FRST:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-02-2015
Ran by Friedrich (administrator) on MACK327 on 25-02-2015 00:12:44
Running from C:\Users\Friedrich\Downloads
Loaded Profiles: Friedrich (Available profiles: Friedrich)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Preventon Technologies Limited) C:\Program Files (x86)\Common Files\Common Toolkit Suite\AVEngine\AVScanningService.exe
(Preventon Technologies Limited) C:\Program Files (x86)\Common Files\Common Toolkit Suite\AVEngine\AVWatchService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(Acer Group) C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Ruiware LLC) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(BonSoft) C:\Program Files (x86)\ClocX\ClocX.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Farbar) C:\Users\Friedrich\Downloads\FRST64(1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-14] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ClocX] => C:\Program Files (x86)\ClocX\ClocX.exe [2090496 2013-01-14] (BonSoft)
HKU\S-1-5-21-3993219044-2753971007-1908284826-1000\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1154112 2014-07-21] (Ruiware LLC)
HKU\S-1-5-21-3993219044-2753971007-1908284826-1000\...\Run: [] => [X]
HKU\S-1-5-21-3993219044-2753971007-1908284826-1000\...\Run: [Microsoft Works Update Detection] => C:\Program Files (x86)\Microsoft Works\WkDetect.exe
HKU\S-1-5-21-3993219044-2753971007-1908284826-1000\...\MountPoints2: {97967562-610d-11e0-99c9-806e6f6e6963} - D:\autorun.exe
HKU\S-1-5-18\...\Run: [Microsoft Works Update Detection] => C:\Program Files (x86)\Microsoft Works\WkDetect.exe
IFEO\bejeweled 2 deluxe-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\build-a-lot 2-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\chuzzle deluxe-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\cnqmmain.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\deathonthenile-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\diner dash 2 restaurant rescue-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\drivegreen1-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\farm-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\fate-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\gameconsole-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\golf-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\insaniquarium-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\jqsolitaire2-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nvstlink.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\nvstview.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\penguins-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\plants vs. zombies-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\polar-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\provider.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\quicktimeplayer.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\racing-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\virtual villagers - the tree of life-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\wordview.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\zuma deluxe-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
IFEO\zumasrevenge-wt.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe"
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:57090;https=127.0.0.1:57090
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-3993219044-2753971007-1908284826-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:tabs
SearchScopes: HKU\S-1-5-21-3993219044-2753971007-1908284826-1000 -> {6FCC6012-E4B7-4DCF-A559-FB107E2F1C64} URL = https://www.google.com/search?q={searchTerms}
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKU\S-1-5-21-3993219044-2753971007-1908284826-1000 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\y83bffm4.default-1415032094794
FF Homepage: hxxp://www.tvinfo.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3993219044-2753971007-1908284826-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Friedrich\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Extension: Download videos and MP3s from YouTube - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\y83bffm4.default-1415032094794\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-11-28]
FF Extension: DownloadHelper - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\y83bffm4.default-1415032094794\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-11-05]
FF Extension: YouTube mp3 - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\y83bffm4.default-1415032094794\Extensions\info@youtube-mp3.org.xpi [2014-11-28]
FF Extension: Tree Style Tab - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\y83bffm4.default-1415032094794\Extensions\treestyletab@piro.sakura.ne.jp.xpi [2015-02-05]
FF Extension: Adblock Plus - C:\Users\Friedrich\AppData\Roaming\Mozilla\Firefox\Profiles\y83bffm4.default-1415032094794\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-05]
FF HKU\S-1-5-21-3993219044-2753971007-1908284826-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-11-28]
Chrome:
=======
CHR Profile: C:\Users\Friedrich\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Wallet) - C:\Users\Friedrich\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-25]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG)
R2 AV Engine Scanning Service; C:\Program Files (x86)\Common Files\Common Toolkit Suite\AVEngine\AVScanningService.exe [1246744 2012-09-17] (Preventon Technologies Limited)
R2 AV Watch Service; C:\Program Files (x86)\Common Files\Common Toolkit Suite\AVEngine\AVWatchService.exe [468064 2012-09-17] (Preventon Technologies Limited)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-14] (Avira Operations GmbH & Co. KG)
S4 Common Toolkit 2; C:\Program Files (x86)\Common Files\Common Toolkit Suite\Tools\x64\CommonToolkit2.exe [338432 2013-04-08] (SPAMfighter ApS) [File not signed]
S4 GameConsoleService; C:\Program Files (x86)\eMachines Games\eMachines Game Console\GameConsoleService.exe [246520 2010-04-04] (WildTangent, Inc.)
S4 GREGService; C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
R2 Updater Service; C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [X]
S3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AVFSFilter; C:\Windows\System32\DRIVERS\avfsfilter.sys [13720 2012-09-17] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-25] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [228768 2012-08-30] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [128456 2012-08-30] (Microsoft Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-09-18] (TuneUp Software)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-25 00:11 - 2015-02-25 00:12 - 02087424 _____ (Farbar) C:\Users\Friedrich\Downloads\FRST64(1).exe
2015-02-24 22:41 - 2015-02-24 22:41 - 00001172 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-24 22:41 - 2015-02-24 22:41 - 00001160 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-24 22:38 - 2015-02-24 22:38 - 00243576 _____ () C:\Users\Friedrich\Downloads\Firefox Setup Stub 36.0.exe
2015-02-24 21:25 - 2015-02-24 21:25 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\SpeedMaxPc
2015-02-24 21:24 - 2015-02-24 21:30 - 00000000 ____D () C:\ProgramData\SpeedMaxPc
