808 2014-09-01] (G Data Software AG)
R1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [20992 2014-07-06] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [142336 2014-09-01] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [64000 2014-07-06] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64000 2014-09-01] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-08-31] (G Data Software)
R3 HCW3x64; C:\Windows\System32\DRIVERS\HCW3x64.sys [1087872 2007-03-26] (Hauppauge Computer Works inc.)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [61440 2014-07-06] (G Data Software AG)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2010-07-22] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-08] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [166944 2008-06-06] (NVIDIA Corporation)
S3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1368960 2006-09-30] (Philips Semiconductors GmbH)
S3 Ps2; C:\Windows\System32\DRIVERS\PS2.sys [21504 2006-09-07] ()
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2014-08-20] ()
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-09-18] (TuneUp Software)
R1 {5eeb83d0-96ea-4249-942c-beead6847053}Gt64; C:\Windows\System32\drivers\{5eeb83d0-96ea-4249-942c-beead6847053}Gt64.sys [60056 2014-09-06] (StdLib)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-08 09:47 - 2014-09-08 09:47 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Adobe
2014-09-08 09:46 - 2014-09-08 11:00 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\TuneUp Software
2014-09-08 09:46 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\TuneUp Software
2014-09-08 09:45 - 2014-09-08 09:45 - 00000951 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\AOL
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Local\AOL
2014-09-08 09:44 - 2014-09-08 09:45 - 00000941 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-08 09:44 - 2014-09-08 09:44 - 00000936 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-09-08 09:42 - 2014-09-08 09:44 - 00000917 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2014-09-08 09:41 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\VirtualStore
2014-09-08 09:41 - 2014-09-08 09:44 - 00000000 ____D () C:\Users\Ute
2014-09-08 09:41 - 2014-09-08 09:41 - 00000020 ___SH () C:\Users\Ute\ntuser.ini
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Vorlagen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Startmenü
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Netzwerkumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Lokale Einstellungen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Eigene Dateien
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Druckumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Musik
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Bilder
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Verlauf
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Anwendungsdaten
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Anwendungsdaten
2014-09-08 09:41 - 2014-04-09 17:34 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Garmin
2014-09-08 09:41 - 2011-11-18 04:55 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Macromedia
2014-09-08 09:41 - 2010-11-16 00:09 - 00000000 ____D () C:\Users\Ute\AppData\Local\Microsoft Help
2014-09-08 09:41 - 2008-01-21 05:20 - 00000000 ___RD () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-09-08 09:41 - 2008-01-21 05:20 - 00000000 ___RD () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-09-08 08:03 - 2014-09-08 08:03 - 00003631 _____ () C:\Users\Manopost\Downloads\FRST.txt
2014-09-08 08:02 - 2014-09-08 08:03 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64(1).exe
2014-09-08 07:44 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-09-08 07:44 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-09-08 07:43 - 2014-09-08 07:43 - 01101648 _____ () C:\Users\Manopost\Downloads\HijackThis - CHIP-Installer.exe
2014-09-07 19:19 - 2014-09-07 19:19 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64.exe
2014-09-07 16:20 - 2014-09-08 10:59 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-07 16:19 - 2014-09-07 16:19 - 00000903 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-07 16:19 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-07 16:19 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-07 16:19 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-07 16:18 - 2014-09-07 16:19 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Manopost\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-07 15:00 - 2014-09-08 12:14 - 00000000 ____D () C:\FRST
2014-09-07 10:24 - 2014-09-07 10:24 - 00388152 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-07 10:23 - 2014-09-07 10:23 - 00185186 _____ () C:\Windows\PFRO.log
2014-09-06 23:41 - 2014-09-06 23:42 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup.exe
2014-09-06 23:27 - 2014-09-06 23:27 - 00000000 ____D () C:\Users\Manopost\Documents\PC Speed Maximizer
2014-09-06 23:27 - 2014-09-06 04:13 - 00060056 _____ (StdLib) C:\Windows\system32\Drivers\{5eeb83d0-96ea-4249-942c-beead6847053}Gt64.sys
2014-09-06 23:24 - 2014-09-07 16:25 - 00000000 ____D () C:\Program Files (x86)\LPT
2014-09-06 23:24 - 2014-09-06 23:24 - 00106712 _____ () C:\Users\Manopost\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-06 23:24 - 2014-09-06 23:24 - 00002379 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-09-06 23:22 - 2014-09-07 00:24 - 00000000 ____D () C:\Users\Manopost\AppData\Local\LPT
2014-09-06 23:22 - 2014-09-06 23:22 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Smartbar
2014-09-06 23:16 - 2014-09-06 23:57 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Gameo
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\Desktop\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000000 ___HD () C:\Users\Manopost\AppData\Roaming\GoldenGate
2014-09-06 21:50 - 2014-09-06 21:50 - 00602112 _____ (OldTimer Tools) C:\Users\Manopost\Desktop\OTL.exe
2014-09-06 16:11 - 2014-09-06 16:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Deployment
2014-09-01 23:00 - 2014-09-01 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA ANTIVIRUS
2014-08-28 21:52 - 2014-08-23 03:05 - 00304128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-28 21:52 - 2014-08-23 02:42 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 21:52 - 2014-08-23 01:38 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 10:03 - 2014-08-27 10:03 - 00000630 _____ () C:\Users\Manopost\Desktop\BLT14-15_209.exe - Verknüpfung.lnk
2014-08-27 09:52 - 2014-08-27 09:52 - 00724992 _____ (Maximilian Stangel) C:\Users\Manopost\Downloads\BLT14-15_209.exe
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\ProgramData\Avg_Update_0814tb
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\Program Files (x86)\AVG Security Toolbar
2014-08-26 18:52 - 2014-08-31 22:03 - 00000000 ___HD () C:\Users\Public\Temp
2014-08-26 18:49 - 2014-08-26 18:50 - 00000000 ____D () C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F
2014-08-26 14:15 - 2013-12-27 16:17 - 37650432 _____ () C:\Users\Manopost\Desktop\M2U00050.MPG
2014-08-26 13:28 - 2014-09-06 23:26 - 00000000 ____D () C:\Users\Manopost\Desktop\Tablet
2014-08-26 13:13 - 2014-08-26 13:13 - 00000000 ____D () C:\ProgramData\Telekom-Browser 7
2014-08-25 17:43 - 2014-09-07 01:20 - 00000000 ___RD () C:\Users\Manopost\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Program Files (x86)\Dropbox
2014-08-25 17:39 - 2014-09-06 22:46 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Dropbox
2014-08-25 07:52 - 2014-08-25 07:52 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Adobe
2014-08-22 15:27 - 2014-08-22 15:27 - 00000000 ____D () C:\ProgramData\Xerox
2014-08-22 14:28 - 2014-09-06 23:32 - 00000000 ____D () C:\Users\Manopost\Desktop\Neuer Ordner
2014-08-22 12:43 - 2014-08-22 12:45 - 00000000 ____D () C:\Users\Public\10F34257C92C4CB28669BE8F744057EF
2014-08-22 10:23 - 2014-08-22 10:24 - 00000000 ____D () C:\Users\Public\39203AE8A0DE4F819CFD816F114013DB
2014-08-22 10:23 - 2014-08-22 10:24 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\InetStat
2014-08-22 10:23 - 2014-08-22 10:23 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat
2014-08-22 10:00 - 2014-04-19 17:34 - 00000426 _____ () C:\AVScanner.ini
2014-08-22 09:12 - 2014-08-29 15:01 - 00004040 _____ () C:\Windows\System32\Tasks\LaunchSignup
2014-08-22 09:11 - 2014-08-31 15:59 - 00000000 ____D () C:\Program Files (x86)\videos MediaPlay-Air
2014-08-22 09:11 - 2014-08-22 09:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\globalUpdate
2014-08-22 09:11 - 2014-08-22 09:11 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-08-22 09:10 - 2014-09-07 18:16 - 00000000 ____D () C:\Program Files (x86)\ver1Re-markit
2014-08-22 09:10 - 2014-08-22 12:46 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\VOPackage
2014-08-22 09:10 - 2014-08-22 12:46 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-08-22 09:10 - 2014-08-22 09:12 - 00062602 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistMSI61B3.txt
2014-08-22 09:10 - 2014-08-22 09:12 - 00012036 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistUI61B3.txt
2014-08-20 14:49 - 2014-08-20 14:49 - 00016152 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-08-20 14:49 - 2014-08-20 14:49 - 00000000 ____D () C:\Users\Manopost\AppData\Local\SlimWare Utilities Inc
2014-08-20 14:48 - 2014-08-20 14:48 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-08-20 14:45 - 2014-08-20 15:13 - 00000732 _____ () C:\Users\Manopost\AppData\Local\d3d9caps64.dat
2014-08-20 14:44 - 2014-08-20 14:44 - 00796720 _____ ( ) C:\Users\Manopost\Downloads\nero_setup.exe
2014-08-17 18:20 - 2014-08-17 18:45 - 00001653 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fotostory 3 für Windows.lnk
2014-08-17 18:20 - 2014-08-17 18:20 - 00000000 ____D () C:\Program Files (x86)\Photo Story 3 for Windows
2014-08-17 18:18 - 2014-08-17 18:18 - 01101648 _____ () C:\Users\Manopost\Documents\Microsoft Photo Story - CHIP-Installer.exe
2014-08-17 13:33 - 2014-08-22 13:21 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo Video 1
2014-08-17 13:26 - 2014-08-22 14:59 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo 2
2014-08-17 11:21 - 2014-08-26 14:04 - 00000000 ____D () C:\Users\Manopost\Desktop\Meine Bilder
2014-08-17 08:49 - 2014-08-17 08:49 - 01058200 _____ (Adobe) C:\Users\Manopost\Downloads\install_flashplayer14x32au_mssa_awc_aih.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 01389200 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 00619664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 00171152 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00008848 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-17 08:36 - 2014-06-06 06:29 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-17 08:36 - 2014-06-06 06:28 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-17 08:32 - 2014-08-17 08:32 - 00001757 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2014-08-17 08:32 - 2014-08-17 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2014-08-17 00:05 - 2014-08-14 12:15 - 36898446 _____ () C:\Users\Manopost\Desktop\20140814_131447.mp4
2014-08-16 23:56 - 2014-08-20 19:35 - 00000000 ____D () C:\Users\Manopost\Desktop\Handy Tolo
2014-08-16 23:37 - 2014-06-14 02:56 - 00901568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-16 23:37 - 2014-06-14 02:51 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-16 23:37 - 2014-06-02 23:30 - 03137536 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-16 23:37 - 2014-06-02 23:30 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-16 23:37 - 2014-06-02 23:29 - 02280448 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-16 23:37 - 2014-06-02 23:29 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-08-16 23:37 - 2014-06-02 22:29 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-16 23:37 - 2014-06-02 12:31 - 02263552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-16 23:37 - 2014-06-02 12:31 - 00332800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-16 23:37 - 2014-06-02 12:30 - 01993728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-16 23:36 - 2014-07-24 21:28 - 17861120 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-16 23:36 - 2014-07-24 21:12 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-16 23:36 - 2014-07-24 21:10 - 10920960 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-16 23:36 - 2014-07-24 21:07 - 01384960 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-16 23:36 - 2014-07-24 21:06 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-16 23:36 - 2014-07-24 21:05 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-16 23:36 - 2014-07-24 21:05 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-08-16 23:36 - 2014-07-24 21:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 02155520 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-16 23:36 - 2014-07-24 21:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-16 23:36 - 2014-07-24 21:03 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-16 23:36 - 2014-07-24 21:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-16 23:36 - 2014-07-24 21:03 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-08-16 23:36 - 2014-07-24 21:03 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-08-16 23:36 - 2014-07-24 21:03 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-08-16 23:36 - 2014-07-24 21:02 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-16 23:36 - 2014-07-24 20:07 - 12356608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-16 23:36 - 2014-07-24 19:58 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-16 23:36 - 2014-07-24 19:57 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-16 23:36 - 2014-07-24 19:52 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-16 23:36 - 2014-07-24 19:51 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-16 23:36 - 2014-07-24 19:51 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-16 23:36 - 2014-07-24 19:50 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-08-16 23:36 - 2014-07-24 19:50 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 01802240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-16 23:36 - 2014-07-24 19:48 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-16 23:36 - 2014-07-24 19:48 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-08-16 23:36 - 2014-07-24 19:48 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-08-16 23:36 - 2014-07-24 19:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-16 23:36 - 2014-07-08 03:12 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-16 23:36 - 2014-07-08 02:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-16 23:06 - 2014-09-06 23:25 - 00000000 ____D () C:\Users\Manopost\Desktop\Kamera Tolo

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-08 12:14 - 2014-09-07 15:00 - 00000000 ____D () C:\FRST
2014-09-08 12:12 - 2010-11-02 18:19 - 01084488 _____ () C:\Windows\WindowsUpdate.log
2014-09-08 11:55 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-08 11:55 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-08 11:35 - 2012-07-19 18:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-08 11:00 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\TuneUp Software
2014-09-08 10:59 - 2014-09-07 16:20 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-08 09:55 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-08 09:54 - 2006-11-02 17:42 - 00032514 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-08 09:47 - 2014-09-08 09:47 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Adobe
2014-09-08 09:46 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\TuneUp Software
2014-09-08 09:46 - 2014-09-08 09:41 - 00000000 ____D () C:\Users\Ute\AppData\Local\VirtualStore
2014-09-08 09:45 - 2014-09-08 09:45 - 00000951 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\AOL
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Local\AOL
2014-09-08 09:45 - 2014-09-08 09:44 - 00000941 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-08 09:44 - 2014-09-08 09:44 - 00000936 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-09-08 09:44 - 2014-09-08 09:42 - 00000917 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2014-09-08 09:44 - 2014-09-08 09:41 - 00000000 ____D () C:\Users\Ute
2014-09-08 09:41 - 2014-09-08 09:41 - 00000020 ___SH () C:\Users\Ute\ntuser.ini
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Vorlagen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Startmenü
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Netzwerkumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Lokale Einstellungen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Eigene Dateien
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Druckumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Musik
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Bilder
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Verlauf
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Anwendungsdaten
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Anwendungsdaten
2014-09-08 08:03 - 2014-09-08 08:03 - 00003631 _____ () C:\Users\Manopost\Downloads\FRST.txt
2014-09-08 08:03 - 2014-09-08 08:02 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64(1).exe
2014-09-08 07:52 - 2009-02-04 12:45 - 00000069 _____ () C:\Windows\NeroDigital.ini
2014-09-08 07:43 - 2014-09-08 07:43 - 01101648 _____ () C:\Users\Manopost\Downloads\HijackThis - CHIP-Installer.exe
2014-09-08 06:31 - 2013-09-17 15:45 - 00000425 _____ () C:\Windows\BRWMARK.INI
2014-09-07 21:28 - 2011-06-11 10:44 - 00003714 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{7D2327BF-DAC5-43D7-8EB3-6EA0AF4A749D}
2014-09-07 19:19 - 2014-09-07 19:19 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64.exe
2014-09-07 18:29 - 2009-01-28 11:48 - 00000108 _____ () C:\Users\Manopost\AppData\Roaming\default.pls
2014-09-07 18:16 - 2014-08-22 09:10 - 00000000 ____D () C:\Program Files (x86)\ver1Re-markit
2014-09-07 16:25 - 2014-09-06 23:24 - 00000000 ____D () C:\Program Files (x86)\LPT
2014-09-07 16:19 - 2014-09-07 16:19 - 00000903 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-07 16:19 - 2014-09-07 16:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Manopost\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-07 11:08 - 2010-11-15 00:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-09-07 11:08 - 2010-11-15 00:52 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-07 10:24 - 2014-09-07 10:24 - 00388152 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-07 10:23 - 2014-09-07 10:23 - 00185186 _____ () C:\Windows\PFRO.log
2014-09-07 01:20 - 2014-08-25 17:43 - 00000000 ___RD () C:\Users\Manopost\Dropbox
2014-09-07 00:24 - 2014-09-06 23:22 - 00000000 ____D () C:\Users\Manopost\AppData\Local\LPT
2014-09-07 00:16 - 2009-01-10 16:50 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-06 23:57 - 2014-09-06 23:16 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Gameo
2014-09-06 23:42 - 2014-09-06 23:41 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup.exe
2014-09-06 23:35 - 2013-12-03 13:32 - 00000000 ___RD () C:\Users\Manopost\Documents\Fugen-T-Poster
2014-09-06 23:34 - 2014-01-02 12:23 - 00000000 ____D () C:\Users\Manopost\Desktop\2014
2014-09-06 23:33 - 2014-01-02 15:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Bayrischer Wald
2014-09-06 23:32 - 2014-08-22 14:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Neuer Ordner
2014-09-06 23:27 - 2014-09-06 23:27 - 00000000 ____D () C:\Users\Manopost\Documents\PC Speed Maximizer
2014-09-06 23:27 - 2013-01-21 16:39 - 00000000 ____D () C:\Users\Manopost\Desktop\Bilder1
2014-09-06 23:26 - 2014-08-26 13:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Tablet
2014-09-06 23:25 - 2014-08-16 23:06 - 00000000 ____D () C:\Users\Manopost\Desktop\Kamera Tolo
2014-09-06 23:24 - 2014-09-06 23:24 - 00106712 _____ () C:\Users\Manopost\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-06 23:24 - 2014-09-06 23:24 - 00002379 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-09-06 23:22 - 2014-09-06 23:22 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Smartbar
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\Desktop\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000000 ___HD () C:\Users\Manopost\AppData\Roaming\GoldenGate
2014-09-06 22:51 - 2006-11-02 15:33 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-09-06 22:50 - 2009-01-07 16:56 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-09-06 22:50 - 2006-11-02 17:15 - 00000000 ____D () C:\Windows\WindowsMobile
2014-09-06 22:46 - 2014-08-25 17:39 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Dropbox
2014-09-06 22:41 - 2013-04-11 17:22 - 00000000 ____D () C:\Program Files\Google
2014-09-06 22:40 - 2013-09-17 15:40 - 00000000 ____D () C:\ProgramData\InstallShield
2014-09-06 22:39 - 2013-09-17 15:42 - 00000000 ____D () C:\Program Files (x86)\Brother
2014-09-06 21:50 - 2014-09-06 21:50 - 00602112 _____ (OldTimer Tools) C:\Users\Manopost\Desktop\OTL.exe
2014-09-06 16:12 - 2009-01-10 16:51 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Google
2014-09-06 16:11 - 2014-09-06 16:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Deployment
2014-09-06 16:11 - 2010-06-03 12:57 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Apps\2.0
2014-09-06 15:57 - 2009-01-10 16:51 - 00000000 ____D () C:\ProgramData\Google
2014-09-06 15:36 - 2011-06-13 13:08 - 00003292 _____ () C:\Windows\System32\Tasks\{4231AEF2-8460-496A-9460-D6D1F6493ADF}
2014-09-06 04:13 - 2014-09-06 23:27 - 00060056 _____ (StdLib) C:\Windows\system32\Drivers\{5eeb83d0-96ea-4249-942c-beead6847053}Gt64.sys
2014-09-02 16:07 - 2008-09-13 07:16 - 00699062 _____ () C:\Windows\system32\perfh007.dat
2014-09-02 16:07 - 2008-09-13 07:16 - 00156416 _____ () C:\Windows\system32\perfc007.dat
2014-09-02 16:07 - 2006-11-02 14:46 - 01638136 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-01 23:00 - 2014-09-01 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA ANTIVIRUS
2014-09-01 23:00 - 2014-04-12 12:28 - 00001794 _____ () C:\Users\Public\Desktop\G DATA ANTIVIRUS.lnk
2014-09-01 23:00 - 2009-10-03 14:49 - 00055808 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2014-09-01 23:00 - 2009-06-20 14:57 - 00142336 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2014-09-01 23:00 - 2009-06-20 14:56 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys
2014-08-31 23:00 - 2014-02-28 00:00 - 00018160 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys
2014-08-31 23:00 - 2009-07-28 16:34 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2014-08-31 22:03 - 2014-08-26 18:52 - 00000000 ___HD () C:\Users\Public\Temp
2014-08-31 15:59 - 2014-08-22 09:11 - 00000000 ____D () C:\Program Files (x86)\videos MediaPlay-Air
2014-08-29 15:01 - 2014-08-22 09:12 - 00004040 _____ () C:\Windows\System32\Tasks\LaunchSignup
2014-08-29 15:01 - 2009-01-08 19:24 - 00003784 _____ () C:\Windows\System32\Tasks\HP-Online-Aktualisierungsprogramm
2014-08-29 15:00 - 2014-04-06 16:26 - 00003558 _____ () C:\Windows\System32\Tasks\GarminUpdaterTask
2014-08-27 10:03 - 2014-08-27 10:03 - 00000630 _____ () C:\Users\Manopost\Desktop\BLT14-15_209.exe - Verknüpfung.lnk
2014-08-27 09:52 - 2014-08-27 09:52 - 00724992 _____ (Maximilian Stangel) C:\Users\Manopost\Downloads\BLT14-15_209.exe
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\ProgramData\Avg_Update_0814tb
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\Program Files (x86)\AVG Security Toolbar
2014-08-27 07:33 - 2014-07-28 19:59 - 00000000 ____D () C:\Program Files (x86)\Browser 7 Maintenance Service
2014-08-26 18:50 - 2014-08-26 18:49 - 00000000 ____D () C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F
2014-08-26 14:04 - 2014-08-17 11:21 - 00000000 ____D () C:\Users\Manopost\Desktop\Meine Bilder
2014-08-26 13:43 - 2009-01-09 17:08 - 00112128 _____ () C:\Users\Manopost\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-08-26 13:13 - 2014-08-26 13:13 - 00000000 ____D () C:\ProgramData\Telekom-Browser 7
2014-08-26 13:13 - 2014-07-28 19:59 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Deutsche Telekom AG
2014-08-26 07:51 - 2012-03-02 20:45 - 00000000 ____D () C:\Program Files (x86)\AVG Secure Search
2014-08-25 17:43 - 2009-01-07 16:52 - 00000000 ____D () C:\Users\Manopost
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Program Files (x86)\Dropbox
2014-08-25 07:52 - 2014-08-25 07:52 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Adobe
2014-08-24 10:30 - 2012-07-19 18:26 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-24 10:30 - 2012-04-08 10:43 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-24 10:30 - 2011-05-14 09:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-23 03:05 - 2014-08-28 21:52 - 00304128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:42 - 2014-08-28 21:52 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 01:38 - 2014-08-28 21:52 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 15:27 - 2014-08-22 15:27 - 00000000 ____D () C:\ProgramData\Xerox
2014-08-22 14:59 - 2014-08-17 13:26 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo 2
2014-08-22 13:21 - 2014-08-17 13:33 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo Video 1
2014-08-22 12:46 - 2014-08-22 09:10 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\VOPackage
2014-08-22 12:46 - 2014-08-22 09:10 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-08-22 12:45 - 2014-08-22 12:43 - 00000000 ____D () C:\Users\Public\10F34257C92C4CB28669BE8F744057EF
2014-08-22 10:24 - 2014-08-22 10:23 - 00000000 ____D () C:\Users\Public\39203AE8A0DE4F819CFD816F114013DB
2014-08-22 10:24 - 2014-08-22 10:23 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\InetStat
2014-08-22 10:23 - 2014-08-22 10:23 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat
2014-08-22 10:20 - 2009-01-28 10:44 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Ahead
2014-08-22 09:57 - 2009-02-02 23:48 - 00000000 __SHD () C:\found.000
2014-08-22 09:36 - 2012-12-16 14:45 - 00000111 _____ () C:\.dir
2014-08-22 09:32 - 2014-07-31 19:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-08-22 09:24 - 2014-01-03 19:18 - 00000008 __RSH () C:\Users\Manopost\ntuser.pol
2014-08-22 09:24 - 2009-11-23 14:04 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-08-22 09:16 - 2006-11-02 15:34 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-08-22 09:12 - 2014-08-22 09:10 - 00062602 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistMSI61B3.txt
2014-08-22 09:12 - 2014-08-22 09:10 - 00012036 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistUI61B3.txt
2014-08-22 09:11 - 2014-08-22 09:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\globalUpdate
2014-08-22 09:11 - 2014-08-22 09:11 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-08-20 19:35 - 2014-08-16 23:56 - 00000000 ____D () C:\Users\Manopost\Desktop\Handy Tolo
2014-08-20 19:28 - 2012-09-05 19:54 - 00050976 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-08-20 17:31 - 2010-08-01 13:11 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Skype
2014-08-20 15:13 - 2014-08-20 14:45 - 00000732 _____ () C:\Users\Manopost\AppData\Local\d3d9caps64.dat
2014-08-20 14:49 - 2014-08-20 14:49 - 00016152 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-08-20 14:49 - 2014-08-20 14:49 - 00000000 ____D () C:\Users\Manopost\AppData\Local\SlimWare Utilities Inc
2014-08-20 14:48 - 2014-08-20 14:48 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-08-20 14:44 - 2014-08-20 14:44 - 00796720 _____ ( ) C:\Users\Manopost\Downloads\nero_setup.exe
2014-08-17 18:45 - 2014-08-17 18:20 - 00001653 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fotostory 3 für Windows.lnk
2014-08-17 18:20 - 2014-08-17 18:20 - 00000000 ____D () C:\Program Files (x86)\Photo Story 3 for Windows
2014-08-17 18:18 - 2014-08-17 18:18 - 01101648 _____ () C:\Users\Manopost\Documents\Microsoft Photo Story - CHIP-Installer.exe
2014-08-17 11:36 - 2013-07-04 09:21 - 00000855 _____ () C:\Users\Manopost\Desktop\Bluetooth-Informationsaustausch.lnk
2014-08-17 09:51 - 2006-11-02 15:33 - 00000000 ____D () C:\Windows\rescache
2014-08-17 08:49 - 2014-08-17 08:49 - 01058200 _____ (Adobe) C:\Users\Manopost\Downloads\install_flashplayer14x32au_mssa_awc_aih.exe
2014-08-17 08:48 - 2013-08-15 20:56 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-17 08:44 - 2006-11-02 14:35 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-08-17 08:33 - 2014-02-19 16:41 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-17 08:32 - 2014-08-17 08:32 - 00001757 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2014-08-17 08:32 - 2014-08-17 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2014-08-17 08:32 - 2014-02-19 16:42 - 00000000 ____D () C:\ProgramData\Garmin
2014-08-17 08:32 - 2014-02-19 16:41 - 00000000 ____D () C:\Program Files (x86)\Garmin
2014-08-14 12:15 - 2014-08-17 00:05 - 36898446 _____ () C:\Users\Manopost\Desktop\20140814_131447.mp4

Files to move or delete:
====================
C:\Users\Manopost\DivXInstaller7.exe
C:\Users\Manopost\googleupdatesetup.exe
C:\Users\Manopost\Nero-8.3.13.0_all_update.exe
C:\Users\Manopost\pcfresh.exe
C:\Users\Manopost\PowerPointViewer.exe


Some content of TEMP:
====================
C:\Users\Manopost\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmphpm47v.dll
C:\Users\Manopost\AppData\Local\Temp\ICReinstall_google-chrome_setup (1).exe
C:\Users\Manopost\AppData\Local\Temp\_isA52C.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-08 10:11

==================== End Of Log ============================

--- --- ---

cosinus 08.09.2014 13:41

Dann bitte jetzt Combofix ausführen:

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Snoosel 08.09.2014 14:26

ist es normal, dass es schon 20 min scannt? Ist auf 64% und hat 7 von 11 (was auch immer) geprüft.

cosinus 08.09.2014 14:31

Ja das dauert, sei bitte geduldig

Snoosel 08.09.2014 15:59

Das Programm reagiert wieder nicht. Es bleibt bei 64% stehen.

Beim erneuten Versuch Combo-Fix zu starten erscheint dauerhaft nur das kleine schwarze Feld mit grüner Schrift. Das Feld mit den 2 Ladebalken verschwindet. Ist auch nirgends zu sehen.

cosinus 08.09.2014 16:18

Windows neu starten, combofix neu runterladen auf den Desktop und nochmal probieren

Snoosel 08.09.2014 17:52

AWin neu gestartet, combofix runtergeladen und nochmal probiert. Ergebnis:
Läuft bis 64% ...7 von 11 Files durchsucht.
Es geht seit 1 Std. nicht weiter. Die Balken sind jedoch da und laufen.

Win neu gestartet, nicht AWin....

cosinus 08.09.2014 22:49

Aha. CF funktioniert also nicht richtig. Dann versuch das:

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Snoosel 09.09.2014 07:38

1.Auswertung
Code:

Malwarebytes Anti-Rootkit BETA 1.07.0.1012
www.malwarebytes.org

Database version: v2014.09.08.10

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Ute :: MANOPOST-PC [administrator]

09.09.2014 07:02:24
mbar-log-2014-09-09 (07-02-24).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 373211
Time elapsed: 25 minute(s), 29 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detectAed)

Registry Keys Detected: 7
HKLM\SOFTWARE\WOW6432NODE\IGB (Malware.Trace) -> Delete on reboot. [9dfc3990f6851d197e37aff634cf53ad]
HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\attrib.exe (Security.Hijack) -> Delete on reboot. [8f0acbfe7407f3432292bd1c9c6754ac]
HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\catchme.exe (Security.Hijack) -> Delete on reboot. [d2c79c2d79024cea38ffc0e821e253ad]
HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\ComboFix.exe (Security.Hijack) -> Delete on reboot. [168362678eed95a15e1ed8d0f70cf808]
HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\dumphive.exe (Security.Hijack) -> Delete on reboot. [c1d8a1281962b3836762e0c8a261fc04]
HKU\S-1-5-21-243317379-2889874547-3061927781-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\fcn (Rogue.Residue) -> Delete on reboot. [c6d3f1d84f2c88aeda12593e35ce9868]
HKU\S-1-5-21-243317379-2889874547-3061927781-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\IGB (Rogue.Residue) -> Delete on reboot. [8e0b0dbc403b32049aa5197f847f2dd3]

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Windows\System32\drivers\{5eeb83d0-96ea-4249-942c-beead6847053}Gt64.sys (PUP.Optional.Sanbreel.A) -> Delete on reboot. [1367504a13b97aba5a26d220711a3845]

Physical Sectors Detected: 0
(No malicious items detected)

(end)

2.Auswertung
Code:

Malwarebytes Anti-Rootkit BETA 1.07.0.1012
www.malwarebytes.org

Database version: v2014.09.09.01

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Ute :: MANOPOST-PC [administrator]

09.09.2014 07:59:00
mbar-log-2014-09-09 (07-59-00).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 372805
Time elapsed: 21 minute(s), 50 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

scheint alles weg zu sein. Die srtpm exe ist nicht mehr zu ehen. Danke

Hallo Cosinus,
wie kann ich den vorigen Administrator wieder aktivieren? Er ist jetzt nur Standardbenutzer.

cosinus 09.09.2014 13:05

Halt wir sind noch nicht fertig.

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Snoosel 09.09.2014 15:01

Code:

