Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: lenovo g700 surkfeepita und winspeed deinstallieren

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 04.09.2014, 21:20   #1
haiflosse
 
lenovo g700 surkfeepita und winspeed deinstallieren - Standard

lenovo g700 surkfeepita und winspeed deinstallieren



Ich hier ein Lenovo g700 Notebook mit Windows 8 und emsisoft Schutz.
Jetzt habe ich bemerkt, dass ich bei Google immer automatisch Werbung von surkfeepita bekomme. Habe dies bei meinen Programmen deinstalliert. Trotzdem kommt die Werbeeinschaltung.
Auch habe ich bei meinen Programmen ein Programm winspeed entdeckt, dass sich nicht deinstallieren lässt.
Hoffe da kann mir jemand weiterhelfen, wie ich dies deinstallieren kann, bzw. wie dies auch mit emsisoft passieren konnte. Meine Firewall Amor läuft immer im Lernmodus, sonst gehen keine Updates von Windows 8
Vielen Dank

Alt 04.09.2014, 22:21   #2
Warlord711
/// TB-Ausbilder
 
lenovo g700 surkfeepita und winspeed deinstallieren - Standard

lenovo g700 surkfeepita und winspeed deinstallieren



Hallo !

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 04.09.2014, 22:55   #3
haiflosse
 
lenovo g700 surkfeepita und winspeed deinstallieren - Standard

lenovo g700 surkfeepita und winspeed deinstallieren



Danke für die Antwort:
Hier die Ergebnisse der Dateien

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2014 02
Ran by harald (administrator) on LAPTOP on 04-09-2014 23:50:50
Running from C:\Users\harald\Downloads\x
Platform: Windows 8.1 Enterprise (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\oacat.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\oasrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files (x86)\TrialReset\TrialReset.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(MAFIA) C:\Program Files\LicenseProxy\LicenseProxy.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\oaui.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\oahlp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2014-07-22] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2014-07-22] (Lenovo(beijing) Limited)
HKLM\...\Run: [LicenseProxy] => C:\Program Files\LicenseProxy\LicenseProxy.exe [298496 2013-06-28] (MAFIA)
HKLM\...\Run: [@OnlineArmor GUI] => C:\Program Files (x86)\Online Armor\oaui.exe [7558464 2013-10-11] (Emsisoft GmbH)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2777840 2013-08-14] (Synaptics Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
HKLM-x32\...\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft anti-malware\a2guard.exe [4857256 2014-08-14] (Emsisoft GmbH)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3477640 2012-09-23] (Adobe Systems Inc.)
HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [273544 2014-08-28] (RealNetworks, Inc.)
AppInit_DLLs: C:\PROGRA~3\WinSpeed\WINSPE~1.DLL => C:\ProgramData\WinSpeed\WinSpeed_x64.dll [4304896 2014-08-20] ()
AppInit_DLLs-x32: c:\programdata\winspeed\winspeed.dll => "c:\programdata\winspeed\winspeed.dll" File Not Found

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.at/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.at.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x45052BA204A5CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKCU - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: surfkeePita -> {AAEB3734-F79C-B310-1448-14ECC679F6D9} -> C:\ProgramData\surfkeePita\UZaFWpjX.x64.dll ()
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: surfkeePita -> {AAEB3734-F79C-B310-1448-14ECC679F6D9} -> C:\ProgramData\surfkeePita\UZaFWpjX.dll ()
BHO-x32: Adobe Acrobat Create PDF Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.138

FireFox:
========
FF ProfilePath: C:\Users\harald\AppData\Roaming\Mozilla\Firefox\Profiles\x9wwz94a.default
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=12.0.1.647 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=12.0.1.647 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=12.0.1.652 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=12.0.1.652 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=12.0.1.647 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: DeAl2dEaliT - C:\Users\harald\AppData\Roaming\Mozilla\Firefox\Profiles\x9wwz94a.default\Extensions\ftq9nau@pdd-yrbt.net [2014-08-21]
FF Extension: suaRFkeePit - C:\Users\harald\AppData\Roaming\Mozilla\Firefox\Profiles\x9wwz94a.default\Extensions\o6yaua@owmn.net [2014-09-03]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-08-18]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2014-08-28]
FF StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome: 
=======
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2012-09-23]
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2014-08-28]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4754256 2014-08-14] (Emsisoft GmbH)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-08-08] (Broadcom Corporation.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-21] (Intel Corporation)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation)
R2 OAcat; C:\Program Files (x86)\Online Armor\OAcat.exe [584864 2013-10-11] (Emsisoft GmbH)
R2 PSI_SVC_2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (arvato digital services llc)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
R2 SvcOnlineArmor; C:\Program Files (x86)\Online Armor\oasrv.exe [4457688 2013-10-11] (Emsisoft GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
R2 AutoTrialReset; C:\Program Files (x86)\TrialReset\TrialReset -runservice [X]
S2 f1f78e38; "C:\Windows\system32\rundll32.exe" "c:\programdata\winspeed\winspeedSvc.dll",service