2015-02-24 21:24 - 2015-01-09 00:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls
2015-02-24 21:24 - 2015-01-09 00:43 - 00419936 _____ () C:\Windows\system32\locale.nls
2015-02-24 21:22 - 2015-02-24 21:23 - 06340808 _____ (SpeedMaxPc) C:\Users\Friedrich\Downloads\SpeedMaxpc_installer_de.exe
2015-02-24 21:10 - 2015-02-24 21:17 - 00000000 ____D () C:\Program Files (x86)\Dll-Files.com Fixer
2015-02-24 21:10 - 2015-02-24 21:10 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\dll-files.com
2015-02-24 05:08 - 2015-02-24 05:08 - 00000000 _____ () C:\Windows\SysWOW64\sho3953.tmp
2015-02-20 14:29 - 2015-02-25 00:06 - 00000000 ____D () C:\Users\Friedrich\Documents\Fehlermeldungen - VBS
2015-02-20 14:29 - 2015-02-20 14:29 - 00000090 _____ () C:\Users\Friedrich\Documents\Fourth Reich.vbs
2015-02-20 05:54 - 2015-02-20 05:54 - 00000000 _____ () C:\Windows\SysWOW64\shoB1A.tmp
2015-02-18 23:21 - 2015-02-25 00:04 - 00000000 ____D () C:\Program Files (x86)\Arena
2015-02-12 14:53 - 2015-01-23 05:42 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-02-12 14:53 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-12 14:53 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-02-12 14:53 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-02-11 13:02 - 2015-02-04 04:16 - 00894976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-11 13:02 - 2015-02-04 04:16 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-11 13:02 - 2015-02-04 04:16 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-11 13:02 - 2015-02-04 04:16 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-11 13:02 - 2015-02-04 04:16 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-11 13:02 - 2015-02-04 04:16 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-02-11 13:02 - 2015-02-04 04:13 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-11 13:02 - 2015-01-28 00:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-02-11 13:02 - 2015-01-10 07:48 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-02-11 13:02 - 2015-01-10 07:48 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-11 13:02 - 2015-01-10 07:48 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-02-11 13:02 - 2015-01-10 07:48 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-02-11 13:02 - 2015-01-10 07:48 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-02-11 13:02 - 2015-01-10 07:48 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-02-11 13:02 - 2015-01-10 07:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-02-11 13:02 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-02-11 13:02 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-02-11 13:02 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-02-11 13:02 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-02-11 13:02 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-02-11 13:02 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-02-11 13:02 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-02-11 13:01 - 2015-01-14 06:47 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-11 13:01 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-02-11 13:01 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-11 13:01 - 2015-01-12 04:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-11 13:01 - 2015-01-12 04:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 13:01 - 2015-01-12 03:49 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-02-11 13:01 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-11 13:01 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-11 13:01 - 2015-01-12 03:48 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-02-11 13:01 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-11 13:01 - 2015-01-12 03:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-11 13:01 - 2015-01-12 03:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-02-11 13:01 - 2015-01-12 03:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-11 13:01 - 2015-01-12 03:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-11 13:01 - 2015-01-12 03:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-02-11 13:01 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-02-11 13:01 - 2015-01-12 03:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 13:01 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-02-11 13:01 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-11 13:01 - 2015-01-12 03:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 13:01 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-02-11 13:01 - 2015-01-12 03:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-02-11 13:01 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-11 13:01 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-02-11 13:01 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-02-11 13:01 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-02-11 13:01 - 2015-01-12 03:04 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-11 13:01 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-02-11 13:01 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-02-11 13:01 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-02-11 13:01 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-02-11 13:01 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-02-11 13:01 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-11 13:01 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-11 13:01 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-11 13:01 - 2015-01-12 02:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-02-11 13:01 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-02-11 13:01 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-11 13:01 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-02-11 13:01 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-02-11 13:01 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-02-11 13:01 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-02-11 13:01 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-11 13:01 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-02-11 13:01 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-02-11 13:01 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-02-11 13:01 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-02-11 13:01 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-11 13:01 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-11 13:01 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-02-11 13:01 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-02-11 13:01 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-02-11 12:59 - 2015-01-15 09:14 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-11 12:59 - 2015-01-15 09:14 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-11 12:59 - 2015-01-15 09:09 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-11 12:59 - 2015-01-15 09:09 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-02-11 12:59 - 2015-01-15 09:09 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-02-11 12:59 - 2015-01-15 09:09 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-02-11 12:59 - 2015-01-15 09:09 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-02-11 12:59 - 2015-01-15 09:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-02-11 12:59 - 2015-01-15 09:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-11 12:59 - 2015-01-15 09:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-02-11 12:59 - 2015-01-15 09:04 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-11 12:59 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-02-11 12:59 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-02-11 12:59 - 2015-01-15 08:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-02-11 12:59 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-02-11 12:59 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-02-11 12:59 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-02-11 12:59 - 2015-01-15 05:22 - 00458824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-11 12:59 - 2015-01-13 04:10 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-11 12:59 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-02-11 12:59 - 2014-12-12 06:31 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-02-11 12:59 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-02-11 12:59 - 2014-11-26 04:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-11 12:59 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-02-11 12:59 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-02-11 12:59 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-02-11 12:59 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-02-11 12:59 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-02-11 12:58 - 2015-01-14 07:09 - 05554112 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-11 12:58 - 2015-01-14 07:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-02-11 12:58 - 2015-01-14 07:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-02-11 12:58 - 2015-01-14 07:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-02-11 12:58 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-02-11 12:58 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-02-11 12:58 - 2015-01-14 06:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-02-11 12:58 - 2014-12-08 04:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-11 12:58 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2015-02-11 12:57 - 2015-01-09 03:03 - 03201536 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-11 01:50 - 2015-02-11 01:50 - 00000000 _____ () C:\Windows\SysWOW64\sho4BA8.tmp
2015-02-10 19:16 - 2015-02-10 19:16 - 00002160 _____ () C:\Users\Friedrich\.recently-used.xbel
2015-02-09 04:14 - 2015-02-09 04:14 - 00031094 _____ () C:\Users\Friedrich\Downloads\westminster.zip
2015-02-09 04:13 - 2015-02-09 04:13 - 00007112 _____ () C:\Users\Friedrich\Downloads\escheresk.zip
2015-02-09 04:09 - 2015-02-09 04:09 - 00024584 _____ () C:\Users\Friedrich\Downloads\sistemas_font_bt.zip
2015-02-09 04:07 - 2015-02-09 04:07 - 00539573 _____ () C:\Users\Friedrich\Downloads\slinkster.zip
2015-02-09 04:06 - 2015-02-09 04:06 - 00044422 _____ () C:\Users\Friedrich\Downloads\starburst.zip
2015-02-09 04:05 - 2015-02-09 04:05 - 00063950 _____ () C:\Users\Friedrich\Downloads\neon_lights.zip
2015-02-09 04:04 - 2015-02-09 04:04 - 00019555 _____ () C:\Users\Friedrich\Downloads\sf_groove_machine.zip
2015-02-09 04:04 - 2015-02-09 04:04 - 00009674 _____ () C:\Users\Friedrich\Downloads\gunmetal.zip
2015-02-09 04:03 - 2015-02-09 04:03 - 00031272 _____ () C:\Users\Friedrich\Downloads\retro_stereo_wide.zip
2015-02-09 04:02 - 2015-02-09 04:02 - 00015882 _____ () C:\Users\Friedrich\Downloads\blackforest.zip
2015-02-09 04:01 - 2015-02-09 04:01 - 00005120 _____ () C:\Users\Friedrich\Downloads\zimbawee_eye_fs.zip
2015-02-09 04:00 - 2015-02-09 04:00 - 00014361 _____ () C:\Users\Friedrich\Downloads\black_forest.zip
2015-02-09 04:00 - 2015-02-09 04:00 - 00009423 _____ () C:\Users\Friedrich\Downloads\i_have_been_waiting_for_you.zip
2015-02-09 03:59 - 2015-02-09 03:59 - 00017785 _____ () C:\Users\Friedrich\Downloads\valkyrie.zip
2015-02-09 03:57 - 2015-02-09 03:57 - 00005034 _____ () C:\Users\Friedrich\Downloads\h74_federation.zip
2015-02-09 03:56 - 2015-02-09 03:56 - 00012346 _____ () C:\Users\Friedrich\Downloads\scary_glyphs_and_nice_characters.zip
2015-02-09 03:54 - 2015-02-09 03:54 - 00004741 _____ () C:\Users\Friedrich\Downloads\foughtknight.zip
2015-02-09 03:53 - 2015-02-09 03:53 - 00027535 _____ () C:\Users\Friedrich\Downloads\vtks_rude_metal.zip
2015-02-09 03:52 - 2015-02-09 03:52 - 00061841 _____ () C:\Users\Friedrich\Downloads\volk_redis.zip
2015-02-09 03:50 - 2015-02-09 03:50 - 00035624 _____ () C:\Users\Friedrich\Downloads\bienchen.zip
2015-02-09 03:48 - 2015-02-09 03:48 - 00066338 _____ () C:\Users\Friedrich\Downloads\tafelschrift.zip
2015-02-09 03:47 - 2015-02-09 03:47 - 00057348 _____ () C:\Users\Friedrich\Downloads\gruenewald_va.zip
2015-02-09 03:46 - 2015-02-09 03:46 - 00020872 _____ () C:\Users\Friedrich\Downloads\schulschrift95.zip
2015-02-09 03:45 - 2015-02-09 03:45 - 00020531 _____ () C:\Users\Friedrich\Downloads\little_school.zip
2015-02-09 03:44 - 2015-02-09 03:44 - 00023116 _____ () C:\Users\Friedrich\Downloads\little_days(1).zip
2015-02-09 03:44 - 2015-02-09 03:44 - 00023008 _____ () C:\Users\Friedrich\Downloads\little_days.zip
2015-02-09 03:43 - 2015-02-09 03:43 - 00034633 _____ () C:\Users\Friedrich\Downloads\learning_curve_pro.zip
2015-02-09 03:43 - 2015-02-09 03:43 - 00023639 _____ () C:\Users\Friedrich\Downloads\hand_writing_mutlu.zip
2015-02-09 03:43 - 2015-02-09 03:43 - 00008842 _____ () C:\Users\Friedrich\Downloads\elementarz.zip
2015-02-09 03:42 - 2015-02-09 03:42 - 00012836 _____ () C:\Users\Friedrich\Downloads\times_square.zip
2015-02-09 03:39 - 2015-02-09 03:39 - 00080956 _____ () C:\Users\Friedrich\Downloads\jfautumnfair.zip
2015-02-09 03:38 - 2015-02-09 03:38 - 00231262 _____ () C:\Users\Friedrich\Downloads\exotica.zip
2015-02-09 03:36 - 2015-02-09 03:36 - 00172608 _____ () C:\Users\Friedrich\Downloads\al_cinderella.zip
2015-02-09 03:36 - 2015-02-09 03:36 - 00053283 _____ () C:\Users\Friedrich\Downloads\birds_of_paradise.zip
2015-02-09 03:35 - 2015-02-09 03:35 - 00051339 _____ () C:\Users\Friedrich\Downloads\tagettes.zip
2015-02-09 03:34 - 2015-02-09 03:34 - 00048019 _____ () C:\Users\Friedrich\Downloads\respective.zip
2015-02-09 03:34 - 2015-02-09 03:34 - 00031084 _____ () C:\Users\Friedrich\Downloads\distemper.zip
2015-02-09 03:33 - 2015-02-09 03:33 - 00022220 _____ () C:\Users\Friedrich\Downloads\quilline_script.zip
2015-02-09 03:32 - 2015-02-09 03:32 - 00049741 _____ () C:\Users\Friedrich\Downloads\easy_street_eps.zip
2015-02-09 03:32 - 2015-02-09 03:32 - 00021492 _____ () C:\Users\Friedrich\Downloads\halohandletter.zip
2015-02-09 03:31 - 2015-02-09 03:31 - 00033295 _____ () C:\Users\Friedrich\Downloads\ford_script.zip
2015-02-09 03:30 - 2015-02-09 03:30 - 00051810 _____ () C:\Users\Friedrich\Downloads\honey_script.zip
2015-02-09 03:29 - 2015-02-09 03:29 - 00072127 _____ () C:\Users\Friedrich\Downloads\marcelle_script.zip
2015-02-09 03:29 - 2015-02-09 03:29 - 00049274 _____ () C:\Users\Friedrich\Downloads\respective_slanted.zip
2015-02-09 03:28 - 2015-02-09 03:28 - 00043085 _____ () C:\Users\Friedrich\Downloads\sacramento.zip
2015-02-09 03:27 - 2015-02-09 03:27 - 00048007 _____ () C:\Users\Friedrich\Downloads\renaissance.zip
2015-02-09 03:27 - 2015-02-09 03:27 - 00020011 _____ () C:\Users\Friedrich\Downloads\champignon.zip
2015-02-09 03:26 - 2015-02-09 03:26 - 00036286 _____ () C:\Users\Friedrich\Downloads\allegro.zip