15:51:22.0640 0x2250  TDSS rootkit removing tool 3.0.0.40 Jul 10 2014 12:37:58
15:51:43.0083 0x2250  ============================================================
15:51:43.0083 0x2250  Current date / time: 2014/09/09 15:51:43.0083
15:51:43.0083 0x2250  SystemInfo:
15:51:43.0083 0x2250 
15:51:43.0083 0x2250  OS Version: 6.0.6002 ServicePack: 2.0
15:51:43.0083 0x2250  Product type: Workstation
15:51:43.0083 0x2250  ComputerName: MANOPOST-PC
15:51:43.0083 0x2250  UserName: Ute
15:51:43.0083 0x2250  Windows directory: C:\Windows
15:51:43.0083 0x2250  System windows directory: C:\Windows
15:51:43.0083 0x2250  Running under WOW64
15:51:43.0083 0x2250  Processor architecture: Intel x64
15:51:43.0083 0x2250  Number of processors: 4
15:51:43.0083 0x2250  Page size: 0x1000
15:51:43.0083 0x2250  Boot type: Normal boot
15:51:43.0083 0x2250  ============================================================
15:51:43.0176 0x2250  KLMD registered as C:\Windows\system32\drivers\32883899.sys
15:51:43.0426 0x2250  System UUID: {410E098B-2232-0245-CF50-60AFD77D275E}
15:51:43.0863 0x2250  Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 ( 596.17 Gb ), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:51:43.0910 0x2250  Drive \Device\Harddisk5\DR5 - Size: 0x25433D6000 ( 149.05 Gb ), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
15:51:43.0910 0x2250  ============================================================
15:51:43.0910 0x2250  \Device\Harddisk0\DR0:
15:51:43.0910 0x2250  MBR partitions:
15:51:43.0910 0x2250  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x48D4099A
15:51:43.0910 0x2250  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x48D409D9, BlocksNum 0x1B164E8
15:51:43.0910 0x2250  \Device\Harddisk5\DR5:
15:51:43.0910 0x2250  MBR partitions:
15:51:43.0910 0x2250  \Device\Harddisk5\DR5\Partition1: MBR, Type 0x7, StartLBA 0x3F00, BlocksNum 0x12A14BC1
15:51:43.0910 0x2250  ============================================================
15:51:43.0941 0x2250  C: <-> \Device\Harddisk0\DR0\Partition1
15:51:44.0003 0x2250  D: <-> \Device\Harddisk0\DR0\Partition2
15:51:44.0003 0x2250  J: <-> \Device\Harddisk5\DR5\Partition1
15:51:44.0003 0x2250  ============================================================
15:51:44.0003 0x2250  Initialize success
15:51:44.0003 0x2250  ============================================================
15:53:10.0940 0x2224  ============================================================
15:53:10.0940 0x2224  Scan started
15:53:10.0940 0x2224  Mode: Manual; SigCheck; TDLFS;
15:53:10.0940 0x2224  ============================================================
15:53:10.0940 0x2224  KSN ping started
15:53:24.0462 0x2224  KSN ping finished: true
15:53:25.0024 0x2224  ================ Scan system memory ========================
15:53:25.0024 0x2224  System memory - ok
15:53:25.0024 0x2224  ================ Scan services =============================
15:53:25.0149 0x2224  [ BBC496CC995FE6AA0524FBFC3C39A878, 7AB01DF636CFE4E8EE156399EC044E64B0875F2A54045A64BC8389B5D383A430 ] ABBYY.Licensing.PDFTransformer.Classic.3.0 C:\Program Files (x86)\ABBYY PDF Transformer 3.0\NetworkLicenseServer.exe
15:53:25.0305 0x2224  ABBYY.Licensing.PDFTransformer.Classic.3.0 - ok
15:53:25.0414 0x2224  [ 1965AAFFAB07E3FB03C77F81BEBA3547, 351A1EBB1B95C8E03ED125C8F997DEE810B4DF36AD290E7685FC01963B522BFC ] ACPI            C:\Windows\system32\drivers\acpi.sys
15:53:25.0445 0x2224  ACPI - ok
15:53:25.0507 0x2224  [ B362181ED3771DC03B4141927C80F801, 69514E5177A0AEA89C27C2234712F9F82E8D8F99E1FD4273898C9324C6FF7472 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
15:53:25.0523 0x2224  AdobeARMservice - ok
15:53:25.0632 0x2224  [ F4BF3ADDDDC1AD372604F13C2B0C1F65, FA37ED5014336A72F778C485226B61BEFECEB861AB754862738795C167F0BAB7 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
15:53:25.0648 0x2224  AdobeFlashPlayerUpdateSvc - ok
15:53:25.0695 0x2224  [ F14215E37CF124104575073F782111D2, 7F624F7F0FE9909C07AB2E4C74727686FDA9DF33778A9CBBE35027D6579E4F71 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
15:53:25.0726 0x2224  adp94xx - ok
15:53:25.0757 0x2224  [ 7D05A75E3066861A6610F7EE04FF085C, 406F2CE539C306BA60C233FBCDB029153588F0499BBE91E66FC915E5C5D7D2A5 ] adpahci        C:\Windows\system32\drivers\adpahci.sys
15:53:25.0788 0x2224  adpahci - ok
15:53:25.0804 0x2224  [ 820A201FE08A0C345B3BEDBC30E1A77C, 3170B308724CAA0AD50B74D045C837C48BD6A3A11ABA222670BEA82192A861BF ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
15:53:25.0819 0x2224  adpu160m - ok
15:53:25.0851 0x2224  [ 9B4AB6854559DC168FBB4C24FC52E794, 83CD75DE0A16AE66586837565ECA8B98BA9309519139C4C2032474B8DDF5A1AD ] adpu320        C:\Windows\system32\drivers\adpu320.sys
15:53:25.0866 0x2224  adpu320 - ok
15:53:25.0897 0x2224  [ 0F421175574BFE0BF2F4D8E910A253BB, CEABE3A4F546EB6ACA079931AB532DC88FF757DEEF6F434991802220328A9CD6 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
15:53:25.0944 0x2224  AeLookupSvc - ok
15:53:25.0991 0x2224  [ E58A17E945593544C707423F9772EEA0, FC17AFF979354EB89DCA307BF07C52B84629AF540D4C6A32DD537695CA654205 ] AFD            C:\Windows\system32\drivers\afd.sys
15:53:26.0053 0x2224  AFD - ok
15:53:26.0116 0x2224  [ F6F6793B7F17B550ECFDBD3B229173F7, 7EB12A9372B7966440E39F1B567A43C21231D67DDFAA9C1DECC7E68627F82346 ] agp440          C:\Windows\system32\drivers\agp440.sys
15:53:26.0131 0x2224  agp440 - ok
15:53:26.0147 0x2224  [ 222CB641B4B8A1D1126F8033F9FD6A00, 8C7FD4BF87DC00893B99E64344C0E6A3F321DAD9BE60A99763629260E7C6312C ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
15:53:26.0163 0x2224  aic78xx - ok
15:53:26.0194 0x2224  [ 5922F4F59B7868F3D74BBBBEB7B825A3, 71504BC8B596F540BF059059670BC0C138D8759C1DD9F99F1EC368FD5C53F573 ] ALG            C:\Windows\System32\alg.exe
15:53:26.0256 0x2224  ALG - ok
15:53:26.0287 0x2224  [ 157D0898D4B73F075CE9FA26B482DF98, 84C3E163D7393FD306842F155C88A50B7D8AE88B59586F9014DB76B749CC33D5 ] aliide          C:\Windows\system32\drivers\aliide.sys
15:53:26.0303 0x2224  aliide - ok
15:53:26.0319 0x2224  [ 970FA5059E61E30D25307B99903E991E, CFB241803A63EA3469B2596462A42DDCA813B3ACF96E56BB34F5979BB34DDC32 ] amdide          C:\Windows\system32\drivers\amdide.sys
15:53:26.0334 0x2224  amdide - ok
15:53:26.0350 0x2224  [ CDC3632A3A5EA4DBB83E46076A3165A1, 40BE3451A3F29CD3352360FF72165C54237E44D01006390805D493B0D06F51DB ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
15:53:26.0412 0x2224  AmdK8 - ok
15:53:26.0443 0x2224  [ B46840E5BDAEE0C749A3E5778F65EBE4, 121C68A65E3D3A9423363C5028568799A81B569801BE0F876AFE6EC86F9D2E92 ] AndNetDiag      C:\Windows\system32\DRIVERS\lgandnetdiag64.sys
15:53:26.0490 0x2224  AndNetDiag - ok
15:53:26.0521 0x2224  [ 130701C53E4DF44B54FED8C3892150F5, C9EB4D1793BA3D20FB1846AD508C6310D038E8BEFBE13B5A0A30A1F39D1586AB ] ANDNetModem    C:\Windows\system32\DRIVERS\lgandnetmodem64.sys
15:53:26.0568 0x2224  ANDNetModem - ok
15:53:26.0615 0x2224  [ 3AB878F98191BC98C1760DC4DDD657FF, EEC3AA37C2234E9D9F35246BCF529516C7847537219F51A55A86A3CB8B3B822A ] andnetndis      C:\Windows\system32\DRIVERS\lgandnetndis64.sys
15:53:26.0662 0x2224  andnetndis - ok
15:53:26.0724 0x2224  [ 85180CF88C5EBAD73B452A43A004CA51, 24D25495DC21293FC1F37EE7E7C2A4725E66D3D25BE05D7EDF4BB4F444C65526 ] AOL ACS        C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe
15:53:26.0740 0x2224  AOL ACS - ok
15:53:26.0771 0x2224  [ 7C8ECAAD76EA1D076A450C8303D9BD98, 90904B2BE380A51BDCEDADA530214CE5321C06456E10F5985B40E3282902BEF6 ] Appinfo        C:\Windows\System32\appinfo.dll
15:53:26.0818 0x2224  Appinfo - ok
15:53:26.0849 0x2224  [ BA8417D4765F3988FF921F30F630E303, 876A8F34E578020DD9EDD64F7F77A0A3B4592EC568830B500D7EA844D3159C72 ] arc            C:\Windows\system32\drivers\arc.sys
15:53:26.0865 0x2224  arc - ok
15:53:26.0880 0x2224  [ 9D41C435619733B34CC16A511E644B11, DEFFBBB5ECE33B7DF949DF979188AF3B6674E7580FC069397AB756EA84E24822 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
15:53:26.0896 0x2224  arcsas - ok
15:53:26.0989 0x2224  [ 9A262EDD17F8473B91B333D6B031A901, 05DFBD3A7D83FDE1D062EA719ACA9EC48CB7FD42D17DDD88B82E5D25469ADD23 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
15:53:27.0005 0x2224  aspnet_state - ok
15:53:27.0021 0x2224  [ 22D13FF3DAFEC2A80634752B1EAA2DE6, 503F7E5F1B14D3F7AEAB0982E812B19DABE38FD4104D93922F50F0B2D19BECFB ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
15:53:27.0067 0x2224  AsyncMac - ok
15:53:27.0099 0x2224  [ E68D9B3A3905619732F7FE039466A623, 74C0B29E54EF064660B9C756E03D5A7EB78F261EFF768EB6E74D261FBD34340D ] atapi          C:\Windows\system32\drivers\atapi.sys
15:53:27.0114 0x2224  atapi - ok
15:53:27.0177 0x2224  [ 0EB0A49C55D0C9102499353B80BDB021, 8B3B7D1CE07AF0A8EEA68BB8DE13983AA8FDD0ADB159299677F0340D3A6CAA6E ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
15:53:27.0223 0x2224  Ati External Event Utility - ok
15:53:27.0379 0x2224  [ 6F677A4B26E88AC10F72F1614FDA470A, 374DB526C9AB518F01121570D4BCA9ED27E829CE575E56AAEC103D74E8AA2C17 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
15:53:27.0613 0x2224  atikmdag - ok
15:53:27.0676 0x2224  [ F88EF61BCD43ADDF2C9555430C16CD96, 7213FE9B9025DA33B0DEA7338B1E00555FCB88326CE26052C9FF16E72E4715AA ] atksgt          C:\Windows\system32\DRIVERS\atksgt.sys
15:53:27.0707 0x2224  atksgt - ok
15:53:27.0754 0x2224  [ 79318C744693EC983D20E9337A2F8196, 94226786EF8A101C2E805C6BA3C1CF46628BAF1AFCECBC1FAB7A7E7E5E642608 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
15:53:27.0832 0x2224  AudioEndpointBuilder - ok
15:53:27.0879 0x2224  [ 79318C744693EC983D20E9337A2F8196, 94226786EF8A101C2E805C6BA3C1CF46628BAF1AFCECBC1FAB7A7E7E5E642608 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
15:53:27.0910 0x2224  AudioSrv - ok
15:53:27.0957 0x2224  [ 68430AD3FB0FADBFA5D1677617D1E1F5, CF732DD21B472653AB0A4063455F2E7608F3075C255B9882D18CB52026B6C972 ] avgtp          C:\Windows\system32\drivers\avgtpx64.sys
15:53:27.0972 0x2224  avgtp - ok
15:53:28.0128 0x2224  [ 6C7718A9054578FEE9BFA222F879B92C, 0F4E1296FE776E263BF507BCD3223DDEE88818EA8752695DF5389C01B2373136 ] AVKProxy        C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
15:53:28.0237 0x2224  AVKProxy - ok
15:53:28.0347 0x2224  [ 56C6F2D7F1D515B4B534217443D3B67F, CB9E94EE515EE7C426B34EC40DFDEF27893C3379C011B2FF6EEF318A34BCF482 ] AVKService      C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe
15:53:28.0393 0x2224  AVKService - ok
15:53:28.0487 0x2224  [ 258B9C230D2A904349CDF18CAD6B22BE, A270FF5D58C516272C248E22FD5ED3C4F279D0348154D56E13E88D05820E9246 ] AVKWCtl        C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe
15:53:28.0596 0x2224  AVKWCtl - ok
15:53:28.0627 0x2224  [ 9BD46C1D2F33A890B7226EDF543F18AA, 9AD05E61F501D2D89554AA5A6BFF1F272FE6B0DED4E43FC8F621F0AF30C859B1 ] AVM WLAN Connection Service C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
15:53:28.0677 0x2224  AVM WLAN Connection Service - detected UnsignedFile.Multi.Generic ( 1 )
15:53:31.0041 0x2224  Detect skipped due to KSN trusted
15:53:31.0041 0x2224  AVM WLAN Connection Service - ok
15:53:31.0057 0x2224  [ 1DC2F715792CF33428AD7993ACBD224D, 129FBD517E016914CD61C35894C0B9B2074E680F1EB21201597E5C13CAF4529F ] avmeject        C:\Windows\system32\drivers\avmeject.sys
15:53:31.0072 0x2224  avmeject - ok
15:53:31.0103 0x2224  [ FFB96C2589FFA60473EAD78B39FBDE29, 6A2792753E2CB580672B3107C0DBB9D26B6DAA14B37D5EC314BD0E304197E03E ] BFE            C:\Windows\System32\bfe.dll
15:53:31.0181 0x2224  BFE - ok
15:53:31.0259 0x2224  [ 6D316F4859634071CC25C4FD4589AD2C, 73F69AC9E505F3B11A3CCFF8571930229A9058E672CD008A4BF26C0189564EAE ] BITS            C:\Windows\System32\qmgr.dll
15:53:31.0353 0x2224  BITS - ok
15:53:31.0400 0x2224  [ 79FEEB40056683F8F61398D81DDA65D2, 5EA3016194F71A2A2177C2B5129E82738EC621ACAD269809F4C131B72CFEB6C6 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys
15:53:31.0462 0x2224  blbdrive - ok
15:53:31.0493 0x2224  [ 1AD25274553AD53051277D6F12A49513, 2263AA99C8A899E5828185C4C79BC7B21706A99E5D579164D7F9C1C7E59DEC76 ] Boonty Games    C:\Program Files (x86)\Common Files\BOONTY Shared\Service\Boonty.exe
15:53:31.0509 0x2224  Boonty Games - detected UnsignedFile.Multi.Generic ( 1 )
15:53:34.0988 0x2224  Detect skipped due to KSN trusted
15:53:34.0988 0x2224  Boonty Games - ok
15:53:35.0019 0x2224  [ 2348447A80920B2493A9B582A23E81E1, 50F9242B7104607E633ABAF4E0A213C1C1226BF81F7FB4E216A9E878247B868C ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
15:53:35.0066 0x2224  bowser - ok
15:53:35.0097 0x2224  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
15:53:35.0128 0x2224  BrFiltLo - ok
15:53:35.0144 0x2224  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
15:53:35.0206 0x2224  BrFiltUp - ok
15:53:35.0237 0x2224  [ A1B39DE453433B115B4EA69EE0343816, 61441E7E9D5259A5987DBD3FC8D4E3221A57F42C7CC0F94DB48E80EEF96CA5D4 ] Browser        C:\Windows\System32\browser.dll
15:53:35.0284 0x2224  Browser - ok
15:53:35.0347 0x2224  [ 7DE1DAC732775591CB716ED0E22A1983, E4F1B8FFFA44F632E3076F18C4D01D38B26E672A3DB280640DCB8217FCFD8F47 ] Browser7Maintenance C:\Program Files (x86)\Browser 7 Maintenance Service\maintenanceservice.exe
15:53:35.0362 0x2224  Browser7Maintenance - detected UnsignedFile.Multi.Generic ( 1 )
15:53:37.0896 0x2224  Detect skipped due to KSN trusted
15:53:37.0896 0x2224  Browser7Maintenance - ok
15:53:37.0916 0x2224  [ F0F0BA4D815BE446AA6A4583CA3BCA9B, E0A5DB5A0C7D6AF93ED45F34D2597F77982DFF41E4FDAC827FE5D80323ADED60 ] Brserid        C:\Windows\system32\drivers\brserid.sys
15:53:37.0996 0x2224  Brserid - ok
15:53:38.0026 0x2224  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
15:53:38.0096 0x2224  BrSerWdm - ok
15:53:38.0126 0x2224  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
15:53:38.0206 0x2224  BrUsbMdm - ok
15:53:38.0246 0x2224  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
15:53:38.0326 0x2224  BrUsbSer - ok
15:53:38.0376 0x2224  [ 732BEA9B5959EAF0773A2C39F9C23B11, 7BE30FE83F0EA25C85B7A7899CE78A510079100AB86865FD00A47D4447E3DCFC ] BthAvrcp        C:\Windows\system32\DRIVERS\BthAvrcp.sys
15:53:38.0386 0x2224  BthAvrcp - ok
15:53:38.0416 0x2224  [ 09F926A0D9C0BAFD8417A4307D2ED13C, 9C86FB0E328D3E14DC6A1BD64CB0E6E61D8DA437FF51399FD87DCA70FDC96C01 ] BthEnum        C:\Windows\system32\DRIVERS\BthEnum.sys
15:53:38.0456 0x2224  BthEnum - ok
15:53:38.0506 0x2224  [ 72F70A38BB15252EB7C4DA7BA3BD4ED1, DFAAB0E8F0F01937F2A451465A67803509A6BFEA248F08389205F73D0115BCDB ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
15:53:38.0556 0x2224  BTHMODEM - ok
15:53:38.0596 0x2224  [ BEFC5311736B475AC5B60C14FF7C775A, 8B9BF5486B09E10361E8C412481E684CD1B03B5C06023AD9B7C29553D51F0455 ] BthPan          C:\Windows\system32\DRIVERS\bthpan.sys
15:53:38.0636 0x2224  BthPan - ok
15:53:38.0686 0x2224  [ E1466882252FF51EDDE48C3F7EDA2591, BBF7B234BC3EB5CB56C6EA502E89C5EF29EC51466E6BE15ECFE49831E2406143 ] BTHPORT        C:\Windows\system32\Drivers\BTHport.sys
15:53:38.0766 0x2224  BTHPORT - ok
15:53:38.0816 0x2224  [ 22E65FFD640F16968F855F5B3528D366, 6EF7FC170E2533BD7BFF0125391757E27E3D5F05EDE1A986E4295CDCD2D9B197 ] BthServ        C:\Windows\System32\bthserv.dll
15:53:38.0856 0x2224  BthServ - ok
15:53:38.0876 0x2224  [ 970192CDED77A128E7E30722E5EE6B9C, 5302B4D1E7A430D1BE9B8ECEED3AAC8095326AFF0226BEDB56CF061CF27BE679 ] BTHUSB          C:\Windows\system32\Drivers\BTHUSB.sys
15:53:38.0896 0x2224  BTHUSB - ok
15:53:38.0916 0x2224  [ B4D787DB8D30793A4D4DF9FEED18F136, 2A956F7DCFE61E556F30BDA6D45592A05533541D6ED321C251C1C05F6CEA6DDC ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
15:53:38.0976 0x2224  cdfs - ok
15:53:38.0996 0x2224  [ C025AA69BE3D0D25C7A2E746EF6F94FC, F4754B23CC256ADF92FDD42A9BA80F1ACB74834A58FCBEA2C52650FAFC7F9483 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
15:53:39.0056 0x2224  cdrom - ok
15:53:39.0086 0x2224  [ 5A268127633C7EE2A7FB87F39D748D56, 45C530A0EE0108543A75B9427F77EBB5E8350AE16C235763B6F32E72CE15C449 ] CertPropSvc    C:\Windows\System32\certprop.dll
15:53:39.0136 0x2224  CertPropSvc - ok
15:53:39.0166 0x2224  [ 02EA568D498BBDD4BA55BF3FCE34D456, 5A418B156CBB48D14E0F6B6AE6E03B8CD97AABE838F260757014479566C63F17 ] circlass        C:\Windows\system32\drivers\circlass.sys
15:53:39.0236 0x2224  circlass - ok
15:53:39.0286 0x2224  [ 3DCA9A18B204939CFB24BEA53E31EB48, 73CEDE020A6C8269EE8847A4E43071FD231179DA9430DE2983263B8345AD92B7 ] CLFS            C:\Windows\system32\CLFS.sys
15:53:39.0326 0x2224  CLFS - ok
15:53:39.0366 0x2224  [ 6B6943A0CA56B47D6FB2EE476890854F, 6DA779879487F4A187DF54B0362642643D7871AA8F7E30992D781F558C50F052 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:53:39.0386 0x2224  clr_optimization_v2.0.50727_32 - ok
15:53:39.0426 0x2224  [ 753049933D5326D835F4FCACDF4AD5E3, 715BEE09C19BCBCAD2A93E4725DB3A1FDD8E2FEFFF6E0C3D2F98FC607FED5D3A ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
15:53:39.0446 0x2224  clr_optimization_v2.0.50727_64 - ok
15:53:39.0486 0x2224  [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
15:53:39.0516 0x2224  clr_optimization_v4.0.30319_32 - ok
15:53:39.0526 0x2224  [ 4AEDAB50F83580D0B4D6CF78191F92AA, D113C47013B018B45161911B96E93AF96A2F3B34FA47061BF6E7A71FBA03194A ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
15:53:39.0546 0x2224  clr_optimization_v4.0.30319_64 - ok
15:53:39.0566 0x2224  [ E5D5499A1C50A54B5161296B6AFE6192, 20A8A0478918063A9EE81565F21F4ACCAA7B6A8B2E9E084099879D85574BAB3E ] cmdide          C:\Windows\system32\drivers\cmdide.sys
15:53:39.0576 0x2224  cmdide - ok
15:53:39.0596 0x2224  [ 7FB8AD01DB0EABE60C8A861531A8F431, E19353C686B07A0DBBA92CFCC88AB9B6BEBAF389416B78F4470BA673E7CD73C3 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
15:53:39.0606 0x2224  Compbatt - ok
15:53:39.0616 0x2224  COMSysApp - ok
15:53:39.0616 0x2224  [ A8585B6412253803CE8EFCBD6D6DC15C, C3906B080D3BB06CB976FD98C62CBA97DAE74970A5559D51EF5111D773949322 ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
15:53:39.0636 0x2224  crcdisk - ok
15:53:39.0666 0x2224  [ 5AAC48EAF8EACF247DB44FB61B900D89, D20FCD5C71CA18F284D3DFD0CED37F6888A296E76B7B0563F2F4668CF90FE752 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
15:53:39.0746 0x2224  CryptSvc - ok
15:53:39.0796 0x2224  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF, 3BE4B8EE22FA55D3A17D3718781C8BCA631C78F7928092561F6B79BB60E7D7FE ] DcomLaunch      C:\Windows\system32\rpcss.dll
15:53:39.0846 0x2224  DcomLaunch - ok
15:53:39.0886 0x2224  [ 8B722BA35205C71E7951CDC4CDBADE19, 39720A60DFD0532F7E1A1976240E9828559BF9E0C6D1CFBF4D911965BFD94158 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
15:53:39.0906 0x2224  DfsC - ok
15:53:40.0036 0x2224  [ C647F468F7DE343DF8C143655C5557D4, E2D35FE49C408B952D8FE0C7EF70D42798229D30B89CEF9858BAC9F4F9E98EF2 ] DFSR            C:\Windows\system32\DFSR.exe
15:53:40.0266 0x2224  DFSR - ok
15:53:40.0326 0x2224  [ 3ED0321127CE70ACDAABBF77E157C2A7, 10973BD0AEF9597A4EA0A4947BDE922F9168F33D6ED97BFFEE6176AADAD78980 ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
15:53:40.0376 0x2224  Dhcp - ok
15:53:40.0426 0x2224  [ B0107E40ECDB5FA692EBF832F295D905, 76466BB9E4F12436ECCCB9D89EB20762B4785F82F02591B51A735A590E248264 ] disk            C:\Windows\system32\drivers\disk.sys
15:53:40.0446 0x2224  disk - ok
15:53:40.0476 0x2224  [ 06230F1B721494A6DF8D47FD395BB1B0, F6CA8270740E01D9CE2FE8E34BC067C7EDC15BA610F461860E1D17D135C8A379 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
15:53:40.0496 0x2224  Dnscache - ok
15:53:40.0536 0x2224  [ 1A7156DD1E850E9914E5E991E3225B94, 99FF0C7125B01FCB0B92DC44756AE8FAA486F2E7F38DC6204F7EFE5918F8480A ] dot3svc        C:\Windows\System32\dot3svc.dll
15:53:40.0586 0x2224  dot3svc - ok
15:53:40.0626 0x2224  [ 74C02B1717740C3B8039539E23E4B53F, FF17BC1DAAE92C99D17EAE5C43FCFCC4B76E390D05EE2C603E5579C78A5536F0 ] Dot4            C:\Windows\system32\DRIVERS\Dot4.sys
15:53:40.0686 0x2224  Dot4 - ok
15:53:40.0716 0x2224  [ 08321D1860235BF42CF2854234337AEA, 39BD593B373A43C34FDDE283BA17F8127558036E8B5604D7C7091BC99CA9D739 ] Dot4Print      C:\Windows\system32\DRIVERS\Dot4Prt.sys
15:53:40.0787 0x2224  Dot4Print - ok
15:53:40.0819 0x2224  [ 4ADCCF0124F2B6911D3786A5D0E779E5, 950B6FA2B9ABF353036A64133ED441EF58EEE36DC4BF5D5C4FFB71796438B5AA ] dot4usb        C:\Windows\system32\DRIVERS\dot4usb.sys
15:53:40.0897 0x2224  dot4usb - ok
15:53:40.0928 0x2224  [ 1583B39790DB3EAEC7EDB0CB0140C708, F94F9AE7054A38602CD25D4E10FE7C7B574BD9ED8440C3FDAA7275A1D1E663E7 ] DPS            C:\Windows\system32\dps.dll
15:53:40.0990 0x2224  DPS - ok
15:53:41.0021 0x2224  [ F1A78A98CFC2EE02144C6BEC945447E6, D2E2AA13BE6319F967002476A5D3CF09B1B44350576DD8E1C1C531854F53B488 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
15:53:41.0037 0x2224  drmkaud - ok
15:53:41.0084 0x2224  [ 362CCEF305F45829316D62D3410F2062, 35033749E9B6B5AFC9C8C305F4AA1597E9776D465E7BBC24A20E836B7BEF0D73 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
15:53:41.0131 0x2224  DXGKrnl - ok
15:53:41.0177 0x2224  [ 264CEE7B031A9D6C827F3D0CB031F2FE, 50CAD28A73D29E7E04A45330146CF713BA17101215955009121E36D43CD5C536 ] E1G60          C:\Windows\system32\DRIVERS\E1G6032E.sys
15:53:41.0255 0x2224  E1G60 - ok
15:53:41.0287 0x2224  [ C2303883FD9BE49DC36A6400643002EA, F062D1D6D503CF5195BDE8C1DC75B541F559CB8175ADABCDB7690E9F1CA3EA4E ] EapHost        C:\Windows\System32\eapsvc.dll
15:53:41.0333 0x2224  EapHost - ok
15:53:41.0380 0x2224  [ 5F94962BE5A62DB6E447FF6470C4F48A, D00F9B3315DE8610BBE93FFD3CA3E2CF5B10697C518FC25FA4274CC6894D022B ] Ecache          C:\Windows\system32\drivers\ecache.sys
15:53:41.0396 0x2224  Ecache - ok
15:53:41.0443 0x2224  [ 14CE384D2E27B64C256BDA4DC39C312D, D5FA9C2BB162F1C22E419D33671B8202AAC245A87F6B183B97F83F5BFA165B41 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
15:53:41.0521 0x2224  ehRecvr - ok
15:53:41.0552 0x2224  [ B93159C1313D66FDFBBE876F5189CD52, 51E39160EA56F6B08449267EDF2A0F604612663768D2348DE23554AB07BDBB62 ] ehSched        C:\Windows\ehome\ehsched.exe
15:53:41.0567 0x2224  ehSched - ok
15:53:41.0567 0x2224  [ F5EE2527D74449868E3C3227A59BCD28, 11640E97EE9D8F9A5DC3FEA6BA7A737AA796A7235C7F5C7EF1ABFB51C9D730D3 ] ehstart        C:\Windows\ehome\ehstart.dll
15:53:41.0614 0x2224  ehstart - ok
15:53:41.0645 0x2224  [ C4636D6E10469404AB5308D9FD45ED07, 367D958D19F672395462206F27C1E138386C2F37B0FA77546F4217CF16D05C84 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
15:53:41.0692 0x2224  elxstor - ok
15:53:41.0770 0x2224  [ A9B18B63A4FD6BAAB83326706D857FAB, 7721CC67C0F8CE3060D0EB35A10E4ADC1E3CB470C0797B17D606060C270F96D7 ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
15:53:41.0833 0x2224  EMDMgmt - ok
15:53:41.0864 0x2224  [ BC3A58E938BB277E46BF4B3003B01ABD, 2BB054E632A96951DAB25B3BE8541AEC1B97A7739FC8D0E34BE8B9295600C8FC ] ErrDev          C:\Windows\system32\drivers\errdev.sys
15:53:41.0926 0x2224  ErrDev - ok
15:53:41.0989 0x2224  [ E12F22B73F153DECE721CD45EC05B4AF, 41887EEF4BB024329B4079AD50FC5FB705F0EB8BAF6C93A8242DC2A73D3AFD86 ] EventSystem    C:\Windows\system32\es.dll
15:53:42.0051 0x2224  EventSystem - ok
15:53:42.0113 0x2224  [ 486844F47B6636044A42454614ED4523, 3E24E78584B199C0FAA59613EEB7DF67B3B878B277A0130C7A3FF608C130BA2F ] exfat          C:\Windows\system32\drivers\exfat.sys
15:53:42.0160 0x2224  exfat - ok
15:53:42.0191 0x2224  ezSharedSvc - ok
15:53:42.0238 0x2224  [ 1A4BEE34277784619DDAF0422C0C6E23, 3223E1B5DD4866D8E09F1B465FF82C911DDEE5B01B084543086E47B11D2AEA77 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
15:53:42.0301 0x2224  fastfat - ok
15:53:42.0332 0x2224  [ 81B79B6DF71FA1D2C6D688D830616E39, 62F8BC0DB918A49B10A5BE1724A2E2F17FA7D8208D5D86822FACB2DCD97B3591 ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
15:53:42.0363 0x2224  fdc - ok
15:53:42.0379 0x2224  [ BB9267ACACD8B7533DD936C34A0CBA5E, 32DE6E10ABA540D62F0D8AE30DE8769D7BF29E547838BEBE67C04183CC0B32C7 ] fdPHost        C:\Windows\system32\fdPHost.dll
15:53:42.0425 0x2224  fdPHost - ok
15:53:42.0441 0x2224  [ 300C80931EABBE1DB7591C516EFE8D0F, F031DA96B06B6FA8E0AD56D5E10E5A5882765C3FF258A4DE06A47EC34829FF04 ] FDResPub        C:\Windows\system32\fdrespub.dll
15:53:42.0503 0x2224  FDResPub - ok
15:53:42.0535 0x2224  [ 457B7D1D533E4BD62A99AED9C7BB4C59, 3933907DE163F8D3A81ED25169B693D723296C437C7C990BFE9DEFD60F7635FD ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
15:53:42.0550 0x2224  FileInfo - ok
15:53:42.0566 0x2224  [ D421327FD6EFCCAF884A54C58E1B0D7F, C2F3B72EA36BA8B74A30E128C088307CA768FDBE232BFA216CD78B0F9B7AF18A ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
15:53:42.0613 0x2224  Filetrace - ok
15:53:42.0644 0x2224  [ 230923EA2B80F79B0F88D90F87B87EBD, 1F3287970FEC73011F3B675C447BF0CA35416490D4740C6960595B091181059C ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
15:53:42.0675 0x2224  flpydisk - ok
15:53:42.0706 0x2224  [ E3041BC26D6930D61F42AEDB79C91720, 3556C033BB78445EC8B2F98A82455914764AFC70CBFF634DDBD3539885A1E457 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
15:53:42.0722 0x2224  FltMgr - ok
15:53:42.0800 0x2224  [ F937F278E44138C0386FA1DE69B1F72B, 49180522CCCB5377B5B3A7EF8B9697FBE19A1E5D84BC282D24C39B3D52698851 ] FontCache      C:\Windows\system32\FntCache.dll
15:53:42.0878 0x2224  FontCache - ok
15:53:42.0925 0x2224  [ BC5B0BE5AF3510B0FD8C140EE42C6D3E, B21CA5F14BDB6CFD97A24C28BB2AD0D704C46058F13B01FF4203514FE8B92591 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
15:53:42.0940 0x2224  FontCache3.0.0.0 - ok
15:53:42.0971 0x2224  [ 53DAB1791917A72738539AD25C4EED7F, 3DE667E8B894EE1A1A814AF2153901AFE2A320BDB3B2A51330D987636B1BC6BE ] fssfltr        C:\Windows\system32\DRIVERS\fssfltr.sys
15:53:42.0987 0x2224  fssfltr - ok
15:53:43.0065 0x2224  [ 206AD9A89BF05DFA1621F1FC7B82592D, EAEE557535D865232237898858F5AE35F868065A1F79BBB48A2173124E2B6F63 ] fsssvc          C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
15:53:43.0127 0x2224  fsssvc - ok
15:53:43.0159 0x2224  [ 5779B86CD8B32519FBECB136394D946A, 68A395CD2287D22CB5C8CFE5A3006A61AC0C3FDAADF166C93240FF83C0315DCF ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
15:53:43.0205 0x2224  Fs_Rec - ok
15:53:43.0252 0x2224  [ 444534CBA693DD23C1CC589681E01656, DF8ED7FFA66E0A88EBB58A491A177D8CEB35B08B0911D7A1F4B8865755DC27CE ] FWLANUSB        C:\Windows\system32\DRIVERS\fwlanusb.sys
15:53:43.0330 0x2224  FWLANUSB - ok
15:53:43.0346 0x2224  [ C8E416668D3DC2BE3D4FE4C79224997F, 7DBC8E7687179A649638F606C9584F2E8EC2065762997CDF151F9BB99FA8D535 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
15:53:43.0361 0x2224  gagp30kx - ok
15:53:43.0471 0x2224  [ 50FFA2F6A5BEC5BB7C39AAB76EEA3C58, E7B0934FF69994F61D9186BF28EE8EAADEB4F64BC6FAE895B2602DAC3B311235 ] Garmin Core Update Service C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
15:53:43.0502 0x2224  Garmin Core Update Service - ok
15:53:43.0549 0x2224  [ 64C55CA530C3E9A85F84752B539272A6, 68C9D94F4C6E0EFF10C281EEBFA922842F712AF5DB9AB204860E93CFD121EC2B ] GDBehave        C:\Windows\system32\drivers\GDBehave.sys
15:53:43.0564 0x2224  GDBehave - ok
15:53:43.0595 0x2224  [ 9F17FCAF51F361A81EE6AB8B0CFDCC96, C9B01E35A442C91F73FA64758734CD553688E19925FEC84A66AF6AEA5033348D ] GDKBFlt        C:\Windows\system32\drivers\GDKBFlt64.sys
15:53:43.0595 0x2224  GDKBFlt - ok
15:53:43.0642 0x2224  [ 9406A983A4460BEF3AB6C5B509F13C55, 8370EA596CFE38B0E6331847229E8C52297C87C53C5689C1CA5C963CF82EB4EA ] GDMnIcpt        C:\Windows\system32\drivers\MiniIcpt.sys
15:53:43.0658 0x2224  GDMnIcpt - ok
15:53:43.0689 0x2224  [ 527B1CAA9661D518AC5182292C35AEC7, 1E56FC0EDFED7D60798930812AB0BB623A6721D433B69AD0152379B412CCE4D4 ] GDPkIcpt        C:\Windows\system32\drivers\PktIcpt.sys
15:53:43.0689 0x2224  GDPkIcpt - ok
15:53:43.0736 0x2224  [ CC88D7254787D15B84377137BF739F90, F01BF995EDB533C7E6F2A5B9591DA0B4F8F4E79CC45C2DA73198F4B4A8624F0B ] GDScan          C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
15:53:43.0783 0x2224  GDScan - ok
15:53:43.0845 0x2224  [ E06B66227AF4E660D5F18D44231D984F, C8E75C7925E74F6811DFFDB81F5572DAAD124EC156B0FFBA4FF0DD60378EFA6A ] gdwfpcd        C:\Windows\system32\drivers\gdwfpcd64.sys
15:53:43.0861 0x2224  gdwfpcd - ok
15:53:43.0876 0x2224  [ 58E581A98A85587E9F5A297D4AD44CC0, 6FA9D9ED4B7D1B0BEC4EB9B97B75E1BC0410CE8929029BF7A276342A94A17F84 ] GEARAspiWDM    C:\Windows\system32\drivers\GEARAspiWDM.sys
15:53:43.0892 0x2224  GEARAspiWDM - ok
15:53:43.0939 0x2224  [ A0E1B575BA8F504968CD40C0FAEB2384, F64A24A5A93F4E757882E97C65DA612F07A87F4DDD2E10C1AB0250AFA03BCEF1 ] gpsvc          C:\Windows\System32\gpsvc.dll
15:53:44.0001 0x2224  gpsvc - ok
15:53:44.0017 0x2224  [ 57875BA7B65C5FE5A87630DC1544C420, 5BB2F6CD21E3855F163B2B15E2E51A3D58637A890D0D3C6AEFB0F60214D6FBD2 ] GRD            C:\Windows\system32\drivers\GRD.sys
15:53:44.0048 0x2224  GRD - ok
15:53:44.0095 0x2224  [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:53:44.0110 0x2224  gupdate - ok
15:53:44.0126 0x2224  [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:53:44.0141 0x2224  gupdatem - ok
15:53:44.0204 0x2224  [ 0DC1D63ECA9E0237E0CAEFD9CEDD07BC, 32488718BA75ADCC9FC0D6760C8E9B83C9EB91FBE9170F05D6BB554FDB5A99D6 ] HCW3x64        C:\Windows\system32\DRIVERS\HCW3x64.sys
15:53:44.0282 0x2224  HCW3x64 - ok
15:53:44.0344 0x2224  [ 68E732382B32417FF61FD663259B4B09, 10C5365AEAC46DF4F5F6A8F96D15141B4709851D4752613233E57EB20CE16446 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
15:53:44.0360 0x2224  HdAudAddService - ok
15:53:44.0422 0x2224  [ F942C5820205F2FB453243EDFEC82A3D, 17A6A3DCF884FB524C93F2477D97E9F2B8E547709F8F2AEA93BEEA322B62E914 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
15:53:44.0516 0x2224  HDAudBus - ok
15:53:44.0563 0x2224  [ B4881C84A180E75B8C25DC1D726C375F, C0BEDBF43EFB0DD442A1D7985EA4A7493671648954B7D1840E30FB2FC46589A4 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
15:53:44.0641 0x2224  HidBth - ok
15:53:44.0672 0x2224  [ 4E77A77E2C986E8F88F996BB3E1AD829, 1748676EB038A145405080B829DF4156C2596691BE5C67FD8269BE8D9351B400 ] HidIr          C:\Windows\system32\drivers\hidir.sys
15:53:44.0734 0x2224  HidIr - ok
15:53:44.0797 0x2224  [ 59361D38A297755D46A540E450202B2A, ED97800A3FF9B90EC58BC5122C42B53F46D9C157EFE488481E8677ED7058E33D ] hidserv        C:\Windows\system32\hidserv.dll
15:53:44.0842 0x2224  hidserv - ok
15:53:44.0892 0x2224  [ 443BDD2D30BB4F00795C797E2CF99EDF, BCE1A241AE5CCE3E1C65CCF07ECB4305C7106F2EFFD51F2C519EB00026B474C4 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
15:53:44.0922 0x2224  HidUsb - ok
15:53:44.0962 0x2224  [ B12F367EA39C0795FD57E31242CE1A5A, 498439FE4D1217211EB6C1AC35CDA5D59F3AE8F06AF5E41EE9FDB0DC559FBE27 ] hkmsvc          C:\Windows\system32\kmsvc.dll
15:53:45.0002 0x2224  hkmsvc - ok
15:53:45.0022 0x2224  [ EB6EB3DCC2AD18236EEC42B2FC7BD806, A1334E802997FA2DF34B3C2860731BE03ADB5D1908DDBBCB4A46761ACC568573 ] HookCentre      C:\Windows\system32\drivers\HookCentre.sys
15:53:45.0032 0x2224  HookCentre - ok
15:53:45.0102 0x2224  [ A3A30438C48D2D71556E120C9C7BA7A0, 4C1353DB10E943A89C3FBC5EDE052A163698BDB11B5506D26A89EDB0DAC8A5B2 ] HP Health Check Service c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
15:53:45.0132 0x2224  HP Health Check Service - detected UnsignedFile.Multi.Generic ( 1 )
15:53:47.0622 0x2224  Detect skipped due to KSN trusted
15:53:47.0622 0x2224  HP Health Check Service - ok
15:53:47.0642 0x2224  [ D7109A1E6BD2DFDBCBA72A6BC626A13B, 6141B6645F4152A326ECA8AD0DD04CB38C9EDA395BDF6FF260AB17CB86FC4C87 ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
15:53:47.0652 0x2224  HpCISSs - ok
15:53:47.0712 0x2224  [ CE0FCEC4D4D860F36D972759B11EAF0F, 81F9E391A71D9FB9DD41BC35BD5136B3A851C231BE5A6E936B84E49CDAAF0B67 ] hpqcxs08        C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
15:53:47.0752 0x2224  hpqcxs08 - detected UnsignedFile.Multi.Generic ( 1 )
15:53:50.0212 0x2224  Detect skipped due to KSN trusted
15:53:50.0212 0x2224  hpqcxs08 - ok
15:53:50.0242 0x2224  [ EE4C7A4CF2316701FFDE90F404520265, 0143BA0EF31D54AC8AA5B1540D3B927293D01A0366C0A5AB2C807F14ED8E23A7 ] hpqddsvc        C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
15:53:50.0262 0x2224  hpqddsvc - detected UnsignedFile.Multi.Generic ( 1 )
15:53:52.0883 0x2224  Detect skipped due to KSN trusted
15:53:52.0883 0x2224  hpqddsvc - ok
15:53:52.0929 0x2224  [ 098F1E4E5C9CB5B0063A959063631610, 36B02A738413E4745978E3E90D9CE8ABC08376BEE411008A4312A752CB4A2E13 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
15:53:52.0992 0x2224  HTTP - ok
15:53:53.0023 0x2224  [ DA94C854CEA5FAC549D4E1F6E88349E8, 10BEB47DB90F55BD1792C2041E49ED13E4E52BCC11BE6599F6DA8D91B79CC8D1 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
15:53:53.0039 0x2224  i2omp - ok
15:53:53.0054 0x2224  [ CBB597659A2713CE0C9CC20C88C7591F, A2BAC75F7247D871842A32EAA7594D338E728D1BFEAEA3C1FCDBF65F007BC06A ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
15:53:53.0117 0x2224  i8042prt - ok
15:53:53.0163 0x2224  [ 3E3BF3627D886736D0B4E90054F929F6, 95A138B65DC9133E92F53A529C7AD897D8823EFAED343756549FDF6C8C749CD0 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
15:53:53.0179 0x2224  iaStorV - ok
15:53:53.0226 0x2224  [ 6F95324909B502E2651442C1548AB12F, FF1B104990FE186C6100ED229A45345FF695323AC778688EC11AA8F5A87B141E ] IDriverT        C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
15:53:53.0273 0x2224  IDriverT - detected UnsignedFile.Multi.Generic ( 1 )
15:53:55.0822 0x2224  Detect skipped due to KSN trusted
15:53:55.0822 0x2224  IDriverT - ok
15:53:55.0892 0x2224  [ A9AA69F749AC1D318151E77372CC83DB, 2A50A4D6ED22F5F6CB5DC56A639D904AD71E511DC744A6F6C3D1D4D39756AF31 ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
15:53:55.0952 0x2224  idsvc - ok
15:53:55.0992 0x2224  [ 8C3951AD2FE886EF76C7B5027C3125D3, 85CF7231756E02BD9E5F4378F3FC794394A072B8028F27827F83ACE9EE554499 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
15:53:56.0012 0x2224  iirsp - ok