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [23088 2014-05-12] (Emsisoft GmbH)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-08-08] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation)
R1 OADevice; C:\Windows\SysWow64\Drivers\OADriver.sys [64720 2013-10-11] ()
R1 oahlpXX; C:\Windows\syswow64\drivers\oahlp64.sys [62008 2013-10-11] ()
R1 OAmon; C:\Windows\SysWOW64\Drivers\OAmon.sys [52360 2013-10-11] (Emsisoft)
R3 OAnet; C:\Windows\system32\DRIVERS\oanet.sys [35368 2013-10-11] (Emsisoft)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-14] (Synaptics Incorporated)
S3 usbrndis6; C:\Windows\System32\drivers\usb80236.sys [20992 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-04 23:50 - 2014-09-04 23:50 - 00000000 ____D () C:\FRST
2014-09-04 23:38 - 2014-09-04 23:50 - 00000000 ____D () C:\Users\harald\Downloads\x
2014-09-03 19:21 - 2014-09-03 19:21 - 00000000 ____D () C:\ProgramData\surfkeePita
2014-08-28 00:47 - 2014-08-28 00:47 - 00003338 _____ () C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4162614285-2887739644-64261045-1001
2014-08-28 00:47 - 2014-08-28 00:47 - 00003282 _____ () C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4162614285-2887739644-64261045-1001
2014-08-28 00:45 - 2014-08-28 00:45 - 00001964 _____ () C:\Users\Public\Desktop\Kostenlose Angebote.lnk
2014-08-28 00:45 - 2014-08-28 00:45 - 00001370 _____ () C:\Users\Public\Desktop\RealPlayer.lnk
2014-08-28 00:44 - 2014-08-28 00:47 - 00000000 ____D () C:\ProgramData\Real
2014-08-28 00:44 - 2014-08-28 00:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
2014-08-28 00:44 - 2014-08-28 00:45 - 00000000 ____D () C:\Program Files (x86)\Real
2014-08-28 00:44 - 2014-08-28 00:44 - 00272896 _____ (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2014-08-28 00:44 - 2014-08-28 00:44 - 00198848 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2014-08-28 00:44 - 2014-08-28 00:44 - 00006656 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2014-08-28 00:44 - 2014-08-28 00:44 - 00005632 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2014-08-28 00:04 - 2014-08-28 00:54 - 00000000 ____D () C:\Users\harald\AppData\Roaming\Real
2014-08-27 22:42 - 2014-08-23 02:42 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____D () C:\Program Files\Synaptics
2014-08-27 18:20 - 2014-08-27 18:22 - 00001404 _____ () C:\Windows\Synaptics.log
2014-08-27 18:20 - 2013-08-14 15:01 - 00722160 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll
2014-08-27 18:20 - 2013-08-14 15:01 - 00527600 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys
2014-08-27 18:20 - 2013-08-14 15:01 - 00421616 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo19.dll
2014-08-27 18:20 - 2013-08-14 15:01 - 00400112 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCom.dll
2014-08-27 18:20 - 2013-08-14 15:01 - 00251632 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll
2014-08-27 18:20 - 2013-08-14 15:01 - 00169712 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynTPCom.dll
2014-08-27 18:20 - 2013-08-14 15:01 - 00034544 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\Smb_driver_Intel.sys
2014-08-27 00:29 - 2014-08-27 00:30 - 00000000 ____D () C:\ProgramData\Protexis
2014-08-27 00:27 - 2014-08-27 00:26 - 00002467 _____ () C:\Users\Public\Desktop\Bitstream Font Navigator.lnk
2014-08-27 00:27 - 2014-08-27 00:24 - 00002847 _____ () C:\Users\Public\Desktop\Corel PHOTO-PAINT X7.lnk
2014-08-27 00:27 - 2014-08-27 00:24 - 00002840 _____ () C:\Users\Public\Desktop\Corel CAPTURE X7.lnk
2014-08-27 00:27 - 2014-08-27 00:24 - 00002371 _____ () C:\Users\Public\Desktop\Corel CONNECT X7.lnk
2014-08-27 00:27 - 2014-08-27 00:23 - 00002799 _____ () C:\Users\Public\Desktop\CorelDRAW X7.lnk
2014-08-27 00:24 - 2014-08-27 00:24 - 00000000 ____D () C:\Users\Public\Documents\Corel
2014-08-27 00:23 - 2014-08-27 00:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7
2014-08-27 00:22 - 2014-09-04 00:44 - 00000000 ____D () C:\ProgramData\Corel
2014-08-27 00:22 - 2014-08-27 00:23 - 00000000 ____D () C:\Program Files (x86)\Corel
2014-08-27 00:13 - 2014-08-27 00:31 - 00000000 ____D () C:\ProgramData\CorelDRAW Graphics Suite X7
2014-08-26 23:46 - 2014-08-26 23:46 - 00000000 ____D () C:\Users\harald\Documents\Meine Paletten