2015-02-09 03:26 - 2015-02-09 03:26 - 00028021 _____ () C:\Users\Friedrich\Downloads\rechtman.zip
2015-02-09 03:25 - 2015-02-09 03:25 - 00032002 _____ () C:\Users\Friedrich\Downloads\coca_cola.zip
2015-02-09 03:24 - 2015-02-09 03:24 - 00368783 _____ () C:\Users\Friedrich\Downloads\hawaii_lover.zip
2015-02-09 03:24 - 2015-02-09 03:24 - 00020214 _____ () C:\Users\Friedrich\Downloads\renegade_mistress.zip
2015-02-09 03:23 - 2015-02-09 03:23 - 00090573 _____ () C:\Users\Friedrich\Downloads\display3dotf.zip
2015-02-09 03:23 - 2015-02-09 03:23 - 00008898 _____ () C:\Users\Friedrich\Downloads\tetroserbogia.zip
2015-02-09 03:22 - 2015-02-09 03:22 - 00048820 _____ () C:\Users\Friedrich\Downloads\rose.zip
2015-02-09 03:20 - 2015-02-09 03:20 - 00098574 _____ () C:\Users\Friedrich\Downloads\nina_s_animals.zip
2015-02-09 03:17 - 2015-02-09 03:17 - 00026491 _____ () C:\Users\Friedrich\Downloads\trekbats.zip
2015-02-09 03:16 - 2015-02-09 03:16 - 00055671 _____ () C:\Users\Friedrich\Downloads\air_force.zip
2015-02-09 03:15 - 2015-02-09 03:15 - 00050417 _____ () C:\Users\Friedrich\Downloads\skullbearer_aoe.zip
2015-02-09 03:15 - 2015-02-09 03:15 - 00017834 _____ () C:\Users\Friedrich\Downloads\skipop.zip
2015-02-09 03:09 - 2015-02-09 03:09 - 00015513 _____ () C:\Users\Friedrich\Downloads\capitalis_goreanis.zip
2015-02-09 03:09 - 2015-02-09 03:09 - 00014906 _____ () C:\Users\Friedrich\Downloads\ds_greece.zip
2015-02-09 03:08 - 2015-02-09 03:08 - 00302001 _____ () C:\Users\Friedrich\Downloads\ungraphic.zip
2015-02-09 03:07 - 2015-02-09 03:07 - 00262443 _____ () C:\Users\Friedrich\Downloads\freeserif.zip
2015-02-09 03:06 - 2015-02-09 03:06 - 00010020 _____ () C:\Users\Friedrich\Downloads\sptiberian.zip
2015-02-09 03:05 - 2015-02-09 03:05 - 00052407 _____ () C:\Users\Friedrich\Downloads\hff_chinese_dragon.zip
2015-02-09 03:04 - 2015-02-09 03:04 - 00010586 _____ () C:\Users\Friedrich\Downloads\the_avengers.zip
2015-02-09 03:03 - 2015-02-09 03:03 - 00018262 _____ () C:\Users\Friedrich\Downloads\starwars.zip
2015-02-09 03:03 - 2015-02-09 03:03 - 00014568 _____ () C:\Users\Friedrich\Downloads\harabara.zip
2015-02-09 03:03 - 2015-02-09 03:03 - 00009640 _____ () C:\Users\Friedrich\Downloads\terminator_real_nfi(1).zip
2015-02-09 03:02 - 2015-02-09 03:02 - 00370270 _____ () C:\Users\Friedrich\Downloads\ma.zip
2015-02-09 03:02 - 2015-02-09 03:02 - 00107667 _____ () C:\Users\Friedrich\Downloads\art_nouveau_flowers.zip
2015-02-09 03:02 - 2015-02-09 03:02 - 00003030 _____ () C:\Users\Friedrich\Downloads\braille_regular.zip
2015-02-09 03:01 - 2015-02-09 03:01 - 00033145 _____ () C:\Users\Friedrich\Downloads\diploma.zip
2015-02-09 03:00 - 2015-02-09 03:01 - 00058378 _____ () C:\Users\Friedrich\Downloads\shadowedblack.zip
2015-02-09 03:00 - 2015-02-09 03:00 - 00067518 _____ () C:\Users\Friedrich\Downloads\abbey_dawn_by_thaiavrillavigne.zip
2015-02-09 03:00 - 2015-02-09 03:00 - 00030523 _____ () C:\Users\Friedrich\Downloads\encient_german_gothic.zip
2015-02-09 02:59 - 2015-02-09 02:59 - 00068181 _____ () C:\Users\Friedrich\Downloads\napalm_vertigo.zip
2015-02-09 02:59 - 2015-02-09 02:59 - 00024438 _____ () C:\Users\Friedrich\Downloads\cast_iron.zip
2015-02-09 02:59 - 2015-02-09 02:59 - 00021740 _____ () C:\Users\Friedrich\Downloads\western.zip
2015-02-09 02:58 - 2015-02-09 02:58 - 00214131 _____ () C:\Users\Friedrich\Downloads\outlaw.zip
2015-02-09 02:58 - 2015-02-09 02:58 - 00027816 _____ () C:\Users\Friedrich\Downloads\rio_grande.zip
2015-02-09 02:58 - 2015-02-09 02:58 - 00009640 _____ () C:\Users\Friedrich\Downloads\terminator_real_nfi.zip
2015-02-09 02:58 - 2015-02-09 02:58 - 00008783 _____ () C:\Users\Friedrich\Downloads\transformers.zip
2015-02-09 02:44 - 2015-02-09 02:44 - 00012653 _____ () C:\Users\Friedrich\Downloads\space_age.zip
2015-02-09 02:27 - 2015-02-09 02:27 - 00070915 _____ () C:\Users\Friedrich\Downloads\gunplay.zip
2015-02-09 02:27 - 2015-02-09 02:27 - 00041238 _____ () C:\Users\Friedrich\Downloads\mkstencilsans_black.zip
2015-02-09 02:26 - 2015-02-09 02:26 - 00398537 _____ () C:\Users\Friedrich\Downloads\army.zip
2015-02-08 02:29 - 2015-02-08 02:29 - 00000000 _____ () C:\Windows\SysWOW64\sho9454.tmp
2015-02-07 17:16 - 2015-02-07 17:16 - 00001565 _____ () C:\Users\Friedrich\Desktop\English Grammar in Use.lnk
2015-02-07 17:16 - 2015-02-07 17:16 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cambridge University Press
2015-02-07 17:16 - 2015-02-07 17:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cambridge University Press
2015-02-07 17:14 - 2015-02-07 17:14 - 00000000 ____D () C:\Cambridge
2015-02-07 17:14 - 2000-08-20 21:00 - 01388544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.00A
2015-02-07 17:14 - 2000-04-12 00:00 - 00598288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.006
2015-02-07 17:14 - 1999-06-03 00:00 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.009
2015-02-07 17:14 - 1999-03-08 00:00 - 00164112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.007
2015-02-07 17:14 - 1999-03-08 00:00 - 00147728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.008
2015-02-07 17:14 - 1999-02-08 01:00 - 00326656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.00B
2015-02-07 17:13 - 2004-05-12 09:31 - 00049152 _____ (Blue Sky Software Corporation.) C:\Windows\SysWOW64\Inetwh32.dll
2015-02-07 17:13 - 2004-02-04 14:16 - 00163840 _____ (CLARITY LANGUAGE CONSULTANTS LTD) C:\Windows\SysWOW64\egusound.ocx
2015-02-07 17:13 - 2001-06-14 10:30 - 01044480 _____ (eHelp Corporation.) C:\Windows\SysWOW64\ROBOEX32.DLL
2015-02-07 17:13 - 2000-08-20 21:00 - 01388544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.004
2015-02-07 17:13 - 2000-04-12 00:00 - 00598288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.000
2015-02-07 17:13 - 1999-06-03 00:00 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.003
2015-02-07 17:13 - 1999-03-13 00:00 - 00127488 _____ (Common Controls Replacement Project) C:\Windows\SysWOW64\Ccrpsld.ocx
2015-02-07 17:13 - 1999-03-08 00:00 - 00164112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.001
2015-02-07 17:13 - 1999-03-08 00:00 - 00147728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.002
2015-02-07 17:13 - 1999-02-08 01:00 - 00326656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.005
2015-02-07 17:13 - 1996-11-08 02:48 - 00368912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbar332.dll
2015-02-07 03:56 - 2015-02-07 03:56 - 00003304 ____N () C:\bootsqm.dat
2015-02-06 23:25 - 2015-02-06 23:25 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\{8C3AC684-091E-4B74-BCC0-2EE7175E22AC}
2015-02-04 02:29 - 2015-02-05 17:29 - 00000000 ____D () C:\Program Files\SoftEther VPN Server
2015-01-29 05:08 - 2015-01-29 05:08 - 00000017 _____ () C:\Windows\SysWOW64\shortcut_ex.dat
2015-01-26 16:40 - 2015-02-25 00:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-25 00:14 - 2014-05-28 03:08 - 01099965 _____ () C:\Windows\WindowsUpdate.log
2015-02-25 00:12 - 2014-04-18 18:19 - 00018637 _____ () C:\Users\Friedrich\Downloads\FRST.txt
2015-02-25 00:12 - 2014-04-18 18:18 - 00000000 ____D () C:\FRST