15:53:56.0052 0x2224  [ 0401A380C88754B2399F8043AC9B2BF9, BFF3B53FAFAE6622AA9F74BAA4A3D522C06E2D732B88916766603B9FE8D0D77F ] IKEEXT          C:\Windows\System32\ikeext.dll
15:53:56.0122 0x2224  IKEEXT - ok
15:53:56.0212 0x2224  [ 46CB3ABE8150E7B181E86D4906DE17E8, 2782CA3D29C53042D63D0A8C1BF4A11BD9AC69879E847D2A11734B36B52ABC1E ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
15:53:56.0332 0x2224  IntcAzAudAddService - ok
15:53:56.0392 0x2224  [ DF797A12176F11B2D301C5B234BB200E, 384343636B21CA7EDF28EFD1B6728EAB1508CA49CE48FF3DC0D91DB843C0C73E ] intelide        C:\Windows\system32\drivers\intelide.sys
15:53:56.0402 0x2224  intelide - ok
15:53:56.0422 0x2224  [ BFD84AF32FA1BAD6231C4585CB469630, 33E0842F2D0879B02C115301174FCB19ED3AAF7B1B8E6284839CE16DE56476EA ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
15:53:56.0482 0x2224  intelppm - ok
15:53:56.0512 0x2224  [ 5624BC1BC5EEB49C0AB76A8114F05EA3, BD5AA534D8A923AF4D205EEC6DA55A3DC5F915E5F3223BF23F24C09824FA90B6 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
15:53:56.0572 0x2224  IPBusEnum - ok
15:53:56.0622 0x2224  [ D8AABC341311E4780D6FCE8C73C0AD81, 141E8032A934777567E6DAC35FB1C77C40D9B6EE477F17F872F35833A8F57F72 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:53:56.0672 0x2224  IpFilterDriver - ok
15:53:56.0722 0x2224  [ BF0DBFA9792C5C14FA00F61C75116C1B, 24C14DCAF57013F1C238E3C123279737420A714EB29CB69239C9838C9A269A59 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
15:53:56.0792 0x2224  iphlpsvc - ok
15:53:56.0792 0x2224  IpInIp - ok
15:53:56.0822 0x2224  [ 9C2EE2E6E5A7203BFAE15C299475EC67, E51628ECAB9CCCBCE02801C5E71406487A280765FEE318D14B0C227141B87658 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
15:53:56.0882 0x2224  IPMIDRV - ok
15:53:56.0912 0x2224  [ B7E6212F581EA5F6AB0C3A6CEEEB89BE, C29D7F392116BB09F7047A90702331F200DACFB3C94E7F912932971E0B7F0413 ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
15:53:56.0972 0x2224  IPNAT - ok
15:53:57.0002 0x2224  [ 8C42CA155343A2F11D29FECA67FAA88D, 699F06D25C5F270CE1194F4D350CB0BE22C6AB609EECF35D066C034AC380BEE3 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
15:53:57.0042 0x2224  IRENUM - ok
15:53:57.0052 0x2224  [ 0672BFCEDC6FC468A2B0500D81437F4F, A0322B569C309F258684AFECCD52924A33F363186261730469245B7FA357C645 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
15:53:57.0072 0x2224  isapnp - ok
15:53:57.0112 0x2224  [ E4FDF99599F27EC25D2CF6D754243520, 9139E708EE30F10652C9A458BD58B0343A3C05E84CD3E71FA0B0E4123503CF7B ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
15:53:57.0132 0x2224  iScsiPrt - ok
15:53:57.0142 0x2224  [ 63C766CDC609FF8206CB447A65ABBA4A, D9CA006FA852C95E90E8A0837E296FCBFD76246DA8AFDE563863D5F95BDFEC52 ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
15:53:57.0152 0x2224  iteatapi - ok
15:53:57.0162 0x2224  [ 1281FE73B17664631D12F643CBEA3F59, B27571A0348CDF81DC102A61712CBA9A4AF7AC0015A7702B0DE73AD4E4646853 ] iteraid        C:\Windows\system32\drivers\iteraid.sys
15:53:57.0182 0x2224  iteraid - ok
15:53:57.0192 0x2224  [ 423696F3BA6472DD17699209B933BC26, 00C2EAA1A8E9D422D178B7678598743234930C1858D76C632F079EF789BB56C3 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
15:53:57.0212 0x2224  kbdclass - ok
15:53:57.0242 0x2224  [ DBDF75D51464FBC47D0104EC3D572C05, E392EE961E734620245874C7700D56621A1A990C45DF5CE0B7D270BA708F255E ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
15:53:57.0292 0x2224  kbdhid - ok
15:53:57.0342 0x2224  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D, 6585A87CE55EE5C51B18DF86E8EDFC6A909D96C87522FF4183F8BA9355E8DD44 ] KeyIso          C:\Windows\system32\lsass.exe
15:53:57.0362 0x2224  KeyIso - ok
15:53:57.0412 0x2224  [ 88956AD9FA510848AD176777A6C6C1F5, 8F2FBF7E70F836C2C11EE5ABCAFE3E51DC26E953DDFBEE3C1B4AA8E58EBDCF5E ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
15:53:57.0442 0x2224  KSecDD - ok
15:53:57.0452 0x2224  [ 1D419CF43DB29396ECD7113D129D94EB, 21ECCE9D17F055C7B5066110864E10C99291CE50B389C545371333904CE2DBB5 ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
15:53:57.0512 0x2224  ksthunk - ok
15:53:57.0562 0x2224  [ 1FAF6926F3416D3DA05C5B265491BDAE, 3989E18522691CC3820092033E00ED39D08861DFB369AA0DFFF4B379E48EA1F0 ] KtmRm          C:\Windows\system32\msdtckrm.dll
15:53:57.0662 0x2224  KtmRm - ok
15:53:57.0712 0x2224  [ 5746399C73B372F0C8E9D3A0CC3B2D8F, 526C4CB39D0EF6C5AEA8DFCB40C337BC215CA6DC86524DDD9EE9932DEC844462 ] L8042Kbd        C:\Windows\system32\DRIVERS\L8042Kbd.sys
15:53:57.0732 0x2224  L8042Kbd - ok
15:53:57.0762 0x2224  [ 1433A7549A64D50E4FBBD747E9143454, A1EEACDB2DCC99BFE267455B1A390954E7FC920732F476498163F39A1C52AF8B ] L8042mou        C:\Windows\system32\DRIVERS\L8042mou.Sys
15:53:57.0772 0x2224  L8042mou - ok
15:53:57.0802 0x2224  [ 50C7A3CB427E9BB5ED0708A669956AB5, 3DAD1C01AE58FE2C6134283B19118E2F3C884DDFFBAE4A46B7B5E4FB1A2567A1 ] LanmanServer    C:\Windows\system32\srvsvc.dll
15:53:57.0832 0x2224  LanmanServer - ok
15:53:57.0852 0x2224  [ CAF86FC1388BE1E470F1A7B43E348ADB, 9E9AE0B617D1031E8462524802A2D997AE7C944A7D00D403FF903145A7FEB761 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
15:53:57.0902 0x2224  LanmanWorkstation - ok
15:53:57.0942 0x2224  [ B6552D382FF070B4ED34CBD6737277C0, 7C2C24454037170311B0267DEFB797E8DF8D157D62157D271BF7F5F74B2A12F3 ] LHidFilt        C:\Windows\system32\DRIVERS\LHidFilt.Sys
15:53:57.0962 0x2224  LHidFilt - ok
15:53:57.0982 0x2224  [ 8E4CA9AFD55EF6B509C80A8715ABF8C6, 45698605D17285D346D2052607AEF492EBD89E9625367C31584C7C84757EEFE0 ] lirsgt          C:\Windows\system32\DRIVERS\lirsgt.sys
15:53:57.0992 0x2224  lirsgt - ok
15:53:58.0002 0x2224  [ 96ECE2659B6654C10A0C310AE3A6D02C, 3322E87B9F64C3ACBCB634F2390AAB212FA7695383BF01F0092A803871BF19B2 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
15:53:58.0062 0x2224  lltdio - ok
15:53:58.0122 0x2224  [ 961CCBD0B1CCB5675D64976FAE37D092, 258378BE76A13E4368C9587E6A22727721E4B267B0D26D3D3E333B3B2A5A0611 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
15:53:58.0200 0x2224  lltdsvc - ok
15:53:58.0215 0x2224  [ A47F8080CACC23C91FE823AD19AA5612, 161575406D158D6D5C9220F1E82C0CC19108C74ADC35C509BAF9B0C414EFD8EE ] lmhosts        C:\Windows\System32\lmhsvc.dll
15:53:58.0262 0x2224  lmhosts - ok
15:53:58.0278 0x2224  [ 73C1F563AB73D459DFFE682D66476558, 9B8BEE384C968DC6C37DD54B9128D9C2BA92EDBF7BDF49D753AA7DB165F18D00 ] LMouFilt        C:\Windows\system32\DRIVERS\LMouFilt.Sys
15:53:58.0293 0x2224  LMouFilt - ok
15:53:58.0309 0x2224  [ 91B345109AD08CC9926EC0299AF60418, 711D56376FC9C91FA1AA30121F655EF4F0CD7D2014CE87E56FB9756889756EA9 ] LMouKE          C:\Windows\system32\DRIVERS\LMouKE.Sys
15:53:58.0325 0x2224  LMouKE - ok
15:53:58.0340 0x2224  [ ACBE1AF32D3123E330A07BFBC5EC4A9B, 0E17E4DD30B5AF8F269EF8EA003836C9E16273262A050B9BE3ED802DD3AC9319 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
15:53:58.0356 0x2224  LSI_FC - ok
15:53:58.0371 0x2224  [ 799FFB2FC4729FA46D2157C0065B3525, AB462A34D061C113DA12641C45159A58D0AEA1C440233D061A20DF99586CFA93 ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
15:53:58.0403 0x2224  LSI_SAS - ok
15:53:58.0418 0x2224  [ F445FF1DAAD8A226366BFAF42551226B, 92B63E15363F1EAE8A54D4E74ED21669D0A9FE99C654671556C58456228278B1 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
15:53:58.0434 0x2224  LSI_SCSI - ok
15:53:58.0449 0x2224  [ 52F87B9CC8932C2A7375C3B2A9BE5E3E, 2EB22DD418D4934BDD22C5DB49D5D06178EC0419AB5CC28DD544CA91823987B0 ] luafv          C:\Windows\system32\drivers\luafv.sys
15:53:58.0512 0x2224  luafv - ok
15:53:58.0543 0x2224  [ 9D9714E78EAC9E5368208649489C920E, 56DF5DBDF4963758A1E6BAD6210F8682A846DA9E5924CFA5879AC89CA7223C93 ] LUsbFilt        C:\Windows\system32\Drivers\LUsbFilt.Sys
15:53:58.0559 0x2224  LUsbFilt - ok
15:53:58.0559 0x2224  MBAMSwissArmy - ok
15:53:58.0590 0x2224  [ 76A58DF02BD4EA29F189B82D0BEF17F8, B3A96AABE050BB332ECD9AF7C35D08B468AC459D30FF4D49B609BA3F95ECEEDA ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
15:53:58.0605 0x2224  Mcx2Svc - ok
15:53:58.0637 0x2224  [ 5C5CD6AACED32FB26C3FB34B3DCF972F, 34A66C21FA79800D3CDE933CFA71343218F94D67AAE763EA0B53AC49060CB6D0 ] megasas        C:\Windows\system32\drivers\megasas.sys
15:53:58.0652 0x2224  megasas - ok
15:53:58.0668 0x2224  [ 859BC2436B076C77C159ED694ACFE8F8, 4AEA57A8B9EACEC1B8DED3ECC95621C56E6D65CFE2DA9F07DAF7C7BAD132B624 ] MegaSR          C:\Windows\system32\drivers\megasr.sys
15:53:58.0699 0x2224  MegaSR - ok
15:53:58.0761 0x2224  [ 123271BD5237AB991DC5C21FDF8835EB, 004F8F9228EE291A0E36CE33078D572D61733516F9AA5CFC832AF204C6869E89 ] Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
15:53:58.0777 0x2224  Microsoft Office Groove Audit Service - ok
15:53:58.0793 0x2224  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A, 18B0E3E83E41C80809E8140F4C90AB051566C84DD891EA411746EA74E6EAF053 ] MMCSS          C:\Windows\system32\mmcss.dll
15:53:58.0839 0x2224  MMCSS - ok
15:53:58.0886 0x2224  [ 59848D5CC74606F0EE7557983BB73C2E, EA6ACF0619DE1E4272AEDC69F2E66E29DA499E8E8094243C9EF735FD8369229D ] Modem          C:\Windows\system32\drivers\modem.sys
15:53:58.0917 0x2224  Modem - ok
15:53:58.0949 0x2224  [ C247CC2A57E0A0C8C6DCCF7807B3E9E5, 357811D1B8F70828F6432879F59DAB916FBB55673B3473D879382DE33CFB3FAF ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
15:53:58.0995 0x2224  monitor - ok
15:53:59.0027 0x2224  [ 9367304E5E412B120CF5F4EA14E4E4F1, F87EBACEE27A50E6610FDCB4BD3001C35A99FEE6D63D643FF2CBF0D484CD082C ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
15:53:59.0042 0x2224  mouclass - ok
15:53:59.0073 0x2224  [ C2C2BD5C5CE5AAF786DDD74B75D2AC69, B77E4A7511923E7BD35A177A40B4E461AC9CB050D6F0575D4799DEF85DA6DA38 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
15:53:59.0136 0x2224  mouhid - ok
15:53:59.0151 0x2224  [ 11BC9B1E8801B01F7F6ADB9EAD30019B, 1BAF820C0AB1B70A114E767B2155A58BF86CD0D9CF582813C1635A86BE3A7A05 ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
15:53:59.0167 0x2224  MountMgr - ok
15:53:59.0229 0x2224  [ 4E9D8041D352A33332FD6F59A3A78B03, D4E6229B07EF9866993EEE4F6223DC7F1FF1108273FE14A3DC74E65C181DE56A ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
15:53:59.0245 0x2224  MozillaMaintenance - ok
15:53:59.0261 0x2224  [ F8276EB8698142884498A528DFEA8478, C0FF504F721F1D00F42CFE783D4F32C6728518F64646F5C5C11BA3A4824815BB ] mpio            C:\Windows\system32\drivers\mpio.sys
15:53:59.0276 0x2224  mpio - ok
15:53:59.0292 0x2224  [ C92B9ABDB65A5991E00C28F13491DBA2, D1233381A9E4262F0AB396BBDB7DE402D4370805E11EB8A118C846F6E9474098 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
15:53:59.0339 0x2224  mpsdrv - ok
15:53:59.0401 0x2224  [ 897E3BAF68BA406A61682AE39C83900C, 13F61D5C22BED061BE7C2669CCCAA2BAD4A0CE83800DF57A50306DE0A476FC27 ] MpsSvc          C:\Windows\system32\mpssvc.dll
15:53:59.0463 0x2224  MpsSvc - ok
15:53:59.0479 0x2224  [ 3C200630A89EF2C0864D515B7A75802E, AA4A312E7A28FCE7A944747BADB809CAAD3D67899EBBE663D473621DB25B140A ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
15:53:59.0495 0x2224  Mraid35x - ok
15:53:59.0526 0x2224  [ 7C1DE4AA96DC0C071611F9E7DE02A68D, 8B248A82324FB23C64D41FA91BCC22093DE44C48D688E5995C484A7072A6EC08 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
15:53:59.0573 0x2224  MRxDAV - ok
15:53:59.0604 0x2224  [ 1485811B320FF8C7EDAD1CAEBB1C6C2B, 9F157AAA1A793EF7E52817E4126B774C17FFA0036DADCF10A024FDC068F94F67 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
15:53:59.0619 0x2224  mrxsmb - ok
15:53:59.0651 0x2224  [ 3B929A60C833FC615FD97FBA82BC7632, 40EEBEB43F42A1A37FAA529E0C21984426F90C1EEFE1EF9BB2F696164595F91D ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
15:53:59.0697 0x2224  mrxsmb10 - ok
15:53:59.0697 0x2224  [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3, 197F70E24D2BBDEC35C2D5BC442267ACC4C5AE3FD5BB30A0928976BE9758C942 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
15:53:59.0729 0x2224  mrxsmb20 - ok
15:53:59.0760 0x2224  [ 1AC860612B85D8E85EE257D372E39F4D, 74682CCE44BCEE31BCA286D4F4E53B64CAAE244155F2B4C8FEB6AE7C391CA89D ] msahci          C:\Windows\system32\drivers\msahci.sys
15:53:59.0775 0x2224  msahci - ok
15:53:59.0791 0x2224  [ 264BBB4AAF312A485F0E44B65A6B7202, 1DF36540C77D5D885B6C2EE91F0446864D8E6D6CFED87A9ED0765E76FE05E102 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
15:53:59.0807 0x2224  msdsm - ok
15:53:59.0838 0x2224  [ 7EC02CE772F068ED0BEAFA3DA341A9BC, 3B5B4EA0BF1D1E57F4DF74A569304A5EE41821F5E2F352760B8C9CA82C6D8292 ] MSDTC          C:\Windows\System32\msdtc.exe
15:53:59.0900 0x2224  MSDTC - ok
15:53:59.0931 0x2224  [ 704F59BFC4512D2BB0146AEC31B10A7C, F7712944DDC192C47953D577BE31B79B4D11217305B1C3D0DCA31B1518CB8DCB ] Msfs            C:\Windows\system32\drivers\Msfs.sys
15:53:59.0994 0x2224  Msfs - ok
15:54:00.0041 0x2224  [ 26668CC2920DE2497A8E369B16E48CA3, 968E2000F20E538922288AB57596B8134E98946899D98E2493722CB3EEE18B14 ] MSHUSBVideo    C:\Windows\system32\Drivers\nx6000.sys
15:54:00.0072 0x2224  MSHUSBVideo - ok
15:54:00.0119 0x2224  [ 00EBC952961664780D43DCA157E79B27, 4F8F5718D8574A128E0F6CD54C9BE59A93A7638A5689A8FF68D0C81D3E67808F ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
15:54:00.0134 0x2224  msisadrv - ok
15:54:00.0150 0x2224  [ 366B0C1F4478B519C181E37D43DCDA32, A98E2BC397FAD7D90653F55AC283CACAE7465D7F10A198D715046B1D896AF246 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
15:54:00.0212 0x2224  MSiSCSI - ok
15:54:00.0228 0x2224  msiserver - ok
15:54:00.0259 0x2224  [ 0EA73E498F53B96D83DBFCA074AD4CF8, E3DDE34FCFF272E06CD8DA836F8D79E2515885715D4A7CD7BF8D97D7A4E0E781 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
15:54:00.0321 0x2224  MSKSSRV - ok
15:54:00.0337 0x2224  [ 52E59B7E992A58E740AA63F57EDBAE8B, A89F607B330BA1F42CA9FF01EF289BBD088350CF376568E58CB9865F1DA6CD72 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
15:54:00.0399 0x2224  MSPCLOCK - ok
15:54:00.0415 0x2224  [ 49084A75BAE043AE02D5B44D02991BB2, 4CD2692D191035CE9D18F4D21F054FF8C3F9CF2734464EA33EAB480A28AD447F ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
15:54:00.0477 0x2224  MSPQM - ok
15:54:00.0540 0x2224  [ DC6CCF440CDEDE4293DB41C37A5060A5, 768D08A67508E1CE69B67642A5E5A639C0DD1E93C956C56ECC5A56B0E502C953 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
15:54:00.0571 0x2224  MsRPC - ok
15:54:00.0587 0x2224  [ 855796E59DF77EA93AF46F20155BF55B, 75DFCEE16A9D94EDF74295B9686D92552817E8A00958917CB0E17089EDCF6A97 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
15:54:00.0602 0x2224  mssmbios - ok
15:54:00.0618 0x2224  [ 86D632D75D05D5B7C7C043FA3564AE86, 96911FBC106B91E76598EE110B5147D4C55E42C9194E857F866B6B395E78D2CB ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
15:54:00.0665 0x2224  MSTEE - ok
15:54:00.0680 0x2224  [ 0CC49F78D8ACA0877D885F149084E543, 984DDCB52F0DFC1B26C6504FE500E8D9C2CA7F79ED34608AE9866A0915B8BA67 ] Mup            C:\Windows\system32\Drivers\mup.sys
15:54:00.0696 0x2224  Mup - ok
15:54:00.0743 0x2224  [ A5B10C845E7538C60C0F5D87A57CB3F5, 2B4E16702591C59BC2CA2B99DBB504BAB4F4EF0835B0D9C7453D340CBF0BDF16 ] napagent        C:\Windows\system32\qagentRT.dll
15:54:00.0821 0x2224  napagent - ok
15:54:00.0852 0x2224  [ 2007B826C4ACD94AE32232B41F0842B9, 6267D165C3C8C5F83194890A6DBF71226D4B891AECD1D06F7AEB5D738C3DC9CA ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
15:54:00.0899 0x2224  NativeWifiP - ok
15:54:00.0977 0x2224  [ 65950E07329FCEE8E6516B17C8D0ABB6, 4429D9FF9B6E376D28D8FA4906B7554DF566EC23E455E3166C496B579622F204 ] NDIS            C:\Windows\system32\drivers\ndis.sys
15:54:01.0023 0x2224  NDIS - ok
15:54:01.0023 0x2224  [ 64DF698A425478E321981431AC171334, C43177CB60F5D58E1FF7A31E9BE5DA7D92C4B25235867DD65BADC069EDF023F3 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
15:54:01.0086 0x2224  NdisTapi - ok
15:54:01.0101 0x2224  [ 8BAA43196D7B5BB972C9A6B2BBF61A19, 8AFFB26F6E8CF67F562818BBFE12FB448E4FCDF9B68858B625681565DE30DDC1 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
15:54:01.0164 0x2224  Ndisuio - ok
15:54:01.0211 0x2224  [ F8158771905260982CE724076419EF19, B86FFA790A30ED614A11C87F4D738C913EFC0924DC14750D544001D4E9556071 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
15:54:01.0257 0x2224  NdisWan - ok
15:54:01.0289 0x2224  [ 9CB77ED7CB72850253E973A2D6AFDF49, C3C15B317A7F7AE68B7BC62343962C47F075240F252727811DB4BEE443F9103F ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
15:54:01.0320 0x2224  NDProxy - ok
15:54:01.0335 0x2224  [ 59267D2F0328599AA3B5408C2E06126F, 54D59079F04F9F08F980C1F1A8F8973ACF9C344218818A15A762287EE6F22F02 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
15:54:01.0367 0x2224  Net Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 )
15:54:04.0409 0x2224  Detect skipped due to KSN trusted
15:54:04.0409 0x2224  Net Driver HPZ12 - ok
15:54:04.0424 0x2224  [ A499294F5029A7862ADC115BDA7371CE, 6BE0AAFE4EB59E056A929D6C1A009D8DFD547025481108CEFB12E5D6F86DBE14 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
15:54:04.0487 0x2224  NetBIOS - ok
15:54:04.0549 0x2224  [ FC2C792EBDDC8E28DF939D6A92C83D61, 9EDF8B56E2B47C31457074DA371B604E5F7EB2B3B5CD4688CBEEDD5B266D119B ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
15:54:04.0596 0x2224  netbt - ok
15:54:04.0627 0x2224  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D, 6585A87CE55EE5C51B18DF86E8EDFC6A909D96C87522FF4183F8BA9355E8DD44 ] Netlogon        C:\Windows\system32\lsass.exe
15:54:04.0643 0x2224  Netlogon - ok
15:54:04.0674 0x2224  [ 9B63B29DEFC0F3115A559D2597BF5D75, 297319D3F2E97CB34464EA59D8FD96AC2B8B1A4F2AEE666937F16A041128021F ] Netman          C:\Windows\System32\netman.dll
15:54:04.0767 0x2224  Netman - ok
15:54:04.0814 0x2224  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:54:04.0845 0x2224  NetMsmqActivator - ok
15:54:04.0845 0x2224  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:54:04.0877 0x2224  NetPipeActivator - ok
15:54:04.0892 0x2224  [ 7846D0136CC2B264926A73047BA7688A, 6F56CC1B17095C378D98B58A92F9EDA2D009529DDB6F60E815D85C7606C8EDC0 ] netprofm        C:\Windows\System32\netprofm.dll
15:54:04.0970 0x2224  netprofm - ok
15:54:04.0986 0x2224  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:54:05.0001 0x2224  NetTcpActivator - ok
15:54:05.0017 0x2224  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:54:05.0033 0x2224  NetTcpPortSharing - ok
15:54:05.0064 0x2224  [ 4AC08BD6AF2DF42E0C3196D826C8AEA7, 8D7DE921E14BAF09D7E2704CFB2FB1C8A78A46DAF86CDF7A347C5D113A8C110B ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
15:54:05.0079 0x2224  nfrd960 - ok
15:54:05.0111 0x2224  [ F145BF4C4668E7E312069F81EF847CFC, C4926EFB41FE2813E90D83456C6CB8F3157D835391B443C7E26168F4E1D67DC7 ] NlaSvc          C:\Windows\System32\nlasvc.dll
15:54:05.0157 0x2224  NlaSvc - ok
15:54:05.0217 0x2224  [ 62F68443D244024845B875B44D76A92F, 60CB13374A8002AFF5AB6D54B0F03ED00A97C4E9D1E1A1BE017A364BA275E928 ] NMIndexingService C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
15:54:05.0257 0x2224  NMIndexingService - ok
15:54:05.0287 0x2224  [ 903681BAB213D5F84717C0FC42AFB28A, C003B3EC4F09D1D7C945C995B2B7F686C07DC0760FECB9590C16ED7CA66ECA3D ] nmwcd          C:\Windows\system32\drivers\ccdcmbx64.sys
15:54:05.0327 0x2224  nmwcd - ok
15:54:05.0377 0x2224  [ EC4C5EBD003E0395BF4EA5A2EFD13CE6, 3F7B1E4131DCD3D37305FDE240D1DA4475C2398397211731D5DD925A05435177 ] nmwcdc          C:\Windows\system32\drivers\ccdcmbox64.sys
15:54:05.0437 0x2224  nmwcdc - ok
15:54:05.0467 0x2224  [ 863AA6C58AC85A22355AE943C605E44B, 571901E1395E88B3687A299E0BA1B43BE452DF9AC70A29CBE9F109A4AC6A300C ] nmwcdnsucx64    C:\Windows\system32\drivers\nmwcdnsucx64.sys
15:54:05.0497 0x2224  nmwcdnsucx64 - ok
15:54:05.0537 0x2224  [ 7983D9201788407C4D1FC4D0BAA04E32, 040439A11B6A6962ADD980F0FC61A54F82A798465B41A1A8AF73974928B4439D ] nmwcdnsux64    C:\Windows\system32\drivers\nmwcdnsux64.sys
15:54:05.0587 0x2224  nmwcdnsux64 - ok
15:54:05.0647 0x2224  [ B298874F8E0EA93F06EC40AA8D146478, 275D769E5EFD3153985DAF84C5B22B9D65428E09AB41099901ABDD03B3A2625D ] Npfs            C:\Windows\system32\drivers\Npfs.sys
15:54:05.0697 0x2224  Npfs - ok
15:54:05.0737 0x2224  [ ACB62BAA1C319B17752553DF3026EEEB, 5A309DF390A097245250BB64AD5F8575BECA601E0A122DDCB494C67D3D9EA089 ] nsi            C:\Windows\system32\nsisvc.dll
15:54:05.0767 0x2224  nsi - ok
15:54:05.0777 0x2224  [ 1523AF19EE8B030BA682F7A53537EAEB, B000630CE4B562D39B5EE4148409B2E01D8924D33D27607B24ADC901357E7AA5 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
15:54:05.0837 0x2224  nsiproxy - ok
15:54:05.0927 0x2224  [ 2ACCAA3C3C55370A32F17B3595E1A217, 8539A293A5E1EBA2CC0FA9E999099D3B6B035D41069398AE17D737BBE4D9FEA8 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
15:54:06.0007 0x2224  Ntfs - ok
15:54:06.0027 0x2224  [ DD5D684975352B85B52E3FD5347C20CB, BB03C50D5178643550C024130E20FD9A023AE110B3C85A2D6E18FB8DBB3A12E4 ] Null            C:\Windows\system32\drivers\Null.sys
15:54:06.0087 0x2224  Null - ok
15:54:06.0157 0x2224  [ 13EC5B8A4B82B6DEB739FC577B4217A7, 905FF255580DE25A32B81D66C8D0CB3F62F6A3A41D796D96BCC943DEE4CD447F ] NVENETFD        C:\Windows\system32\DRIVERS\nvmfdx64.sys
15:54:06.0227 0x2224  NVENETFD - ok
15:54:06.0267 0x2224  [ 2C040B7ADA5B06F6FACADAC8514AA034, EF32F7C411090230ED1D95B2D01E8464DCC89D72EFD94BBC8DF6856D00B1A783 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
15:54:06.0287 0x2224  nvraid - ok
15:54:06.0307 0x2224  [ A4B9AF8D1793F67CE894BF051342110F, CC8BED39599A236BE3910C8605D0DE4E2EA95FF0A0645C9066F9767CE0F4E72A ] nvrd64          C:\Windows\system32\drivers\nvrd64.sys
15:54:06.0327 0x2224  nvrd64 - ok
15:54:06.0347 0x2224  [ 16D36074B84DA72D160233C8D132DC89, B68AB500A052F2FF5B32EC58E32796B9CD06F7C752DBC03B023AD5A0EC826C54 ] nvsmu          C:\Windows\system32\drivers\nvsmu.sys
15:54:06.0367 0x2224  nvsmu - ok
15:54:06.0377 0x2224  [ F7EA0FE82842D05EDA3EFDD376DBFDBA, 0ED0543A5331C0D8BBFD1BE3174482ED1B3EE70CA41CE8CE5C81977C37B3D129 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
15:54:06.0387 0x2224  nvstor - ok
15:54:06.0417 0x2224  [ 7919EE9458B6D84517BC5A598D795931, 8107C703879229323A82913AF3B9E88A14669DA67ADAC22B2A71A1A4D20EBF20 ] nvstor64        C:\Windows\system32\drivers\nvstor64.sys
15:54:06.0437 0x2224  nvstor64 - ok
15:54:06.0447 0x2224  [ 19067CA93075EF4823E3938A686F532F, 81339372E90CE9E2594461146A82B62452CF9DB3FF53381D30F6922059EDCF99 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
15:54:06.0467 0x2224  nv_agp - ok
15:54:06.0467 0x2224  NwlnkFlt - ok
15:54:06.0477 0x2224  NwlnkFwd - ok
15:54:06.0527 0x2224  [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
15:54:06.0547 0x2224  odserv - ok
15:54:06.0577 0x2224  [ B5B1CE65AC15BBD11C0619E3EF7CFC28, E9AA27724A7576D1869FF861A498DB8AF79A7B297F10272F1D63E6CB88CD455B ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
15:54:06.0627 0x2224  ohci1394 - ok
15:54:06.0677 0x2224  [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:54:06.0687 0x2224  ose - ok
15:54:06.0757 0x2224  [ 9AE31D2E1D15C10D91318E0EC149CEAC, CEA8A4AD1D6BB9C1ECBDE7A1946DD655104E20224436B96AD69A76F8E2B25680 ] p2pimsvc        C:\Windows\system32\p2psvc.dll
15:54:06.0837 0x2224  p2pimsvc - ok
15:54:06.0887 0x2224  [ 9AE31D2E1D15C10D91318E0EC149CEAC, CEA8A4AD1D6BB9C1ECBDE7A1946DD655104E20224436B96AD69A76F8E2B25680 ] p2psvc          C:\Windows\system32\p2psvc.dll
15:54:06.0937 0x2224  p2psvc - ok
15:54:06.0967 0x2224  [ AECD57F94C887F58919F307C35498EA0, CD8E8B54A445EF0DC485D5F221588875C98328596F64EE03B2D8BD0B860504FB ] Parport        C:\Windows\system32\drivers\parport.sys
15:54:07.0037 0x2224  Parport - ok
15:54:07.0077 0x2224  [ B43751085E2ABE389DA466BC62A4B987, 167CB6B18B6B7B74A229A976833E1FBE6D51C9C0EB8A23C92FC2465B692DF383 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
15:54:07.0097 0x2224  partmgr - ok
15:54:07.0127 0x2224  [ 9AB157B374192FF276C1628FBDBA2B0E, E63E2EE1ABEEC5234F4F1318757EDB4A7567057B1DF1A2414C8698D47062B6AC ] PcaSvc          C:\Windows\System32\pcasvc.dll
15:54:07.0147 0x2224  PcaSvc - ok
15:54:07.0177 0x2224  [ BC0018C2D29F655188A0ED3FA94FDB24, BCF7F2CA5E30F569AEB69049BA3C196982C72EA7264CFBA59D7123041BA96E5A ] pccsmcfd        C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
15:54:07.0207 0x2224  pccsmcfd - ok
15:54:07.0237 0x2224  [ 47AB1E0FC9D0E12BB53BA246E3A0906D, 82B452D614B535FAD3AFEEA06DFBBF8F7C5031563A2558CFA04F9B94C76E45DF ] pci            C:\Windows\system32\drivers\pci.sys
15:54:07.0257 0x2224  pci - ok
15:54:07.0277 0x2224  [ 2657F6C0B78C36D95034BE109336E382, C85CFDA57A64B7CC1BB09225C2F81629CEF21C5F25735B098F214397D6DE0D2C ] pciide          C:\Windows\system32\drivers\pciide.sys
15:54:07.0287 0x2224  pciide - ok
15:54:07.0307 0x2224  [ 037661F3D7C507C9993B7010CEEE6288, A7B415675B14FD755D0167BBA458A902AA9ABFC4343A1B887289D31DE8A55285 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
15:54:07.0327 0x2224  pcmcia - ok
15:54:07.0367 0x2224  [ 58865916F53592A61549B04941BFD80D, 3511AF2EFD06636E144C36ECA8C7AA1A33C269EDB10A6D879AA25D9E11359AA9 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
15:54:07.0487 0x2224  PEAUTH - ok
15:54:07.0557 0x2224  [ 0ED8727EA0172860F47258456C06CAEA, 3CDAA1044E412EC4303CEABD36A8C7BADA2D6C6692E09B8FE440709E3F4F0166 ] PerfHost        C:\Windows\SysWow64\perfhost.exe
15:54:07.0607 0x2224  PerfHost - ok
15:54:07.0697 0x2224  [ EDCF18EE6169F4C7CC6E451F03F59377, 32BBBD4BC4D88AC35D0E01AC9E5CF385234711C6372A290B68E852A92485D643 ] Ph3xIB64        C:\Windows\system32\DRIVERS\Ph3xIB64.sys
15:54:07.0817 0x2224  Ph3xIB64 - ok
15:54:07.0877 0x2224  [ E9E68C1A0F25CF4A7AC966EEA74EE89E, 6C6903A856C29AD690FDA1B74ADB2222C3453FBE2B364245FA61D53C77C586C0 ] pla            C:\Windows\system32\pla.dll
15:54:07.0977 0x2224  pla - ok
15:54:08.0047 0x2224  [ 875E4E0661F3A5994DF9E5E3A0A4F96B, 7198C02935B3714C455EE94305D2A21D900D72AC67049C11A1E842572AD6C5E1 ] PLFlash DeviceIoControl Service C:\Windows\SysWOW64\IoctlSvc.exe
15:54:08.0077 0x2224  PLFlash DeviceIoControl Service - detected UnsignedFile.Multi.Generic ( 1 )
15:54:10.0682 0x2224  Detect skipped due to KSN trusted
15:54:10.0682 0x2224  PLFlash DeviceIoControl Service - ok
15:54:10.0713 0x2224  [ FE6B0F59215C9FD9F9D26539C58C8B82, 52CF8BE31A28430226D117EB80974AEAE5EA07F39DE881164232D44BF67FF752 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
15:54:10.0760 0x2224  PlugPlay - ok
15:54:10.0791 0x2224  [ 5261A2FD55183AC6993145AB6662CDDF, 996358C80674B1310B3C42BB45254AFC7FF90F12176FE76EF3C930D6D3C647FE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
15:54:10.0807 0x2224  Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 )
15:54:13.0516 0x2224  Detect skipped due to KSN trusted
15:54:13.0516 0x2224  Pml Driver HPZ12 - ok
15:54:13.0546 0x2224  [ 9AE31D2E1D15C10D91318E0EC149CEAC, CEA8A4AD1D6BB9C1ECBDE7A1946DD655104E20224436B96AD69A76F8E2B25680 ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
15:54:13.0626 0x2224  PNRPAutoReg - ok
15:54:13.0686 0x2224  [ 9AE31D2E1D15C10D91318E0EC149CEAC, CEA8A4AD1D6BB9C1ECBDE7A1946DD655104E20224436B96AD69A76F8E2B25680 ] PNRPsvc        C:\Windows\system32\p2psvc.dll
15:54:13.0736 0x2224  PNRPsvc - ok
15:54:13.0796 0x2224  [ 89A5560671C2D8B4A4B51F3E1AA069D8, 07DEE5D73DDE09F954E2E13BB5603F0033829B6199C81A7C1709D94AB92B351E ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
15:54:13.0876 0x2224  PolicyAgent - ok
15:54:13.0926 0x2224  [ 23386E9952025F5F21C368971E2E7301, F7241C1799A8AA0E9106B101B841670304DC695FD8D290C690CE0ED5C13BC514 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
15:54:13.0986 0x2224  PptpMiniport - ok
15:54:14.0016 0x2224  [ 5080E59ECEE0BC923F14018803AA7A01, 2E201511821AECCF056962399AFA3533ED765A3E7FD30E7B38A6D13837367E69 ] Processor      C:\Windows\system32\DRIVERS\processr.sys
15:54:14.0076 0x2224  Processor - ok
15:54:14.0136 0x2224  [ E058CE4FC2449D8BFA14739C83B7FF2A, 6ACA086D5E0EF3C3EAEBD78010E50739BBA7CA05E937FFF3A4F2AD22FD57B54A ] ProfSvc        C:\Windows\system32\profsvc.dll
15:54:14.0186 0x2224  ProfSvc - ok
15:54:14.0216 0x2224  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D, 6585A87CE55EE5C51B18DF86E8EDFC6A909D96C87522FF4183F8BA9355E8DD44 ] ProtectedStorage C:\Windows\system32\lsass.exe
15:54:14.0236 0x2224  ProtectedStorage - ok
15:54:14.0266 0x2224  [ 1D0A3F565397D08707F3D75B88586645, 92EC9C26CD446E86C37CB2FAF235B97D68D9682DD240563EC0C81000FAD7AF25 ] Ps2            C:\Windows\system32\DRIVERS\PS2.sys
15:54:14.0296 0x2224  Ps2 - ok
15:54:14.0356 0x2224  [ C5AB7F0809392D0DA027F4A2A81BFA31, B5BC9712AD93661A77AF4D67DB5F05C58A93CF7CDD6F7BA20568C0A9F4630321 ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
15:54:14.0376 0x2224  PSched - ok
15:54:14.0406 0x2224  [ 87B04878A6D59D6C79251DC960C674C1, 3EB8DB0624E646F0A65D0381408D35CF9FDC5ABFC30DF6431F4070A8EB68447C ] PxHlpa64        C:\Windows\system32\Drivers\PxHlpa64.sys
15:54:14.0426 0x2224  PxHlpa64 - ok
15:54:14.0486 0x2224  [ 0B83F4E681062F3839BE2EC1D98FD94A, 47E1B8014C59981693F5544872AF00383528AAEF0C6FE9AE8C45A6359EFB067D ] ql2300          C:\Windows\system32\drivers\ql2300.sys
15:54:14.0556 0x2224  ql2300 - ok
15:54:14.0606 0x2224  [ E1C80F8D4D1E39EF9595809C1369BF2A, 5C18F8366049C690FC8AA4A992AA0765A6607F72E0EF889A5F3757E59FB1C143 ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
15:54:14.0616 0x2224  ql40xx - ok
15:54:14.0656 0x2224  [ 90574842C3DA781E279061A3EFF91F07, F87DE7355DAA4FACF2126A0427C08BAAD9E647E0B02EE5447746BE969B28DA8D ] QWAVE          C:\Windows\system32\qwave.dll
15:54:14.0706 0x2224  QWAVE - ok
15:54:14.0736 0x2224  [ E8D76EDAB77EC9C634C27B8EAC33ADC5, 171A3C5D5C3C5845C3BF9A4BCD88E744B025C910AC2F528D0E7D66F173FF0BED ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
15:54:14.0756 0x2224  QWAVEdrv - ok
15:54:15.0386 0x2224  [ 138F7963118EC710C348819C08F72230, A5ED1F4C69132944EFF1BF91F59FF0C47BA54E6C8AC2124B36BF5C8B79E16441 ] Radio.fx        J:\Tobit Radio.fx\Server\rfx-server.exe
15:54:15.0556 0x2224  Radio.fx - ok
15:54:15.0626 0x2224  [ ED4E69C31EF566266BE13638EBE9DA56, BF47F5955BF271E509136677A0ABD37F490066111A76E621257A0F297D8DE8CC ] RapiMgr        C:\Windows\WindowsMobile\rapimgr.dll
15:54:15.0656 0x2224  RapiMgr - ok
15:54:15.0666 0x2224  [ 1013B3B663A56D3DDD784F581C1BD005, 36B83F234C2D6A6112BC8B5EF0AB5075EE98AC0BED702C37E4C1C3D17EB49956 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
15:54:15.0726 0x2224  RasAcd - ok
15:54:15.0766 0x2224  [ B2AE18F847D07F0044404DDF7CB04497, 24B1D5E1D0621160640264656E3D447C611DEE1B0EE308971EF85F0AC3D9F7DD ] RasAuto        C:\Windows\System32\rasauto.dll
15:54:15.0806 0x2224  RasAuto - ok
15:54:15.0846 0x2224  [ AC7BC4D42A7E558718DFDEC599BBFC2C, E059EB9472FDDB73AF09FFEBA58D8284AFCDAB1516E0C5759980E60C892F8126 ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
15:54:15.0896 0x2224  Rasl2tp - ok
15:54:15.0936 0x2224  [ 3AD83E4046C43BE510DE681588ACB8AF, C5445A23F35395B3EA3974C0D5E314E23D900C694D31F7B7A83FE9027D95A91C ] RasMan          C:\Windows\System32\rasmans.dll
15:54:15.0966 0x2224  RasMan - ok
15:54:16.0006 0x2224  [ 4517FBF8B42524AFE4EDE1DE102AAE3E, F01C8A773A637B66192BD16DDE467CAECC6E62853DBDB507FF3FC67B4B388988 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
15:54:16.0036 0x2224  RasPppoe - ok
15:54:16.0076 0x2224  [ C6A593B51F34C33E5474539544072527, 8182C1D15CDC164363D3DD355197160167A00BA9FA833AA444317D06344EF7CE ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
15:54:16.0106 0x2224  RasSstp - ok
15:54:16.0146 0x2224  [ 322DB5C6B55E8D8EE8D6F358B2AAABB1, 07B89F701594F680F50A885B923521763A6131104CEE63D422E1C359C23AE2F6 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
15:54:16.0186 0x2224  rdbss - ok
15:54:16.0186 0x2224  [ 603900CC05F6BE65CCBF373800AF3716, 83B010D51D1087673CF15FD0A992FD91CC910A073FEA9A8F20F6124B6E5489F2 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
15:54:16.0226 0x2224  RDPCDD - ok
15:54:16.0256 0x2224  [ C045D1FB111C28DF0D1BE8D4BDA22C06, 572986C93B982387EE94797A1EDE1C6C444B0F1078AC8201099452BFA021458F ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
15:54:16.0326 0x2224  rdpdr - ok
15:54:16.0326 0x2224  [ CAB9421DAF3D97B33D0D055858E2C3AB, 66C353CD310A91FAB0D0871ACCE71110595B63536560D0331DA70B1E33AC45BE ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
15:54:16.0366 0x2224  RDPENCDD - ok
15:54:16.0426 0x2224  [ AE4BD9E1C33D351D8E607FC81F15160C, AD785CA72B7C6EB9F94B2E797C758C0F804DB26EE056DDC6D4F85BB562A02EA4 ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
15:54:16.0466 0x2224  RDPWD - ok
15:54:16.0506 0x2224  [ C612B9557DA73F70D41F8A6FBC8E5344, D7D11F202066F848FBD3F26D9FF915C7F3D68F30631393B2049F3AC5A40FD108 ] RemoteAccess    C:\Windows\System32\mprdim.dll
15:54:16.0566 0x2224  RemoteAccess - ok
15:54:16.0616 0x2224  [ 44B9D8EC2F3EF3A0EFB00857AF70D861, A45D8024A242456A73337C91663A3E1633BF163234CDFD5DF86840F31FFFE84D ] RemoteRegistry  C:\Windows\system32\regsvc.dll
15:54:16.0666 0x2224  RemoteRegistry - ok
15:54:16.0726 0x2224  [ CD71E053D7260E4102D99A28F9196070, FD6E3CCB76D2700C50D2C9E98AA4D1AB97F73D9A502E2F705DA5CC5810F5A090 ] RFCOMM          C:\Windows\system32\DRIVERS\rfcomm.sys
15:54:16.0776 0x2224  RFCOMM - ok
15:54:16.0796 0x2224  [ F46C457840D4B7A4DAAFEE739CE04102, 94E946036240B3BAFF17C4A49745E29E492ABBC7BE5110741B212DF4D7F45B84 ] RpcLocator      C:\Windows\system32\locator.exe
15:54:16.0842 0x2224  RpcLocator - ok
15:54:16.0920 0x2224  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF, 3BE4B8EE22FA55D3A17D3718781C8BCA631C78F7928092561F6B79BB60E7D7FE ] RpcSs          C:\Windows\system32\rpcss.dll
15:54:16.0998 0x2224  RpcSs - ok
15:54:17.0013 0x2224  [ 22A9CB08B1A6707C1550C6BF099AAE73, 46A9D40A03DC0B6C93274C0C1CDB132B2339E76E77CAB0F12AEDAD4C31822B91 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
15:54:17.0045 0x2224  rspndr - ok
15:54:17.0060 0x2224  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D, 6585A87CE55EE5C51B18DF86E8EDFC6A909D96C87522FF4183F8BA9355E8DD44 ] SamSs          C:\Windows\system32\lsass.exe
15:54:17.0091 0x2224  SamSs - ok