2014-08-26 23:45 - 2014-08-26 23:45 - 00000000 ____D () C:\Users\harald\Documents\Corel
2014-08-26 23:43 - 2014-08-27 00:30 - 00000000 ____D () C:\Users\harald\AppData\Roaming\Corel
2014-08-26 23:43 - 2014-08-26 23:43 - 00000000 ____D () C:\ProgramData\Protexis64
2014-08-26 23:39 - 2014-08-26 23:39 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-26 23:37 - 2014-08-26 23:37 - 00000000 ____D () C:\Program Files\Common Files\Protexis
2014-08-26 23:23 - 2014-08-26 23:44 - 00000000 ____D () C:\ProgramData\CorelDRAW Graphics Suite X7 x64
2014-08-26 22:40 - 2014-08-26 22:40 - 00000000 _____ () C:\Windows\longfile.INI
2014-08-26 22:39 - 2014-08-26 22:39 - 00008198 _____ () C:\Windows\WT61US.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61UK.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61SD.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61OZ.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61KR.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61DE.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61CE.UWL
2014-08-26 22:39 - 1996-04-11 17:34 - 00965904 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSJT3032.DLL
2014-08-26 22:39 - 1996-03-15 18:47 - 00098356 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSJTER32.DLL
2014-08-26 22:39 - 1996-03-15 18:15 - 00033552 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSJINT32.DLL
2014-08-26 22:39 - 1995-09-24 11:02 - 00243472 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBAR2232.DLL
2014-08-26 22:39 - 1995-09-20 17:16 - 00245520 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSRD2X32.DLL
2014-08-26 22:39 - 1995-08-15 01:00 - 00144144 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSLT3032.DLL
2014-08-26 22:39 - 1995-08-07 06:33 - 00043008 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSOC95.DLL
2014-08-26 22:39 - 1995-07-20 01:00 - 01371436 ____R () C:\Windows\SysWOW64\VBAR2132.DLL
2014-08-26 22:39 - 1995-07-20 01:00 - 00816720 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBA32.DLL
2014-08-26 22:39 - 1995-07-20 01:00 - 00240912 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSPX3032.DLL
2014-08-26 22:39 - 1995-07-20 01:00 - 00220944 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSXL3032.DLL
2014-08-26 22:39 - 1995-07-20 01:00 - 00121104 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSTX3032.DLL
2014-08-26 22:39 - 1995-07-20 01:00 - 00025564 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBAEN32.OLB
2014-08-26 22:39 - 1995-07-20 01:00 - 00008976 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBAEN32.DLL
2014-08-26 22:39 - 1995-07-11 10:50 - 00398416 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBRUN300.DLL
2014-08-26 22:39 - 1995-06-15 01:00 - 00037376 ____R () C:\Windows\SysWOW64\VEN2132.OLB
2014-08-26 22:39 - 1995-05-12 01:00 - 00260368 ____R (Microsoft Corporation) C:\Windows\SysWOW64\MSXB3032.DLL
2014-08-26 22:39 - 1994-04-13 00:00 - 00095200 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBDB300.DLL
2014-08-26 22:39 - 1993-04-28 01:00 - 00013824 ____R (Microsoft Corporation) C:\Windows\SysWOW64\VBOA300.DLL
2014-08-26 22:37 - 1996-11-25 23:28 - 00345600 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\qtim32.dll
2014-08-26 22:37 - 1996-11-25 23:28 - 00229376 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\rpza32.qtc
2014-08-26 22:37 - 1996-11-25 23:28 - 00165888 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\smc32.qtc
2014-08-26 22:37 - 1996-11-25 23:28 - 00151040 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\cvid32.qtc
2014-08-26 22:37 - 1996-11-25 23:28 - 00128000 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\mc32.qtc
2014-08-26 22:37 - 1996-11-25 23:28 - 00103936 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\rle32.qtc
2014-08-26 22:37 - 1996-11-25 23:28 - 00083456 ____N (Intel(R) Corporation) C:\Windows\SysWOW64\iv32qt32.qtc
2014-08-26 22:37 - 1996-11-25 23:28 - 00038912 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\dhio32.qtc
2014-08-26 22:37 - 1996-11-25 23:28 - 00035840 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\navg32.qtc
2014-08-26 22:37 - 1996-11-25 23:28 - 00034816 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\jpeg32.qtc