2015-02-25 00:09 - 2009-07-14 05:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-25 00:09 - 2009-07-14 05:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-25 00:08 - 2014-12-21 13:52 - 00143520 _____ () C:\Users\Friedrich\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-25 00:07 - 2014-04-18 02:25 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-25 00:06 - 2014-12-21 13:51 - 00010080 _____ () C:\Windows\setupact.log
2015-02-25 00:06 - 2011-09-21 16:16 - 00000000 ____D () C:\Users\Friedrich
2015-02-25 00:06 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-25 00:05 - 2014-12-11 17:13 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-25 00:05 - 2014-05-06 13:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-25 00:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-02-25 00:04 - 2014-11-14 20:51 - 00000000 ___HD () C:\ProgramData\CanonIJScan
2015-02-25 00:04 - 2012-11-14 23:32 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\Stellarium
2015-02-25 00:04 - 2012-10-15 12:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-25 00:04 - 2012-06-18 21:32 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\gtk-2.0
2015-02-25 00:04 - 2011-11-09 23:53 - 00000000 ____D () C:\ProgramData\clp
2015-02-25 00:04 - 2011-09-25 13:54 - 00000000 ____D () C:\Users\Friedrich\AppData\Roaming\PhotoScape
2015-02-25 00:04 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2015-02-25 00:04 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-02-24 22:55 - 2012-11-10 12:48 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-24 22:36 - 2011-03-28 19:10 - 00699884 _____ () C:\Windows\system32\perfh007.dat
2015-02-24 22:36 - 2011-03-28 19:10 - 00149766 _____ () C:\Windows\system32\perfc007.dat
2015-02-24 22:36 - 2009-07-14 06:13 - 01622300 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-24 22:31 - 2014-12-21 13:51 - 00003102 _____ () C:\Windows\PFRO.log
2015-02-24 21:48 - 2013-10-04 13:30 - 00000000 ___RD () C:\Users\Friedrich\Eigene Bilder
2015-02-24 17:38 - 2014-01-25 17:00 - 00000000 ____D () C:\Windows\Minidump
2015-02-22 05:17 - 2014-11-05 18:24 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\dgswb
2015-02-22 01:55 - 2011-09-23 11:48 - 00000000 ___RD () C:\Users\Friedrich\Eigene Texte
2015-02-19 13:33 - 2014-12-21 13:51 - 00479864 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-18 23:29 - 2011-10-12 18:27 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\CrashDumps
2015-02-12 16:10 - 2011-09-22 14:42 - 00141944 _____ () C:\Users\Friedrich\AppData\Roaming\GDIPFONTCACHEV1.DAT
2015-02-11 13:41 - 2013-08-15 02:14 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-11 13:34 - 2011-09-21 17:29 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-11 01:50 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\schemas
2015-02-11 01:44 - 2014-11-05 02:04 - 00000000 ____D () C:\Users\Friedrich\dwhelper
2015-02-10 19:19 - 2011-09-25 15:00 - 00000000 ____D () C:\Users\Friedrich\.gimp-2.6
2015-02-09 01:58 - 2013-08-07 12:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2015-02-09 01:58 - 2011-09-25 10:23 - 00000000 ____D () C:\Users\Friedrich\AppData\Local\Thunderbird
2015-02-08 01:17 - 2014-11-14 21:07 - 00000000 ____D () C:\Users\Friedrich\Eigene PDF
2015-02-06 22:01 - 2011-09-21 17:37 - 01595644 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-02-06 17:11 - 2012-05-25 19:33 - 00000000 ____D () C:\Users\Friedrich\Fremde PDF
2015-02-05 19:55 - 2012-11-10 12:48 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-05 19:55 - 2012-05-08 09:08 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-05 19:55 - 2011-09-28 18:16 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-05 04:36 - 2013-11-30 18:42 - 00000000 ____D () C:\Users\Friedrich\.thumbnails
2015-01-28 18:00 - 2013-10-28 19:12 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-28 18:00 - 2013-07-01 12:18 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-28 17:59 - 2014-10-17 15:30 - 00272296 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2015-01-28 17:59 - 2014-10-17 15:29 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2015-01-28 17:59 - 2014-10-17 15:29 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2015-01-28 17:59 - 2014-10-17 15:29 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-28 17:59 - 2013-10-28 19:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
==================== Files in the root of some directories =======
2015-02-24 21:25 - 2015-02-24 21:25 - 0000053 _____ () C:\Users\Friedrich\AppData\Roaming\LogFile.txt
2012-11-06 22:43 - 2013-05-19 17:22 - 0000078 _____ () C:\Users\Friedrich\AppData\Roaming\mbam.context.scan
2014-01-08 00:05 - 2014-10-21 23:05 - 0000093 _____ () C:\Users\Friedrich\AppData\Roaming\WB.CFG
2011-10-12 18:27 - 2013-07-04 21:32 - 0047616 _____ () C:\Users\Friedrich\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-11-05 18:25 - 2014-11-05 18:25 - 0000290 _____ () C:\ProgramData\wb764821reg.bin
Some content of TEMP:
====================
C:\Users\Friedrich\AppData\Local\Temp\avgnt.exe
C:\Users\Friedrich\AppData\Local\Temp\efficient-diary.exe
C:\Users\Friedrich\AppData\Local\Temp\FreeVideoToMP3Converter.exe
C:\Users\Friedrich\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Friedrich\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Friedrich\AppData\Local\Temp\SIntf16.dll
C:\Users\Friedrich\AppData\Local\Temp\SIntf32.dll
C:\Users\Friedrich\AppData\Local\Temp\SIntfNT.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-15 01:57
==================== End Of Log ============================
--- --- ---
Addition:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-04-2014 01
Ran by Friedrich at 2014-04-18 19:20:12
Running from C:\Users\Friedrich\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.03) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.95 - WildTangent) Hidden
Agent Ransack 2010 (64-bit) (HKLM\...\Agent Ransack (64-bit)_is1) (Version: - )
Amazon MP3-Downloader 1.0.17 (HKLM-x32\...\Amazon MP3-Downloader) (Version: 1.0.17 - Amazon Services LLC)
Amazon MP3-Downloader 1.0.18 (HKCU\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC)
Apple Application Support (HKLM-x32\...\{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}) (Version: 2.1.7 - Apple Inc.)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Build-a-lot 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.00 - Piriform)
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
DRIVERfighter (x32 Version: 1.1.31 - SPAMfighter ApS) Hidden
Efficient Diary 3.0 (HKLM-x32\...\Efficient Diary_is1) (Version: - Efficient Software)
eMachines Game Console (x32 Version: - WildTangent) Hidden
eMachines Games (HKLM-x32\...\WildTangent emachines Master Uninstall) (Version: 1.0.1.3 - WildTangent)
eMachines Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Acer Incorporated)
eMachines Registration (HKLM-x32\...\eMachines Registration) (Version: 1.03.3003 - Acer Incorporated)
eMachines ScreenSaver (HKLM-x32\...\eMachines Screensaver) (Version: 1.1.0825.2010 - Acer Incorporated)
eMachines Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3001 - Acer Incorporated)
Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden
FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden
Fighters (x32 Version: 4.1.265 - SPAMFIGHTER ApS) Hidden
Final Drive Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
Free Studio version 5.5.0 (HKLM-x32\...\Free Studio_is1) (Version: 5.5.0 - DVDVideoSoft Ltd.)