15:54:17.0107 0x2224  [ CD9C693589C60AD59BBBCFB0E524E01B, F9EBD4FF4C712A563B1120D123012E41105D31402BE45D6F8C8DA71155D64ECB ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
15:54:17.0123 0x2224  sbp2port - ok
15:54:17.0154 0x2224  [ FD1CDCF108D5EF3366F00D18B70FB89B, 5BCE3A9D5DC0B6937A734264C5B8DE0E6B8F77A869A118F94D57E662AAB28FE2 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
15:54:17.0497 0x2224  SCardSvr - ok
15:54:17.0544 0x2224  [ 0F838C811AD295D2A4489B9993096C63, 3DF2F973359249735810CB5AD52E05126A93A1C7D9F6274ACB018A0A125846BD ] Schedule        C:\Windows\system32\schedsvc.dll
15:54:17.0622 0x2224  Schedule - ok
15:54:17.0653 0x2224  scores - ok
15:54:17.0684 0x2224  [ 5A268127633C7EE2A7FB87F39D748D56, 45C530A0EE0108543A75B9427F77EBB5E8350AE16C235763B6F32E72CE15C449 ] SCPolicySvc    C:\Windows\System32\certprop.dll
15:54:17.0715 0x2224  SCPolicySvc - ok
15:54:17.0747 0x2224  [ 4FF71B076A7760FE75EA5AE2D0EE0018, DDDBC9530120F8C1AB449076F6F06F74354149B4C458E6682F957628EE795DE8 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
15:54:17.0793 0x2224  SDRSVC - ok
15:54:17.0825 0x2224  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
15:54:17.0903 0x2224  secdrv - ok
15:54:17.0934 0x2224  [ 5ACDCBC67FCF894A1815B9F96D704490, FE0247A8BEDB860EBD46A9D49C641D0B9AA24EE34132CDDADC9F5A605238FDA7 ] seclogon        C:\Windows\system32\seclogon.dll
15:54:17.0996 0x2224  seclogon - ok
15:54:18.0012 0x2224  [ 90973A64B96CD647FF81C79443618EED, 1D3CB7F724B7EADA6443DF07B258EE7FB7FEC92C2A7A9D3C57F6A220EF0DDDC4 ] SENS            C:\Windows\System32\sens.dll
15:54:18.0059 0x2224  SENS - ok
15:54:18.0069 0x2224  [ F71BFE7AC6C52273B7C82CBF1BB2A222, 8C7F0E426B266DBBFE4BBE3333A33C338209BD8BE0E434A98D0D2CFD78D3F758 ] Serenum        C:\Windows\system32\drivers\serenum.sys
15:54:18.0139 0x2224  Serenum - ok
15:54:18.0169 0x2224  [ E62FAC91EE288DB29A9696A9D279929C, 9B6A420556532F7F8D55FB6580A592A43BEA579A068B970C741A23DB079ECAD1 ] Serial          C:\Windows\system32\drivers\serial.sys
15:54:18.0219 0x2224  Serial - ok
15:54:18.0259 0x2224  [ A842F04833684BCEEA7336211BE478DF, 9D964AEA237C44898098AC9C2D043F00C66EDA7D73C381D616737C01A9D0FF45 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
15:54:18.0309 0x2224  sermouse - ok
15:54:18.0419 0x2224  [ 12B41D84A4D058ADC60853C365DBFCCA, E53454E065F505DCF55D45AEFCC2F9EC45F2ED71BE64CC7F224E9736578B1AD4 ] ServiceLayer    C:\Program Files (x86)\Nokia\PC Connectivity Solution\ServiceLayer.exe
15:54:18.0449 0x2224  ServiceLayer - detected UnsignedFile.Multi.Generic ( 1 )
15:54:22.0230 0x2224  Detect skipped due to KSN trusted
15:54:22.0230 0x2224  ServiceLayer - ok
15:54:22.0261 0x2224  [ A8E4A4407A09F35DCCC3771AF590B0C4, F56ECE42CE81098FCCBCDFBBF006C3FB9EDD29C62F03C4EAE012EE690669481B ] SessionEnv      C:\Windows\system32\sessenv.dll
15:54:22.0291 0x2224  SessionEnv - ok
15:54:22.0311 0x2224  [ 14D4B4465193A87C127933978E8C4106, A5C3F2F09E9A0715529B05AC1020EF0F432121E129447795257087E0D6A812FC ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
15:54:22.0361 0x2224  sffdisk - ok
15:54:22.0401 0x2224  [ 7073AEE3F82F3D598E3825962AA98AB2, 82A959A0970CBA8CC16D44736ED12158E59E138484F3F53EBDD3A4C02DA3700D ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
15:54:22.0451 0x2224  sffp_mmc - ok
15:54:22.0481 0x2224  [ 35E59EBE4A01A0532ED67975161C7B82, 4F4296B8903FCD06439CC8BF93C703852E523834F09CF9121FDA729A988AF11B ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
15:54:22.0531 0x2224  sffp_sd - ok
15:54:22.0571 0x2224  [ 6B7838C94135768BD455CBDC23E39E5F, 868E054ED546479DEAD7C2834C7AB080820522C16F5B4BEF0F3B279A33ABA9C8 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
15:54:22.0621 0x2224  sfloppy - ok
15:54:22.0691 0x2224  [ 4C5AEE179DA7E1EE9A9CCB9DA289AF34, 9659C7B5046DE2C0416A74FDE6F798C3E78D38327CB71BAE49D57A8347A9097D ] SharedAccess    C:\Windows\System32\ipnathlp.dll
15:54:22.0771 0x2224  SharedAccess - ok
15:54:22.0821 0x2224  [ 56793271ECDEDD350C5ADD305603E963, 7A29407C1C550FF3A6A3544811ABD971E9C760B984A7E64D5A1440C69D6AF483 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
15:54:22.0851 0x2224  ShellHWDetection - ok
15:54:22.0871 0x2224  [ 7A5DE502AEB719D4594C6471060A78B3, E8E16DF8AFFC230FBB1A5938925D464A1BA776184B8C020B37669EE2105DB9F2 ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
15:54:22.0891 0x2224  SiSRaid2 - ok
15:54:22.0911 0x2224  [ 3A2F769FAB9582BC720E11EA1DFB184D, 83EEBCE37E8709FCE15FB44F546C727C56064ED49B73A471EA33480573558419 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
15:54:22.0931 0x2224  SiSRaid4 - ok
15:54:22.0991 0x2224  [ 50D9949020E02B847CD48F1243FCB895, 5BDAD5E44DE5B412645142810C5FCE4B2D9685F928FF4A6B836A9DCE7725BD78 ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
15:54:23.0011 0x2224  SkypeUpdate - ok
15:54:23.0121 0x2224  [ A9A27A8E257B45A604FDAD4F26FE7241, C5A1056522EE2BA7B70D34E391477A0E9351569CEF28B875172F4B363F6D4177 ] slsvc          C:\Windows\system32\SLsvc.exe
15:54:23.0301 0x2224  slsvc - ok
15:54:23.0361 0x2224  [ FD74B4B7C2088E390A30C85A896FC3AF, 897F1F89A4DDB356CF6E59EFBC32A2081C0CADE283793DB6879D263F7B2E313F ] SLUINotify      C:\Windows\system32\SLUINotify.dll
15:54:23.0391 0x2224  SLUINotify - ok
15:54:23.0421 0x2224  [ 290B6F6A0EC4FCDFC90F5CB6D7020473, 971888FE760641FF86165B9876E6FC12DBC309C0FED2734C60B9E0EBC078AAE0 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
15:54:23.0471 0x2224  Smb - ok
15:54:23.0511 0x2224  [ F8F47F38909823B1AF28D60B96340CFF, EFD948EE09F22F9F373A98BA6D9BC519FD9244986E4BE7B2BACD92D3C145AD1D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
15:54:23.0551 0x2224  SNMPTRAP - ok
15:54:23.0591 0x2224  [ 386C3C63F00A7040C7EC5E384217E89D, DD8766BCBD77EC6F67979A8B37B943A3A0E5478CE3FB129BF8FCA29B66529721 ] spldr          C:\Windows\system32\drivers\spldr.sys
15:54:23.0611 0x2224  spldr - ok
15:54:23.0651 0x2224  [ F66FF751E7EFC816D266977939EF5DC3, 689BDD0B442830E162F2F9A8EFBD0E137F518C7F0CD92EDF4A43EFBA188B69F4 ] Spooler        C:\Windows\System32\spoolsv.exe
15:54:23.0681 0x2224  Spooler - ok
15:54:23.0721 0x2224  [ 880A57FCCB571EBD063D4DD50E93E46D, D46BA584D1C33F17C4156127742FA470AA044C4BCE9E6A209E5B1F3A44C73350 ] srv            C:\Windows\system32\DRIVERS\srv.sys
15:54:23.0761 0x2224  srv - ok
15:54:23.0801 0x2224  [ A1AD14A6D7A37891FFFECA35EBBB0730, AE00950D330EE4C05F5AA9BC7E63E974766D8E93B607CB3E683C727E8A65049D ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
15:54:23.0841 0x2224  srv2 - ok
15:54:23.0891 0x2224  [ 4BED62F4FA4D8300973F1151F4C4D8A7, 1835895B3E837F8862F7F669DFBDF5EAB627E5656377624474C17E92CF440D2A ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
15:54:23.0941 0x2224  srvnet - ok
15:54:23.0991 0x2224  [ 192C74646EC5725AEF3F80D19FF75F6A, 8F24FF139A46B1F837356B9D682526107D7BADCFA510842FEACB6F06C02D93D9 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
15:54:24.0031 0x2224  SSDPSRV - ok
15:54:24.0051 0x2224  [ 2EE3FA0308E6185BA64A9A7F2E74332B, EC6A15281685E6CDEADABDFD08C4AF980AD3B404C945EB121D7F90AFCA3D6849 ] SstpSvc        C:\Windows\system32\sstpsvc.dll
15:54:24.0091 0x2224  SstpSvc - ok
15:54:24.0131 0x2224  [ 14B4DB4381E4A55F570D8BB699B791D6, 14975F249C59F9D13359FF064433246C46A8A3328ED69A23712649ACAAE9121D ] StillCam        C:\Windows\system32\DRIVERS\serscan.sys
15:54:24.0161 0x2224  StillCam - ok
15:54:24.0241 0x2224  [ 15825C1FBFB8779992CB65087F316AF5, E9431C016D209A7322C0586F11EEF0AB461AB5822960287BB1D0FBC30183614D ] stisvc          C:\Windows\System32\wiaservc.dll
15:54:24.0321 0x2224  stisvc - ok
15:54:24.0371 0x2224  [ F0563DB310C7748705AA0BE194A6BC9E, E8785690F2D1642AC708ADF0F527BC09E4851100C9A19904F7531F0CA76B02AD ] SWDUMon        C:\Windows\system32\DRIVERS\SWDUMon.sys
15:54:24.0381 0x2224  SWDUMon - ok
15:54:24.0401 0x2224  [ 8A851CA908B8B974F89C50D2E18D4F0C, 27EA13E50B5B72ABF6C5B7B7D34A7154A12BB27B1C1B2EEFCAA36A96010DB4DC ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
15:54:24.0411 0x2224  swenum - ok
15:54:24.0471 0x2224  [ 6DE37F4DE19D4EFD9C48C43ADDBC949A, 9C3714238571704CEE2AD4F1E15029243E00B494345C41F74EFDF3F0328CC9EA ] swprv          C:\Windows\System32\swprv.dll
15:54:24.0511 0x2224  swprv - ok
15:54:24.0531 0x2224  [ 2F26A2C6FC96B29BEFF5D8ED74E6625B, 0227EAF144BC35AA4FF2535E8C9974C0609B7634EE45F4166B9F88F79B17BBF1 ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
15:54:24.0551 0x2224  Symc8xx - ok
15:54:24.0571 0x2224  [ A909667976D3BCCD1DF813FED517D837, 0874DD4C1CA7AE2E519EBB45433BC9F11A574408F5D2F9E23A340CA76512F5CE ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
15:54:24.0581 0x2224  Sym_hi - ok
15:54:24.0601 0x2224  [ 36887B56EC2D98B9C362F6AE4DE5B7B0, 7349FABACB633A9EEE3D4E241A5F443C28D23CC87F21EAAB3F1711644AA21D7C ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
15:54:24.0611 0x2224  Sym_u3 - ok
15:54:24.0688 0x2224  [ 92D7A8B0F87B036F17D25885937897A6, 6759BAB11E5FBB143BE13DF1611AE5D41D379DF423D881E92E910DF6A37CBA85 ] SysMain        C:\Windows\system32\sysmain.dll
15:54:24.0782 0x2224  SysMain - ok
15:54:24.0813 0x2224  [ 005CE42567F9113A3BCCB3B20073B029, B1831D71410AD6E7DEB59D26BF6D2D07D2F6112936D6A6FDA57E9296ADA4076D ] TabletInputService C:\Windows\System32\TabSvc.dll
15:54:24.0860 0x2224  TabletInputService - ok
15:54:24.0907 0x2224  [ CC2562B4D55E0B6A4758C65407F63B79, C6AD05B345C699A715EC13830D8EA6EE9822F4B713D15B1F29AC044674A0F498 ] TapiSrv        C:\Windows\System32\tapisrv.dll
15:54:24.0969 0x2224  TapiSrv - ok
15:54:25.0016 0x2224  [ CDBE8D7C1E201B911CDC346D06617FB5, 16D5965E32A109DA38D77F4B6281081569D78371B2F522DE51100967F8776C7A ] TBS            C:\Windows\System32\tbssvc.dll
15:54:25.0078 0x2224  TBS - ok
15:54:25.0156 0x2224  [ 00F77C4555FFABC21ADDB3160B2F574A, 292D3D9FC923283A25717831C5F1EA3046CB09F4F1B342BB93A506E68B9D4090 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
15:54:25.0219 0x2224  Tcpip - ok
15:54:25.0281 0x2224  [ 00F77C4555FFABC21ADDB3160B2F574A, 292D3D9FC923283A25717831C5F1EA3046CB09F4F1B342BB93A506E68B9D4090 ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
15:54:25.0343 0x2224  Tcpip6 - ok
15:54:25.0406 0x2224  [ C7E72A4071EE0200E3C075DACFB2B334, 925A68FD021C7957792F31E9D69A31C180BEB878CD93D2C3E2BE463F58011A6C ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
15:54:25.0687 0x2224  tcpipreg - ok
15:54:25.0733 0x2224  [ 1D8BF4AAA5FB7A2761475781DC1195BC, A28E972E9331BAD685D4C786FDE221565E0AD3E222B24B9182B7FA916BFCD9C8 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
15:54:25.0780 0x2224  TDPIPE - ok
15:54:25.0827 0x2224  [ 7F7E00CDF609DF657F4CDA02DD1C9BB1, 42A408E82D4017D27D3B0BBBA02BF4B21DEC060C89849785ED65962D18029B65 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
15:54:25.0874 0x2224  TDTCP - ok
15:54:25.0921 0x2224  [ 458919C8C42E398DC4802178D5FFEE27, E38828411DCE0AE2E2BF0D270FD80E47B46EDE4B44DAFD1DF11F54D427EACEB5 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
15:54:25.0983 0x2224  tdx - ok
15:54:25.0999 0x2224  [ 8C19678D22649EC002EF2282EAE92F98, 551E7EBA54C2345F2B7FD7AAA7ADA4C852C94F1B35E6E4BBEF883BAFA34F6262 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
15:54:26.0014 0x2224  TermDD - ok
15:54:26.0061 0x2224  [ 5CDD30BC217082DAC71A9878D9BFD566, 260D40973F9EEAE9A1890B813D8DCC01A9434D17DCE5DA1D16B72A57DCF59194 ] TermService    C:\Windows\System32\termsrv.dll
15:54:26.0108 0x2224  TermService - ok
15:54:26.0139 0x2224  [ 56793271ECDEDD350C5ADD305603E963, 7A29407C1C550FF3A6A3544811ABD971E9C760B984A7E64D5A1440C69D6AF483 ] Themes          C:\Windows\system32\shsvcs.dll
15:54:26.0170 0x2224  Themes - ok
15:54:26.0186 0x2224  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A, 18B0E3E83E41C80809E8140F4C90AB051566C84DD891EA411746EA74E6EAF053 ] THREADORDER    C:\Windows\system32\mmcss.dll
15:54:26.0233 0x2224  THREADORDER - ok
15:54:26.0311 0x2224  [ AB2D61A032A01BF9E84F03CAA9D22932, C321BC2199D76EE84CD794C976D26B16F2ADF3EB3A07D1832A3D1D2E3795A341 ] TOSHIBA Bluetooth Service C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
15:54:26.0326 0x2224  TOSHIBA Bluetooth Service - ok
15:54:26.0357 0x2224  [ 8021F63311797085949FA387F7C83583, 7781994B9F06784807D32FD5A93C5406A441908870B1328BBDA9D15C5DD98C1B ] tosporte        C:\Windows\system32\DRIVERS\tosporte.sys
15:54:26.0373 0x2224  tosporte - ok
15:54:26.0420 0x2224  [ 71BB669BFCADE1580FDCE010ABC76310, 5791BC27BD35EE7048237D42478C9DFF313F4918E692C3DD69F86E3A831E465B ] tosrfbd        C:\Windows\system32\DRIVERS\tosrfbd.sys
15:54:26.0435 0x2224  tosrfbd - ok
15:54:26.0498 0x2224  [ 62512B5277D88600F8BD4B7AEC43569D, 94724FEF7CD61E8E614921C94B24237E7E7E51DA6B9530E953F37E010F94F504 ] tosrfbnp        C:\Windows\system32\Drivers\tosrfbnp.sys
15:54:26.0498 0x2224  tosrfbnp - ok
15:54:26.0513 0x2224  [ C523A9186C39D65CC9ADEBB2E1B93CCD, B04E73CAFFD8100512686F3487D28FE62AC3538F6A71DBC94AA724824256E2E4 ] Tosrfcom        C:\Windows\system32\Drivers\tosrfcom.sys
15:54:26.0529 0x2224  Tosrfcom - ok
15:54:26.0576 0x2224  [ 451B8C1815C6CC39650AF916C2A382CD, 562B90A9D15F728D76E274FD165D82AACED54B29910001C8C7DB1E3DE9386E16 ] Tosrfhid        C:\Windows\system32\DRIVERS\Tosrfhid.sys
15:54:26.0591 0x2224  Tosrfhid - ok
15:54:26.0623 0x2224  [ B6FDC3C76FFE9C5171EEA9C37EA367C2, 4F8D4E2E37164DB91F396B836BD888CF221010103CF3FBECE00B747155819374 ] tosrfnds        C:\Windows\system32\DRIVERS\tosrfnds.sys
15:54:26.0638 0x2224  tosrfnds - ok
15:54:26.0638 0x2224  [ 4B7139C5DE6E59BA5C0F9163BEFFE31E, A4A93F705B11E7BA4B2F58B285F8EFEAE5E4F33A52D71B65985D6DBC481C57CE ] TosRfSnd        C:\Windows\system32\drivers\tosrfsnd.sys
15:54:26.0654 0x2224  TosRfSnd - ok
15:54:26.0701 0x2224  [ 463785C39F247580E16DAEF760E7EA86, 75838B030CA9357A27B25254F5E1D68D2211ECDBAF7BC4118A34AAE3C8F121AE ] Tosrfusb        C:\Windows\system32\DRIVERS\tosrfusb.sys
15:54:26.0716 0x2224  Tosrfusb - ok
15:54:26.0747 0x2224  [ F4689F05AF472A651A7B1B7B02D200E7, 3D34B8879DBC69013D1A87A3F47B8A622A60B57F2E962E9F5925C5A01F44640F ] TrkWks          C:\Windows\System32\trkwks.dll
15:54:26.0810 0x2224  TrkWks - ok
15:54:26.0872 0x2224  [ 66328B08EF5A9305D8EDE36B93930369, FD8136BF15AB8D2DB15D011C4F813737D68EED1178462DB8CE40606C16185A30 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
15:54:26.0903 0x2224  TrustedInstaller - ok
15:54:26.0935 0x2224  [ B2388462329ACD17AF50D8701E0C1B18, 959D7B7CCB526367645BAA11C56C88C9AD741EE338BAD6513C54FC7ED43F3AC0 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
15:54:26.0950 0x2224  tssecsrv - ok
15:54:27.0075 0x2224  [ 258C050D197D923668B36C8D3F6A2353, 9A8CDC8FDCF24986FE963566591E2B535653837A8A63EE462126D336E6F94E97 ] TuneUp.UtilitiesSvc C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
15:54:27.0184 0x2224  TuneUp.UtilitiesSvc - ok
15:54:27.0231 0x2224  [ 45427C4B8CAC6B241478F149B935CD80, 7F772D6D00D1ADD394F5907804661C75780EE9F8DF21EF0719D3E4ABA00092B7 ] TuneUpUtilitiesDrv C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys
15:54:27.0247 0x2224  TuneUpUtilitiesDrv - ok
15:54:27.0262 0x2224  [ 89EC74A9E602D16A75A4170511029B3C, AACD82A6F5FE31FF1315F5CA69E5EB6BD172DD86610F0641177CCC131B542034 ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
15:54:27.0325 0x2224  tunmp - ok
15:54:27.0356 0x2224  [ 30A9B3F45AD081BFFC3BCAA9C812B609, 57204F1F72FEFA086FF1D8A14487D56F4DEDD3C50FBB6903E0C4AC749EA720DE ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
15:54:27.0371 0x2224  tunnel - ok
15:54:27.0387 0x2224  [ FEC266EF401966311744BD0F359F7F56, 6EE0223AEFA7A81BEB155FC0CD4421C2BEBCDCBC9663C23064B0445101114BF8 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
15:54:27.0403 0x2224  uagp35 - ok
15:54:27.0434 0x2224  [ FAF2640A2A76ED03D449E443194C4C34, CC2517DCFE6962EB2EDEB93E44CB53B113974C9C69A050E3F36385C8D78E810B ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
15:54:27.0496 0x2224  udfs - ok
15:54:27.0543 0x2224  [ 060507C4113391394478F6953A79EEDC, 5D0AE5F1184165289DC8E8CD493607FCB68512CF90F748E3BFD2250655D784D4 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
15:54:27.0574 0x2224  UI0Detect - ok
15:54:27.0584 0x2224  [ 4EC9447AC3AB462647F60E547208CA00, F304125321B1ECA915EDDBDB6A71EAEF3123DCB5604C9497D72F12E0C1BD5315 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
15:54:27.0604 0x2224  uliagpkx - ok
15:54:27.0654 0x2224  [ 697F0446134CDC8F99E69306184FBBB4, A741882B8FE403E3A5DECED5D4A2254B14AF40ACECD4DAA3D00D71C2205C2C5F ] uliahci        C:\Windows\system32\drivers\uliahci.sys
15:54:27.0674 0x2224  uliahci - ok
15:54:27.0714 0x2224  [ 31707F09846056651EA2C37858F5DDB0, A619AC4B32EA77AC29458894614870086C4DDB81525ADBCFF1AB8970FC5C257A ] UlSata          C:\Windows\system32\drivers\ulsata.sys
15:54:27.0734 0x2224  UlSata - ok
15:54:27.0754 0x2224  [ 85E5E43ED5B48C8376281BAB519271B7, DBDA4216553F7C5EA0C579346D0A638E62766D5B8FCB1BFF3149BB37BBF978D3 ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
15:54:27.0774 0x2224  ulsata2 - ok
15:54:27.0784 0x2224  [ 46E9A994C4FED537DD951F60B86AD3F4, 256F93ED3BD43B50F0D4489164D959F95AB070CC25A80A46355D2B387D336224 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
15:54:27.0814 0x2224  umbus - ok
15:54:27.0844 0x2224  [ 7093799FF80E9DECA0680D2E3535BE60, 1CBFCCA84CB9212176BF5A1D32334BD54E58A2668A4746252738800468AD4AD4 ] upnphost        C:\Windows\System32\upnphost.dll
15:54:27.0924 0x2224  upnphost - ok
15:54:27.0994 0x2224  [ 7168819F30FE9622284EA19BDE7F8AB4, 7E6DF7700E51670214F3AA65E4E4C3231879577EE13643A045FE47C9C5BC5B54 ] upperdev        C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
15:54:28.0034 0x2224  upperdev - ok
15:54:28.0074 0x2224  [ A565B509000BD3E42A9B93B9FFD40D3D, A22734F2DDAAD743D479D40EA91024F1A16A18D9D6C9FC4F90F3930AD040BFA3 ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
15:54:28.0094 0x2224  usbaudio - ok
15:54:28.0134 0x2224  [ 858CC93477F9A9383E07861892600FF9, C72B25E7F6AF46AC22F8D2A1FA0345B290AAE642442C8A388EA75944334BB289 ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
15:54:28.0144 0x2224  usbccgp - ok
15:54:28.0174 0x2224  [ 9247F7E0B65852C1F6631480984D6ED2, E3360A0EE891B8BADEF5FF53F796C79D6AD218961087F866E451F3B6F278672A ] usbcir          C:\Windows\system32\drivers\usbcir.sys
15:54:28.0254 0x2224  usbcir - ok
15:54:28.0294 0x2224  [ 82C3790E4E6F35087EF00994C7A72988, 95FA022BDAC65DCD2DA52C8FCC1F2C186B321F4599F40CB90262E24FD10AE16C ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
15:54:28.0334 0x2224  usbehci - ok
15:54:28.0384 0x2224  [ BE2EB33AF6EE2E5DA07EB987E0A321F5, 0FCFABA080C553451AE4FAFB54DFE57639251D97DA204C07EC66F469826F3B46 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
15:54:28.0434 0x2224  usbhub - ok
15:54:28.0484 0x2224  [ 396041C6EA61202991221AA6A3B16190, 42B2372CF3496F53710C1DEBE49E18B1DAD38F7474A72B0F744DD98EBD3E21E5 ] usbohci        C:\Windows\system32\DRIVERS\usbohci.sys
15:54:28.0514 0x2224  usbohci - ok
15:54:28.0554 0x2224  [ 28B693B6D31E7B9332C1BDCEFEF228C1, 6B756E6D7459F755C76BC3F497643F6818F107304B789952B233C6585434F3A8 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
15:54:28.0594 0x2224  usbprint - ok
15:54:28.0624 0x2224  [ C024814884CE9E6C2E6ED76A63AC3B9A, 39C9EB54998547B0B65EEE6391AA326B02C7CA52FAE9CEB98D538FEC8D9F1858 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
15:54:28.0664 0x2224  usbscan - ok
15:54:28.0714 0x2224  [ 05AF574F0BC4A29D8AB000FC886E80CC, BB279552CD692F4EC463547C77AFBA906E8F24D844B5131645B0EA70578DEB14 ] usbser          C:\Windows\system32\drivers\usbser.sys
15:54:28.0734 0x2224  usbser - ok
15:54:28.0764 0x2224  [ 66C25CB20B2974E0C0CFDAB49FB72A02, DA865FCF667A2053D34906F230B6EC71B800EA5FA39BCD4B77E4FA233EF8E88D ] UsbserFilt      C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
15:54:28.0824 0x2224  UsbserFilt - ok
15:54:28.0864 0x2224  [ B854C1558FCA0C269A38663E8B59B581, 08CC36B33FA2281FC88671BE051863AA8CA911446D24596049DB77FB4CB09EA6 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
15:54:28.0914 0x2224  USBSTOR - ok
15:54:28.0944 0x2224  [ B2872CBF9F47316ABD0E0C74A1ABA507, E9FB3EEA1D834A035675E22A3224E4E278C4D304F6511822D83250409D62BD3A ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
15:54:28.0984 0x2224  usbuhci - ok
15:54:29.0034 0x2224  [ BF7A051DCCBA57C95541135B29CE0FB4, F3570ED5B57CB64A8222164038D53D1C2009013C50CFDE2E6105E8D4F642FEA6 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
15:54:29.0074 0x2224  usbvideo - ok
15:54:29.0124 0x2224  [ D76E231E4850BB3F88A3D9A78DF191E3, 98CAD31C41AD155EA853DF850D94FA29543C3A7D26262D1B6881281D033CEBAF ] UxSms          C:\Windows\System32\uxsms.dll
15:54:29.0154 0x2224  UxSms - ok
15:54:29.0194 0x2224  [ 294945381DFA7CE58CECF0A9896AF327, 67414C6D79D2826BC86BB37349C9D74DB4B667310CBC1ABFD103E26332AE4A00 ] vds            C:\Windows\System32\vds.exe
15:54:29.0244 0x2224  vds - ok
15:54:29.0264 0x2224  [ 916B94BCF1E09873FFF2D5FB11767BBC, 072007FED4EF30C4D7AF8628CBEB2AC99EEAD99D7AB533E90E3748E3D4F11C28 ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
15:54:29.0324 0x2224  vga - ok
15:54:29.0354 0x2224  [ B83AB16B51FEDA65DD81B8C59D114D63, 97D39AA763037752D87216B83896AFD2AD6DFEBB3BCDCED7A9ABFE5706B804C5 ] VgaSave        C:\Windows\System32\drivers\vga.sys
15:54:29.0414 0x2224  VgaSave - ok
15:54:29.0454 0x2224  [ 8294B6C3FDB6C33F24E150DE647ECDAA, FEBD9536EF61F700DFD5D9CB815808C8415D5B23590B3CE17B12D84F4670EA4D ] viaide          C:\Windows\system32\drivers\viaide.sys
15:54:29.0464 0x2224  viaide - ok
15:54:29.0504 0x2224  [ 2B7E885ED951519A12C450D24535DFCA, 249009EBC1D306D51FDFA4A89588462AA2D8B6DF0A20BE250B60DD73200CB7F3 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
15:54:29.0514 0x2224  volmgr - ok
15:54:29.0564 0x2224  [ CEC5AC15277D75D9E5DEC2E1C6EAF877, EA989E257C4409F9AF3B35C4D7ED9134D930FE3733B077C4F3AA5497796F2CB0 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
15:54:29.0594 0x2224  volmgrx - ok
15:54:29.0624 0x2224  [ 582F710097B46140F5A89A19A6573D4B, 6F695B17BF476D027D3012352F3D4DFD0E0815823DA51A136767ECEF6D64A1CA ] volsnap        C:\Windows\system32\drivers\volsnap.sys
15:54:29.0655 0x2224  volsnap - ok
15:54:29.0687 0x2224  [ A68F455ED2673835209318DD61BFBB0E, 8B2B255E8E2F8B415F7AC0F7F4C423F639DD47737F7CEE0F7C816D9A6893C5F7 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
15:54:29.0718 0x2224  vsmraid - ok
15:54:29.0780 0x2224  [ B75232DAD33BFD95BF6F0A3E6BFF51E1, A8120040F144AD42A39347A615F31BF752634994D4D134E2FAD23FEA9C1D71DF ] VSS            C:\Windows\system32\vssvc.exe
15:54:29.0936 0x2224  VSS - ok
15:54:30.0108 0x2224  [ 42E5B5428401F7CB56A5D585DCE46982, 1A2A24D32E1B1408071408BA9ADCE9A84A4E92C7B81469FCF9DC65EB8F0AFF89 ] vToolbarUpdater18.1.9 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe
15:54:30.0201 0x2224  vToolbarUpdater18.1.9 - ok
15:54:30.0279 0x2224  [ F14A7DE2EA41883E250892E1E5230A9A, EBCB74BE26437F6FE84A3B41AD034F451D4BD12CA77D4C7A433DB912E7D31593 ] W32Time        C:\Windows\system32\w32time.dll
15:54:30.0311 0x2224  W32Time - ok
15:54:30.0342 0x2224  [ FEF8FE5923FEAD2CEE4DFABFCE3393A7, D682FBF78CF987609AF35A019E7C90CBE02800D7DFC272FFDD71D82AA362FA7A ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
15:54:30.0420 0x2224  WacomPen - ok
15:54:30.0467 0x2224  [ B8E7049622300D20BA6D8BE0C47C0CFD, 57CF218D1F7D505E354A15C552D94E3C5A68C2B07D7A76EBB0C87A0BFF5772D9 ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
15:54:30.0529 0x2224  Wanarp - ok
15:54:30.0545 0x2224  [ B8E7049622300D20BA6D8BE0C47C0CFD, 57CF218D1F7D505E354A15C552D94E3C5A68C2B07D7A76EBB0C87A0BFF5772D9 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
15:54:30.0576 0x2224  Wanarpv6 - ok
15:54:30.0607 0x2224  [ ECEB715BECE47E101DDEC06B11126066, 6BD577D6EABD48B1BA31955DB3DEEE68528EA54375CA64D233B723D161B45CBA ] wanatw          C:\Windows\system32\DRIVERS\wanatw64.sys
15:54:30.0654 0x2224  wanatw - ok
15:54:30.0716 0x2224  [ 382A7B0B632EC98DE5F0658DA9DE6159, 97C3B3B78FC7A6716C909CECAC006A37BF54EAAC57A5CCA0F38C85A9B56FA045 ] WcesComm        C:\Windows\WindowsMobile\wcescomm.dll
15:54:30.0763 0x2224  WcesComm - ok
15:54:30.0794 0x2224  [ B4E4C37D0AA6100090A53213EE2BF1C1, 67107F542F3C937FA5D9B28BA2EBFE994FFE287F16C0BFCF79AD20B95C13F78B ] wcncsvc        C:\Windows\System32\wcncsvc.dll
15:54:30.0872 0x2224  wcncsvc - ok
15:54:30.0919 0x2224  [ EA4B369560E986F19D93F45A881484AC, B61411D64901C9CB8C80402CD1E8808F5A0FACA38206C8D584C7C1019F5ADF5A ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
15:54:30.0966 0x2224  WcsPlugInService - ok
15:54:31.0013 0x2224  [ 0C17A0816F65B89E362E682AD5E7266E, 6233213D07B234056A1EC6FE1166A65371645269132B428FF3A29DDC0000301A ] Wd              C:\Windows\system32\drivers\wd.sys
15:54:31.0028 0x2224  Wd - ok
15:54:31.0075 0x2224  [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
15:54:31.0122 0x2224  Wdf01000 - ok
15:54:31.0169 0x2224  [ C5EFDA73EBFCA8B02A094898DE0A9276, DE54E06CBE20EB27D88B29C3AE19CDFA0AE4933D6DCD640912C74A1065C9391C ] WdiServiceHost  C:\Windows\system32\wdi.dll
15:54:31.0231 0x2224  WdiServiceHost - ok
15:54:31.0247 0x2224  [ C5EFDA73EBFCA8B02A094898DE0A9276, DE54E06CBE20EB27D88B29C3AE19CDFA0AE4933D6DCD640912C74A1065C9391C ] WdiSystemHost  C:\Windows\system32\wdi.dll
15:54:31.0278 0x2224  WdiSystemHost - ok
15:54:31.0325 0x2224  [ 3E6D05381CF35F75EBB055544A8ED9AC, BEC43932BD6C34406B8850E28178B937BFD9512E49FD9F8C54DA7EE272B478A9 ] WebClient      C:\Windows\System32\webclnt.dll
15:54:31.0387 0x2224  WebClient - ok
15:54:31.0449 0x2224  [ 8D40BC587993F876658BF9FB0F7D3462, 23748E11F5CCE3D4978D748780283FA5A1154F53FF70D924CB2128FF8A4705F7 ] Wecsvc          C:\Windows\system32\wecsvc.dll
15:54:31.0499 0x2224  Wecsvc - ok
15:54:31.0539 0x2224  [ 9C980351D7E96288EA0C23AE232BD065, BA627B04C4259716B451F421F5310A69D8DE9407DE496AA0489139125E9DC16A ] wercplsupport  C:\Windows\System32\wercplsupport.dll
15:54:31.0569 0x2224  wercplsupport - ok
15:54:31.0589 0x2224  [ 66B9ECEBC46683F47EDC06333C075FEF, 35C33596D97DB65DE0A687644E9AD924AD5FCBAFD83FE4D23E7E58EF4BC4CC87 ] WerSvc          C:\Windows\System32\WerSvc.dll
15:54:31.0649 0x2224  WerSvc - ok
15:54:31.0699 0x2224  WinDefend - ok
15:54:31.0709 0x2224  WinHttpAutoProxySvc - ok
15:54:31.0779 0x2224  [ D2E7296ED1BD26D8DB2799770C077A02, B494719C2DEB7B9D2505866868143C4E4F59B88461920AA49BD9F1251B6571B8 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
15:54:31.0829 0x2224  Winmgmt - ok
15:54:31.0929 0x2224  [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869, 22D53818F4A4ACE441E121151CFD7CB1EDF5E8303DF9E113C9BB304B418A96EF ] WinRM          C:\Windows\system32\WsmSvc.dll
15:54:32.0089 0x2224  WinRM - ok
15:54:32.0139 0x2224  [ 817EAFF5D38674EDD7713B9DFB8E9791, F6E0BFC503BA7395F92989C11B454D1F1E58E29302BA203801449A2C5236E84D ] winusb          C:\Windows\system32\DRIVERS\winusb.sys
15:54:32.0179 0x2224  winusb - ok
15:54:32.0239 0x2224  [ EC339C8115E91BAED835957E9A677F16, 3BBE6D4F1731198E8F0CFEE67C4CCA5C31E6968F8E02EF9E029C1847A26F513B ] Wlansvc        C:\Windows\System32\wlansvc.dll
15:54:32.0319 0x2224  Wlansvc - ok
15:54:32.0369 0x2224  [ E18AEBAAA5A773FE11AA2C70F65320F5, 9E2F6FC0F46D0EEEBF4BC1E3D8800B3D268079ABF8EDDD70CD21B789883D7390 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
15:54:32.0419 0x2224  WmiAcpi - ok
15:54:32.0469 0x2224  [ 21FA389E65A852698B6A1341F36EE02D, 2D60911EAAE26C4CE3DEF4FAD1EDE093F912209AA90741AAA8B93F06B37DF605 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
15:54:32.0509 0x2224  wmiApSrv - ok
15:54:32.0529 0x2224  WMPNetworkSvc - ok
15:54:32.0609 0x2224  [ 83B6CA03C846FCD47F9883D77D1EB27B, 1616DBBC95085B6618B7F884383507E2A54D561A41288E79FA6DC99218C02802 ] WMZuneComm      C:\Program Files\Zune\WMZuneComm.exe
15:54:32.0649 0x2224  WMZuneComm - ok
15:54:32.0679 0x2224  [ CBC156C913F099E6680D1DF9307DB7A8, FD8B227F445679E31048CA41442A978A98F267FED96E22C235F63C72AEEE2AB0 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
15:54:32.0729 0x2224  WPCSvc - ok
15:54:32.0779 0x2224  [ 490A18B4E4D53DC10879DEAA8E8B70D9, D069D8C22CF78A0970E85C0B9879E08FF19458FAA75AE447BCF9236731F64252 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
15:54:32.0839 0x2224  WPDBusEnum - ok
15:54:32.0879 0x2224  [ 5E2401B3FC1089C90E081291357371A9, 224D378EEBFB721CBC24896CAE01B31DC54B6ED82C19C5B954E96D5E98B83C59 ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
15:54:32.0909 0x2224  WpdUsb - ok
15:54:33.0039 0x2224  [ A2BFEDF5D926CBED9C5F7BC46169A99C, 4F336C0D1DFBCDF9583F528331300FD377AE6565E0C70D58CD9E6ACE95B7273F ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
15:54:33.0099 0x2224  WPFFontCache_v0400 - ok
15:54:33.0139 0x2224  [ 8A900348370E359B6BFF6A550E4649E1, 3EAD0B951EAF8E940ED6A79FAAAB7D22ACCF3985795F80206A3A07161D319B39 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
15:54:33.0199 0x2224  ws2ifsl - ok
15:54:33.0249 0x2224  [ 9EA3E6D0EF7A5C2B9181961052A4B01A, F39BAF1FC7DD1600C0052C2A6AA3BCBC8CA3DA96D1AC7B42B0F2810D051EE1B0 ] wscsvc          C:\Windows\System32\wscsvc.dll
15:54:33.0269 0x2224  wscsvc - ok
15:54:33.0279 0x2224  WSearch - ok
15:54:33.0389 0x2224  [ D9EF901DCA379CFE914E9FA13B73B4C4, 3BE9693B7B2AFEE23D72AF5DA211379724D752F0EC18ACB7D3DE3DDFC5AE0004 ] wuauserv        C:\Windows\system32\wuaueng.dll
15:54:33.0549 0x2224  wuauserv - ok
15:54:33.0609 0x2224  [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
15:54:33.0649 0x2224  WudfPf - ok
15:54:33.0699 0x2224  [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
15:54:33.0719 0x2224  WUDFRd - ok
15:54:33.0739 0x2224  [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
15:54:33.0779 0x2224  wudfsvc - ok
15:54:34.0109 0x2224  [ 67B787C34FB2888D01B130AE007042D8, E44878E53F265C89F271B08B81C129105E42D1C78C14467B2D96E28A9A428B1A ] ZuneNetworkSvc  C:\Program Files\Zune\ZuneNss.exe
15:54:34.0561 0x2224  ZuneNetworkSvc - ok
15:54:34.0608 0x2224  [ 4D89FC1C20CF655739EFAC5DA81A67BC, 788D0A5B9972ED6D80242C0C5E80AB0FAB44A708B896D5F724AC1559A291C8DD ] ZuneWlanCfgSvc  C:\Program Files\Zune\ZuneWlanCfgSvc.exe
15:54:34.0655 0x2224  ZuneWlanCfgSvc - ok
15:54:34.0671 0x2224  {5eeb83d0-96ea-4249-942c-beead6847053}Gt64 - ok
15:54:34.0686 0x2224  ================ Scan global ===============================
15:54:34.0733 0x2224  [ 060DC3A7A9A2626031EB23D90151428D, 4AADA06E83603E9D4894D6CFC8DADB018307B384F438C809D4BC8E22BD937C3B ] C:\Windows\system32\basesrv.dll
15:54:34.0780 0x2224  [ D665D594B7E11133D29D726BDDC7A5B0, 8EE45E719ACB23F388F2BE7E4311588E90DE7CF50988927CF0FED36DE380FACB ] C:\Windows\system32\winsrv.dll
15:54:34.0811 0x2224  [ D665D594B7E11133D29D726BDDC7A5B0, 8EE45E719ACB23F388F2BE7E4311588E90DE7CF50988927CF0FED36DE380FACB ] C:\Windows\system32\winsrv.dll
15:54:34.0858 0x2224  [ 934E0B7D77FF78C18D9F8891221B6DE3, BB1ACD3CD6482D8B7C5931E8733B8094D2CE59C4FBC4012BD0799C8DC367FB74 ] C:\Windows\system32\services.exe
15:54:34.0873 0x2224  [ Global ] - ok
15:54:34.0873 0x2224  ================ Scan MBR ==================================
15:54:34.0889 0x2224  [ A5EF69613E96C38F1EE5912A74381181 ] \Device\Harddisk0\DR0
15:54:35.0154 0x2224  \Device\Harddisk0\DR0 - ok
15:54:35.0154 0x2224  [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk5\DR5
15:54:35.0575 0x2224  \Device\Harddisk5\DR5 - ok
15:54:35.0575 0x2224  ================ Scan VBR ==================================
15:54:35.0575 0x2224  [ 40F97F33AF810CE7C49DFF033F039256 ] \Device\Harddisk0\DR0\Partition1
15:54:35.0607 0x2224  \Device\Harddisk0\DR0\Partition1 - ok
15:54:35.0607 0x2224  [ 47E08F221A672C56310A42E368D7F0C2 ] \Device\Harddisk0\DR0\Partition2
15:54:35.0638 0x2224  \Device\Harddisk0\DR0\Partition2 - ok
15:54:35.0638 0x2224  [ FD8EA44F60C963B01CBDACAEF104AB79 ] \Device\Harddisk5\DR5\Partition1
15:54:35.0669 0x2224  \Device\Harddisk5\DR5\Partition1 - ok
15:54:35.0669 0x2224  ================ Scan generic autorun ======================
15:54:35.0778 0x2224  [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
15:54:35.0887 0x2224  Sidebar - ok
15:54:35.0887 0x2224  WindowsWelcomeCenter - ok
15:54:35.0950 0x2224  [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
15:54:36.0012 0x2224  Sidebar - ok
15:54:36.0012 0x2224  WindowsWelcomeCenter - ok
15:54:36.0075 0x2224  [ C84F100FF7A65DF5FAD4682041CA51E4, 580BADC917C497F526B42174C1CA89045760807EB170A6449B6D14BCE475C993 ] C:\Program Files (x86)\AOL 9.0 VR\AOL.EXE
15:54:36.0090 0x2224  AOL Fast Start - ok
15:54:36.0168 0x2224  [ 9C5A0F070196B601D629F5BA9AA921F8, BB77BAD24B44A3CB32CD1FACB758E347BE2F5C49C11E494797635D741867AF2B ] C:\Program Files\Windows Sidebar\sidebar.exe
15:54:36.0277 0x2224  Sidebar - ok
15:54:36.0277 0x2224  [ C84F100FF7A65DF5FAD4682041CA51E4, 580BADC917C497F526B42174C1CA89045760807EB170A6449B6D14BCE475C993 ] C:\Program Files (x86)\AOL 9.0 VR\AOL.EXE
15:54:36.0293 0x2224  AOL Fast Start - ok
15:54:36.0293 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:37.0307 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:38.0321 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:39.0335 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:40.0326 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:41.0326 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:42.0326 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:43.0343 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:44.0357 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:45.0371 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:46.0385 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:47.0399 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:48.0413 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:49.0427 0x2224  Waiting for KSN requests completion. In queue: 132
15:54:50.0473 0x2224  AV detected via SS2: G DATA ANTIVIRUS, C:\Program Files (x86)\G Data\AntiVirus\AVK\avkwscpe.exe ( 25.0.0.0 ), 0x42000 ( disabled : updated )
15:54:50.0488 0x2224  Win FW state via NFP2: enabled
15:54:52.0972 0x2224  ============================================================
15:54:52.0972 0x2224  Scan finished
15:54:52.0972 0x2224  ============================================================
15:54:52.0972 0x2204  Detected object count: 0
15:54:52.0972 0x2204  Actual detected object count: 0