2014-08-26 22:37 - 1996-11-25 23:28 - 00032768 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\cmgr32.dll
2014-08-26 22:37 - 1996-11-25 23:28 - 00024064 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\dci32.qtc
2014-08-26 22:37 - 1996-11-25 23:28 - 00020480 ____N (Apple Computer, Inc.) C:\Windows\SysWOW64\raw32.qtc
2014-08-26 22:36 - 1996-11-25 23:31 - 00088916 ____N () C:\Windows\twain.dll
2014-08-26 22:36 - 1996-10-29 23:01 - 00409600 ____N (Corel Corporation) C:\Windows\SysWOW64\scint70.dll
2014-08-26 22:36 - 1996-09-24 12:54 - 00033280 ____N () C:\Windows\SysWOW64\picbuttn.ocx
2014-08-26 22:36 - 1996-06-04 23:51 - 00721168 ____N (Microsoft Corporation) C:\Windows\SysWOW64\vb40032.dll
2014-08-26 22:36 - 1996-06-04 23:51 - 00330752 ____N (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.ocx
2014-08-26 22:36 - 1995-11-07 09:57 - 00006144 ____N (Corel Corporation) C:\Windows\SysWOW64\Drivers\crlscsi.sys
2014-08-26 22:36 - 1995-10-18 14:46 - 00000142 ____N () C:\Windows\SysWOW64\scanners.reg
2014-08-26 22:36 - 1995-09-15 11:51 - 00069632 ____N (Twain Working Group) C:\Windows\twunk_32.exe
2014-08-26 22:36 - 1995-09-15 11:51 - 00048560 ____N (Twain Working Group) C:\Windows\twunk_16.exe
2014-08-26 22:36 - 1995-08-15 01:00 - 00136704 ____N (Apex Software Corporation) C:\Windows\SysWOW64\grdkrn32.dll
2014-08-26 22:36 - 1995-07-26 01:00 - 00288256 ____N (Apex Software Corporation) C:\Windows\SysWOW64\dbgrid32.ocx
2014-08-26 22:36 - 1995-07-26 01:00 - 00263680 ____N (Microsoft Corporation) C:\Windows\SysWOW64\msrdo32.dll
2014-08-26 22:36 - 1995-07-26 01:00 - 00200704 ____N (Sheridan Software Systems, Inc.) C:\Windows\SysWOW64\threed32.ocx
2014-08-26 22:36 - 1995-07-26 01:00 - 00141824 ____N (Microsoft Corporation) C:\Windows\SysWOW64\dblist32.ocx
2014-08-26 22:36 - 1995-07-26 01:00 - 00136192 ____N (Microsoft Corporation) C:\Windows\SysWOW64\msrdc32.ocx
2014-08-26 22:36 - 1995-07-26 01:00 - 00129024 ____N (Sheridan Software Systems, Inc.) C:\Windows\SysWOW64\tabctl32.ocx
2014-08-26 22:36 - 1995-07-26 01:00 - 00081408 ____N (Microsoft Corporation) C:\Windows\SysWOW64\richtx32.ocx
2014-08-26 22:36 - 1995-05-22 14:05 - 00108032 ____N (Microsoft Corporation) C:\Windows\SysWOW64\mfcuia32.dll
2014-08-26 22:36 - 1995-05-19 15:44 - 00322832 ____N (Microsoft Corporation) C:\Windows\SysWOW64\mfc30.dll
2014-08-26 22:36 - 1995-05-19 14:49 - 00133904 ____N (Microsoft Corporation) C:\Windows\SysWOW64\mfcans32.dll
2014-08-26 22:35 - 2014-08-26 23:52 - 00000000 ____D () C:\Windows\COREL
2014-08-26 22:35 - 2014-08-26 22:35 - 00000000 ____D () C:\Corel
2014-08-23 19:15 - 2014-08-23 19:15 - 00001181 _____ () C:\Users\tn\Documents\info.dat
2014-08-23 19:15 - 2012-05-30 21:31 - 00024576 _____ (Hochl-it) C:\Users\tn\Documents\info.exe
2014-08-23 15:13 - 2014-08-23 15:13 - 00000000 ____D () C:\Program Files (x86)\deal2ddealit
2014-08-23 14:53 - 2014-08-25 21:37 - 02482176 _____ () C:\Users\tn\Documents\kassa.accdb
2014-08-23 14:52 - 2014-08-23 14:53 - 00000000 ____D () C:\Users\tn
2014-08-23 13:08 - 2014-08-23 13:08 - 06052529 _____ (Tim Kosse) C:\Users\harald\Downloads\FileZilla_3.9.0.3_win32-setup.exe
2014-08-21 21:18 - 2014-09-03 19:21 - 00000000 ____D () C:\ProgramData\5940d185bd756d33
2014-08-21 21:18 - 2014-08-23 15:13 - 00000000 ____D () C:\ProgramData\deal2ddealit
2014-08-21 21:04 - 2014-08-23 12:36 - 00000940 _____ () C:\EamClean.log
2014-08-20 06:22 - 2014-08-21 21:04 - 00000000 ____D () C:\ProgramData\WinSpeed
2014-08-18 20:31 - 2014-08-18 20:31 - 00000000 ____D () C:\Users\harald\AppData\Local\PDF Writer
2014-08-18 20:24 - 2014-08-18 20:24 - 00000000 ____D () C:\Users\harald\AppData\Roaming\PDF Writer
2014-08-18 20:24 - 2012-11-05 11:02 - 00218624 _____ (Bullzip) C:\Windows\system32\bzpdf.dll
2014-08-18 20:13 - 2014-08-18 20:15 - 00000000 ____D () C:\ProgramData\PDF Writer
2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip
2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\Program Files\Common Files\Bullzip
2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\Program Files\Bullzip
2014-08-18 20:13 - 2014-08-01 20:29 - 00147456 _____ (Bullzip) C:\Windows\SysWOW64\bzpdfc.dll
2014-08-18 20:13 - 2013-09-01 12:59 - 01103872 _____ () C:\Windows\SysWOW64\CBLCtlsU.ocx
2014-08-18 20:13 - 2013-07-13 12:15 - 00805376 _____ () C:\Windows\SysWOW64\EditCtlsU.ocx