Free YouTube Download version 3.1.39.1015 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.1.39.1015 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.11.26.706 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.26.706 - DVDVideoSoft Ltd.)
FULL-DISKfighter (x32 Version: 1.4.28 - SPAMfighter ApS.) Hidden
GIMP 2.6.8 (HKLM\...\WinGimp-2.0_is1) (Version: - )
Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3009 - Acer Incorporated)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
Insaniquarium Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Internet-TV für Windows Media Center (HKLM-x32\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 4.2.2.0 - Microsoft Corporation)
Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 29 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216022FF}) (Version: 6.0.290 - Oracle)
Java(TM) 6 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle)
Jewel Quest Solitaire 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Lernen durch Wiederholung 6.2.3 (HKLM-x32\...\Lernen durch Wiederholung_is1) (Version: - ©Matthias Kraus)
Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
map&guide base (HKLM-x32\...\{8BECCB29-DA5E-4002-B211-C3A148E48D63}) (Version: 1.05.00000 - MAP&GUIDE GmbH)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft AutoRoute 2002 (HKLM-x32\...\{F7F2DC0A-C22E-49AD-AD37-797309A54E7B}) (Version: 9.00.17.0200 - Microsoft)
Microsoft Encarta Enzyklopädie 2002 (HKLM-x32\...\{01008202-823E-46CD-A70E-BEE818F97169}) (Version: 2002 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Picture It! Foto 2002 (HKLM-x32\...\{C769A271-7E1C-48F9-B331-474600DD4C06}) (Version: 6.0.0.0000 - Microsoft)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Word 2002 (HKLM-x32\...\{911B0407-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Works 2002-Setup-Start (HKLM-x32\...\Works2002Setup) (Version: - )
Microsoft Works 6.0 (HKLM-x32\...\{ED5EDCD0-5745-4B13-8061-58C9833FD06D}) (Version: 06.00.0000 - Microsoft Corporation)
Microsoft Works Suite-Add-Ins für Microsoft Word (HKLM-x32\...\{25F60491-F5AB-4985-9354-37C146783F35}) (Version: 2.0.0.0000 - Microsoft Corporation)
Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1 - Nokia) Hidden
Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1 - Nokia) Hidden
Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
Mozilla Thunderbird 17.0.8 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 17.0.8 (x86 de)) (Version: 17.0.8 - Mozilla)
MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden
MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 9 Essentials (HKLM-x32\...\{19d74c6e-c6f0-493a-832f-03edf5aad5b8}) (Version: - Nero AG)
Nero ControlCenter (x32 Version: 9.0.0.1 - Nero AG) Hidden
Nero DiscSpeed (x32 Version: 5.4.13.100 - Nero AG) Hidden
Nero DiscSpeed Help (x32 Version: 5.4.4.100 - Nero AG) Hidden
Nero DriveSpeed (x32 Version: 4.4.12.100 - Nero AG) Hidden
Nero DriveSpeed Help (x32 Version: 4.4.4.100 - Nero AG) Hidden
Nero Express Help (x32 Version: 9.4.37.100 - Nero AG) Hidden
Nero InfoTool (x32 Version: 6.4.12.100 - Nero AG) Hidden
Nero InfoTool Help (x32 Version: 6.4.4.100 - Nero AG) Hidden
Nero Installer (x32 Version: 4.4.9.0 - Nero AG) Hidden
Nero Online Upgrade (x32 Version: 1.3.0.0 - Nero AG) Hidden
Nero StartSmart (x32 Version: 9.4.37.100 - Nero AG) Hidden
Nero StartSmart Help (x32 Version: 9.4.27.100 - Nero AG) Hidden
Nero StartSmart OEM (x32 Version: 9.15.0.100 - Nero AG) Hidden
NeroExpress (x32 Version: 9.4.37.100 - Nero AG) Hidden
neroxml (x32 Version: 1.0.0 - Nero AG) Hidden
Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia)
Nokia Suite (HKLM-x32\...\Nokia Suite) (Version: 3.8.30.0 - Nokia)
Nokia Suite (x32 Version: 3.8.30.0 - Nokia) Hidden
NVIDIA Grafiktreiber 266.84 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 266.84 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.109.718 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.10.0514 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.10.0514 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.10.0514 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (HKLM-x32\...\NVIDIAStereo) (Version: 7.17.12.6684 - NVIDIA Corporation)
NVIDIA Systemsteuerung 266.84 (Version: 266.84 - NVIDIA Corporation) Hidden
OpenOffice.org 3.3 (HKLM-x32\...\{4286716B-1287-48E7-9078-3DC8248DBA96}) (Version: 3.3.9567 - OpenOffice.org)
Opera 12.15 (HKLM-x32\...\Opera 12.15.1748) (Version: 12.15.1748 - Opera Software ASA)
PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
PhotoScape (HKLM-x32\...\PhotoScape) (Version: - )
Plants vs. Zombies (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.)