Den Rechner habe ich inzwischen runter gefahren und wieder rauf. Jetzt ist die Srptm-Exe wieder da. Von der lrcnta-Exe ist schon lange nichts mehr zu sehen.

cosinus 09.09.2014 15:19

Adware/Junkware/Toolbars entfernen

(alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen aus den Desktop!)

1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Snoosel 10.09.2014 11:39

Code:

# AdwCleaner v3.309 - Bericht erstellt am 09/09/2014 um 17:51:19
# Aktualisiert 02/09/2014 von Xplode
# Betriebssystem : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Benutzername : Ute - MANOPOST-PC
# Gestartet von : C:\Users\Ute\Desktop\adwcleaner_3.309.exe
# Option : Löschen

***** [ Dienste ] *****

[#] Dienst Gelöscht : {5eeb83d0-96ea-4249-942c-beead6847053}Gt64

***** [ Dateien / Ordner ] *****

[!] Ordner Gelöscht : C:\ProgramData\AVG Secure Search
[!] Ordner Gelöscht : C:\ProgramData\NCH Software
[!] Ordner Gelöscht : C:\ProgramData\SpeedMaxPc
[!] Ordner Gelöscht : C:\ProgramData\Trymedia
[!] Ordner Gelöscht : C:\ProgramData\Viewpoint
[!] Ordner Gelöscht : C:\Program Files (x86)\AskTBar
[!] Ordner Gelöscht : C:\Program Files (x86)\AVG Secure Search
[!] Ordner Gelöscht : C:\Program Files (x86)\AVG Security Toolbar
[!] Ordner Gelöscht : C:\Program Files (x86)\BabylonToolbar
[!] Ordner Gelöscht : C:\Program Files (x86)\FunWebProducts
[!] Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
[!] Ordner Gelöscht : C:\Program Files (x86)\Mobogenie
[!] Ordner Gelöscht : C:\Program Files (x86)\NCH Software
[!] Ordner Gelöscht : C:\Program Files (x86)\SpeedMaxPc
[!] Ordner Gelöscht : C:\Program Files (x86)\Viewpoint
[!] Ordner Gelöscht : C:\Program Files (x86)\ver1Re-markit
[!] Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search
[!] Ordner Gelöscht : C:\Program Files (x86)\Common Files\Software Update Utility
[!] Ordner Gelöscht : C:\Program Files (x86)\Common Files\Tobit
[!] Ordner Gelöscht : C:\Program Files\Babylon
[/!\] Nicht Gelöscht ( Junction ) : C:\Program Files\Gemeinsame Dateien
[!] Ordner Gelöscht : C:\Program Files\webHancer
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Local\AVG Secure Search
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Local\DownloadGuide
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Local\genienext
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Local\globalUpdate
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Local\LPT
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Local\Mobogenie
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Local\Smartbar
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Local\Temp\Smartbar
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\LocalLow\AVG Secure Search
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\LocalLow\Conduit
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\LocalLow\Smartbar
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\LocalLow\Softonic
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\DriverCure
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\Gutscheinmieze
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\InetStat
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\iWin
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\NCH Software
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\newnext.me
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\SpeedMaxPc
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\Tobit
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\VOPackage
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
[!] Ordner Gelöscht : C:\Users\Manopost\Documents\Mobogenie
[!] Ordner Gelöscht : C:\Users\Manopost\Documents\PC Speed Maximizer
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\Extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[!] Ordner Gelöscht : C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\Extensions\faststartff@gmail.com
[!] Ordner Gelöscht : C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Datei Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
Datei Gelöscht : C:\Users\Manopost\daemonprocess.txt
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
Datei Gelöscht : C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\searchplugins\SafeFinder Search.xml
Datei Gelöscht : C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\searchplugins\softonic.xml
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\sweet-page.xml
Datei Gelöscht : C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\user.js

***** [ Tasks ] *****

Task Gelöscht : LaunchSignup

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\BabylonHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\b
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Babylon.dskBnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylnApp.appCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\FunWebProductsInstaller.Start
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\FunWebProductsInstaller.Start.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IMsiDe1egate.Application.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@funwebproducts.com/Plugin
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2801937
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{6536801B-F50C-449B-9476-093DFD3789E3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1D4DB7D0-6EC9-47A3-BD87-1E41684E07BB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\AskTBar
Schlüssel Gelöscht : HKLM\SOFTWARE\AVG Secure Search
Schlüssel Gelöscht : HKLM\SOFTWARE\AVG Security Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\BabylonToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\FunWebProducts
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\MetaStream
Schlüssel Gelöscht : HKLM\SOFTWARE\SpeedMaxPC
Schlüssel Gelöscht : HKLM\SOFTWARE\sweet-pageSoftware
Schlüssel Gelöscht : HKLM\SOFTWARE\Trymedia Systems
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
Schlüssel Gelöscht : HKLM\SOFTWARE\Viewpoint
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdUtility
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4

***** [ Browser ] *****

-\\ Internet Explorer v9.0.8112.16563

Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v37.0.2062.103

[ Datei : C:\Users\Manopost\AppData\Local\Google\Chrome\User Data\Default\preferences ]


[ Datei : C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof

*************************

AdwCleaner[R0].txt - [24282 octets] - [09/09/2014 17:49:08]
AdwCleaner[S0].txt - [20559 octets] - [09/09/2014 17:51:19]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [20620 octets] ##########

JRT läd seit 1 Std. und ist seither auf 7 von 9 Files und auf 78%.
Vorher waren es 7von 11 Files und 68%.
Hab den Rechner ganz nackich gemacht, keine Programme im Hintergrund, G-Data aus und Firerwall aus.
Soll ich FRST starten?

Hi Cosinus,
bin ich jetzt fertig? Die Exe ist immer noch da.

cosinus 10.09.2014 12:09

Neu starten, JRT neu runterladen auf den Desktop, nochmal probieren

Snoosel 10.09.2014 14:55

Vor 3 Std. alles gemacht, es läuft weiter auf 7 von 11 Dateien und 70%
weitermachen oder abbrechen?.

cosinus 10.09.2014 15:00

Lass JRT weg.

Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken

http://saved.im/mtg0mjy4yjlu/2014-04...ryscantool.png

Snoosel 10.09.2014 15:40

Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-09-2014
Ran by Ute at 2014-09-10 16:25:29
Running from C:\Users\Ute\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: G DATA ANTIVIRUS (Disabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0}
AS: G DATA ANTIVIRUS (Disabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
 Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
64 Bit HP CIO Components Installer (Version: 1.0.0 - Hewlett-Packard) Hidden
ABBYY PDF Transformer 3.0 (HKLM-x32\...\ABBYY PDF Transformer 3.0) (Version: 3.00.317.68010 - ABBYY)
ABBYY PDF Transformer 3.0 (Version: 3.00.317.68010 - ABBYY) Hidden
Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0.1 - Microsoft Corporation) Hidden
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader X (10.1.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.8.638 - Adobe Systems, Inc.)
AGEIA PhysX v7.01.12 (HKLM-x32\...\{E2BE1618-AF5F-4F7D-8484-42E080EDF609}) (Version: 7.01.12 - AGEIA Technologies, Inc.)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
AOL Deinstallation (HKLM-x32\...\AOL Deinstallation) (Version:  - )
Apple Application Support (HKLM-x32\...\{3FA365DF-2D68-45ED-8F83-8C8A33E65143}) (Version: 1.1.0 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ATI Catalyst Install Manager (HKLM\...\{9EA8213A-9080-C41F-2F85-8FF98374AB9F}) (Version: 3.0.678.0 - ATI Technologies, Inc.)
AVM FRITZ!Box Dokumentation (HKLM-x32\...\AVMFBox) (Version:  - AVM Berlin)
AVM FRITZ!Box Druckeranschluss (HKLM-x32\...\AVMFBoxPrinter) (Version:  - AVM Berlin)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Big Fish Games Client (HKLM-x32\...\BFGC) (Version: 1.4.0.11 - )
Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v7.00.05 - TOSHIBA CORPORATION)
Browser 7 der Telekom 31.0.19 (x86 de) (HKLM-x32\...\Browser 7 der Telekom 31.0.19 (x86 de)) (Version: 31.0.19 - Deutsche Telekom AG)
Browser 7 Maintenance Service (HKLM-x32\...\Browser7MaintenanceService) (Version: 29.0.40 - Deutsche Telekom AG)
BufferChm (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2008.0514.2139.36863 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization Chinese Standard (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Chinese Traditional (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Czech (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Danish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Dutch (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Finnish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization French (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization German (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Greek (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Hungarian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Italian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Japanese (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Korean (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Norwegian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Polish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Portuguese (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Russian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Spanish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Swedish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Thai (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Turkish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Czech (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Danish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Dutch (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help English (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Finnish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help French (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help German (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Greek (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Italian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Japanese (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Korean (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Polish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Russian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Spanish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Swedish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Thai (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Turkish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
ccc-core-static (x32 Version: 2008.0514.2139.36863 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2008.0514.2139.36863 - ATI) Hidden
Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Copy (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
Destination Component (x32 Version: 090.000.091.086 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 110.0.180.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
DivX Converter (HKLM-x32\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 7.1.0 - DivX, Inc.)
DivX Plus DirectShow Filters (HKLM-x32\...\DivX Plus DirectShow Filters) (Version:  - DivX, Inc.)
DivX-Setup (HKLM-x32\...\DivX Setup.divx.com) (Version: 2.5.0.8 - DivX, LLC)
Elevated Installer (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Favorit (HKLM-x32\...\koega) (Version:  - )
Fax (x32 Version: 120.0.194.000 - Hewlett-Packard) Hidden
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
G DATA ANTIVIRUS (HKLM-x32\...\{B9FC0A7D-FA1D-4347-ABED-AD8AD5305633}) (Version: 25.0.2.1 - G DATA Software AG)
Garmin Express (HKLM-x32\...\{b43ffffb-1adc-4bcb-b277-7844ebff94da}) (Version: 3.2.17.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
GEAR driver installer for AMD64 and Intel EM64T (HKLM\...\{50CBBEC7-1010-41C5-8718-A1A6FEDD9C3A}) (Version: 2.003.1 - GEAR Software, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.103 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Hewlett-Packard Active Check for Health Check (x32 Version: 1.1.15.2 - Hewlett-Packard) Hidden
Hewlett-Packard Asset Agent for Health Check (x32 Version: 2.0.63.2 - HP) Hidden
HP Active Support Library (x32 Version: 3.1.6.1 - Hewlett-Packard) Hidden
HP Customer Experience Enhancements (HKLM-x32\...\{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}) (Version: 5.6.0.2510 - Hewlett-Packard)
HP Customer Feedback (x32 Version: 1.0.0 - Hewlett-Packard) Hidden
HP Customer Participation Program 9.0 (HKLM\...\HPExtendedCapabilities) (Version: 9.0 - HP)
HP Imaging Device Functions 9.0 (HKLM\...\HP Imaging Device Functions) (Version: 9.0 - HP)
HP Picasso Media Center Add-In (x32 Version: 1.0.0 - HP) Hidden
HP Recovery Manager RSS (x32 Version: 84.0.0.7 - Hewlet Packard Company) Hidden
HP Update (HKLM-x32\...\{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}) (Version: 4.000.010.008 - Hewlett-Packard)
HP_Network_UserGuide (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
HPSSupply (HKLM-x32\...\{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}) (Version: 2.2.0.0000 - Ihr Firmenname)
Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
king.com (remove only) (HKLM-x32\...\king.com) (Version:  - Midasplayer Ltd (king.com))
LG United Mobile Driver (HKLM-x32\...\{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}) (Version: 3.10.1.0 - LG Electronics)
Marco Polo Mobile Navigator 2 (HKLM-x32\...\{5F65ECEE-EB1D-4C85-8D8C-9C7CE2DBB1D6}) (Version:  - )
MarketResearch (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Corporation (Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft Corporation (x32 Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft VC9 runtime libraries (x32 Version: 2.0.0 - AOL Inc.) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Works (HKLM-x32\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation)
MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 24.2.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.2.0 (x86 de)) (Version: 24.2.0 - Mozilla)
MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NAVIGON Fresh 3.5.1 (HKLM-x32\...\NAVIGON Fresh) (Version: 3.5.1 - NAVIGON)
Nero 8 (HKLM-x32\...\{1CA7ACD6-B21B-4240-AA05-4FC55F6E1031}) (Version: 8.3.465 - Nero AG)
neroxml (x32 Version: 1.0.0 - Nero AG) Hidden
NewFreeScreensaver nfsHDWaterfall03 (HKLM-x32\...\nfsHDWaterfall03 New Free Screensaver_is1) (Version:  - )
Nokia Connectivity Cable Driver (HKLM-x32\...\{25CFEF55-A945-41FC-86ED-76469F31DF37}) (Version: 7.1.41.0 - Nokia)
Nokia Music Player (HKLM-x32\...\{4FCB1267-7380-4EBA-9A6C-69809C6E8227}) (Version: 2.5.11021 - Nokia Music Player)
Nokia_Multimedia_Common_Components_2_5 (HKLM-x32\...\{25F61E72-AAA4-4607-95D2-1E5139C98FFB}) (Version: 2.7.69 - Nokia)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Optimierte Multimedia-Tastatur-Lösung (HKLM-x32\...\KBD) (Version:  - Hewlett-Packard)
PanoStandAlone (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
PaperPort Image Printer 64-bit (HKLM\...\{ABA4FAF1-6389-45F9-92CE-3914A4E5C471}) (Version: 1.00.0000 - Nuance Communications, Inc.)
PC Connectivity Solution (HKLM-x32\...\{4B28C077-9958-45F1-8BB4-CBF90A69AD4E}) (Version: 11.4.15.0 - Nokia)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 6.5.2926 - CyberLink Corp.)
PowerDirector (x32 Version: 6.5.2926 - CyberLink Corp.) Hidden
Primo (x32 Version: 1.00.0000 - Your Company Name) Hidden
Python 2.5.2 (HKLM-x32\...\{6B976ADF-8AE8-434E-B282-A06C7F624D2F}) (Version: 2.5.2150 - Python Software Foundation)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5657 - Realtek Semiconductor Corp.)
RTC Client API v1.2 (HKLM-x32\...\{44CDBD1B-89FB-4E02-8319-2A4C550F664A}) (Version: 1.2.0000 - Microsoft)
Runtime (x32 Version: 1.00.0000 - Your Company Name) Hidden
SafeFinder Smartbar (HKLM-x32\...\{1898B668-CCF5-429F-A86F-9837E5439D77}) (Version: 11.114.72.19232 - Linkury Ltd.) <==== ATTENTION
Skins (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.9.9216 - Skype Technologies S.A.)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Sony USB Driver (HKLM-x32\...\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}) (Version: 2.00 - Sony Corporation)
Spielefieber Patiencen für Vista    (HKLM-x32\...\Spielefieber Patiencen für Vista) (Version:  - KlickMedia)
Status (x32 Version: 110.0.180.000 - Hewlett-Packard) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Top Ten Solitaire (HKLM-x32\...\{51790747-4141-2516-5286-723025870322}) (Version: 1.0 - Bluefish Games)
TrayApp (x32 Version: 110.0.180.000 - Hewlett-Packard) Hidden
TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.340 - TuneUp Software)
TuneUp Utilities 2014 (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.171 - TuneUp Software) Hidden
UnloadSupport (x32 Version: 9.0.0 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2883097) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{B2260BC9-D561-46EE-B33D-739CF760A2A9}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
VR-NetWorld (HKLM-x32\...\{8815F011-43AF-4F50-BBD8-D78ED3D6F5B9}) (Version:  - )
WDR RadioRecorder (HKLM-x32\...\Tobit Radio.fx Server 1) (Version:  - Tobit.Software)
Windows 7 Upgrade Advisor (HKLM-x32\...\{9A4D182C-35C7-4791-8484-4304EBC9101A}) (Version: 2.0.5000.0 - Microsoft Corporation)
Windows Live Call (x32 Version: 14.0.8064.0206 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 14.0.8098.930 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 14.0.8093.805 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 14.0.8081.709 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 14.0.8091.0730 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live Writer (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0) (HKLM\...\FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D) (Version: 08/22/2008 7.0.0.0 - Nokia)
Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Wondershare MobileTrans ( Version 4.2.0 ) (HKLM-x32\...\{18CDCEAA-A9E4-4A4C-AC0E-C15E87C30EA5}_is1) (Version: 4.2.0 - Wondershare)
Xvid 1.1.2 final uninstall (HKLM-x32\...\Xvid_is1) (Version: 1.1 - Xvid team (Koepi))
Zoo Tycoon: Complete Collection (HKLM-x32\...\Zoo Tycoon 1.0) (Version:  - )
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)
Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 14:34 - 2006-09-18 23:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {00BCCA01-A40B-4CAE-8227-2F62DC9E814B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-09] (Google Inc.)
Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {279F157C-71B0-48BD-869F-5517150C523D} - System32\Tasks\HP Health Check Scheduler => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-02] (Hewlett-Packard)
Task: {28D5FA8E-3458-4145-A83A-4C217971EE93} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2007-03-11] (Hewlett-Packard Co.)
Task: {36094E77-3C21-421B-8EAB-76A357083F9B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10] (Adobe Systems Incorporated)
Task: {376BB1C6-EE4E-4BEC-B4FE-84F31A30F5B1} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {468EF5B9-5FB1-4743-B57F-2607EADD3A6C} - System32\Tasks\HP Health Check => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-02] (Hewlett-Packard)
Task: {4C1210EF-7F37-4352-A913-6973F45DEBA2} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {4F0D940C-AD4F-4AE6-AF83-44F78476290D} - System32\Tasks\ScanSoft Background Update => C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
Task: {50B63E3C-8429-4B61-9671-2F1989927645} - System32\Tasks\Automatische Wartung => C:\Program Files (x86)\TuneUp Utilities 2009\OneClickStarter.exe
Task: {5EE7DBA1-E02B-449D-A55F-76653BBFC245} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated)
Task: {5F5E9998-8B9C-481E-94C4-CA2EB746A438} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {A4B635A8-CB6E-4CC9-A4C2-ED29C5B288AD} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe [2014-08-07] ()
Task: {ADFA917F-CC05-4250-BF79-23261ED49A92} - System32\Tasks\Desktop Messenger => C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Task: {B000A09E-317B-407D-BA22-B7FEDB6F3186} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2014-07-16] (TuneUp Software)
Task: {CDBEB6A4-BC55-4040-88D6-844C74525DBE} - System32\Tasks\{4231AEF2-8460-496A-9460-D6D1F6493ADF} => Chrome.exe hxxp://ui.skype.com/ui/0/5.3.0.116/de/abandoninstall?source=lightinstaller&amp;page=tsDownload&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;ienotdefaultbrowser2
Task: {DD7781E1-AD7A-437B-8126-4B49A280B14A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-09] (Google Inc.)
Task: {E6C229EB-FEFD-4A53-A5C9-7AE2CDBC5A82} - System32\Tasks\RecoveryCD => C:\Program Files (x86)\Hewlett-Packard\SDP\RemEngine.exe [2008-06-12] ()
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-01-22 19:58 - 2011-11-18 15:51 - 03673944 _____ () J:\Tobit Radio.fx\Server\rfx-server.exe
2014-07-16 10:24 - 2014-07-16 10:24 - 00699704 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll
2008-09-12 21:49 - 2008-05-15 00:04 - 00116736 _____ () C:\Windows\system32\atitmm64.dll
2014-05-20 03:38 - 2014-05-20 03:38 - 00340088 ____N () C:\Program Files (x86)\Common Files\G Data\AVKProxy\PktIcpt2x64.dll
2004-01-09 22:02 - 2004-01-09 22:02 - 00045056 _____ () C:\Program Files (x86)\AOL 9.0 VR\zlib.dll
2002-04-22 23:08 - 2002-04-22 23:08 - 00053248 _____ () C:\Program Files (x86)\AOL 9.0 VR\xmlparse.dll
2002-04-22 23:08 - 2002-04-22 23:08 - 00081920 _____ () C:\Program Files (x86)\AOL 9.0 VR\xmltok.dll
2007-05-24 10:01 - 2007-05-24 10:01 - 00090112 _____ () C:\Program Files (x86)\AOL 9.0 VR\Components\Tier2Svc.dll
2007-05-24 10:01 - 2007-05-24 10:01 - 00061440 _____ () C:\Program Files (x86)\AOL 9.0 VR\Components\DataSvcs.dll
2009-01-07 17:42 - 2007-05-24 04:49 - 00131072 _____ () c:\program files (x86)\common files\aol\1231342872\ee\services\proxyprovider\ver1_0_0_1\proxyprovider.dll
2009-01-07 17:42 - 2007-05-24 04:57 - 00094208 _____ () c:\program files (x86)\common files\aol\1231342872\ee\services\waolTrayMenuService\ver_0_9_1\waolTrayMenuService.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Manopost:zylomtest
AlternateDataStreams: C:\Users\Manopost:zylomtr{000HQ7FF-AD7A-3FG7-DNQC-2227NIQAQVVE}
AlternateDataStreams: C:\Users\Manopost:zylomtr{000HQ7FF-AD7A-3FG7-FCUD-28A45N46SVT9}
AlternateDataStreams: C:\ProgramData\TEMP:2B1EA607
AlternateDataStreams: C:\ProgramData\TEMP:8AD1F2E0
AlternateDataStreams: C:\ProgramData\TEMP:957E9765
AlternateDataStreams: C:\ProgramData\TEMP:BD36345D
AlternateDataStreams: C:\ProgramData\TEMP:F0D7EE30

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: KBD => C:\HP\KBD\KbdStub.EXE                                                                                                                                                                                                                                                   
MSCONFIG\startupreg: Wondershare Helper Compact.exe => "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"                                                                                                                                                                               
MSCONFIG\startupreg: WSHelperSetup.exe => "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"                                                                                                                                                                               

==================== Faulty Device Manager Devices =============

Name: isatap.{A615081A-DB1C-42C8-8B6A-0E4FEC46738B}
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: isatap.{1AFC8298-E6C4-448F-A08D-F0585C2E35D5}
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (09/10/2014 04:25:32 PM) (Source: VSS) (EventID: 12292) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422] ist ein Fehler aufgetreten.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien abfragen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 13
  Snapshotkontext: 13
  Ausführungskontext: Coordinator

Error: (09/10/2014 04:25:32 PM) (Source: VSS) (EventID: 40) (User: )
Description: Volumeschattenkopie-Dienst-Fehler: Der Dienst "Microsoft-Softwareschattenkopie-Anbieter"
(SWPRV) ist deaktiviert. Aktivieren Sie den Dienst, und wiederholen Sie den Vorgang.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien abfragen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 13
  Snapshotkontext: 13
  Ausführungskontext: Coordinator

Error: (09/10/2014 01:39:00 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts auf dem Volume (Prozess = C:\Windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Hr = 0x8004230f).

Error: (09/10/2014 01:39:00 PM) (Source: VSS) (EventID: 12292) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422] ist ein Fehler aufgetreten.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien löschen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 0
  Snapshotkontext: 0
  Ausführungskontext: Coordinator

Error: (09/10/2014 01:39:00 PM) (Source: VSS) (EventID: 40) (User: )
Description: Volumeschattenkopie-Dienst-Fehler: Der Dienst "Microsoft-Softwareschattenkopie-Anbieter"
(SWPRV) ist deaktiviert. Aktivieren Sie den Dienst, und wiederholen Sie den Vorgang.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien löschen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 0
  Snapshotkontext: 0
  Ausführungskontext: Coordinator

Error: (09/10/2014 01:39:00 PM) (Source: VSS) (EventID: 12292) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422] ist ein Fehler aufgetreten.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien abfragen
  Schattenkopien löschen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 0
  Snapshotkontext: 0
  Ausführungskontext: Coordinator
  Ausführungskontext: Coordinator

Error: (09/10/2014 01:39:00 PM) (Source: VSS) (EventID: 40) (User: )
Description: Volumeschattenkopie-Dienst-Fehler: Der Dienst "Microsoft-Softwareschattenkopie-Anbieter"
(SWPRV) ist deaktiviert. Aktivieren Sie den Dienst, und wiederholen Sie den Vorgang.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien abfragen
  Schattenkopien löschen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 0
  Snapshotkontext: 0
  Ausführungskontext: Coordinator
  Ausführungskontext: Coordinator

Error: (09/10/2014 01:39:00 PM) (Source: VSS) (EventID: 12292) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422] ist ein Fehler aufgetreten.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Überprüfen, ob das Volume vom Anbieter unterstützt wird
  Volume einem Schattenkopiesatz hinzufügen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {00000000-0000-0000-0000-000000000000}
  Snapshotkontext: 4194317
  Ausführungskontext: Coordinator
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Volumename: \\?\Volume{cc3cf33a-b60c-11dd-934c-806e6f6e6963}\
  Ausführungskontext: Coordinator

Error: (09/10/2014 01:39:00 PM) (Source: VSS) (EventID: 40) (User: )
Description: Volumeschattenkopie-Dienst-Fehler: Der Dienst "Microsoft-Softwareschattenkopie-Anbieter"
(SWPRV) ist deaktiviert. Aktivieren Sie den Dienst, und wiederholen Sie den Vorgang.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Überprüfen, ob das Volume vom Anbieter unterstützt wird
  Volume einem Schattenkopiesatz hinzufügen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {00000000-0000-0000-0000-000000000000}
  Snapshotkontext: 4194317
  Ausführungskontext: Coordinator
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Volumename: \\?\Volume{cc3cf33a-b60c-11dd-934c-806e6f6e6963}\
  Ausführungskontext: Coordinator

Error: (09/10/2014 01:28:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sidebar.exe, Version 6.0.6002.18005, Zeitstempel 0x49e035b8, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.18508, Zeitstempel 0x4e567628, Ausnahmecode 0xc0000005, Fehleroffset 0x0000000000001149,
Prozess-ID 0xfb4, Anwendungsstartzeit sidebar.exe0.


System errors:
=============
Error: (09/10/2014 01:26:41 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: HP CUE DeviceDiscovery Service%%2147500037

Error: (09/10/2014 01:26:38 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt

Error: (09/10/2014 01:26:38 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: HP CUE DeviceDiscovery Service

Error: (09/10/2014 01:26:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: vToolbarUpdater18.1.9%%2

Error: (09/10/2014 01:26:38 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Windows-BilderfassungShellhardwareerkennung%%1058

Error: (09/10/2014 01:26:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: scores%%2

Error: (09/10/2014 01:15:16 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: HP CUE DeviceDiscovery Service%%2147500037

Error: (09/10/2014 01:15:02 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt

Error: (09/10/2014 01:15:01 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: HP CUE DeviceDiscovery Service

Error: (09/10/2014 01:15:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: vToolbarUpdater18.1.9%%2


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2014-09-10 16:24:56.932
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:24:56.168
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:24:55.388
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:24:54.624
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:22:57.072
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:22:56.339
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:22:55.559
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:22:54.779
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 13:37:00.279
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 13:36:59.727
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Processor: AMD Phenom(tm) 9650 Quad-Core Processor
Percentage of memory in use: 46%
Total physical RAM: 4093.58 MB
Available physical RAM: 2170.86 MB
Total Pagefile: 8395.68 MB
Available Pagefile: 6175.43 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB

==================== Drives ================================

Drive c: (HP) (Fixed) (Total:582.63 GB) (Free:325.56 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (FACTORY_IMAGE) (Fixed) (Total:13.54 GB) (Free:1.86 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (AVK_09Sep14) (CDROM) (Total:0.19 GB) (Free:0 GB) UDF
Drive j: (HP Pocket Media Drive) (Fixed) (Total:149.04 GB) (Free:126.5 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 596.2 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=582.6 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=13.5 GB) - (Type=07 NTFS)

========================================================
Disk: 5 (MBR Code: Windows XP) (Size: 149.1 GB) (Disk ID: 2BD35C77)
Partition 1: (Not Active) - (Size=149 GB) - (Type=OF Extended)

==================== End Of Log ============================

Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-09-2014
Ran by Ute (administrator) on MANOPOST-PC on 10-09-2014 16:24:43
Running from C:\Users\Ute\Desktop
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(AOL LLC) C:\Program Files (x86)\Common Files\aol\acs\AOLacsd.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() J:\Tobit Radio.fx\Server\rfx-server.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GDKBFltExe32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\AVKBap64.exe
(AOL, LLC.) C:\Program Files (x86)\AOL 9.0 VR\waol.exe
(America Online, Inc.) C:\Program Files (x86)\Common Files\aol\1231342872\ee\aolsoftware.exe
(AOL, LLC.) C:\Program Files (x86)\AOL 9.0 VR\shellmon.exe
(America Online Inc) C:\Program Files (x86)\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [ITSecMng] => C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [83336 2009-07-22] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [SunJavaUpdateReg] => C:\Windows\SysWOW64\jureg.exe [54936 2007-04-07] (Sun Microsystems, Inc.)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe,
HKU\.DEFAULT\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
HKU\.DEFAULT\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-243317379-2889874547-3061927781-1001\...\Run: [AOL Fast Start] => C:\Program Files (x86)\AOL 9.0 VR\AOL.EXE [50480 2007-06-21] (AOL, LLC.)
AppInit_DLLs-x32: C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil.dll => "C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil.dll" File Not Found
IFEO: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\bip_camera1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\browser7.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\btassist1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\coverdes.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\discspeed.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\drivespeed.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\eccenter1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\excel.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\express.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\frontpg.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\groove.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\hpwucli.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\infopath.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\infotool.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\lifecam.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mobiletrans.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\msaccess.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\msoxmled.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mspub.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mstore.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mypc backup.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nero.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neroburnrights.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerohome.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neromediahome.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerorescueagent.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neroscoutoptions.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerostartsmart.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerovision.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\offdiag.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\ois.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\onenote.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\osa.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\outlook.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\photosnap.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\photosnapviewer.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\powerpnt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\pptview.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\recode.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\setupx.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\showtime.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\skype.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\soundtrax.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\tosbtmng.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\tosbtproc1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\uninst.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\usrguide.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\waveedit.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\winword.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\wirelessftp1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\wlangui.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\zune.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt1" -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt2" -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt3" -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt4" -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt5" -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt6" -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt7" -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt8" -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/cpm-redir/ie-9.html
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.t-online.de/cpm-redir/ie-9.html
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.t-online.de/cpm-redir/ie-9.html
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.t-online.de/cpm-redir/ie-9.html
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {D6E4D59A-E5FE-4C8D-8347-B99B76E656E5} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
SearchScopes: HKLM - {F137222E-6DE9-44E9-8EF2-CC5A8D3833BB} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
SearchScopes: HKLM-x32 - {2059CF48-25F3-40d7-9D37-24A3142FD20B} URL = hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=3379&q={searchTerms}&rp=&s_it=tb50-ie-aolde-chromesbox-de-de
SearchScopes: HKLM-x32 - {D6E4D59A-E5FE-4C8D-8347-B99B76E656E5} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
SearchScopes: HKCU - DefaultScope {83CB6700-9424-4FE4-B1F4-F9BC555167F3} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {6C7BD9C4-A466-46C4-82C4-CC66701D1395} URL = hxxp://rover.ebay.com/rover/1/707-1403-276402/4?mpre=hxxp://search.ebay.de/search/search.dll?shortcut=4&query={sear chTerms}
SearchScopes: HKCU - {83CB6700-9424-4FE4-B1F4-F9BC555167F3} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {E6396811-2413-44EC-A69B-A788B0E124FC} URL = hxxp://suche.t-online.de/fastcgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&d ia=suche&context=wiki-tab&tpc=internet&ptl=std&classification=wikitab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {F048D832-4CD6-4A55-AAC4-45E3EE19F9B4} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag= interactivemesuche21&index=blended&linkCode=ur2&camp=1638&creative=6742
BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: HKLM-x32 {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: HKLM-x32 {477E2667-7E7A-4737-BFF5-121D68EF7816} hxxp://musikdownloads.aol.de/imcdms-static/code/AOL%20Download%20Assistent.ocx
DPF: HKLM-x32 {74E4A24D-5224-4F05-8A41-99445E0FC22B} hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: HKLM-x32 {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} -  No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.5.0 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-03-21]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-03-07]