2014-08-18 20:13 - 2013-07-12 22:57 - 00539648 _____ () C:\Windows\SysWOW64\LblCtlsU.ocx
2014-08-18 20:13 - 2013-04-05 13:55 - 00476160 _____ () C:\Windows\SysWOW64\TabStripCtlU.ocx
2014-08-18 20:13 - 2013-03-28 23:13 - 00645632 _____ () C:\Windows\SysWOW64\BtnCtlsU.ocx
2014-08-18 20:13 - 2013-03-03 14:37 - 01061888 _____ () C:\Windows\SysWOW64\ExLvwU.ocx
2014-08-18 20:13 - 2008-10-30 20:29 - 00227840 _____ (Bullzip) C:\Windows\SysWOW64\bzFlRdr.dll
2014-08-18 20:13 - 2008-07-09 20:29 - 00103424 _____ (Bullzip) C:\Windows\SysWOW64\bzDCT.dll
2014-08-18 20:13 - 1999-05-07 00:00 - 00140288 ____N (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.OCX
2014-08-18 16:36 - 2014-08-18 16:57 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-08-18 16:34 - 2014-08-18 16:57 - 00000000 ____D () C:\Users\harald\AppData\Local\Adobe
2014-08-18 16:33 - 2014-08-18 16:33 - 00002469 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk
2014-08-18 16:33 - 2014-08-18 16:33 - 00002230 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk
2014-08-18 16:33 - 2014-08-18 16:33 - 00002160 _____ () C:\Users\Public\Desktop\Adobe FormsCentral.lnk
2014-08-18 16:33 - 2014-08-18 16:33 - 00002069 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk
2014-08-18 16:33 - 2014-08-18 16:33 - 00002046 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk
2014-08-18 16:30 - 2014-08-18 16:57 - 00000000 ____D () C:\ProgramData\Adobe
2014-08-18 16:30 - 2014-08-18 16:30 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-08-18 16:25 - 2014-08-18 16:28 - 00000000 ____D () C:\Users\harald\Desktop\Adobe Acrobat XI
2014-08-18 15:58 - 2014-08-02 05:11 - 00918528 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-08-18 15:56 - 2014-08-07 00:38 - 00697856 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-18 15:56 - 2014-08-02 07:44 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-18 15:56 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-18 15:56 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-18 15:56 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-18 15:56 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-18 15:56 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-18 15:56 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-18 15:56 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-18 15:56 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-18 15:56 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-18 15:56 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-18 15:56 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-18 15:56 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-18 15:56 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-18 15:56 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-18 15:56 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-18 15:56 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-18 15:56 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-18 15:56 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-18 15:56 - 2014-07-25 13:43 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-18 15:56 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-18 15:56 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-18 15:56 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-18 15:56 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-18 15:56 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-18 15:56 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-18 15:56 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-18 15:56 - 2014-07-25 13:09 - 00291840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-18 15:56 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-18 15:56 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-18 15:56 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-18 15:56 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-18 15:56 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-18 15:56 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-18 15:56 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-18 15:56 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-18 15:56 - 2014-07-15 20:16 - 03048880 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2014-08-18 15:56 - 2014-07-15 10:29 - 03118080 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-08-18 15:56 - 2014-07-15 10:22 - 02861056 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll
2014-08-18 15:56 - 2014-07-15 10:03 - 02344448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-08-18 15:56 - 2014-07-12 06:17 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe
2014-08-18 15:56 - 2014-06-20 03:48 - 01273184 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-18 15:56 - 2014-06-20 01:52 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-18 15:56 - 2014-06-13 03:15 - 00517528 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-08-18 15:56 - 2014-06-13 03:14 - 01557848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-18 15:56 - 2014-06-13 02:10 - 00406400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-08-18 15:56 - 2014-06-06 13:34 - 02133504 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2014-08-18 15:52 - 2014-08-07 04:12 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-18 15:52 - 2014-08-02 05:56 - 01064448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-15 10:45 - 2014-08-15 10:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2014-08-15 10:45 - 2014-08-15 10:45 - 00000000 ____D () C:\Program Files (x86)\Acro Software
2014-08-15 10:45 - 2009-11-05 08:40 - 00085504 _____ () C:\Windows\system32\cpwmon64.dll
2014-08-15 10:35 - 2014-06-04 11:27 - 00114520 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-15 10:35 - 2014-06-04 07:31 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-15 10:35 - 2014-06-04 07:22 - 02790912 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-15 10:35 - 2014-06-04 06:43 - 00281088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-15 10:35 - 2014-06-04 06:38 - 03304448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-15 10:35 - 2014-06-04 04:15 - 02642944 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-15 10:35 - 2014-06-04 04:14 - 02318336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-04 23:50 - 2014-09-04 23:50 - 00000000 ____D () C:\FRST
2014-09-04 23:50 - 2014-09-04 23:38 - 00000000 ____D () C:\Users\harald\Downloads\x
2014-09-04 23:06 - 2014-06-23 10:32 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware
2014-09-04 23:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-09-04 22:15 - 2013-09-30 06:14 - 01686150 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-04 22:15 - 2013-09-30 05:58 - 00727930 _____ () C:\Windows\system32\perfh007.dat
2014-09-04 22:15 - 2013-09-30 05:58 - 00151586 _____ () C:\Windows\system32\perfc007.dat
2014-09-04 22:10 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-04 21:31 - 2014-07-30 22:55 - 00000000 ____D () C:\Program Files (x86)\JDownloader
2014-09-04 21:27 - 2014-06-22 15:14 - 01264886 _____ () C:\Windows\WindowsUpdate.log
2014-09-04 21:02 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-09-04 15:34 - 2014-06-22 15:14 - 00000000 ____D () C:\Users\harald\AppData\Local\Packages
2014-09-04 11:15 - 2014-07-08 14:33 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{DC4EDA5E-B3C8-4505-80D9-A694042D1F7C}
2014-09-04 00:44 - 2014-08-27 00:22 - 00000000 ____D () C:\ProgramData\Corel
2014-09-03 19:21 - 2014-09-03 19:21 - 00000000 ____D () C:\ProgramData\surfkeePita
2014-09-03 19:21 - 2014-08-21 21:18 - 00000000 ____D () C:\ProgramData\5940d185bd756d33
2014-09-03 11:55 - 2014-06-22 15:20 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4162614285-2887739644-64261045-1001
2014-09-01 10:02 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-08-29 12:38 - 2013-08-22 16:44 - 00604560 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 16:24 - 2014-07-22 22:08 - 00000000 ____D () C:\Users\harald\AppData\Roaming\FileZilla
2014-08-28 00:54 - 2014-08-28 00:04 - 00000000 ____D () C:\Users\harald\AppData\Roaming\Real
2014-08-28 00:47 - 2014-08-28 00:47 - 00003338 _____ () C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4162614285-2887739644-64261045-1001
2014-08-28 00:47 - 2014-08-28 00:47 - 00003282 _____ () C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4162614285-2887739644-64261045-1001
2014-08-28 00:47 - 2014-08-28 00:44 - 00000000 ____D () C:\ProgramData\Real
2014-08-28 00:45 - 2014-08-28 00:45 - 00001964 _____ () C:\Users\Public\Desktop\Kostenlose Angebote.lnk