Shockwave (HKLM-x32\...\Shockwave) (Version: - )
Sonnensystem 3.0 (HKLM-x32\...\{44104223-5CFF-4ADE-AF33-584CF83FA1B8}) (Version: 1.0.0 - Standardfirmenname)
SpywareBlaster 5.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC)
Stellarium 0.11.4 (HKLM\...\Stellarium_is1) (Version: 0.11.4 - Stellarium team)
Teachmaster 4.3 (nur Entfernen) (HKLM-x32\...\Teachmaster 4.3) (Version: - )
TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.275 - TuneUp Software) Hidden
TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.275 - TuneUp Software)
TuneUp Utilities 2014 (x32 Version: 14.0.1000.275 - TuneUp Software) Hidden
Update_for_BonanzaDeals (HKCU\...\Bonanza) (Version: - Update_for_BonanzaDeals) <==== ATTENTION
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95 - WildTangent) Hidden
VIS (HKLM-x32\...\VIS) (Version: - ) <==== ATTENTION
VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN)
Welcome Center (HKLM-x32\...\eMachines Welcome Center) (Version: 1.02.3005 - Acer Incorporated)
Windows Installer Clean Up (HKLM-x32\...\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}) (Version: 3.00.00.0000 - Microsoft Corporation)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Media Center Add-in for Silverlight (HKLM-x32\...\{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}) (Version: 4.7.3.0 - Microsoft Corporation)
Windows-Treiberpaket - Intel hdc (10/05/2012 9.1.9.1002) (HKLM\...\29B76F9C91EE9BA9A63E88D9F0000E010363DCB5) (Version: 10/05/2012 9.1.9.1002 - Intel)
Windows-Treiberpaket - Intel System (10/05/2012 9.1.9.1002) (HKLM\...\5E9040CBF06133134873F64C0D152BEBA5F98677) (Version: 10/05/2012 9.1.9.1002 - Intel)
Windows-Treiberpaket - Intel System (10/05/2012 9.1.9.1002) (HKLM\...\6C352BEA80A0DBEB6FCE6F10DEDB382409B6E4CF) (Version: 10/05/2012 9.1.9.1002 - Intel)
Windows-Treiberpaket - Intel USB (10/05/2012 9.1.9.1002) (HKLM\...\62461C94E7F67025AC113795AF5428E1B73EA068) (Version: 10/05/2012 9.1.9.1002 - Intel)
Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Windows-Treiberpaket - NVIDIA Corporation (NVHDA) MEDIA (12/18/2012 1.3.23.1) (HKLM\...\53E1594B2022B94BADE3466EE5459687E18D582E) (Version: 12/18/2012 1.3.23.1 - NVIDIA Corporation)
Windows-Treiberpaket - Realtek (RTL8167) Net (12/26/2012 7.067.1226.2012) (HKLM\...\85BB2284011D96871518CFA7B57630FE47BEA2B4) (Version: 12/26/2012 7.067.1226.2012 - Realtek)
Windows-Treiberpaket - Realtek Semiconductor Corp. HD Audio Driver (06/19/2012 6.0.1.6662) (HKLM\...\4A5EF81C80190F479C6FB16BC8CF595275AAC778) (Version: 06/19/2012 6.0.1.6662 - Realtek Semiconductor Corp.)
Works Suite-Betriebssystem-Pack (x32 Version: 1.0.0.0000 - Microsoft Corporation) Hidden
Works-Synchronisierung (x32 Version: 1.0.0.0000 - Firmenname) Hidden
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Zuma's Revenge (x32 Version: 2.2.0.95 - WildTangent) Hidden
==================== Restore Points =========================
15-04-2014 02:34:37 Windows Update
18-04-2014 01:10:41 Wiederherstellungsvorgang
18-04-2014 01:21:42 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0CE1FA3A-A6A8-4465-9A39-CA6B135407EF} - System32\Tasks\Works Update Find => C:\Program Files (x86)\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [2001-10-04] (Microsoft® Corporation)
Task: {10E0C014-034C-4949-9061-0E56F6F9A85E} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {222D648C-17E5-4407-A70A-886BDF6946DE} - System32\Tasks\{F68F6828-01AF-41FF-AA08-8B6B93DB25B3} => Firefox.exe
Task: {2DDAF7C7-3832-4581-B931-412F6EDEAC3F} - System32\Tasks\{1271A5A0-75B0-483B-8AD1-39947713A666} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-08-07] (Mozilla Corporation)
Task: {30D9DFA6-1A63-4D63-A1D6-60EA5511F124} - System32\Tasks\Bonanza => C:\Users\Friedrich\AppData\Roaming\Bonanza\UpdateProc\UpdateTask.exe [2013-04-30] () <==== ATTENTION
Task: {35163004-3616-46A1-BCC6-7978278A20C8} - System32\Tasks\{C8706F56-E750-4BAF-899E-81231C1758EF} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-08-07] (Mozilla Corporation)
Task: {46E6A429-0F35-43E6-B847-C2342C12BDE0} - System32\Tasks\{000C7954-D2C1-4C99-B852-AE2778220F87} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-08-07] (Mozilla Corporation)
Task: {5AD13413-C681-424E-B81F-04A64AC24C8A} - System32\Tasks\{02E8F160-9E00-43CF-90E6-A0134BDCFB26} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-08-07] (Mozilla Corporation)
Task: {5FE11406-462A-48D3-B2EA-82326B38684D} - System32\Tasks\{E7CBE3C0-0922-4D3A-B048-1F267137476D} => Firefox.exe
Task: {6411C364-7165-4194-8090-C10B4318A12C} - System32\Tasks\{C6E01112-7AA7-457A-8F52-4D1FD33771F7} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-08-07] (Mozilla Corporation)
Task: {71414F16-5607-4060-BE9E-5C4063852EED} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated)
Task: {756AF612-BA9D-4313-BACA-6187BC787B39} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated)
Task: {82B45D92-0A35-4540-B186-2EEBF19AC08D} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2014-03-20] (TuneUp Software)
Task: {9C40CB84-0919-442B-8496-346E127C5808} - System32\Tasks\{BCDFC23F-C327-40F0-8FCE-A3795C9CF42F} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-08-07] (Mozilla Corporation)
Task: {9DDFF567-DFE6-4E1C-A656-6B99F81B6005} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {A0933171-C5B6-4534-8EC7-2108A966E05E} - System32\Tasks\{A1607798-32C2-433E-A44B-F36BBA68A77C} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-08-07] (Mozilla Corporation)
Task: {A25ABDA7-5A55-49C3-833B-40969ED51735} - System32\Tasks\{EFD8CBAE-B54F-4872-870F-96CEB3D37E5A} => Firefox.exe
Task: {A917DEA8-1BC7-48A1-A848-E38A83F68443} - System32\Tasks\{05D09816-6C61-4C18-B9D0-E1D45D4F4E9B} => Firefox.exe
Task: {BF7FDDFB-F791-43E7-A842-98835B0C5E87} - System32\Tasks\{95D1313C-B743-4D4E-87E8-6BDC6D289719} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-08-07] (Mozilla Corporation)
Task: {C6BE140C-5021-4648-A8BD-548540598BFE} - System32\Tasks\Works Update Detect => C:\Program Files (x86)\Microsoft Works\WkDetect.exe
Task: {D534C6CD-A653-402E-B54A-0CABC8F7EEF4} - System32\Tasks\{BABE475E-9A80-4E1C-BA91-2D026A5776B4} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-08-07] (Mozilla Corporation)
Task: {D6B4E7DD-157E-4E06-B289-8CFF5188E564} - System32\Tasks\Update Bonanza => C:\Users\Friedrich\AppData\Roaming\UpdateBonanza\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {D82610B3-D9D7-4C2A-8822-D62C963083AB} - System32\Tasks\{EB35C9A5-4AEA-47A8-8DAC-AC0471A74024} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2013-08-07] (Mozilla Corporation)
Task: {E971C3CD-B88E-408C-BBB4-A898B7F4A5E5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-03-25] (Piriform Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Bonanza.job => C:\Users\FRIEDR~1\AppData\Roaming\Bonanza\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\Update Bonanza.job => C:\Users\FRIEDR~1\AppData\Roaming\UPDATE~2\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
==================== Loaded Modules (whitelisted) =============
2014-03-20 15:44 - 2014-03-20 15:44 - 00675640 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll
2013-05-29 21:56 - 2013-05-29 21:38 - 00397704 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 08507232 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtGui4.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 02354016 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtCore4.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 01014624 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtNetwork4.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 00364384 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtXml4.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 02480992 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtDeclarative4.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 01346912 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtScript4.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 00206176 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtSql4.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 02653024 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtXmlPatterns4.dll
2013-04-19 01:45 - 2013-04-19 01:45 - 00033120 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\imageformats\qgif4.dll
2013-04-19 01:45 - 2013-04-19 01:45 - 00035680 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\imageformats\qico4.dll
2013-04-19 01:45 - 2013-04-19 01:45 - 00207200 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\imageformats\qjpeg4.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 11166560 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtWebKit4.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 00276832 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\phonon4.dll
2013-04-15 13:26 - 2013-04-15 13:26 - 00391600 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\ssoengine.dll
2013-04-15 13:26 - 2013-04-15 13:26 - 00059280 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\securestorage.dll
2013-04-19 01:45 - 2013-04-19 01:45 - 00438624 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\NService.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 00446304 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 00520544 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtMultimediaKit1.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 00720736 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtOpenGL4.dll
2013-04-19 01:44 - 2013-04-19 01:44 - 00606560 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\CommonUpdateChecker.dll
2013-04-19 01:46 - 2013-04-19 01:46 - 00093024 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\qjson.dll
2013-12-15 16:31 - 2013-08-07 13:10 - 02244504 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2013-12-15 16:31 - 2013-08-07 13:10 - 00158104 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2013-12-15 16:31 - 2013-08-07 13:10 - 00022424 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2014-03-20 15:00 - 2014-03-20 15:00 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2011-01-26 17:48 - 2011-01-26 17:48 - 00237160 _____ () C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
2014-03-12 02:55 - 2014-03-12 02:55 - 16276872 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34
AlternateDataStreams: C:\ProgramData\TEMP:CB0AACC9
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/18/2014 07:16:24 PM) (Source: Windows Search Service) (User: )
Description: Der Filterhostprozess kann nicht initialisiert werden. Der Vorgang wird abgebrochen.
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 07:12:14 PM) (Source: Windows Search Service) (User: )
Description: Der Filterhostprozess kann nicht initialisiert werden. Der Vorgang wird abgebrochen.
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 07:08:03 PM) (Source: Windows Search Service) (User: )
Description: Der Filterhostprozess kann nicht initialisiert werden. Der Vorgang wird abgebrochen.
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 07:04:02 PM) (Source: Windows Search Service) (User: )
Description: Der Filterhostprozess kann nicht initialisiert werden. Der Vorgang wird abgebrochen.
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 07:00:00 PM) (Source: Windows Search Service) (User: )
Description: Der Filterhostprozess kann nicht initialisiert werden. Der Vorgang wird abgebrochen.
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 06:55:49 PM) (Source: Windows Search Service) (User: )
Description: Der Filterhostprozess kann nicht initialisiert werden. Der Vorgang wird abgebrochen.
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 06:51:38 PM) (Source: Windows Search Service) (User: )
Description: Der Filterhostprozess kann nicht initialisiert werden. Der Vorgang wird abgebrochen.
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 06:47:37 PM) (Source: Windows Search Service) (User: )
Description: Der Filterhostprozess kann nicht initialisiert werden. Der Vorgang wird abgebrochen.
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 06:43:35 PM) (Source: Windows Search Service) (User: )
Description: Der Filterhostprozess kann nicht initialisiert werden. Der Vorgang wird abgebrochen.
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 06:39:33 PM) (Source: Windows Search Service) (User: )
Description: Der Filterhostprozess kann nicht initialisiert werden. Der Vorgang wird abgebrochen.
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
System errors:
=============
Error: (04/18/2014 03:01:20 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Microsoft Antimalware Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/18/2014 03:38:29 AM) (Source: Service Control Manager) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler:
%%1056
Error: (04/18/2014 03:37:59 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (04/18/2014 03:37:56 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535.
Error: (04/18/2014 03:36:38 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Microsoft Antimalware Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/18/2014 03:36:38 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 18.04.2014 um 03:36:00 unerwartet heruntergefahren.
Error: (04/18/2014 03:35:55 AM) (Source: DCOM) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Error: (04/18/2014 03:22:45 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597 (Definition 1.169.2651.0)
Error: (04/18/2014 03:14:59 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Microsoft Antimalware Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/18/2014 02:37:07 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Microsoft Office Sessions:
=========================
Error: (04/18/2014 07:16:24 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 07:12:14 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 07:08:03 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 07:04:02 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 07:00:00 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 06:55:49 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 06:51:38 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 06:47:37 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 06:43:35 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
Error: (04/18/2014 06:39:33 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Dieser Vorgang wurde wegen Zeitüberschreitung zurückgegeben. (HRESULT : 0x800705b4) (0x800705b4)
==================== Memory info ===========================
Percentage of memory in use: 66%
Total physical RAM: 4095.24 MB
Available physical RAM: 1382.13 MB
Total Pagefile: 8188.66 MB
Available Pagefile: 4959.26 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (eMachines) (Fixed) (Total:916.91 GB) (Free:813.82 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 0F7E7F14)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=917 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Danke für die Hilfe! :-)