Chrome:
=======
CHR HomePage: Default -> CA7071918667F4327D423F4D70E794BF606311A235D4A490FC145E6BC7418393
CHR DefaultSearchKeyword: Default -> 199E29FAA7C54775CD180793079F5617B561B965549C89D4A6FC35C2896A28AE
CHR DefaultSearchProvider: Default -> 9F43598E6FC84D62FAD3F1C6194BCCCF9B797405CD55613E71E6FE5656259DC3
CHR DefaultSearchURL: Default -> C67BD8333C5775407A7F68E95C2FCB3F70A25EEE0505DE41C14945691D0CE179
CHR Profile: C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-09]
CHR Extension: (Docs) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-09]
CHR Extension: (Google Drive) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-09]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-09]
CHR Extension: (YouTube) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-09]
CHR Extension: (Google-Suche) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-09]
CHR Extension: (Google Sheets) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-09]
CHR Extension: (Skype Click to Call) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-09-09]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2014-09-09]
CHR Extension: (Google Mail) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-09]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 ABBYY.Licensing.PDFTransformer.Classic.3.0; C:\Program Files (x86)\ABBYY PDF Transformer 3.0\NetworkLicenseServer.exe [759048 2010-02-01] (ABBYY)
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2250360 2014-07-30] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe [2683760 2014-05-20] (G Data Software AG)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [356352 2006-12-28] (AVM Berlin) [File not signed]
S4 Boonty Games; C:\Program Files (x86)\Common Files\BOONTY Shared\Service\Boonty.exe [69120 2009-01-28] (BOONTY) [File not signed]
S4 Browser7Maintenance; C:\Program Files (x86)\Browser 7 Maintenance Service\maintenanceservice.exe [112128 2014-08-26] (Deutsche Telekom AG) [File not signed]
R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [File not signed]
S4 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700536 2014-05-20] (G Data Software AG)
S3 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-06-02] (Hewlett-Packard) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2008-10-16] (Hewlett-Packard Co.) [File not signed]
S2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [135168 2008-03-25] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [69632 2006-11-08] (Hewlett-Packard) [File not signed]
S4 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-12-12] (Nero AG)
S4 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [88064 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Radio.fx; J:\Tobit Radio.fx\Server\rfx-server.exe [3673944 2011-11-18] ()
S4 ServiceLayer; C:\Program Files (x86)\Nokia\PC Connectivity Solution\ServiceLayer.exe [632832 2011-03-21] (Nokia) [File not signed]
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
S2 scores; C:\Windows\score.exe [X]
S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [103936 2013-04-23] (LG Electronics Inc.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2010-07-22] ()
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-08-20] (AVG Technologies)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2006-12-28] (AVM Berlin)
S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [34704 2010-02-05] (CSR, plc)
R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2006-12-28] (AVM GmbH)
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [55808 2014-09-01] (G Data Software AG)
R1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [20992 2014-07-06] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [142336 2014-09-01] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [64000 2014-07-06] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64000 2014-09-01] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-08-31] (G Data Software)
R3 HCW3x64; C:\Windows\System32\DRIVERS\HCW3x64.sys [1087872 2007-03-26] (Hauppauge Computer Works inc.)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [61440 2014-07-06] (G Data Software AG)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2010-07-22] ()
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [166944 2008-06-06] (NVIDIA Corporation)
S3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1368960 2006-09-30] (Philips Semiconductors GmbH)
S3 Ps2; C:\Windows\System32\DRIVERS\PS2.sys [21504 2006-09-07] ()
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2014-08-20] ()
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-09-18] (TuneUp Software)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


Snoosel 10.09.2014 15:43

Code:


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-10 16:24 - 2014-09-10 16:25 - 00029459 _____ () C:\Users\Ute\Desktop\FRST.txt
2014-09-10 16:22 - 2014-09-10 16:24 - 02105856 _____ (Farbar) C:\Users\Ute\Desktop\FRST64.exe
2014-09-10 13:38 - 2014-09-10 13:38 - 01016261 _____ (Thisisu) C:\Users\Ute\Desktop\JRT.exe
2014-09-09 18:21 - 2014-09-09 18:21 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT (2).exe
2014-09-09 18:08 - 2014-09-09 18:08 - 00000000 ____D () C:\Windows\ERUNT
2014-09-09 18:06 - 2014-09-09 18:06 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT (1).exe
2014-09-09 18:05 - 2014-09-09 18:06 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT.exe
2014-09-09 17:48 - 2014-09-09 17:52 - 00000000 ____D () C:\AdwCleaner
2014-09-09 17:45 - 2014-09-09 17:45 - 01370483 _____ () C:\Users\Ute\Desktop\adwcleaner_3.309.exe
2014-09-09 15:48 - 2014-09-09 15:49 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Ute\Desktop\tdsskiller.exe
2014-09-09 15:44 - 2014-09-09 15:44 - 00000000 ____D () C:\Users\Ute\AppData\Local\Google
2014-09-09 12:52 - 2014-09-09 12:52 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup(3).exe
2014-09-09 12:50 - 2014-09-09 12:50 - 00733168 _____ () C:\Users\Manopost\Downloads\chromesetup(2).exe
2014-09-09 12:44 - 2014-09-09 13:06 - 00001979 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-09 12:44 - 2014-09-09 12:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-09-09 12:43 - 2014-09-10 15:48 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-09 12:43 - 2014-09-10 13:28 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-09 12:43 - 2014-09-09 12:43 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-09-09 12:43 - 2014-09-09 12:43 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-09-09 12:42 - 2014-09-09 12:42 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup(1).exe
2014-09-09 07:02 - 2014-09-09 09:03 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-09-09 06:56 - 2014-09-09 08:20 - 00000000 ____D () C:\Users\Ute\Desktop\mbar
2014-09-09 06:55 - 2014-09-09 06:56 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Ute\Desktop\mbar-1.07.0.1012.exe
2014-09-08 14:59 - 2014-09-08 18:17 - 00000000 ___SD () C:\32788R22FWJFW
2014-09-08 14:59 - 2014-09-08 14:59 - 00000000 ____D () C:\Windows\erdnt
2014-09-08 12:17 - 2014-09-08 12:17 - 00054750 _____ () C:\Users\Ute\Desktop\Addition1.txt
2014-09-08 09:47 - 2014-09-08 09:47 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Adobe
2014-09-08 09:46 - 2014-09-08 11:00 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\TuneUp Software
2014-09-08 09:46 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\TuneUp Software
2014-09-08 09:45 - 2014-09-08 09:45 - 00000951 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\AOL
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Local\AOL
2014-09-08 09:44 - 2014-09-08 09:45 - 00000941 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-08 09:44 - 2014-09-08 09:44 - 00000936 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-09-08 09:42 - 2014-09-08 09:44 - 00000917 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2014-09-08 09:41 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\VirtualStore
2014-09-08 09:41 - 2014-09-08 09:44 - 00000000 ____D () C:\Users\Ute
2014-09-08 09:41 - 2014-09-08 09:41 - 00000020 ___SH () C:\Users\Ute\ntuser.ini
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Vorlagen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Startmenü
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Netzwerkumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Lokale Einstellungen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Eigene Dateien
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Druckumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Musik
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Bilder
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Verlauf
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Anwendungsdaten
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Anwendungsdaten
2014-09-08 09:41 - 2014-04-09 17:34 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Garmin
2014-09-08 09:41 - 2011-11-18 04:55 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Macromedia
2014-09-08 09:41 - 2010-11-16 00:09 - 00000000 ____D () C:\Users\Ute\AppData\Local\Microsoft Help
2014-09-08 09:41 - 2008-01-21 05:20 - 00000000 ___RD () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-09-08 09:41 - 2008-01-21 05:20 - 00000000 ___RD () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-09-08 08:03 - 2014-09-08 08:03 - 00003631 _____ () C:\Users\Manopost\Downloads\FRST.txt
2014-09-08 08:02 - 2014-09-08 08:03 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64(1).exe
2014-09-08 07:44 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-09-08 07:44 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-09-08 07:43 - 2014-09-08 07:43 - 01101648 _____ () C:\Users\Manopost\Downloads\HijackThis - CHIP-Installer.exe
2014-09-07 19:19 - 2014-09-07 19:19 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64.exe
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-07 16:18 - 2014-09-07 16:19 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Manopost\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-07 15:00 - 2014-09-10 16:24 - 00000000 ____D () C:\FRST
2014-09-07 10:24 - 2014-09-07 10:24 - 00388152 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-07 10:23 - 2014-09-09 17:56 - 00187784 _____ () C:\Windows\PFRO.log
2014-09-06 23:41 - 2014-09-06 23:42 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup.exe
2014-09-06 23:24 - 2014-09-06 23:24 - 00106712 _____ () C:\Users\Manopost\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-06 23:24 - 2014-09-06 23:24 - 00002379 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-09-06 23:16 - 2014-09-06 23:57 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Gameo
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\Desktop\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000000 ___HD () C:\Users\Manopost\AppData\Roaming\GoldenGate
2014-09-06 16:11 - 2014-09-06 16:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Deployment
2014-09-01 23:00 - 2014-09-01 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA ANTIVIRUS
2014-08-28 21:52 - 2014-08-23 03:05 - 00304128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-28 21:52 - 2014-08-23 02:42 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 21:52 - 2014-08-23 01:38 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 10:03 - 2014-08-27 10:03 - 00000630 _____ () C:\Users\Manopost\Desktop\BLT14-15_209.exe - Verknüpfung.lnk
2014-08-27 09:52 - 2014-08-27 09:52 - 00724992 _____ (Maximilian Stangel) C:\Users\Manopost\Downloads\BLT14-15_209.exe
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\ProgramData\Avg_Update_0814tb
2014-08-26 18:52 - 2014-08-31 22:03 - 00000000 ___HD () C:\Users\Public\Temp
2014-08-26 18:49 - 2014-08-26 18:50 - 00000000 ____D () C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F
2014-08-26 14:15 - 2013-12-27 16:17 - 37650432 _____ () C:\Users\Manopost\Desktop\M2U00050.MPG
2014-08-26 13:28 - 2014-09-06 23:26 - 00000000 ____D () C:\Users\Manopost\Desktop\Tablet
2014-08-26 13:13 - 2014-08-26 13:13 - 00000000 ____D () C:\ProgramData\Telekom-Browser 7
2014-08-25 17:43 - 2014-09-07 01:20 - 00000000 ___RD () C:\Users\Manopost\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Program Files (x86)\Dropbox
2014-08-25 17:39 - 2014-09-06 22:46 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Dropbox
2014-08-25 07:52 - 2014-08-25 07:52 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Adobe
2014-08-22 15:27 - 2014-08-22 15:27 - 00000000 ____D () C:\ProgramData\Xerox
2014-08-22 14:28 - 2014-09-06 23:32 - 00000000 ____D () C:\Users\Manopost\Desktop\Neuer Ordner
2014-08-22 12:43 - 2014-08-22 12:45 - 00000000 ____D () C:\Users\Public\10F34257C92C4CB28669BE8F744057EF
2014-08-22 10:23 - 2014-08-22 10:24 - 00000000 ____D () C:\Users\Public\39203AE8A0DE4F819CFD816F114013DB
2014-08-22 10:00 - 2014-04-19 17:34 - 00000426 _____ () C:\AVScanner.ini
2014-08-22 09:11 - 2014-08-31 15:59 - 00000000 ____D () C:\Program Files (x86)\videos MediaPlay-Air
2014-08-22 09:10 - 2014-08-22 09:12 - 00062602 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistMSI61B3.txt
2014-08-22 09:10 - 2014-08-22 09:12 - 00012036 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistUI61B3.txt
2014-08-20 14:49 - 2014-08-20 14:49 - 00016152 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-08-20 14:49 - 2014-08-20 14:49 - 00000000 ____D () C:\Users\Manopost\AppData\Local\SlimWare Utilities Inc
2014-08-20 14:48 - 2014-08-20 14:48 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-08-20 14:45 - 2014-08-20 15:13 - 00000732 _____ () C:\Users\Manopost\AppData\Local\d3d9caps64.dat
2014-08-20 14:44 - 2014-08-20 14:44 - 00796720 _____ ( ) C:\Users\Manopost\Downloads\nero_setup.exe
2014-08-17 18:20 - 2014-08-17 18:45 - 00001653 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fotostory 3 für Windows.lnk
2014-08-17 18:20 - 2014-08-17 18:20 - 00000000 ____D () C:\Program Files (x86)\Photo Story 3 for Windows
2014-08-17 18:18 - 2014-08-17 18:18 - 01101648 _____ () C:\Users\Manopost\Documents\Microsoft Photo Story - CHIP-Installer.exe
2014-08-17 13:33 - 2014-08-22 13:21 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo Video 1
2014-08-17 13:26 - 2014-08-22 14:59 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo 2
2014-08-17 11:21 - 2014-08-26 14:04 - 00000000 ____D () C:\Users\Manopost\Desktop\Meine Bilder
2014-08-17 08:49 - 2014-08-17 08:49 - 01058200 _____ (Adobe) C:\Users\Manopost\Downloads\install_flashplayer14x32au_mssa_awc_aih.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 01389200 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 00619664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 00171152 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00008848 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-17 08:36 - 2014-06-06 06:29 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-17 08:36 - 2014-06-06 06:28 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-17 08:32 - 2014-08-17 08:32 - 00001757 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2014-08-17 08:32 - 2014-08-17 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2014-08-17 00:05 - 2014-08-14 12:15 - 36898446 _____ () C:\Users\Manopost\Desktop\20140814_131447.mp4
2014-08-16 23:56 - 2014-08-20 19:35 - 00000000 ____D () C:\Users\Manopost\Desktop\Handy Tolo
2014-08-16 23:37 - 2014-06-14 02:56 - 00901568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-16 23:37 - 2014-06-14 02:51 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-16 23:37 - 2014-06-02 23:30 - 03137536 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-16 23:37 - 2014-06-02 23:30 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-16 23:37 - 2014-06-02 23:29 - 02280448 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-16 23:37 - 2014-06-02 23:29 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-08-16 23:37 - 2014-06-02 22:29 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-16 23:37 - 2014-06-02 12:31 - 02263552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-16 23:37 - 2014-06-02 12:31 - 00332800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-16 23:37 - 2014-06-02 12:30 - 01993728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-16 23:36 - 2014-07-24 21:28 - 17861120 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-16 23:36 - 2014-07-24 21:12 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-16 23:36 - 2014-07-24 21:10 - 10920960 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-16 23:36 - 2014-07-24 21:07 - 01384960 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-16 23:36 - 2014-07-24 21:06 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-16 23:36 - 2014-07-24 21:05 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-16 23:36 - 2014-07-24 21:05 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-08-16 23:36 - 2014-07-24 21:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 02155520 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-16 23:36 - 2014-07-24 21:04 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-16 23:36 - 2014-07-24 21:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-16 23:36 - 2014-07-24 21:03 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-16 23:36 - 2014-07-24 21:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-16 23:36 - 2014-07-24 21:03 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-08-16 23:36 - 2014-07-24 21:03 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-08-16 23:36 - 2014-07-24 21:03 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-08-16 23:36 - 2014-07-24 21:02 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-16 23:36 - 2014-07-24 20:07 - 12356608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-16 23:36 - 2014-07-24 19:58 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-16 23:36 - 2014-07-24 19:57 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-16 23:36 - 2014-07-24 19:52 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-16 23:36 - 2014-07-24 19:51 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-16 23:36 - 2014-07-24 19:51 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-16 23:36 - 2014-07-24 19:50 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-08-16 23:36 - 2014-07-24 19:50 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 01802240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-16 23:36 - 2014-07-24 19:49 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-16 23:36 - 2014-07-24 19:48 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-16 23:36 - 2014-07-24 19:48 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-08-16 23:36 - 2014-07-24 19:48 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-08-16 23:36 - 2014-07-24 19:48 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-08-16 23:36 - 2014-07-24 19:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-16 23:36 - 2014-07-08 03:12 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-16 23:36 - 2014-07-08 02:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-16 23:06 - 2014-09-06 23:25 - 00000000 ____D () C:\Users\Manopost\Desktop\Kamera Tolo

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-10 16:25 - 2014-09-10 16:24 - 00029459 _____ () C:\Users\Ute\Desktop\FRST.txt
2014-09-10 16:24 - 2014-09-10 16:22 - 02105856 _____ (Farbar) C:\Users\Ute\Desktop\FRST64.exe
2014-09-10 16:24 - 2014-09-07 15:00 - 00000000 ____D () C:\FRST
2014-09-10 15:48 - 2014-09-09 12:43 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-10 15:35 - 2012-07-19 18:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-10 15:25 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-10 15:25 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-10 14:47 - 2010-11-02 18:19 - 01227917 _____ () C:\Windows\WindowsUpdate.log
2014-09-10 14:35 - 2012-07-19 18:26 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-10 14:35 - 2012-04-08 10:43 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-10 14:35 - 2011-05-14 09:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-10 13:38 - 2014-09-10 13:38 - 01016261 _____ (Thisisu) C:\Users\Ute\Desktop\JRT.exe
2014-09-10 13:28 - 2014-09-09 12:43 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-10 13:25 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-10 13:21 - 2006-11-02 17:42 - 00032514 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-09 18:21 - 2014-09-09 18:21 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT (2).exe
2014-09-09 18:08 - 2014-09-09 18:08 - 00000000 ____D () C:\Windows\ERUNT
2014-09-09 18:06 - 2014-09-09 18:06 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT (1).exe
2014-09-09 18:06 - 2014-09-09 18:05 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT.exe
2014-09-09 17:56 - 2014-09-07 10:23 - 00187784 _____ () C:\Windows\PFRO.log
2014-09-09 17:52 - 2014-09-09 17:48 - 00000000 ____D () C:\AdwCleaner
2014-09-09 17:52 - 2009-01-07 16:52 - 00000000 ____D () C:\Users\Manopost
2014-09-09 17:45 - 2014-09-09 17:45 - 01370483 _____ () C:\Users\Ute\Desktop\adwcleaner_3.309.exe
2014-09-09 15:49 - 2014-09-09 15:48 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Ute\Desktop\tdsskiller.exe
2014-09-09 15:44 - 2014-09-09 15:44 - 00000000 ____D () C:\Users\Ute\AppData\Local\Google
2014-09-09 13:06 - 2014-09-09 12:44 - 00001979 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-09 12:52 - 2014-09-09 12:52 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup(3).exe
2014-09-09 12:50 - 2014-09-09 12:50 - 00733168 _____ () C:\Users\Manopost\Downloads\chromesetup(2).exe
2014-09-09 12:44 - 2014-09-09 12:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-09-09 12:43 - 2014-09-09 12:43 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-09-09 12:43 - 2014-09-09 12:43 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-09-09 12:43 - 2009-01-10 16:50 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-09 12:42 - 2014-09-09 12:42 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup(1).exe
2014-09-09 09:03 - 2014-09-09 07:02 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-09-09 08:33 - 2008-09-13 07:16 - 00699062 _____ () C:\Windows\system32\perfh007.dat
2014-09-09 08:33 - 2008-09-13 07:16 - 00156416 _____ () C:\Windows\system32\perfc007.dat
2014-09-09 08:33 - 2006-11-02 14:46 - 01638136 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-09 08:20 - 2014-09-09 06:56 - 00000000 ____D () C:\Users\Ute\Desktop\mbar
2014-09-09 07:35 - 2010-04-27 13:26 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-09-09 06:56 - 2014-09-09 06:55 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Ute\Desktop\mbar-1.07.0.1012.exe
2014-09-08 19:58 - 2009-01-08 19:17 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2009
2014-09-08 19:45 - 2014-07-31 19:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-08 18:17 - 2014-09-08 14:59 - 00000000 ___SD () C:\32788R22FWJFW
2014-09-08 14:59 - 2014-09-08 14:59 - 00000000 ____D () C:\Windows\erdnt
2014-09-08 12:17 - 2014-09-08 12:17 - 00054750 _____ () C:\Users\Ute\Desktop\Addition1.txt
2014-09-08 11:00 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\TuneUp Software
2014-09-08 09:47 - 2014-09-08 09:47 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Adobe
2014-09-08 09:46 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\TuneUp Software
2014-09-08 09:46 - 2014-09-08 09:41 - 00000000 ____D () C:\Users\Ute\AppData\Local\VirtualStore
2014-09-08 09:45 - 2014-09-08 09:45 - 00000951 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\AOL
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Local\AOL
2014-09-08 09:45 - 2014-09-08 09:44 - 00000941 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-08 09:44 - 2014-09-08 09:44 - 00000936 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-09-08 09:44 - 2014-09-08 09:42 - 00000917 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2014-09-08 09:44 - 2014-09-08 09:41 - 00000000 ____D () C:\Users\Ute
2014-09-08 09:41 - 2014-09-08 09:41 - 00000020 ___SH () C:\Users\Ute\ntuser.ini
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Vorlagen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Startmenü
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Netzwerkumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Lokale Einstellungen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Eigene Dateien
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Druckumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Musik
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Bilder
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Verlauf
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Anwendungsdaten
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Anwendungsdaten
2014-09-08 08:03 - 2014-09-08 08:03 - 00003631 _____ () C:\Users\Manopost\Downloads\FRST.txt
2014-09-08 08:03 - 2014-09-08 08:02 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64(1).exe
2014-09-08 07:52 - 2009-02-04 12:45 - 00000069 _____ () C:\Windows\NeroDigital.ini
2014-09-08 07:43 - 2014-09-08 07:43 - 01101648 _____ () C:\Users\Manopost\Downloads\HijackThis - CHIP-Installer.exe
2014-09-08 06:31 - 2013-09-17 15:45 - 00000425 _____ () C:\Windows\BRWMARK.INI
2014-09-07 21:28 - 2011-06-11 10:44 - 00003714 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{7D2327BF-DAC5-43D7-8EB3-6EA0AF4A749D}
2014-09-07 19:19 - 2014-09-07 19:19 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64.exe
2014-09-07 18:29 - 2009-01-28 11:48 - 00000108 _____ () C:\Users\Manopost\AppData\Roaming\default.pls
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-07 16:19 - 2014-09-07 16:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Manopost\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-07 11:08 - 2010-11-15 00:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-09-07 11:08 - 2010-11-15 00:52 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-07 10:24 - 2014-09-07 10:24 - 00388152 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-07 01:20 - 2014-08-25 17:43 - 00000000 ___RD () C:\Users\Manopost\Dropbox
2014-09-06 23:57 - 2014-09-06 23:16 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Gameo
2014-09-06 23:42 - 2014-09-06 23:41 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup.exe
2014-09-06 23:35 - 2013-12-03 13:32 - 00000000 ___RD () C:\Users\Manopost\Documents\Fugen-T-Poster
2014-09-06 23:34 - 2014-01-02 12:23 - 00000000 ____D () C:\Users\Manopost\Desktop\2014
2014-09-06 23:33 - 2014-01-02 15:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Bayrischer Wald
2014-09-06 23:32 - 2014-08-22 14:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Neuer Ordner
2014-09-06 23:27 - 2013-01-21 16:39 - 00000000 ____D () C:\Users\Manopost\Desktop\Bilder1
2014-09-06 23:26 - 2014-08-26 13:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Tablet
2014-09-06 23:25 - 2014-08-16 23:06 - 00000000 ____D () C:\Users\Manopost\Desktop\Kamera Tolo
2014-09-06 23:24 - 2014-09-06 23:24 - 00106712 _____ () C:\Users\Manopost\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-06 23:24 - 2014-09-06 23:24 - 00002379 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\Desktop\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000000 ___HD () C:\Users\Manopost\AppData\Roaming\GoldenGate
2014-09-06 22:51 - 2006-11-02 15:33 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-09-06 22:50 - 2009-01-07 16:56 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-09-06 22:50 - 2006-11-02 17:15 - 00000000 ____D () C:\Windows\WindowsMobile
2014-09-06 22:46 - 2014-08-25 17:39 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Dropbox
2014-09-06 22:41 - 2013-04-11 17:22 - 00000000 ____D () C:\Program Files\Google
2014-09-06 22:40 - 2013-09-17 15:40 - 00000000 ____D () C:\ProgramData\InstallShield
2014-09-06 22:39 - 2013-09-17 15:42 - 00000000 ____D () C:\Program Files (x86)\Brother
2014-09-06 16:12 - 2009-01-10 16:51 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Google
2014-09-06 16:11 - 2014-09-06 16:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Deployment
2014-09-06 16:11 - 2010-06-03 12:57 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Apps\2.0
2014-09-06 15:57 - 2009-01-10 16:51 - 00000000 ____D () C:\ProgramData\Google
2014-09-06 15:36 - 2011-06-13 13:08 - 00003292 _____ () C:\Windows\System32\Tasks\{4231AEF2-8460-496A-9460-D6D1F6493ADF}
2014-09-01 23:00 - 2014-09-01 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA ANTIVIRUS
2014-09-01 23:00 - 2014-04-12 12:28 - 00001794 _____ () C:\Users\Public\Desktop\G DATA ANTIVIRUS.lnk
2014-09-01 23:00 - 2009-10-03 14:49 - 00055808 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2014-09-01 23:00 - 2009-06-20 14:57 - 00142336 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2014-09-01 23:00 - 2009-06-20 14:56 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys
2014-08-31 23:00 - 2014-02-28 00:00 - 00018160 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys
2014-08-31 23:00 - 2009-07-28 16:34 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2014-08-31 22:03 - 2014-08-26 18:52 - 00000000 ___HD () C:\Users\Public\Temp
2014-08-31 15:59 - 2014-08-22 09:11 - 00000000 ____D () C:\Program Files (x86)\videos MediaPlay-Air
2014-08-29 15:01 - 2009-01-08 19:24 - 00003784 _____ () C:\Windows\System32\Tasks\HP-Online-Aktualisierungsprogramm
2014-08-29 15:00 - 2014-04-06 16:26 - 00003558 _____ () C:\Windows\System32\Tasks\GarminUpdaterTask
2014-08-27 10:03 - 2014-08-27 10:03 - 00000630 _____ () C:\Users\Manopost\Desktop\BLT14-15_209.exe - Verknüpfung.lnk
2014-08-27 09:52 - 2014-08-27 09:52 - 00724992 _____ (Maximilian Stangel) C:\Users\Manopost\Downloads\BLT14-15_209.exe
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\ProgramData\Avg_Update_0814tb
2014-08-27 07:33 - 2014-07-28 19:59 - 00000000 ____D () C:\Program Files (x86)\Browser 7 Maintenance Service
2014-08-26 18:50 - 2014-08-26 18:49 - 00000000 ____D () C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F
2014-08-26 14:04 - 2014-08-17 11:21 - 00000000 ____D () C:\Users\Manopost\Desktop\Meine Bilder
2014-08-26 13:43 - 2009-01-09 17:08 - 00112128 _____ () C:\Users\Manopost\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-08-26 13:13 - 2014-08-26 13:13 - 00000000 ____D () C:\ProgramData\Telekom-Browser 7
2014-08-26 13:13 - 2014-07-28 19:59 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Deutsche Telekom AG
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Program Files (x86)\Dropbox
2014-08-25 07:52 - 2014-08-25 07:52 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Adobe
2014-08-23 03:05 - 2014-08-28 21:52 - 00304128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:42 - 2014-08-28 21:52 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 01:38 - 2014-08-28 21:52 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 15:27 - 2014-08-22 15:27 - 00000000 ____D () C:\ProgramData\Xerox
2014-08-22 14:59 - 2014-08-17 13:26 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo 2
2014-08-22 13:21 - 2014-08-17 13:33 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo Video 1
2014-08-22 12:45 - 2014-08-22 12:43 - 00000000 ____D () C:\Users\Public\10F34257C92C4CB28669BE8F744057EF
2014-08-22 10:24 - 2014-08-22 10:23 - 00000000 ____D () C:\Users\Public\39203AE8A0DE4F819CFD816F114013DB
2014-08-22 10:20 - 2009-01-28 10:44 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Ahead
2014-08-22 09:57 - 2009-02-02 23:48 - 00000000 __SHD () C:\found.000
2014-08-22 09:36 - 2012-12-16 14:45 - 00000111 _____ () C:\.dir
2014-08-22 09:24 - 2014-01-03 19:18 - 00000008 __RSH () C:\Users\Manopost\ntuser.pol
2014-08-22 09:24 - 2009-11-23 14:04 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-08-22 09:16 - 2006-11-02 15:34 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-08-22 09:12 - 2014-08-22 09:10 - 00062602 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistMSI61B3.txt
2014-08-22 09:12 - 2014-08-22 09:10 - 00012036 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistUI61B3.txt
2014-08-20 19:35 - 2014-08-16 23:56 - 00000000 ____D () C:\Users\Manopost\Desktop\Handy Tolo
2014-08-20 19:28 - 2012-09-05 19:54 - 00050976 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-08-20 17:31 - 2010-08-01 13:11 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Skype
2014-08-20 15:13 - 2014-08-20 14:45 - 00000732 _____ () C:\Users\Manopost\AppData\Local\d3d9caps64.dat
2014-08-20 14:49 - 2014-08-20 14:49 - 00016152 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-08-20 14:49 - 2014-08-20 14:49 - 00000000 ____D () C:\Users\Manopost\AppData\Local\SlimWare Utilities Inc
2014-08-20 14:48 - 2014-08-20 14:48 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-08-20 14:44 - 2014-08-20 14:44 - 00796720 _____ ( ) C:\Users\Manopost\Downloads\nero_setup.exe
2014-08-17 18:45 - 2014-08-17 18:20 - 00001653 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fotostory 3 für Windows.lnk
2014-08-17 18:20 - 2014-08-17 18:20 - 00000000 ____D () C:\Program Files (x86)\Photo Story 3 for Windows
2014-08-17 18:18 - 2014-08-17 18:18 - 01101648 _____ () C:\Users\Manopost\Documents\Microsoft Photo Story - CHIP-Installer.exe
2014-08-17 11:36 - 2013-07-04 09:21 - 00000855 _____ () C:\Users\Manopost\Desktop\Bluetooth-Informationsaustausch.lnk
2014-08-17 09:51 - 2006-11-02 15:33 - 00000000 ____D () C:\Windows\rescache
2014-08-17 08:49 - 2014-08-17 08:49 - 01058200 _____ (Adobe) C:\Users\Manopost\Downloads\install_flashplayer14x32au_mssa_awc_aih.exe
2014-08-17 08:48 - 2013-08-15 20:56 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-17 08:44 - 2006-11-02 14:35 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-08-17 08:33 - 2014-02-19 16:41 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-17 08:32 - 2014-08-17 08:32 - 00001757 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2014-08-17 08:32 - 2014-08-17 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2014-08-17 08:32 - 2014-02-19 16:42 - 00000000 ____D () C:\ProgramData\Garmin
2014-08-17 08:32 - 2014-02-19 16:41 - 00000000 ____D () C:\Program Files (x86)\Garmin
2014-08-14 12:15 - 2014-08-17 00:05 - 36898446 _____ () C:\Users\Manopost\Desktop\20140814_131447.mp4

Files to move or delete:
====================
C:\Users\Manopost\DivXInstaller7.exe
C:\Users\Manopost\googleupdatesetup.exe
C:\Users\Manopost\Nero-8.3.13.0_all_update.exe
C:\Users\Manopost\pcfresh.exe
C:\Users\Manopost\PowerPointViewer.exe


Some content of TEMP:
====================
C:\Users\Manopost\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmphpm47v.dll
C:\Users\Manopost\AppData\Local\Temp\ICReinstall_google-chrome_setup (1).exe
C:\Users\Manopost\AppData\Local\Temp\_isA52C.exe
C:\Users\Ute\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-10 13:37

==================== End Of Log ============================

mußte isplitten, da Rechner nicht alles hochgeladen hat.

cosinus 10.09.2014 22:36

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\.DEFAULT\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
AppInit_DLLs-x32: C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil.dll => "C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil.dll" File Not Found
CHR HomePage: Default -> CA7071918667F4327D423F4D70E794BF606311A235D4A490FC145E6BC7418393
CHR DefaultSearchKeyword: Default -> 199E29FAA7C54775CD180793079F5617B561B965549C89D4A6FC35C2896A28AE
CHR DefaultSearchProvider: Default -> 9F43598E6FC84D62FAD3F1C6194BCCCF9B797405CD55613E71E6FE5656259DC3
CHR DefaultSearchURL: Default -> C67BD8333C5775407A7F68E95C2FCB3F70A25EEE0505DE41C14945691D0CE179
S2 scores; C:\Windows\score.exe [X]
C:\Users\Manopost\AppData\Local\Smartbar
C:\Windows\score.exe
AlternateDataStreams: C:\Users\Manopost:zylomtest
AlternateDataStreams: C:\Users\Manopost:zylomtr{000HQ7FF-AD7A-3FG7-DNQC-2227NIQAQVVE}
AlternateDataStreams: C:\Users\Manopost:zylomtr{000HQ7FF-AD7A-3FG7-FCUD-28A45N46SVT9}
AlternateDataStreams: C:\ProgramData\TEMP:2B1EA607
AlternateDataStreams: C:\ProgramData\TEMP:8AD1F2E0
AlternateDataStreams: C:\ProgramData\TEMP:957E9765
AlternateDataStreams: C:\ProgramData\TEMP:BD36345D
AlternateDataStreams: C:\ProgramData\TEMP:F0D7EE30
C:\Users\Manopost\DivXInstaller7.exe
C:\Users\Manopost\googleupdatesetup.exe
C:\Users\Manopost\Nero-8.3.13.0_all_update.exe
C:\Users\Manopost\pcfresh.exe
C:\Users\Manopost\PowerPointViewer.exe
C:\Users\Public\10F34257C92C4CB28669BE8F744057EF
C:\Users\Public\39203AE8A0DE4F819CFD816F114013DB
C:\Windows\System32\Tasks\{4231AEF2-8460-496A-9460-D6D1F6493ADF}
EmptyTemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Snoosel 11.09.2014 12:30

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-09-2014
Ran by Ute at 2014-09-11 13:07:01 Run:2
Running from C:\Users\Ute\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKU\.DEFAULT\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\explorer.exe [3079168 2009-04-11] (Microsoft Corporation) <==== ATTENTION
AppInit_DLLs-x32: C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil.dll => "C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil.dll" File Not Found
CHR HomePage: Default -> CA7071918667F4327D423F4D70E794BF606311A235D4A490FC145E6BC7418393
CHR DefaultSearchKeyword: Default -> 199E29FAA7C54775CD180793079F5617B561B965549C89D4A6FC35C2896A28AE
CHR DefaultSearchProvider: Default -> 9F43598E6FC84D62FAD3F1C6194BCCCF9B797405CD55613E71E6FE5656259DC3
CHR DefaultSearchURL: Default -> C67BD8333C5775407A7F68E95C2FCB3F70A25EEE0505DE41C14945691D0CE179
S2 scores; C:\Windows\score.exe [X]
C:\Users\Manopost\AppData\Local\Smartbar
C:\Windows\score.exe
AlternateDataStreams: C:\Users\Manopost:zylomtest
AlternateDataStreams: C:\Users\Manopost:zylomtr{000HQ7FF-AD7A-3FG7-DNQC-2227NIQAQVVE}
AlternateDataStreams: C:\Users\Manopost:zylomtr{000HQ7FF-AD7A-3FG7-FCUD-28A45N46SVT9}
AlternateDataStreams: C:\ProgramData\TEMP:2B1EA607
AlternateDataStreams: C:\ProgramData\TEMP:8AD1F2E0
AlternateDataStreams: C:\ProgramData\TEMP:957E9765
AlternateDataStreams: C:\ProgramData\TEMP:BD36345D
AlternateDataStreams: C:\ProgramData\TEMP:F0D7EE30
C:\Users\Manopost\DivXInstaller7.exe
C:\Users\Manopost\googleupdatesetup.exe
C:\Users\Manopost\Nero-8.3.13.0_all_update.exe
C:\Users\Manopost\pcfresh.exe
C:\Users\Manopost\PowerPointViewer.exe
C:\Users\Public\10F34257C92C4CB28669BE8F744057EF
C:\Users\Public\39203AE8A0DE4F819CFD816F114013DB
C:\Windows\System32\Tasks\{4231AEF2-8460-496A-9460-D6D1F6493ADF}
EmptyTemp:
*****************

HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value not found.
HKU\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value not found.
HKU\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value not found.
"C:\Users\Manopost\AppData\Local\Smartbar\Application\Resources\crdlil.dll" => Value Data not found.
Chrome HomePage deleted successfully.
Chrome DefaultSearchKeyword deleted successfully.
CHR DefaultSearchProvider: Default -> 9F43598E6FC84D62FAD3F1C6194BCCCF9B797405CD55613E71E6FE5656259DC3 ==> The Chrome "Settings" can be used to fix the entry.
Chrome DefaultSearchURL deleted successfully.
scores => Service deleted successfully.
"C:\Users\Manopost\AppData\Local\Smartbar" => File/Directory not found.
"C:\Windows\score.exe" => File/Directory not found.
C:\Users\Manopost => ":zylomtest" ADS removed successfully.
C:\Users\Manopost => ":zylomtr{000HQ7FF-AD7A-3FG7-DNQC-2227NIQAQVVE}" ADS removed successfully.
C:\Users\Manopost => ":zylomtr{000HQ7FF-AD7A-3FG7-FCUD-28A45N46SVT9}" ADS removed successfully.
C:\ProgramData\TEMP => ":2B1EA607" ADS removed successfully.
C:\ProgramData\TEMP => ":8AD1F2E0" ADS removed successfully.
C:\ProgramData\TEMP => ":957E9765" ADS removed successfully.
C:\ProgramData\TEMP => ":BD36345D" ADS removed successfully.
C:\ProgramData\TEMP => ":F0D7EE30" ADS removed successfully.
C:\Users\Manopost\DivXInstaller7.exe => Moved successfully.
C:\Users\Manopost\googleupdatesetup.exe => Moved successfully.
C:\Users\Manopost\Nero-8.3.13.0_all_update.exe => Moved successfully.
C:\Users\Manopost\pcfresh.exe => Moved successfully.
C:\Users\Manopost\PowerPointViewer.exe => Moved successfully.
C:\Users\Public\10F34257C92C4CB28669BE8F744057EF => Moved successfully.
C:\Users\Public\39203AE8A0DE4F819CFD816F114013DB => Moved successfully.
C:\Windows\System32\Tasks\{4231AEF2-8460-496A-9460-D6D1F6493ADF} => Moved successfully.
EmptyTemp: => Removed 5.5 GB temporary data.


The system needed a reboot.