2014-08-28 00:45 - 2014-08-28 00:45 - 00001370 _____ () C:\Users\Public\Desktop\RealPlayer.lnk
2014-08-28 00:45 - 2014-08-28 00:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
2014-08-28 00:45 - 2014-08-28 00:44 - 00000000 ____D () C:\Program Files (x86)\Real
2014-08-28 00:44 - 2014-08-28 00:44 - 00272896 _____ (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2014-08-28 00:44 - 2014-08-28 00:44 - 00198848 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2014-08-28 00:44 - 2014-08-28 00:44 - 00006656 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2014-08-28 00:44 - 2014-08-28 00:44 - 00005632 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2014-08-28 00:44 - 2012-09-23 20:43 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2014-08-28 00:44 - 2012-09-23 20:43 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2014-08-27 23:32 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-08-27 18:22 - 2014-08-27 18:20 - 00001404 _____ () C:\Windows\Synaptics.log
2014-08-27 18:22 - 2014-06-22 16:24 - 00021624 _____ () C:\Windows\DPINST.LOG
2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2014-08-27 18:21 - 2014-08-27 18:21 - 00000000 ____D () C:\Program Files\Synaptics
2014-08-27 18:21 - 2013-08-22 16:46 - 00028779 _____ () C:\Windows\setupact.log
2014-08-27 00:31 - 2014-08-27 00:13 - 00000000 ____D () C:\ProgramData\CorelDRAW Graphics Suite X7
2014-08-27 00:30 - 2014-08-27 00:29 - 00000000 ____D () C:\ProgramData\Protexis
2014-08-27 00:30 - 2014-08-26 23:43 - 00000000 ____D () C:\Users\harald\AppData\Roaming\Corel
2014-08-27 00:29 - 2014-08-27 00:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7
2014-08-27 00:26 - 2014-08-27 00:27 - 00002467 _____ () C:\Users\Public\Desktop\Bitstream Font Navigator.lnk
2014-08-27 00:24 - 2014-08-27 00:27 - 00002847 _____ () C:\Users\Public\Desktop\Corel PHOTO-PAINT X7.lnk
2014-08-27 00:24 - 2014-08-27 00:27 - 00002840 _____ () C:\Users\Public\Desktop\Corel CAPTURE X7.lnk
2014-08-27 00:24 - 2014-08-27 00:27 - 00002371 _____ () C:\Users\Public\Desktop\Corel CONNECT X7.lnk
2014-08-27 00:24 - 2014-08-27 00:24 - 00000000 ____D () C:\Users\Public\Documents\Corel
2014-08-27 00:23 - 2014-08-27 00:27 - 00002799 _____ () C:\Users\Public\Desktop\CorelDRAW X7.lnk
2014-08-27 00:23 - 2014-08-27 00:22 - 00000000 ____D () C:\Program Files (x86)\Corel
2014-08-27 00:01 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-08-26 23:52 - 2014-08-26 22:35 - 00000000 ____D () C:\Windows\COREL
2014-08-26 23:46 - 2014-08-26 23:46 - 00000000 ____D () C:\Users\harald\Documents\Meine Paletten
2014-08-26 23:45 - 2014-08-26 23:45 - 00000000 ____D () C:\Users\harald\Documents\Corel
2014-08-26 23:44 - 2014-08-26 23:23 - 00000000 ____D () C:\ProgramData\CorelDRAW Graphics Suite X7 x64
2014-08-26 23:43 - 2014-08-26 23:43 - 00000000 ____D () C:\ProgramData\Protexis64
2014-08-26 23:39 - 2014-08-26 23:39 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-26 23:37 - 2014-08-26 23:37 - 00000000 ____D () C:\Program Files\Common Files\Protexis
2014-08-26 22:40 - 2014-08-26 22:40 - 00000000 _____ () C:\Windows\longfile.INI
2014-08-26 22:39 - 2014-08-26 22:39 - 00008198 _____ () C:\Windows\WT61US.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61UK.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61SD.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61OZ.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61KR.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61DE.UWL
2014-08-26 22:39 - 2014-08-26 22:39 - 00000546 _____ () C:\Windows\WT61CE.UWL
2014-08-26 22:35 - 2014-08-26 22:35 - 00000000 ____D () C:\Corel
2014-08-25 21:37 - 2014-08-23 14:53 - 02482176 _____ () C:\Users\tn\Documents\kassa.accdb
2014-08-23 19:15 - 2014-08-23 19:15 - 00001181 _____ () C:\Users\tn\Documents\info.dat
2014-08-23 15:13 - 2014-08-23 15:13 - 00000000 ____D () C:\Program Files (x86)\deal2ddealit
2014-08-23 15:13 - 2014-08-21 21:18 - 00000000 ____D () C:\ProgramData\deal2ddealit
2014-08-23 14:53 - 2014-08-23 14:52 - 00000000 ____D () C:\Users\tn
2014-08-23 13:10 - 2014-07-22 22:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2014-08-23 13:10 - 2014-07-22 22:07 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client