==== End of Fixlog ====

Windowa Sidebar funktioniert jetzt nicht mehr.

cosinus 11.09.2014 14:08

Rechner neu starten, dann neue FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken

http://saved.im/mtg0mjy4yjlu/2014-04...ryscantool.png

Snoosel 11.09.2014 14:41

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-09-2014
Ran by Ute (administrator) on MANOPOST-PC on 11-09-2014 15:36:07
Running from C:\Users\Ute\Desktop
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(AOL LLC) C:\Program Files (x86)\Common Files\aol\acs\AOLacsd.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() J:\Tobit Radio.fx\Server\rfx-server.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GDKBFltExe32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe
(AOL, LLC.) C:\Program Files (x86)\AOL 9.0 VR\waol.exe
(America Online, Inc.) C:\Program Files (x86)\Common Files\aol\1231342872\ee\aolsoftware.exe
(AOL, LLC.) C:\Program Files (x86)\AOL 9.0 VR\shellmon.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\AVKBap64.exe
(America Online Inc) C:\Program Files (x86)\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [ITSecMng] => C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [83336 2009-07-22] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [SunJavaUpdateReg] => C:\Windows\SysWOW64\jureg.exe [54936 2007-04-07] (Sun Microsystems, Inc.)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe,
HKU\.DEFAULT\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-243317379-2889874547-3061927781-1001\...\Run: [AOL Fast Start] => C:\Program Files (x86)\AOL 9.0 VR\AOL.EXE [50480 2007-06-21] (AOL, LLC.)
IFEO: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\bip_camera1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\browser7.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\btassist1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\coverdes.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\discspeed.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\drivespeed.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\eccenter1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\excel.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\express.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\frontpg.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\groove.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\hpwucli.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\infopath.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\infotool.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\lifecam.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mobiletrans.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\msaccess.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\msoxmled.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mspub.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mstore.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\mypc backup.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nero.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neroburnrights.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerohome.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neromediahome.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerorescueagent.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\neroscoutoptions.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerostartsmart.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nerovision.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\offdiag.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\ois.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\onenote.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\osa.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\outlook.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\photosnap.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\photosnapviewer.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\powerpnt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\pptview.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\recode.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\setupx.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\showtime.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\skype.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\soundtrax.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\tosbtmng.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\tosbtproc1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\uninst.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\usrguide.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\waveedit.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\winword.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\wirelessftp1.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\wlangui.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\zune.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt1" -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt2" -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt3" -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt4" -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt5" -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt6" -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt7" -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: "DropboxExt8" -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/cpm-redir/ie-9.html
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.t-online.de/cpm-redir/ie-9.html
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.t-online.de/cpm-redir/ie-9.html
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.t-online.de/cpm-redir/ie-9.html
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {D6E4D59A-E5FE-4C8D-8347-B99B76E656E5} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
SearchScopes: HKLM - {F137222E-6DE9-44E9-8EF2-CC5A8D3833BB} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
SearchScopes: HKLM-x32 - {2059CF48-25F3-40d7-9D37-24A3142FD20B} URL = hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=3379&q={searchTerms}&rp=&s_it=tb50-ie-aolde-chromesbox-de-de
SearchScopes: HKLM-x32 - {D6E4D59A-E5FE-4C8D-8347-B99B76E656E5} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
SearchScopes: HKCU - DefaultScope {83CB6700-9424-4FE4-B1F4-F9BC555167F3} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {6C7BD9C4-A466-46C4-82C4-CC66701D1395} URL = hxxp://rover.ebay.com/rover/1/707-1403-276402/4?mpre=hxxp://search.ebay.de/search/search.dll?shortcut=4&query={sear chTerms}
SearchScopes: HKCU - {83CB6700-9424-4FE4-B1F4-F9BC555167F3} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {E6396811-2413-44EC-A69B-A788B0E124FC} URL = hxxp://suche.t-online.de/fastcgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&d ia=suche&context=wiki-tab&tpc=internet&ptl=std&classification=wikitab_internet_std&q={searchTerms}&br=ie7-toi
SearchScopes: HKCU - {F048D832-4CD6-4A55-AAC4-45E3EE19F9B4} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag= interactivemesuche21&index=blended&linkCode=ur2&camp=1638&creative=6742
BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: HKLM-x32 {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: HKLM-x32 {477E2667-7E7A-4737-BFF5-121D68EF7816} hxxp://musikdownloads.aol.de/imcdms-static/code/AOL%20Download%20Assistent.ocx
DPF: HKLM-x32 {74E4A24D-5224-4F05-8A41-99445E0FC22B} hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: HKLM-x32 {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} -  No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.5.0 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-03-21]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-03-07]

Chrome:
=======
CHR DefaultSearchProvider: Default -> 9F43598E6FC84D62FAD3F1C6194BCCCF9B797405CD55613E71E6FE5656259DC3
CHR Profile: C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-09]
CHR Extension: (Google Docs) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-09]
CHR Extension: (Google Drive) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-09]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-09]
CHR Extension: (YouTube) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-09]
CHR Extension: (Google-Suche) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-09]
CHR Extension: (Skype Click to Call) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-09-09]
CHR Extension: (Google Wallet) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-10]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2014-09-09]
CHR Extension: (Google Mail) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-09]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 ABBYY.Licensing.PDFTransformer.Classic.3.0; C:\Program Files (x86)\ABBYY PDF Transformer 3.0\NetworkLicenseServer.exe [759048 2010-02-01] (ABBYY)
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2250360 2014-07-30] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe [2683760 2014-05-20] (G Data Software AG)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [356352 2006-12-28] (AVM Berlin) [File not signed]
S4 Boonty Games; C:\Program Files (x86)\Common Files\BOONTY Shared\Service\Boonty.exe [69120 2009-01-28] (BOONTY) [File not signed]
S4 Browser7Maintenance; C:\Program Files (x86)\Browser 7 Maintenance Service\maintenanceservice.exe [112128 2014-08-26] (Deutsche Telekom AG) [File not signed]
R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [File not signed]
S4 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700536 2014-05-20] (G Data Software AG)
S3 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-06-02] (Hewlett-Packard) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2008-10-16] (Hewlett-Packard Co.) [File not signed]
S2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [135168 2008-03-25] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [69632 2006-11-08] (Hewlett-Packard) [File not signed]
S4 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-12-12] (Nero AG)
S4 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [88064 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Radio.fx; J:\Tobit Radio.fx\Server\rfx-server.exe [3673944 2011-11-18] ()
S4 ServiceLayer; C:\Program Files (x86)\Nokia\PC Connectivity Solution\ServiceLayer.exe [632832 2011-03-21] (Nokia) [File not signed]
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [103936 2013-04-23] (LG Electronics Inc.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2010-07-22] ()
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-08-20] (AVG Technologies)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2006-12-28] (AVM Berlin)
S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [34704 2010-02-05] (CSR, plc)
R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2006-12-28] (AVM GmbH)
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [55808 2014-09-01] (G Data Software AG)
R1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [20992 2014-07-06] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [142336 2014-09-01] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [64000 2014-07-06] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64000 2014-09-01] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-08-31] (G Data Software)
R3 HCW3x64; C:\Windows\System32\DRIVERS\HCW3x64.sys [1087872 2007-03-26] (Hauppauge Computer Works inc.)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [61440 2014-07-06] (G Data Software AG)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2010-07-22] ()
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [166944 2008-06-06] (NVIDIA Corporation)
S3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1368960 2006-09-30] (Philips Semiconductors GmbH)
S3 Ps2; C:\Windows\System32\DRIVERS\PS2.sys [21504 2006-09-07] ()
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2014-08-20] ()
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-09-18] (TuneUp Software)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-11 15:36 - 2014-09-11 15:36 - 00028470 _____ () C:\Users\Ute\Desktop\FRST.txt
2014-09-11 15:35 - 2014-09-11 15:35 - 02105856 _____ (Farbar) C:\Users\Ute\Desktop\FRST64.exe
2014-09-11 12:33 - 2014-08-15 17:48 - 17868288 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 12:33 - 2014-08-15 17:36 - 10920960 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 12:33 - 2014-08-15 17:35 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 12:33 - 2014-08-15 17:31 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 12:33 - 2014-08-15 17:31 - 01384960 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 12:33 - 2014-08-15 17:30 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 12:33 - 2014-08-15 17:30 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-09-11 12:33 - 2014-08-15 17:30 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-11 12:33 - 2014-08-15 17:29 - 02156032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 12:33 - 2014-08-15 17:29 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 12:33 - 2014-08-15 17:29 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 12:33 - 2014-08-15 17:29 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 12:33 - 2014-08-15 17:29 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-09-11 12:33 - 2014-08-15 17:29 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-11 12:33 - 2014-08-15 17:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 12:33 - 2014-08-15 17:29 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 12:33 - 2014-08-15 17:29 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-09-11 12:33 - 2014-08-15 17:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 12:33 - 2014-08-15 17:28 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-11 12:33 - 2014-08-15 17:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-09-11 12:33 - 2014-08-15 17:28 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-09-11 12:33 - 2014-08-15 16:51 - 12363264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 12:33 - 2014-08-15 16:42 - 09739776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 12:33 - 2014-08-15 16:42 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 12:33 - 2014-08-15 16:37 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 12:33 - 2014-08-15 16:37 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 12:33 - 2014-08-15 16:36 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 12:33 - 2014-08-15 16:35 - 01802240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 12:33 - 2014-08-15 16:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-09-11 12:33 - 2014-08-15 16:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 12:33 - 2014-08-15 16:35 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-11 12:33 - 2014-08-15 16:35 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 12:33 - 2014-08-15 16:35 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-09-11 12:33 - 2014-08-15 16:35 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 12:33 - 2014-08-15 16:35 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 12:33 - 2014-08-15 16:35 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 12:33 - 2014-08-15 16:35 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-09-11 12:33 - 2014-08-15 16:34 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 12:33 - 2014-08-15 16:34 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-11 12:33 - 2014-08-15 16:34 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 12:33 - 2014-08-15 16:34 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-09-11 12:33 - 2014-08-15 16:34 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-09-10 13:38 - 2014-09-10 13:38 - 01016261 _____ (Thisisu) C:\Users\Ute\Desktop\JRT.exe
2014-09-09 18:21 - 2014-09-09 18:21 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT (2).exe
2014-09-09 18:08 - 2014-09-09 18:08 - 00000000 ____D () C:\Windows\ERUNT
2014-09-09 18:06 - 2014-09-09 18:06 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT (1).exe
2014-09-09 18:05 - 2014-09-09 18:06 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT.exe
2014-09-09 17:48 - 2014-09-09 17:52 - 00000000 ____D () C:\AdwCleaner
2014-09-09 17:45 - 2014-09-09 17:45 - 01370483 _____ () C:\Users\Ute\Desktop\adwcleaner_3.309.exe
2014-09-09 15:48 - 2014-09-09 15:49 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Ute\Desktop\tdsskiller.exe
2014-09-09 15:44 - 2014-09-09 15:44 - 00000000 ____D () C:\Users\Ute\AppData\Local\Google
2014-09-09 12:52 - 2014-09-09 12:52 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup(3).exe
2014-09-09 12:50 - 2014-09-09 12:50 - 00733168 _____ () C:\Users\Manopost\Downloads\chromesetup(2).exe
2014-09-09 12:44 - 2014-09-09 13:06 - 00001979 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-09 12:44 - 2014-09-09 12:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-09-09 12:43 - 2014-09-11 15:23 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-09 12:43 - 2014-09-11 14:48 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-09 12:43 - 2014-09-09 12:43 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-09-09 12:43 - 2014-09-09 12:43 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-09-09 12:42 - 2014-09-09 12:42 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup(1).exe
2014-09-09 07:02 - 2014-09-09 09:03 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-09-09 06:56 - 2014-09-09 08:20 - 00000000 ____D () C:\Users\Ute\Desktop\mbar
2014-09-09 06:55 - 2014-09-09 06:56 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Ute\Desktop\mbar-1.07.0.1012.exe
2014-09-08 14:59 - 2014-09-08 18:17 - 00000000 ___SD () C:\32788R22FWJFW
2014-09-08 14:59 - 2014-09-08 14:59 - 00000000 ____D () C:\Windows\erdnt
2014-09-08 09:47 - 2014-09-08 09:47 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Adobe
2014-09-08 09:46 - 2014-09-08 11:00 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\TuneUp Software
2014-09-08 09:46 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\TuneUp Software
2014-09-08 09:45 - 2014-09-08 09:45 - 00000951 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\AOL
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Local\AOL
2014-09-08 09:44 - 2014-09-08 09:45 - 00000941 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-08 09:44 - 2014-09-08 09:44 - 00000936 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-09-08 09:42 - 2014-09-08 09:44 - 00000917 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2014-09-08 09:41 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\VirtualStore
2014-09-08 09:41 - 2014-09-08 09:44 - 00000000 ____D () C:\Users\Ute
2014-09-08 09:41 - 2014-09-08 09:41 - 00000020 ___SH () C:\Users\Ute\ntuser.ini
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Vorlagen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Startmenü
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Netzwerkumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Lokale Einstellungen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Eigene Dateien
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Druckumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Musik
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Bilder
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Verlauf
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Anwendungsdaten
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Anwendungsdaten
2014-09-08 09:41 - 2014-04-09 17:34 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Garmin
2014-09-08 09:41 - 2011-11-18 04:55 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Macromedia
2014-09-08 09:41 - 2010-11-16 00:09 - 00000000 ____D () C:\Users\Ute\AppData\Local\Microsoft Help
2014-09-08 09:41 - 2008-01-21 05:20 - 00000000 ___RD () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-09-08 09:41 - 2008-01-21 05:20 - 00000000 ___RD () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-09-08 08:03 - 2014-09-08 08:03 - 00003631 _____ () C:\Users\Manopost\Downloads\FRST.txt
2014-09-08 08:02 - 2014-09-08 08:03 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64(1).exe
2014-09-08 07:44 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-09-08 07:44 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-09-08 07:43 - 2014-09-08 07:43 - 01101648 _____ () C:\Users\Manopost\Downloads\HijackThis - CHIP-Installer.exe
2014-09-07 19:19 - 2014-09-07 19:19 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64.exe
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-07 16:18 - 2014-09-07 16:19 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Manopost\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-07 15:00 - 2014-09-11 15:36 - 00000000 ____D () C:\FRST
2014-09-07 10:24 - 2014-09-07 10:24 - 00388152 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-07 10:23 - 2014-09-11 13:18 - 00658662 _____ () C:\Windows\PFRO.log
2014-09-06 23:41 - 2014-09-06 23:42 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup.exe
2014-09-06 23:24 - 2014-09-06 23:24 - 00106712 _____ () C:\Users\Manopost\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-06 23:24 - 2014-09-06 23:24 - 00002379 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-09-06 23:16 - 2014-09-06 23:57 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Gameo
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\Desktop\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000000 ___HD () C:\Users\Manopost\AppData\Roaming\GoldenGate
2014-09-06 16:11 - 2014-09-06 16:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Deployment
2014-09-01 23:00 - 2014-09-01 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA ANTIVIRUS
2014-08-28 21:52 - 2014-08-23 03:05 - 00304128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-28 21:52 - 2014-08-23 02:42 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 21:52 - 2014-08-23 01:38 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 10:03 - 2014-08-27 10:03 - 00000630 _____ () C:\Users\Manopost\Desktop\BLT14-15_209.exe - Verknüpfung.lnk
2014-08-27 09:52 - 2014-08-27 09:52 - 00724992 _____ (Maximilian Stangel) C:\Users\Manopost\Downloads\BLT14-15_209.exe
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\ProgramData\Avg_Update_0814tb
2014-08-26 18:52 - 2014-08-31 22:03 - 00000000 ___HD () C:\Users\Public\Temp
2014-08-26 18:49 - 2014-08-26 18:50 - 00000000 ____D () C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F
2014-08-26 14:15 - 2013-12-27 16:17 - 37650432 _____ () C:\Users\Manopost\Desktop\M2U00050.MPG
2014-08-26 13:28 - 2014-09-06 23:26 - 00000000 ____D () C:\Users\Manopost\Desktop\Tablet
2014-08-26 13:13 - 2014-08-26 13:13 - 00000000 ____D () C:\ProgramData\Telekom-Browser 7
2014-08-25 17:43 - 2014-09-07 01:20 - 00000000 ___RD () C:\Users\Manopost\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Program Files (x86)\Dropbox
2014-08-25 17:39 - 2014-09-06 22:46 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Dropbox
2014-08-25 07:52 - 2014-08-25 07:52 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Adobe
2014-08-22 15:27 - 2014-08-22 15:27 - 00000000 ____D () C:\ProgramData\Xerox
2014-08-22 14:28 - 2014-09-06 23:32 - 00000000 ____D () C:\Users\Manopost\Desktop\Neuer Ordner
2014-08-22 10:00 - 2014-04-19 17:34 - 00000426 _____ () C:\AVScanner.ini
2014-08-22 09:11 - 2014-08-31 15:59 - 00000000 ____D () C:\Program Files (x86)\videos MediaPlay-Air
2014-08-22 09:10 - 2014-08-22 09:12 - 00062602 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistMSI61B3.txt
2014-08-22 09:10 - 2014-08-22 09:12 - 00012036 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistUI61B3.txt
2014-08-20 14:49 - 2014-08-20 14:49 - 00016152 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-08-20 14:49 - 2014-08-20 14:49 - 00000000 ____D () C:\Users\Manopost\AppData\Local\SlimWare Utilities Inc
2014-08-20 14:48 - 2014-08-20 14:48 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-08-20 14:45 - 2014-08-20 15:13 - 00000732 _____ () C:\Users\Manopost\AppData\Local\d3d9caps64.dat
2014-08-20 14:44 - 2014-08-20 14:44 - 00796720 _____ ( ) C:\Users\Manopost\Downloads\nero_setup.exe
2014-08-17 18:20 - 2014-08-17 18:45 - 00001653 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fotostory 3 für Windows.lnk
2014-08-17 18:20 - 2014-08-17 18:20 - 00000000 ____D () C:\Program Files (x86)\Photo Story 3 for Windows
2014-08-17 18:18 - 2014-08-17 18:18 - 01101648 _____ () C:\Users\Manopost\Documents\Microsoft Photo Story - CHIP-Installer.exe
2014-08-17 13:33 - 2014-08-22 13:21 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo Video 1
2014-08-17 13:26 - 2014-08-22 14:59 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo 2
2014-08-17 11:21 - 2014-08-26 14:04 - 00000000 ____D () C:\Users\Manopost\Desktop\Meine Bilder
2014-08-17 08:49 - 2014-08-17 08:49 - 01058200 _____ (Adobe) C:\Users\Manopost\Downloads\install_flashplayer14x32au_mssa_awc_aih.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 01389200 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 00619664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-17 08:36 - 2014-06-27 00:17 - 00171152 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-17 08:36 - 2014-06-27 00:17 - 00008848 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-17 08:36 - 2014-06-06 06:29 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-17 08:36 - 2014-06-06 06:28 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-17 08:32 - 2014-08-17 08:32 - 00001757 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2014-08-17 08:32 - 2014-08-17 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2014-08-17 00:05 - 2014-08-14 12:15 - 36898446 _____ () C:\Users\Manopost\Desktop\20140814_131447.mp4
2014-08-16 23:56 - 2014-08-20 19:35 - 00000000 ____D () C:\Users\Manopost\Desktop\Handy Tolo
2014-08-16 23:37 - 2014-06-14 02:56 - 00901568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-16 23:37 - 2014-06-14 02:51 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-16 23:37 - 2014-06-02 23:30 - 03137536 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-16 23:37 - 2014-06-02 23:30 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-16 23:37 - 2014-06-02 23:29 - 02280448 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-16 23:37 - 2014-06-02 23:29 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-08-16 23:37 - 2014-06-02 22:29 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-16 23:37 - 2014-06-02 12:31 - 02263552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-16 23:37 - 2014-06-02 12:31 - 00332800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-16 23:37 - 2014-06-02 12:30 - 01993728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-16 23:36 - 2014-07-08 03:12 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-16 23:36 - 2014-07-08 02:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-16 23:06 - 2014-09-06 23:25 - 00000000 ____D () C:\Users\Manopost\Desktop\Kamera Tolo

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-11 15:36 - 2014-09-11 15:36 - 00028470 _____ () C:\Users\Ute\Desktop\FRST.txt
2014-09-11 15:36 - 2014-09-07 15:00 - 00000000 ____D () C:\FRST
2014-09-11 15:35 - 2014-09-11 15:35 - 02105856 _____ (Farbar) C:\Users\Ute\Desktop\FRST64.exe
2014-09-11 15:35 - 2012-07-19 18:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-11 15:27 - 2010-11-02 18:19 - 01283890 _____ () C:\Windows\WindowsUpdate.log
2014-09-11 15:23 - 2014-09-09 12:43 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-11 15:23 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-11 15:23 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-11 15:23 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-11 15:21 - 2006-11-02 17:42 - 00032514 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-11 14:48 - 2014-09-09 12:43 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-11 13:18 - 2014-09-07 10:23 - 00658662 _____ () C:\Windows\PFRO.log
2014-09-11 13:08 - 2009-01-07 16:52 - 00000000 ____D () C:\Users\Manopost
2014-09-11 12:38 - 2010-11-15 00:52 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-11 12:32 - 2010-05-06 16:04 - 01613592 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-11 12:32 - 2008-09-13 07:16 - 00699062 _____ () C:\Windows\system32\perfh007.dat
2014-09-11 12:32 - 2008-09-13 07:16 - 00156416 _____ () C:\Windows\system32\perfc007.dat
2014-09-11 12:32 - 2006-11-02 14:46 - 01613592 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-11 12:31 - 2013-08-15 20:56 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 11:59 - 2006-11-02 14:35 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-09-10 14:35 - 2012-07-19 18:26 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-10 14:35 - 2012-04-08 10:43 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-10 14:35 - 2011-05-14 09:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-10 13:38 - 2014-09-10 13:38 - 01016261 _____ (Thisisu) C:\Users\Ute\Desktop\JRT.exe
2014-09-09 18:21 - 2014-09-09 18:21 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT (2).exe
2014-09-09 18:08 - 2014-09-09 18:08 - 00000000 ____D () C:\Windows\ERUNT
2014-09-09 18:06 - 2014-09-09 18:06 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT (1).exe
2014-09-09 18:06 - 2014-09-09 18:05 - 01016261 _____ (Thisisu) C:\Users\Ute\Downloads\JRT.exe
2014-09-09 17:52 - 2014-09-09 17:48 - 00000000 ____D () C:\AdwCleaner
2014-09-09 17:45 - 2014-09-09 17:45 - 01370483 _____ () C:\Users\Ute\Desktop\adwcleaner_3.309.exe
2014-09-09 15:49 - 2014-09-09 15:48 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Ute\Desktop\tdsskiller.exe
2014-09-09 15:44 - 2014-09-09 15:44 - 00000000 ____D () C:\Users\Ute\AppData\Local\Google
2014-09-09 13:06 - 2014-09-09 12:44 - 00001979 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-09 12:52 - 2014-09-09 12:52 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup(3).exe
2014-09-09 12:50 - 2014-09-09 12:50 - 00733168 _____ () C:\Users\Manopost\Downloads\chromesetup(2).exe
2014-09-09 12:44 - 2014-09-09 12:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-09-09 12:43 - 2014-09-09 12:43 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-09-09 12:43 - 2014-09-09 12:43 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-09-09 12:43 - 2009-01-10 16:50 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-09 12:42 - 2014-09-09 12:42 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup(1).exe
2014-09-09 09:03 - 2014-09-09 07:02 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-09-09 08:20 - 2014-09-09 06:56 - 00000000 ____D () C:\Users\Ute\Desktop\mbar
2014-09-09 07:35 - 2010-04-27 13:26 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-09-09 06:56 - 2014-09-09 06:55 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Ute\Desktop\mbar-1.07.0.1012.exe
2014-09-08 19:58 - 2009-01-08 19:17 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2009
2014-09-08 19:45 - 2014-07-31 19:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-08 18:17 - 2014-09-08 14:59 - 00000000 ___SD () C:\32788R22FWJFW
2014-09-08 14:59 - 2014-09-08 14:59 - 00000000 ____D () C:\Windows\erdnt
2014-09-08 11:00 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\TuneUp Software
2014-09-08 09:47 - 2014-09-08 09:47 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\Adobe
2014-09-08 09:46 - 2014-09-08 09:46 - 00000000 ____D () C:\Users\Ute\AppData\Local\TuneUp Software
2014-09-08 09:46 - 2014-09-08 09:41 - 00000000 ____D () C:\Users\Ute\AppData\Local\VirtualStore
2014-09-08 09:45 - 2014-09-08 09:45 - 00000951 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Roaming\AOL
2014-09-08 09:45 - 2014-09-08 09:45 - 00000000 ____D () C:\Users\Ute\AppData\Local\AOL
2014-09-08 09:45 - 2014-09-08 09:44 - 00000941 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-08 09:44 - 2014-09-08 09:44 - 00000936 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-09-08 09:44 - 2014-09-08 09:42 - 00000917 _____ () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2014-09-08 09:44 - 2014-09-08 09:41 - 00000000 ____D () C:\Users\Ute
2014-09-08 09:41 - 2014-09-08 09:41 - 00000020 ___SH () C:\Users\Ute\ntuser.ini
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Vorlagen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Startmenü
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Netzwerkumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Lokale Einstellungen
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Eigene Dateien
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Druckumgebung
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Musik
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Documents\Eigene Bilder
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Verlauf
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\AppData\Local\Anwendungsdaten
2014-09-08 09:41 - 2014-09-08 09:41 - 00000000 _SHDL () C:\Users\Ute\Anwendungsdaten
2014-09-08 08:03 - 2014-09-08 08:03 - 00003631 _____ () C:\Users\Manopost\Downloads\FRST.txt
2014-09-08 08:03 - 2014-09-08 08:02 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64(1).exe
2014-09-08 07:52 - 2009-02-04 12:45 - 00000069 _____ () C:\Windows\NeroDigital.ini
2014-09-08 07:43 - 2014-09-08 07:43 - 01101648 _____ () C:\Users\Manopost\Downloads\HijackThis - CHIP-Installer.exe
2014-09-08 06:31 - 2013-09-17 15:45 - 00000425 _____ () C:\Windows\BRWMARK.INI
2014-09-07 21:28 - 2011-06-11 10:44 - 00003714 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{7D2327BF-DAC5-43D7-8EB3-6EA0AF4A749D}
2014-09-07 19:19 - 2014-09-07 19:19 - 02105344 _____ (Farbar) C:\Users\Manopost\Downloads\FRST64.exe
2014-09-07 18:29 - 2009-01-28 11:48 - 00000108 _____ () C:\Users\Manopost\AppData\Roaming\default.pls
2014-09-07 16:19 - 2014-09-07 16:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-07 16:19 - 2014-09-07 16:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Manopost\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-07 11:08 - 2010-11-15 00:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-09-07 10:24 - 2014-09-07 10:24 - 00388152 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-07 01:20 - 2014-08-25 17:43 - 00000000 ___RD () C:\Users\Manopost\Dropbox
2014-09-06 23:57 - 2014-09-06 23:16 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Gameo
2014-09-06 23:42 - 2014-09-06 23:41 - 00895120 _____ (Google Inc.) C:\Users\Manopost\Downloads\ChromeSetup.exe
2014-09-06 23:35 - 2013-12-03 13:32 - 00000000 ___RD () C:\Users\Manopost\Documents\Fugen-T-Poster
2014-09-06 23:34 - 2014-01-02 12:23 - 00000000 ____D () C:\Users\Manopost\Desktop\2014
2014-09-06 23:33 - 2014-01-02 15:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Bayrischer Wald
2014-09-06 23:32 - 2014-08-22 14:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Neuer Ordner
2014-09-06 23:27 - 2013-01-21 16:39 - 00000000 ____D () C:\Users\Manopost\Desktop\Bilder1
2014-09-06 23:26 - 2014-08-26 13:28 - 00000000 ____D () C:\Users\Manopost\Desktop\Tablet
2014-09-06 23:25 - 2014-08-16 23:06 - 00000000 ____D () C:\Users\Manopost\Desktop\Kamera Tolo
2014-09-06 23:24 - 2014-09-06 23:24 - 00106712 _____ () C:\Users\Manopost\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-06 23:24 - 2014-09-06 23:24 - 00002379 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\Desktop\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000174 _____ () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
2014-09-06 23:16 - 2014-09-06 23:16 - 00000000 ___HD () C:\Users\Manopost\AppData\Roaming\GoldenGate
2014-09-06 22:51 - 2006-11-02 15:33 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-09-06 22:50 - 2009-01-07 16:56 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-09-06 22:50 - 2006-11-02 17:15 - 00000000 ____D () C:\Windows\WindowsMobile
2014-09-06 22:46 - 2014-08-25 17:39 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Dropbox
2014-09-06 22:41 - 2013-04-11 17:22 - 00000000 ____D () C:\Program Files\Google
2014-09-06 22:40 - 2013-09-17 15:40 - 00000000 ____D () C:\ProgramData\InstallShield
2014-09-06 22:39 - 2013-09-17 15:42 - 00000000 ____D () C:\Program Files (x86)\Brother
2014-09-06 16:12 - 2009-01-10 16:51 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Google
2014-09-06 16:11 - 2014-09-06 16:11 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Deployment
2014-09-06 16:11 - 2010-06-03 12:57 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Apps\2.0
2014-09-06 15:57 - 2009-01-10 16:51 - 00000000 ____D () C:\ProgramData\Google
2014-09-01 23:00 - 2014-09-01 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA ANTIVIRUS
2014-09-01 23:00 - 2014-04-12 12:28 - 00001794 _____ () C:\Users\Public\Desktop\G DATA ANTIVIRUS.lnk
2014-09-01 23:00 - 2009-10-03 14:49 - 00055808 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2014-09-01 23:00 - 2009-06-20 14:57 - 00142336 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2014-09-01 23:00 - 2009-06-20 14:56 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys
2014-08-31 23:00 - 2014-02-28 00:00 - 00018160 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys
2014-08-31 23:00 - 2009-07-28 16:34 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2014-08-31 22:03 - 2014-08-26 18:52 - 00000000 ___HD () C:\Users\Public\Temp
2014-08-31 15:59 - 2014-08-22 09:11 - 00000000 ____D () C:\Program Files (x86)\videos MediaPlay-Air
2014-08-29 15:01 - 2009-01-08 19:24 - 00003784 _____ () C:\Windows\System32\Tasks\HP-Online-Aktualisierungsprogramm
2014-08-29 15:00 - 2014-04-06 16:26 - 00003558 _____ () C:\Windows\System32\Tasks\GarminUpdaterTask
2014-08-27 10:03 - 2014-08-27 10:03 - 00000630 _____ () C:\Users\Manopost\Desktop\BLT14-15_209.exe - Verknüpfung.lnk
2014-08-27 09:52 - 2014-08-27 09:52 - 00724992 _____ (Maximilian Stangel) C:\Users\Manopost\Downloads\BLT14-15_209.exe
2014-08-27 09:33 - 2014-08-27 09:33 - 00000000 ____D () C:\ProgramData\Avg_Update_0814tb
2014-08-27 07:33 - 2014-07-28 19:59 - 00000000 ____D () C:\Program Files (x86)\Browser 7 Maintenance Service
2014-08-26 18:50 - 2014-08-26 18:49 - 00000000 ____D () C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F
2014-08-26 14:04 - 2014-08-17 11:21 - 00000000 ____D () C:\Users\Manopost\Desktop\Meine Bilder
2014-08-26 13:43 - 2009-01-09 17:08 - 00112128 _____ () C:\Users\Manopost\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-08-26 13:13 - 2014-08-26 13:13 - 00000000 ____D () C:\ProgramData\Telekom-Browser 7
2014-08-26 13:13 - 2014-07-28 19:59 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Deutsche Telekom AG
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-25 17:41 - 2014-08-25 17:41 - 00000000 ____D () C:\Program Files (x86)\Dropbox
2014-08-25 07:52 - 2014-08-25 07:52 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Adobe
2014-08-23 03:05 - 2014-08-28 21:52 - 00304128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:42 - 2014-08-28 21:52 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 01:38 - 2014-08-28 21:52 - 02782208 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 15:27 - 2014-08-22 15:27 - 00000000 ____D () C:\ProgramData\Xerox
2014-08-22 14:59 - 2014-08-17 13:26 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo 2
2014-08-22 13:21 - 2014-08-17 13:33 - 00000000 ____D () C:\Users\Manopost\Desktop\Tolo Video 1
2014-08-22 10:20 - 2009-01-28 10:44 - 00000000 ____D () C:\Users\Manopost\AppData\Local\Ahead
2014-08-22 09:57 - 2009-02-02 23:48 - 00000000 __SHD () C:\found.000
2014-08-22 09:36 - 2012-12-16 14:45 - 00000111 _____ () C:\.dir
2014-08-22 09:24 - 2014-01-03 19:18 - 00000008 __RSH () C:\Users\Manopost\ntuser.pol
2014-08-22 09:24 - 2009-11-23 14:04 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-08-22 09:16 - 2006-11-02 15:34 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-08-22 09:12 - 2014-08-22 09:10 - 00062602 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistMSI61B3.txt
2014-08-22 09:12 - 2014-08-22 09:10 - 00012036 _____ () C:\Users\Manopost\AppData\Local\dd_vcredistUI61B3.txt
2014-08-20 19:35 - 2014-08-16 23:56 - 00000000 ____D () C:\Users\Manopost\Desktop\Handy Tolo
2014-08-20 19:28 - 2012-09-05 19:54 - 00050976 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-08-20 17:31 - 2010-08-01 13:11 - 00000000 ____D () C:\Users\Manopost\AppData\Roaming\Skype
2014-08-20 15:13 - 2014-08-20 14:45 - 00000732 _____ () C:\Users\Manopost\AppData\Local\d3d9caps64.dat
2014-08-20 14:49 - 2014-08-20 14:49 - 00016152 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-08-20 14:49 - 2014-08-20 14:49 - 00000000 ____D () C:\Users\Manopost\AppData\Local\SlimWare Utilities Inc
2014-08-20 14:48 - 2014-08-20 14:48 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-08-20 14:44 - 2014-08-20 14:44 - 00796720 _____ ( ) C:\Users\Manopost\Downloads\nero_setup.exe
2014-08-17 18:45 - 2014-08-17 18:20 - 00001653 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fotostory 3 für Windows.lnk
2014-08-17 18:20 - 2014-08-17 18:20 - 00000000 ____D () C:\Program Files (x86)\Photo Story 3 for Windows
2014-08-17 18:18 - 2014-08-17 18:18 - 01101648 _____ () C:\Users\Manopost\Documents\Microsoft Photo Story - CHIP-Installer.exe
2014-08-17 11:36 - 2013-07-04 09:21 - 00000855 _____ () C:\Users\Manopost\Desktop\Bluetooth-Informationsaustausch.lnk
2014-08-17 09:51 - 2006-11-02 15:33 - 00000000 ____D () C:\Windows\rescache
2014-08-17 08:49 - 2014-08-17 08:49 - 01058200 _____ (Adobe) C:\Users\Manopost\Downloads\install_flashplayer14x32au_mssa_awc_aih.exe
2014-08-17 08:33 - 2014-02-19 16:41 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-17 08:32 - 2014-08-17 08:32 - 00001757 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2014-08-17 08:32 - 2014-08-17 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2014-08-17 08:32 - 2014-02-19 16:42 - 00000000 ____D () C:\ProgramData\Garmin
2014-08-17 08:32 - 2014-02-19 16:41 - 00000000 ____D () C:\Program Files (x86)\Garmin
2014-08-15 17:48 - 2014-09-11 12:33 - 17868288 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-15 17:36 - 2014-09-11 12:33 - 10920960 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-15 17:35 - 2014-09-11 12:33 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-15 17:31 - 2014-09-11 12:33 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-15 17:31 - 2014-09-11 12:33 - 01384960 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-15 17:30 - 2014-09-11 12:33 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-15 17:30 - 2014-09-11 12:33 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-15 17:30 - 2014-09-11 12:33 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-15 17:29 - 2014-09-11 12:33 - 02156032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-15 17:29 - 2014-09-11 12:33 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-15 17:29 - 2014-09-11 12:33 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-15 17:29 - 2014-09-11 12:33 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-15 17:29 - 2014-09-11 12:33 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-08-15 17:29 - 2014-09-11 12:33 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-15 17:29 - 2014-09-11 12:33 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-15 17:29 - 2014-09-11 12:33 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-15 17:29 - 2014-09-11 12:33 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-08-15 17:28 - 2014-09-11 12:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-15 17:28 - 2014-09-11 12:33 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-15 17:28 - 2014-09-11 12:33 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-08-15 17:28 - 2014-09-11 12:33 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-08-15 16:51 - 2014-09-11 12:33 - 12363264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-15 16:42 - 2014-09-11 12:33 - 09739776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-15 16:42 - 2014-09-11 12:33 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-15 16:37 - 2014-09-11 12:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-15 16:37 - 2014-09-11 12:33 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-15 16:36 - 2014-09-11 12:33 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-15 16:35 - 2014-09-11 12:33 - 01802240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-15 16:35 - 2014-09-11 12:33 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-08-15 16:35 - 2014-09-11 12:33 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-15 16:35 - 2014-09-11 12:33 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-15 16:35 - 2014-09-11 12:33 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-15 16:35 - 2014-09-11 12:33 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-08-15 16:35 - 2014-09-11 12:33 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-15 16:35 - 2014-09-11 12:33 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-15 16:35 - 2014-09-11 12:33 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-15 16:35 - 2014-09-11 12:33 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-08-15 16:34 - 2014-09-11 12:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-15 16:34 - 2014-09-11 12:33 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-15 16:34 - 2014-09-11 12:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-15 16:34 - 2014-09-11 12:33 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-08-15 16:34 - 2014-09-11 12:33 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-08-14 12:15 - 2014-08-17 00:05 - 36898446 _____ () C:\Users\Manopost\Desktop\20140814_131447.mp4

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-11 15:29

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-09-2014
Ran by Ute at 2014-09-11 15:36:52
Running from C:\Users\Ute\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: G DATA ANTIVIRUS (Disabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0}
AS: G DATA ANTIVIRUS (Disabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
 Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
64 Bit HP CIO Components Installer (Version: 1.0.0 - Hewlett-Packard) Hidden
ABBYY PDF Transformer 3.0 (HKLM-x32\...\ABBYY PDF Transformer 3.0) (Version: 3.00.317.68010 - ABBYY)
ABBYY PDF Transformer 3.0 (Version: 3.00.317.68010 - ABBYY) Hidden
Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0.1 - Microsoft Corporation) Hidden
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader X (10.1.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.8.638 - Adobe Systems, Inc.)
AGEIA PhysX v7.01.12 (HKLM-x32\...\{E2BE1618-AF5F-4F7D-8484-42E080EDF609}) (Version: 7.01.12 - AGEIA Technologies, Inc.)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
AOL Deinstallation (HKLM-x32\...\AOL Deinstallation) (Version:  - )
Apple Application Support (HKLM-x32\...\{3FA365DF-2D68-45ED-8F83-8C8A33E65143}) (Version: 1.1.0 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ATI Catalyst Install Manager (HKLM\...\{9EA8213A-9080-C41F-2F85-8FF98374AB9F}) (Version: 3.0.678.0 - ATI Technologies, Inc.)
AVM FRITZ!Box Dokumentation (HKLM-x32\...\AVMFBox) (Version:  - AVM Berlin)
AVM FRITZ!Box Druckeranschluss (HKLM-x32\...\AVMFBoxPrinter) (Version:  - AVM Berlin)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Big Fish Games Client (HKLM-x32\...\BFGC) (Version: 1.4.0.11 - )
Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v7.00.05 - TOSHIBA CORPORATION)
Browser 7 der Telekom 31.0.19 (x86 de) (HKLM-x32\...\Browser 7 der Telekom 31.0.19 (x86 de)) (Version: 31.0.19 - Deutsche Telekom AG)
Browser 7 Maintenance Service (HKLM-x32\...\Browser7MaintenanceService) (Version: 29.0.40 - Deutsche Telekom AG)
BufferChm (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2008.0514.2139.36863 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization Chinese Standard (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Chinese Traditional (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Czech (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Danish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Dutch (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Finnish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization French (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization German (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Greek (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Hungarian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Italian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Japanese (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Korean (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Norwegian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Polish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Portuguese (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Russian (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Spanish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Swedish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Thai (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Catalyst Control Center Localization Turkish (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Czech (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Danish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Dutch (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help English (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Finnish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help French (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help German (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Greek (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Italian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Japanese (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Korean (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Polish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Russian (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Spanish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Swedish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Thai (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
CCC Help Turkish (x32 Version: 2008.0514.2138.36863 - ATI) Hidden
ccc-core-static (x32 Version: 2008.0514.2139.36863 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2008.0514.2139.36863 - ATI) Hidden
Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Copy (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
Destination Component (x32 Version: 090.000.091.086 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 110.0.180.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
DivX Converter (HKLM-x32\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 7.1.0 - DivX, Inc.)
DivX Plus DirectShow Filters (HKLM-x32\...\DivX Plus DirectShow Filters) (Version:  - DivX, Inc.)
DivX-Setup (HKLM-x32\...\DivX Setup.divx.com) (Version: 2.5.0.8 - DivX, LLC)
Elevated Installer (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Favorit (HKLM-x32\...\koega) (Version:  - )
Fax (x32 Version: 120.0.194.000 - Hewlett-Packard) Hidden
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
G DATA ANTIVIRUS (HKLM-x32\...\{B9FC0A7D-FA1D-4347-ABED-AD8AD5305633}) (Version: 25.0.2.1 - G DATA Software AG)
Garmin Express (HKLM-x32\...\{b43ffffb-1adc-4bcb-b277-7844ebff94da}) (Version: 3.2.17.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
GEAR driver installer for AMD64 and Intel EM64T (HKLM\...\{50CBBEC7-1010-41C5-8718-A1A6FEDD9C3A}) (Version: 2.003.1 - GEAR Software, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.103 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Hewlett-Packard Active Check for Health Check (x32 Version: 1.1.15.2 - Hewlett-Packard) Hidden
Hewlett-Packard Asset Agent for Health Check (x32 Version: 2.0.63.2 - HP) Hidden
HP Active Support Library (x32 Version: 3.1.6.1 - Hewlett-Packard) Hidden
HP Customer Experience Enhancements (HKLM-x32\...\{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}) (Version: 5.6.0.2510 - Hewlett-Packard)
HP Customer Feedback (x32 Version: 1.0.0 - Hewlett-Packard) Hidden
HP Customer Participation Program 9.0 (HKLM\...\HPExtendedCapabilities) (Version: 9.0 - HP)
HP Imaging Device Functions 9.0 (HKLM\...\HP Imaging Device Functions) (Version: 9.0 - HP)
HP Picasso Media Center Add-In (x32 Version: 1.0.0 - HP) Hidden
HP Recovery Manager RSS (x32 Version: 84.0.0.7 - Hewlet Packard Company) Hidden
HP Update (HKLM-x32\...\{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}) (Version: 4.000.010.008 - Hewlett-Packard)
HP_Network_UserGuide (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
HPSSupply (HKLM-x32\...\{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}) (Version: 2.2.0.0000 - Ihr Firmenname)
Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
king.com (remove only) (HKLM-x32\...\king.com) (Version:  - Midasplayer Ltd (king.com))
LG United Mobile Driver (HKLM-x32\...\{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}) (Version: 3.10.1.0 - LG Electronics)
Marco Polo Mobile Navigator 2 (HKLM-x32\...\{5F65ECEE-EB1D-4C85-8D8C-9C7CE2DBB1D6}) (Version:  - )
MarketResearch (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Corporation (Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft Corporation (x32 Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft VC9 runtime libraries (x32 Version: 2.0.0 - AOL Inc.) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Works (HKLM-x32\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation)
MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 24.2.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.2.0 (x86 de)) (Version: 24.2.0 - Mozilla)
MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NAVIGON Fresh 3.5.1 (HKLM-x32\...\NAVIGON Fresh) (Version: 3.5.1 - NAVIGON)
Nero 8 (HKLM-x32\...\{1CA7ACD6-B21B-4240-AA05-4FC55F6E1031}) (Version: 8.3.465 - Nero AG)
neroxml (x32 Version: 1.0.0 - Nero AG) Hidden
NewFreeScreensaver nfsHDWaterfall03 (HKLM-x32\...\nfsHDWaterfall03 New Free Screensaver_is1) (Version:  - )
Nokia Connectivity Cable Driver (HKLM-x32\...\{25CFEF55-A945-41FC-86ED-76469F31DF37}) (Version: 7.1.41.0 - Nokia)
Nokia Music Player (HKLM-x32\...\{4FCB1267-7380-4EBA-9A6C-69809C6E8227}) (Version: 2.5.11021 - Nokia Music Player)
Nokia_Multimedia_Common_Components_2_5 (HKLM-x32\...\{25F61E72-AAA4-4607-95D2-1E5139C98FFB}) (Version: 2.7.69 - Nokia)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Optimierte Multimedia-Tastatur-Lösung (HKLM-x32\...\KBD) (Version:  - Hewlett-Packard)
PanoStandAlone (x32 Version: 90.0.146.000 - Hewlett-Packard) Hidden
PaperPort Image Printer 64-bit (HKLM\...\{ABA4FAF1-6389-45F9-92CE-3914A4E5C471}) (Version: 1.00.0000 - Nuance Communications, Inc.)
PC Connectivity Solution (HKLM-x32\...\{4B28C077-9958-45F1-8BB4-CBF90A69AD4E}) (Version: 11.4.15.0 - Nokia)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 6.5.2926 - CyberLink Corp.)
PowerDirector (x32 Version: 6.5.2926 - CyberLink Corp.) Hidden
Primo (x32 Version: 1.00.0000 - Your Company Name) Hidden
Python 2.5.2 (HKLM-x32\...\{6B976ADF-8AE8-434E-B282-A06C7F624D2F}) (Version: 2.5.2150 - Python Software Foundation)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5657 - Realtek Semiconductor Corp.)
RTC Client API v1.2 (HKLM-x32\...\{44CDBD1B-89FB-4E02-8319-2A4C550F664A}) (Version: 1.2.0000 - Microsoft)
Runtime (x32 Version: 1.00.0000 - Your Company Name) Hidden
SafeFinder Smartbar (HKLM-x32\...\{1898B668-CCF5-429F-A86F-9837E5439D77}) (Version: 11.114.72.19232 - Linkury Ltd.) <==== ATTENTION
Skins (x32 Version: 2008.0514.2139.36863 - ATI) Hidden
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.9.9216 - Skype Technologies S.A.)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Sony USB Driver (HKLM-x32\...\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}) (Version: 2.00 - Sony Corporation)
Spielefieber Patiencen für Vista    (HKLM-x32\...\Spielefieber Patiencen für Vista) (Version:  - KlickMedia)
Status (x32 Version: 110.0.180.000 - Hewlett-Packard) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Top Ten Solitaire (HKLM-x32\...\{51790747-4141-2516-5286-723025870322}) (Version: 1.0 - Bluefish Games)
TrayApp (x32 Version: 110.0.180.000 - Hewlett-Packard) Hidden
TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.340 - TuneUp Software)
TuneUp Utilities 2014 (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.171 - TuneUp Software) Hidden
UnloadSupport (x32 Version: 9.0.0 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2889914) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{F3F83933-75FC-4B60-84F2-3F8FA63D042E}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
VR-NetWorld (HKLM-x32\...\{8815F011-43AF-4F50-BBD8-D78ED3D6F5B9}) (Version:  - )
WDR RadioRecorder (HKLM-x32\...\Tobit Radio.fx Server 1) (Version:  - Tobit.Software)
Windows 7 Upgrade Advisor (HKLM-x32\...\{9A4D182C-35C7-4791-8484-4304EBC9101A}) (Version: 2.0.5000.0 - Microsoft Corporation)
Windows Live Call (x32 Version: 14.0.8064.0206 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 14.0.8098.930 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 14.0.8093.805 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 14.0.8081.709 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 14.0.8091.0730 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live Writer (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0) (HKLM\...\FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D) (Version: 08/22/2008 7.0.0.0 - Nokia)
Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Wondershare MobileTrans ( Version 4.2.0 ) (HKLM-x32\...\{18CDCEAA-A9E4-4A4C-AC0E-C15E87C30EA5}_is1) (Version: 4.2.0 - Wondershare)
Xvid 1.1.2 final uninstall (HKLM-x32\...\Xvid_is1) (Version: 1.1 - Xvid team (Koepi))
Zoo Tycoon: Complete Collection (HKLM-x32\...\Zoo Tycoon 1.0) (Version:  - )
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)
Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 14:34 - 2006-09-18 23:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {00BCCA01-A40B-4CAE-8227-2F62DC9E814B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-09] (Google Inc.)
Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {279F157C-71B0-48BD-869F-5517150C523D} - System32\Tasks\HP Health Check Scheduler => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-02] (Hewlett-Packard)
Task: {28D5FA8E-3458-4145-A83A-4C217971EE93} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2007-03-11] (Hewlett-Packard Co.)
Task: {36094E77-3C21-421B-8EAB-76A357083F9B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10] (Adobe Systems Incorporated)
Task: {376BB1C6-EE4E-4BEC-B4FE-84F31A30F5B1} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {468EF5B9-5FB1-4743-B57F-2607EADD3A6C} - System32\Tasks\HP Health Check => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-02] (Hewlett-Packard)
Task: {4C1210EF-7F37-4352-A913-6973F45DEBA2} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {4F0D940C-AD4F-4AE6-AF83-44F78476290D} - System32\Tasks\ScanSoft Background Update => C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
Task: {50B63E3C-8429-4B61-9671-2F1989927645} - System32\Tasks\Automatische Wartung => C:\Program Files (x86)\TuneUp Utilities 2009\OneClickStarter.exe
Task: {5EE7DBA1-E02B-449D-A55F-76653BBFC245} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated)
Task: {5F5E9998-8B9C-481E-94C4-CA2EB746A438} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {A4B635A8-CB6E-4CC9-A4C2-ED29C5B288AD} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe [2014-08-07] ()
Task: {ADFA917F-CC05-4250-BF79-23261ED49A92} - System32\Tasks\Desktop Messenger => C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Task: {B000A09E-317B-407D-BA22-B7FEDB6F3186} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2014-07-16] (TuneUp Software)
Task: {CDBEB6A4-BC55-4040-88D6-844C74525DBE} - \{4231AEF2-8460-496A-9460-D6D1F6493ADF} No Task File <==== ATTENTION
Task: {DD7781E1-AD7A-437B-8126-4B49A280B14A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-09] (Google Inc.)
Task: {E6C229EB-FEFD-4A53-A5C9-7AE2CDBC5A82} - System32\Tasks\RecoveryCD => C:\Program Files (x86)\Hewlett-Packard\SDP\RemEngine.exe [2008-06-12] ()
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-01-22 19:58 - 2011-11-18 15:51 - 03673944 _____ () J:\Tobit Radio.fx\Server\rfx-server.exe
2014-07-16 10:24 - 2014-07-16 10:24 - 00699704 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll
2008-09-12 21:49 - 2008-05-15 00:04 - 00116736 _____ () C:\Windows\system32\atitmm64.dll
2014-05-20 03:38 - 2014-05-20 03:38 - 00340088 ____N () C:\Program Files (x86)\Common Files\G Data\AVKProxy\PktIcpt2x64.dll
2004-01-09 22:02 - 2004-01-09 22:02 - 00045056 _____ () C:\Program Files (x86)\AOL 9.0 VR\zlib.dll
2002-04-22 23:08 - 2002-04-22 23:08 - 00053248 _____ () C:\Program Files (x86)\AOL 9.0 VR\xmlparse.dll
2002-04-22 23:08 - 2002-04-22 23:08 - 00081920 _____ () C:\Program Files (x86)\AOL 9.0 VR\xmltok.dll
2007-05-24 10:01 - 2007-05-24 10:01 - 00090112 _____ () C:\Program Files (x86)\AOL 9.0 VR\Components\Tier2Svc.dll
2007-05-24 10:01 - 2007-05-24 10:01 - 00061440 _____ () C:\Program Files (x86)\AOL 9.0 VR\Components\DataSvcs.dll
2009-01-07 17:42 - 2007-05-24 04:49 - 00131072 _____ () c:\program files (x86)\common files\aol\1231342872\ee\services\proxyprovider\ver1_0_0_1\proxyprovider.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: KBD => C:\HP\KBD\KbdStub.EXE                                                                                                                                                                                                                                                   
MSCONFIG\startupreg: Wondershare Helper Compact.exe => "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"                                                                                                                                                                               
MSCONFIG\startupreg: WSHelperSetup.exe => "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"                                                                                                                                                                               

==================== Faulty Device Manager Devices =============

Name: isatap.{A615081A-DB1C-42C8-8B6A-0E4FEC46738B}
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: isatap.{1AFC8298-E6C4-448F-A08D-F0585C2E35D5}
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Code:


==================== Event log errors: =========================

Application errors:
==================
Error: (09/11/2014 03:36:54 PM) (Source: VSS) (EventID: 12292) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Erstellen der Schattenkopieanbieter-COM-Klasse mit CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422] ist ein Fehler aufgetreten.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien abfragen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 13
  Snapshotkontext: 13
  Ausführungskontext: Coordinator

Error: (09/11/2014 03:36:54 PM) (Source: VSS) (EventID: 40) (User: )
Description: Volumeschattenkopie-Dienst-Fehler: Der Dienst "Microsoft-Softwareschattenkopie-Anbieter"
(SWPRV) ist deaktiviert. Aktivieren Sie den Dienst, und wiederholen Sie den Vorgang.


Vorgang:
  Für diesen Anbieter eine aufrufbare Schnittstelle abrufen
  Schnittstellen für alle Anbieter auflisten, die diesen Kontext unterstützen
  Schattenkopien abfragen

Kontext:
  Anbieter-ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
  Klassen-ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}
  Snapshotkontext: 13
  Snapshotkontext: 13
  Ausführungskontext: Coordinator

Error: (09/11/2014 03:25:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sidebar.exe, Version 6.0.6002.18005, Zeitstempel 0x49e035b8, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.18508, Zeitstempel 0x4e567628, Ausnahmecode 0xc0000005, Fehleroffset 0x0000000000001149,
Prozess-ID 0xc7c, Anwendungsstartzeit sidebar.exe0.

Error: (09/11/2014 03:25:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sidebar.exe, Version 6.0.6002.18005, Zeitstempel 0x49e035b8, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.18508, Zeitstempel 0x4e567628, Ausnahmecode 0xc0000005, Fehleroffset 0x0000000000001149,
Prozess-ID 0xd28, Anwendungsstartzeit sidebar.exe0.

Error: (09/11/2014 03:24:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/11/2014 01:24:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sidebar.exe, Version 6.0.6002.18005, Zeitstempel 0x49e035b8, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.18508, Zeitstempel 0x4e567628, Ausnahmecode 0xc0000005, Fehleroffset 0x0000000000001149,
Prozess-ID 0x12d0, Anwendungsstartzeit sidebar.exe0.

Error: (09/11/2014 01:23:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sidebar.exe, Version 6.0.6002.18005, Zeitstempel 0x49e035b8, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.18508, Zeitstempel 0x4e567628, Ausnahmecode 0xc0000005, Fehleroffset 0x0000000000001149,
Prozess-ID 0xe44, Anwendungsstartzeit sidebar.exe0.

Error: (09/11/2014 01:19:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/11/2014 00:35:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sidebar.exe, Version 6.0.6002.18005, Zeitstempel 0x49e035b8, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.18508, Zeitstempel 0x4e567628, Ausnahmecode 0xc0000005, Fehleroffset 0x0000000000001149,
Prozess-ID 0x12d4, Anwendungsstartzeit sidebar.exe0.

Error: (09/11/2014 00:35:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sidebar.exe, Version 6.0.6002.18005, Zeitstempel 0x49e035b8, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.18508, Zeitstempel 0x4e567628, Ausnahmecode 0xc0000005, Fehleroffset 0x0000000000001149,
Prozess-ID 0xfc0, Anwendungsstartzeit sidebar.exe0.


System errors:
=============
Error: (09/11/2014 03:25:02 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: HP CUE DeviceDiscovery Service%%2147500037

Error: (09/11/2014 03:25:00 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt

Error: (09/11/2014 03:25:00 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: HP CUE DeviceDiscovery Service

Error: (09/11/2014 03:24:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: vToolbarUpdater18.1.9%%2

Error: (09/11/2014 03:24:26 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Windows-BilderfassungShellhardwareerkennung%%1058

Error: (09/11/2014 01:20:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: HP CUE DeviceDiscovery Service%%2147500037

Error: (09/11/2014 01:20:13 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt

Error: (09/11/2014 01:20:12 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: HP CUE DeviceDiscovery Service

Error: (09/11/2014 01:19:58 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: vToolbarUpdater18.1.9%%2

Error: (09/11/2014 01:19:58 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Windows-BilderfassungShellhardwareerkennung%%1058


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2014-09-10 16:24:56.932
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:24:56.168
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:24:55.388
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:24:54.624
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:22:57.072
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:22:56.339
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:22:55.559
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 16:22:54.779
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 13:37:00.279
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-09-10 13:36:59.727
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Processor: AMD Phenom(tm) 9650 Quad-Core Processor
Percentage of memory in use: 35%
Total physical RAM: 4093.58 MB
Available physical RAM: 2635.82 MB
Total Pagefile: 8389.68 MB
Available Pagefile: 6529.21 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (HP) (Fixed) (Total:582.63 GB) (Free:331.14 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (FACTORY_IMAGE) (Fixed) (Total:13.54 GB) (Free:1.86 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (AVK_09Sep14) (CDROM) (Total:0.19 GB) (Free:0 GB) UDF
Drive j: (HP Pocket Media Drive) (Fixed) (Total:149.04 GB) (Free:126.5 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 596.2 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=582.6 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=13.5 GB) - (Type=07 NTFS)

========================================================
Disk: 5 (MBR Code: Windows XP) (Size: 149.1 GB) (Disk ID: 2BD35C77)
Partition 1: (Not Active) - (Size=149 GB) - (Type=OF Extended)

==================== End Of Log ============================


cosinus 11.09.2014 20:56

Okay, dann Kontrollscans mit MBAM und ESET bitte:

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Snoosel 12.09.2014 07:21

Mist, beim MBAM hängt sich der Rechner immer auf. Es wurden etliche Bedrohungen gefunden, beim speichern auf dem Desktop geht dann gar nichts mehr. Wollte alle Bedrohungen wieder Einspielen um erneut den Suchlauf zu aktivieren doch der Rechner macht nix. Die Resultate sind im Verlauf, können aber nicht gespeichert werden, nur wieder hergestellt oder gelöscht.

Soll ich mit ESET weitermachen?

cosinus 12.09.2014 08:17

Log von MBAM als XML speichern, manchmal stürzt MBAM beim Umwandeln von XML zu TXT nämlich ab

Snoosel 12.09.2014 09:24

Code:

<?xml version="1.0" encoding="UTF-16"?>
-<mbam-log> -<header> <date>2014/09/12 09:55:12 +0200</date> <logfile>mbam-log-2014-09-12 (09-55-10).xml</logfile> <isadmin>yes</isadmin> </header> -<engine> <version>2.00.2.1012</version> <malware-database>v2014.09.12.02</malware-database> <rootkit-database>v2014.09.10.02</rootkit-database> <license>trial</license> <file-protection>enabled</file-protection> <web-protection>enabled</web-protection> <self-protection>disabled</self-protection> </engine> -<system> <osversion>Windows Vista Service Pack 2</osversion> <arch>x64</arch> <username>Ute</username> <filesys>NTFS</filesys> </system> -<summary> <type>threat</type> <result>completed</result> <objects>373379</objects> <time>1387</time> <processes>0</processes> <modules>0</modules> <keys>0</keys> <values>0</values> <datas>0</datas> <folders>1</folders> <files>29</files> <sectors>0</sectors> </summary> -<options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>enabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> -<items> -<folder><path>C:\Program Files (x86)\ver1Re-markit</path><vendor>PUP.Optional.ReMarkIt.A</vendor><action/><hash>34ccfbf1572458def3b9f8ef3ec44db3</hash></folder> -<file><path>C:\Program Files (x86)\ver1Re-markit\e6Re-markite74.dll</path><vendor>PUP.Optional.ReMarkIt.A</vendor><action/><hash>34ccfbf1572458def3b9f8ef3ec44db3</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.admin", false);</baddata><gooddata/><hash>6d9312da5f1cc86e83e433faae578c74</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.aflt", "SD");</baddata><gooddata/><hash>c33d1cd0106b1b1b4d1af439fa0bb050</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");</baddata><gooddata/><hash>4eb237b598e3cb6b2f381a13699c3dc3</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.autoRvrt", "false");</baddata><gooddata/><hash>f808f0fc48338aacb1b6230a2dd812ee</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.dfltLng", "de");</baddata><gooddata/><hash>10f01ad2eb904de9c99e5dd0e61fe917</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.dfltSrch", true);</baddata><gooddata/><hash>d52bdb1153280a2cbbac68c57491b34d</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.dnsErr", true);</baddata><gooddata/><hash>a35d09e37a0150e62e39230ae22353ad</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.excTlbr", false);</baddata><gooddata/><hash>50b059939ae1072f363143ea5baa0ef2</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.ffxUnstlRst", false);</baddata><gooddata/><hash>e51b48a47605cb6b4d1a4de00302d22e</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.hmpg", true);</baddata><gooddata/><hash>9e623ab2df9c37ff6ef91617d92ca060</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00009/tb_v1?SearchSource=13&cc=&mi=7047a004000000000000001a4f9d7b72&toi=16073");</baddata><gooddata/><hash>f01037b52e4d1125214644e9699cfc04</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.hpOld0", "hxxp://www.aol.de/");</baddata><gooddata/><hash>0bf52dbf26550630e6815ecf877ec23e</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.id", "7047a004000000000000001a4f9d7b72");</baddata><gooddata/><hash>3bc59a525d1eff3798cf16171de84fb1</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.instlDay", "16073");</baddata><gooddata/><hash>e51bcf1db2c9f73f88df82abb84d3cc4</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.instlRef", "MOY00009");</baddata><gooddata/><hash>40c08c607a01dc5a580f4de005007e82</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.kw_url", "hxxp://search.softonic.com/MOY00009/tb_v1?SearchSource=2&cc=&mi=7047a004000000000000001a4f9d7b72&toi=16073&q=");</baddata><gooddata/><hash>2cd49953c4b7af8779ee53dadc29827e</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.newTab", true);</baddata><gooddata/><hash>4fb187653d3e3df94126ba73818458a8</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00009/tb_v1/?SearchSource=15&cc=&mi=7047a004000000000000001a4f9d7b72&toi=16073");</baddata><gooddata/><hash>837dfdef166524125b0c8da037ceb64a</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.prdct", "Softonic");</baddata><gooddata/><hash>11ef63898deed363580f5fcee61f0ff1</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.prtnrId", "softonic");</baddata><gooddata/><hash>d7294f9d5922b1854720240962a33ac6</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.rvrt", "false");</baddata><gooddata/><hash>ed139c50c0bbdc5a6700c96408fd51af</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.smplGrp", "none");</baddata><gooddata/><hash>12ee6f7dd2a986b08ed940ed6f9638c8</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");</baddata><gooddata/><hash>e21e6d7fa0dbba7c65022ffe9174b749</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.tlbrId", "2013desingbrand");</baddata><gooddata/><hash>46ba32baa4d73df9b4b39994897caa56</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00009/tb_v1?SearchSource=1&cc=&mi=7047a004000000000000001a4f9d7b72&toi=16073&q=");</baddata><gooddata/><hash>6f9145a7d3a87cbafa6d9d909e676a96</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.vrsn", "1.8.29.3");</baddata><gooddata/><hash>db25af3d7506db5bde893feea36256aa</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.vrsnTs", "1.8.29.318:18:22");</baddata><gooddata/><hash>48b8c527aecd7db9f86f220b37cea060</hash></file> -<file><path>C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action/><baddata>user_pref("extensions.Softonic.vrsni", "1.8.29.3");</baddata><gooddata/><hash>6d93925ae992112551168ca14abb4eb2</hash></file> </items> </mbam-log>


cosinus 12.09.2014 10:49

Junkware-Reste. Diese Junkware kam auch mit kräftiger Mithilfe deinerseits auf den Rechner, da du vermüllte Software von Softonic runtergeladen und installiert ist.

Funde mit MBAM entfernt?

Snoosel 12.09.2014 11:51

in Quarantäne. Soll ich löschen?

Eset Scanner zeigt schon einen Trojaner an. Ist aber noch am suchen, hat erst ein Drittel.

kann ich Softronicmüll irgendwie löschen?

Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=52214efe42a7c0468d2926f2b9b16a93
# engine=20121
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-09-12 09:44:34
# local_time=2014-09-12 11:44:34 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode_1=''
# compatibility_mode=5892 16776573 100 100 82941 248038980 0 0
# scanned=206169
# found=26
# cleaned=0
# scan_time=4176
sh=844949940EDFA51D38C5FA3294892B92C8D3CF8E ft=1 fh=c71c00116efa4a17 vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskTBar\bar\1.bin\A5POPSWT.DLL.vir"
sh=BB975EE11563FEB8F5AE1EA682E97A00D689F4E9 ft=1 fh=e477418542ff9b15 vn="Win32/Toolbar.MyWebSearch evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FunWebProducts\Installr\1.bin\F3PLUGIN.DLL.vir"
sh=A4C84CDB3FF2839E3E634D8872F3FB1E6CC4FCD2 ft=1 fh=98329bfe943c52a7 vn="Variante von Win32/AdWare.AddLyrics.BJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver1Re-markit\Uninstall.exe.vir"
sh=8E85D93BE859D28C3AD8F3F6B4D26E939D54B7F1 ft=1 fh=444194059f223716 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll.vir"
sh=B0312E8AF5F085D4D7C4AC12A6C902CD3ACB799E ft=1 fh=1042727feb7509bb vn="Variante von MSIL/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll.vir"
sh=70511E1DC237B11EB2DA47764E2F58D66884A8D4 ft=1 fh=8926dceffb73a01c vn="Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll.vir"
sh=857CC3345A3822AF53B1929B8A2BBCF72BB1391E ft=1 fh=acc9f12da781c207 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_26.dll.vir"
sh=0414957AE0D2B342AB58CA7C0DEB191EB252F689 ft=1 fh=513fca58ac50a90d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_27.dll.vir"
sh=2A78FC37034AA9C58B1B2D47929D23620D62C657 ft=1 fh=3d7c65ead160cf01 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_28.dll.vir"
sh=D0E111B46081B7F29F5F97BBD27826BE7FF2D100 ft=1 fh=8fb3d533241ad012 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_29.dll.vir"
sh=DA8A32C2FC62802F155C7B8DC2B3DFBB58672098 ft=1 fh=6e51ce951b902f0d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_30.dll.vir"
sh=FA63E2B986E0D6F5312E74B7AFFF49030529B199 ft=1 fh=5eb8c17bce0f839a vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_31.dll.vir"
sh=857CC3345A3822AF53B1929B8A2BBCF72BB1391E ft=1 fh=acc9f12da781c207 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_26.dll"
sh=0414957AE0D2B342AB58CA7C0DEB191EB252F689 ft=1 fh=513fca58ac50a90d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_27.dll"
sh=2A78FC37034AA9C58B1B2D47929D23620D62C657 ft=1 fh=3d7c65ead160cf01 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_28.dll"
sh=D0E111B46081B7F29F5F97BBD27826BE7FF2D100 ft=1 fh=8fb3d533241ad012 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_29.dll"
sh=DA8A32C2FC62802F155C7B8DC2B3DFBB58672098 ft=1 fh=6e51ce951b902f0d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_30.dll"
sh=FA63E2B986E0D6F5312E74B7AFFF49030529B199 ft=1 fh=5eb8c17bce0f839a vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_31.dll"
sh=4073DB60355D23C0B264619DE291A9860E26ED9C ft=1 fh=15dba066dc8bc1b4 vn="Variante von MSIL/DownloadGuide.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\Downloads\chromesetup(2).exe"
sh=771B12AB94CBB0E497C3450804AA6CC4019AC67A ft=1 fh=16d4b30a78ab41fc vn="Variante von Win32/Adware.Trymedia.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\Downloads\JewelQuestSolitaireSetup-dm.exe"
sh=9EA889A4E7B92AB5F2FE85A49F9A4394FF0AAF89 ft=1 fh=f70fea66ab3f997c vn="Variante von Win32/InstallCore.MZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\Downloads\nero_setup.exe"
sh=FD36D8CB741325ADE0CA2D40A0833C565718FA6C ft=1 fh=7ef4a03c64850da1 vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung" ac=I fn="C:\Users\Manopost\Downloads\Shockwave_Installer_Slim (1).exe"
sh=894DFE8FCB1A8E53F1222164B75F89F5E106EEC5 ft=1 fh=cc13cead9c6e9f3a vn="Variante von Win32/Agent.WGA Trojaner" ac=I fn="C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F\plugin_0.0.4.exe"
sh=4B2E8508043C514D6135F7781E5711CB1B6754EA ft=1 fh=232577bd78ab41fc vn="Variante von Win32/Adware.Trymedia.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Public\Downloads\TopTenSolitaireSetup-dm[1].exe"
sh=B5B41E946960F17050C00A4891CFF46B08486A4D ft=1 fh=79895fd74f1827db vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung" ac=I fn="C:\Windows\System32\Adobe\Shockwave 11\gt.exe"
sh=B5B41E946960F17050C00A4891CFF46B08486A4D ft=1 fh=79895fd74f1827db vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung" ac=I fn="C:\Windows\SysWOW64\Adobe\Shockwave 11\gt.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=52214efe42a7c0468d2926f2b9b16a93
# engine=20121
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-09-12 10:42:15
# local_time=2014-09-12 12:42:15 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode_1=''
# compatibility_mode=5892 16776573 100 100 86402 248042441 0 0
# scanned=90390
# found=14
# cleaned=0
# scan_time=3358
sh=844949940EDFA51D38C5FA3294892B92C8D3CF8E ft=1 fh=c71c00116efa4a17 vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskTBar\bar\1.bin\A5POPSWT.DLL.vir"
sh=BB975EE11563FEB8F5AE1EA682E97A00D689F4E9 ft=1 fh=e477418542ff9b15 vn="Win32/Toolbar.MyWebSearch evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FunWebProducts\Installr\1.bin\F3PLUGIN.DLL.vir"
sh=A4C84CDB3FF2839E3E634D8872F3FB1E6CC4FCD2 ft=1 fh=98329bfe943c52a7 vn="Variante von Win32/AdWare.AddLyrics.BJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver1Re-markit\Uninstall.exe.vir"
sh=9DD0F7453F429A74EDA0C5519D70C91AF1EC6AA2 ft=0 fh=0000000000000000 vn="Variante von Win32/Mobogenie.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Mobogenie\Version\NewVersion\Mobogenie2.1.36.zip.vir"
sh=659E678C5D8CE742CC03A211C59AA57E6018FDC6 ft=0 fh=0000000000000000 vn="Variante von Android/Mobserv.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Mobogenie\Version\NewVersion\Mobogenie\MUServer.apk.vir"
sh=8E85D93BE859D28C3AD8F3F6B4D26E939D54B7F1 ft=1 fh=444194059f223716 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll.vir"
sh=B0312E8AF5F085D4D7C4AC12A6C902CD3ACB799E ft=1 fh=1042727feb7509bb vn="Variante von MSIL/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll.vir"
sh=70511E1DC237B11EB2DA47764E2F58D66884A8D4 ft=1 fh=8926dceffb73a01c vn="Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll.vir"
sh=857CC3345A3822AF53B1929B8A2BBCF72BB1391E ft=1 fh=acc9f12da781c207 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_26.dll.vir"
sh=0414957AE0D2B342AB58CA7C0DEB191EB252F689 ft=1 fh=513fca58ac50a90d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_27.dll.vir"
sh=2A78FC37034AA9C58B1B2D47929D23620D62C657 ft=1 fh=3d7c65ead160cf01 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_28.dll.vir"
sh=D0E111B46081B7F29F5F97BBD27826BE7FF2D100 ft=1 fh=8fb3d533241ad012 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_29.dll.vir"
sh=DA8A32C2FC62802F155C7B8DC2B3DFBB58672098 ft=1 fh=6e51ce951b902f0d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_30.dll.vir"
sh=FA63E2B986E0D6F5312E74B7AFFF49030529B199 ft=1 fh=5eb8c17bce0f839a vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_31.dll.vir"

Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=52214efe42a7c0468d2926f2b9b16a93
# engine=20121
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-09-12 09:44:34
# local_time=2014-09-12 11:44:34 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode_1=''
# compatibility_mode=5892 16776573 100 100 82941 248038980 0 0
# scanned=206169
# found=26
# cleaned=0
# scan_time=4176
sh=844949940EDFA51D38C5FA3294892B92C8D3CF8E ft=1 fh=c71c00116efa4a17 vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskTBar\bar\1.bin\A5POPSWT.DLL.vir"
sh=BB975EE11563FEB8F5AE1EA682E97A00D689F4E9 ft=1 fh=e477418542ff9b15 vn="Win32/Toolbar.MyWebSearch evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FunWebProducts\Installr\1.bin\F3PLUGIN.DLL.vir"
sh=A4C84CDB3FF2839E3E634D8872F3FB1E6CC4FCD2 ft=1 fh=98329bfe943c52a7 vn="Variante von Win32/AdWare.AddLyrics.BJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver1Re-markit\Uninstall.exe.vir"
sh=8E85D93BE859D28C3AD8F3F6B4D26E939D54B7F1 ft=1 fh=444194059f223716 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll.vir"
sh=B0312E8AF5F085D4D7C4AC12A6C902CD3ACB799E ft=1 fh=1042727feb7509bb vn="Variante von MSIL/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll.vir"
sh=70511E1DC237B11EB2DA47764E2F58D66884A8D4 ft=1 fh=8926dceffb73a01c vn="Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll.vir"
sh=857CC3345A3822AF53B1929B8A2BBCF72BB1391E ft=1 fh=acc9f12da781c207 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_26.dll.vir"
sh=0414957AE0D2B342AB58CA7C0DEB191EB252F689 ft=1 fh=513fca58ac50a90d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_27.dll.vir"
sh=2A78FC37034AA9C58B1B2D47929D23620D62C657 ft=1 fh=3d7c65ead160cf01 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_28.dll.vir"
sh=D0E111B46081B7F29F5F97BBD27826BE7FF2D100 ft=1 fh=8fb3d533241ad012 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_29.dll.vir"
sh=DA8A32C2FC62802F155C7B8DC2B3DFBB58672098 ft=1 fh=6e51ce951b902f0d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_30.dll.vir"
sh=FA63E2B986E0D6F5312E74B7AFFF49030529B199 ft=1 fh=5eb8c17bce0f839a vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_31.dll.vir"
sh=857CC3345A3822AF53B1929B8A2BBCF72BB1391E ft=1 fh=acc9f12da781c207 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_26.dll"
sh=0414957AE0D2B342AB58CA7C0DEB191EB252F689 ft=1 fh=513fca58ac50a90d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_27.dll"
sh=2A78FC37034AA9C58B1B2D47929D23620D62C657 ft=1 fh=3d7c65ead160cf01 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_28.dll"
sh=D0E111B46081B7F29F5F97BBD27826BE7FF2D100 ft=1 fh=8fb3d533241ad012 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_29.dll"
sh=DA8A32C2FC62802F155C7B8DC2B3DFBB58672098 ft=1 fh=6e51ce951b902f0d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_30.dll"
sh=FA63E2B986E0D6F5312E74B7AFFF49030529B199 ft=1 fh=5eb8c17bce0f839a vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}\components\SmartbarFireFoxRemotePlugin_31.dll"
sh=4073DB60355D23C0B264619DE291A9860E26ED9C ft=1 fh=15dba066dc8bc1b4 vn="Variante von MSIL/DownloadGuide.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\Downloads\chromesetup(2).exe"
sh=771B12AB94CBB0E497C3450804AA6CC4019AC67A ft=1 fh=16d4b30a78ab41fc vn="Variante von Win32/Adware.Trymedia.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\Downloads\JewelQuestSolitaireSetup-dm.exe"
sh=9EA889A4E7B92AB5F2FE85A49F9A4394FF0AAF89 ft=1 fh=f70fea66ab3f997c vn="Variante von Win32/InstallCore.MZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manopost\Downloads\nero_setup.exe"
sh=FD36D8CB741325ADE0CA2D40A0833C565718FA6C ft=1 fh=7ef4a03c64850da1 vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung" ac=I fn="C:\Users\Manopost\Downloads\Shockwave_Installer_Slim (1).exe"
sh=894DFE8FCB1A8E53F1222164B75F89F5E106EEC5 ft=1 fh=cc13cead9c6e9f3a vn="Variante von Win32/Agent.WGA Trojaner" ac=I fn="C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F\plugin_0.0.4.exe"
sh=4B2E8508043C514D6135F7781E5711CB1B6754EA ft=1 fh=232577bd78ab41fc vn="Variante von Win32/Adware.Trymedia.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Public\Downloads\TopTenSolitaireSetup-dm[1].exe"
sh=B5B41E946960F17050C00A4891CFF46B08486A4D ft=1 fh=79895fd74f1827db vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung" ac=I fn="C:\Windows\System32\Adobe\Shockwave 11\gt.exe"
sh=B5B41E946960F17050C00A4891CFF46B08486A4D ft=1 fh=79895fd74f1827db vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung" ac=I fn="C:\Windows\SysWOW64\Adobe\Shockwave 11\gt.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=52214efe42a7c0468d2926f2b9b16a93
# engine=20121
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-09-12 10:42:15
# local_time=2014-09-12 12:42:15 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode_1=''
# compatibility_mode=5892 16776573 100 100 86402 248042441 0 0
# scanned=90390
# found=14
# cleaned=0
# scan_time=3358
sh=844949940EDFA51D38C5FA3294892B92C8D3CF8E ft=1 fh=c71c00116efa4a17 vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\AskTBar\bar\1.bin\A5POPSWT.DLL.vir"
sh=BB975EE11563FEB8F5AE1EA682E97A00D689F4E9 ft=1 fh=e477418542ff9b15 vn="Win32/Toolbar.MyWebSearch evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\FunWebProducts\Installr\1.bin\F3PLUGIN.DLL.vir"
sh=A4C84CDB3FF2839E3E634D8872F3FB1E6CC4FCD2 ft=1 fh=98329bfe943c52a7 vn="Variante von Win32/AdWare.AddLyrics.BJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver1Re-markit\Uninstall.exe.vir"
sh=9DD0F7453F429A74EDA0C5519D70C91AF1EC6AA2 ft=0 fh=0000000000000000 vn="Variante von Win32/Mobogenie.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Mobogenie\Version\NewVersion\Mobogenie2.1.36.zip.vir"
sh=659E678C5D8CE742CC03A211C59AA57E6018FDC6 ft=0 fh=0000000000000000 vn="Variante von Android/Mobserv.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Mobogenie\Version\NewVersion\Mobogenie\MUServer.apk.vir"
sh=8E85D93BE859D28C3AD8F3F6B4D26E939D54B7F1 ft=1 fh=444194059f223716 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll.vir"
sh=B0312E8AF5F085D4D7C4AC12A6C902CD3ACB799E ft=1 fh=1042727feb7509bb vn="Variante von MSIL/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll.vir"
sh=70511E1DC237B11EB2DA47764E2F58D66884A8D4 ft=1 fh=8926dceffb73a01c vn="Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll.vir"
sh=857CC3345A3822AF53B1929B8A2BBCF72BB1391E ft=1 fh=acc9f12da781c207 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_26.dll.vir"
sh=0414957AE0D2B342AB58CA7C0DEB191EB252F689 ft=1 fh=513fca58ac50a90d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_27.dll.vir"
sh=2A78FC37034AA9C58B1B2D47929D23620D62C657 ft=1 fh=3d7c65ead160cf01 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_28.dll.vir"
sh=D0E111B46081B7F29F5F97BBD27826BE7FF2D100 ft=1 fh=8fb3d533241ad012 vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_29.dll.vir"
sh=DA8A32C2FC62802F155C7B8DC2B3DFBB58672098 ft=1 fh=6e51ce951b902f0d vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_30.dll.vir"
sh=FA63E2B986E0D6F5312E74B7AFFF49030529B199 ft=1 fh=5eb8c17bce0f839a vn="Variante von Win32/Toolbar.Linkury.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Manopost\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_31.dll.vir"

toll, ich bekomme immer alles 2x hin.

cosinus 12.09.2014 12:21

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}
C:\Windows\System32\Adobe\Shockwave 11\gt.exe
C:\Users\Manopost\Downloads\*.exe
C:\Users\Public\Downloads\*.exe
C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F
EmptyTemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Snoosel 12.09.2014 13:10

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-09-2014
Ran by Ute at 2014-09-12 14:09:06 Run:3
Running from C:\Users\Ute\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05} C:\Windows\System32\Adobe\Shockwave 11\gt.exe C:\Users\Manopost\Downloads\*.exe C:\Users\Public\Downloads\*.exe C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F EmptyTemp:
*****************

"C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05} C:\Windows\System32\Adobe\Shockwave 11\gt.exe C:\Users\Manopost\Downloads\*.exe C:\Users\Public\Downloads\*.exe C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F EmptyTemp:" => File/Directory not found.

==== End of Fixlog ====


cosinus 12.09.2014 13:29

Du hast den Fix falsch gemacht. Mein Fix ist mehrzeilig und du hast alle Zeilen in eine kopiert. Das geht nicht.

Snoosel 12.09.2014 16:09

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-09-2014
Ran by Ute at 2014-09-12 16:46:57 Run:4
Running from C:\Users\Ute\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05}
C:\Windows\System32\Adobe\Shockwave 11\gt.exe
C:\Users\Manopost\Downloads\*.exe
C:\Users\Public\Downloads\*.exe
C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F
EmptyTemp:
*****************

C:\Users\Manopost\AppData\Roaming\Mozilla\Firefox\Profiles\rjmb4qdq.default\extensions\{dd6584dc-e4dc-64c2-eaa6-c04952c01f05} => Moved successfully.
"C:\Windows\System32\Adobe\Shockwave 11\gt.exe" => File/Directory not found.
C:\Users\Manopost\Downloads\*.exe => Moved successfully.
C:\Users\Public\Downloads\*.exe => Moved successfully.
C:\Users\Public\29B3597AA0BC4491BC3F1A409CD7CF3F => Moved successfully.
EmptyTemp: => Removed 220.4 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====


cosinus 13.09.2014 16:42

Sieht soweit ok aus :daumenhoc

Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Ist aber nur optional. Um Usertracking zu verhindern kann man gut die Firefox-Erweiterung Ghostery verwenden.

Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Snoosel 13.09.2014 16:52

Zitat:

Zitat von cosinus (Beitrag 1358970)
Sieht soweit ok aus :daumenhoc

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Jau alles ok hier :dankeschoen:, Ihr seid einfach spitze. Meinen Obolus habe ich in Spendenform geleistet.:blabla:
Deine Empfehlungen werde ich mir in Ruhe ansehen, ist vielleicht auch besser sich immer neu einzuloggen.

Nochmal Danke
Gruß Ute

cosinus 13.09.2014 16:55

Dann wären wir durch! :daumenhoc


Falls du noch Lob oder Kritik loswerden möchtest => Lob, Kritik und Wünsche - Trojaner-Board

Die Programme, die hier zum Einsatz kamen, können alle deinstalliert werden. Es empfiehlt sich Malwarebytes Anti-Malware zu behalten und damit wöchentlich nach Malware zu scannen.

Helfen kann dir dabei delfix:


Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.






Bitte abschließend noch die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate
Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.
Windows Vista/7: Start, Systemsteuerung, Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks findest du hier => Browsers and Plugins - FilePony.de

Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

Snoosel 13.09.2014 18:14

Zitat:

Zitat von cosinus (Beitrag 1358978)
Dann wären wir durch! :daumenhoc

:taenzer:"froi"
Habe alles gespeichert und setze mich gleich morgen dran.


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:51 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19