2014-08-23 13:08 - 2014-08-23 13:08 - 06052529 _____ (Tim Kosse) C:\Users\harald\Downloads\FileZilla_3.9.0.3_win32-setup.exe
2014-08-23 12:36 - 2014-08-21 21:04 - 00000940 _____ () C:\EamClean.log
2014-08-23 10:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2014-08-23 02:42 - 2014-08-27 22:42 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 20:07 - 2014-06-22 15:15 - 00000000 ____D () C:\Users\harald\AppData\Roaming\Adobe
2014-08-22 09:11 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-22 09:10 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2014-08-22 09:09 - 2014-07-26 13:10 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-21 21:04 - 2014-08-20 06:22 - 00000000 ____D () C:\ProgramData\WinSpeed
2014-08-20 06:23 - 2014-07-30 22:49 - 00000000 ____D () C:\ProgramData\374311380
2014-08-18 20:31 - 2014-08-18 20:31 - 00000000 ____D () C:\Users\harald\AppData\Local\PDF Writer
2014-08-18 20:24 - 2014-08-18 20:24 - 00000000 ____D () C:\Users\harald\AppData\Roaming\PDF Writer
2014-08-18 20:15 - 2014-08-18 20:13 - 00000000 ____D () C:\ProgramData\PDF Writer
2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip
2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\Program Files\Common Files\Bullzip
2014-08-18 20:13 - 2014-08-18 20:13 - 00000000 ____D () C:\Program Files\Bullzip
2014-08-18 16:57 - 2014-08-18 16:36 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-08-18 16:57 - 2014-08-18 16:34 - 00000000 ____D () C:\Users\harald\AppData\Local\Adobe
2014-08-18 16:57 - 2014-08-18 16:30 - 00000000 ____D () C:\ProgramData\Adobe
2014-08-18 16:53 - 2014-07-10 22:09 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-08-18 16:53 - 2014-07-10 22:07 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-18 16:33 - 2014-08-18 16:33 - 00002469 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk
2014-08-18 16:33 - 2014-08-18 16:33 - 00002230 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk
2014-08-18 16:33 - 2014-08-18 16:33 - 00002160 _____ () C:\Users\Public\Desktop\Adobe FormsCentral.lnk
2014-08-18 16:33 - 2014-08-18 16:33 - 00002069 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk
2014-08-18 16:33 - 2014-08-18 16:33 - 00002046 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk
2014-08-18 16:30 - 2014-08-18 16:30 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-08-18 16:28 - 2014-08-18 16:25 - 00000000 ____D () C:\Users\harald\Desktop\Adobe Acrobat XI
2014-08-15 11:23 - 2014-07-10 21:23 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-15 11:21 - 2014-07-10 21:23 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-15 10:45 - 2014-08-15 10:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2014-08-15 10:45 - 2014-08-15 10:45 - 00000000 ____D () C:\Program Files (x86)\Acro Software
2014-08-15 09:02 - 2014-07-14 11:09 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-15 09:02 - 2014-07-14 11:08 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-15 09:02 - 2014-07-14 11:08 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-15 09:02 - 2013-08-22 13:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-15 09:02 - 2013-08-22 13:44 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-15 09:02 - 2013-08-22 13:22 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-15 09:02 - 2013-08-22 13:21 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-15 09:02 - 2013-08-22 13:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-15 09:02 - 2013-08-22 13:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-15 09:02 - 2013-08-22 12:32 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-15 09:02 - 2013-08-22 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-15 09:02 - 2013-08-22 05:55 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-15 09:02 - 2013-08-22 05:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-15 09:02 - 2013-08-22 05:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-15 09:02 - 2013-08-22 05:40 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-15 09:02 - 2013-08-22 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-07 04:12 - 2014-08-18 15:52 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-07 00:38 - 2014-08-18 15:56 - 00697856 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll

Some content of TEMP:
====================
C:\Users\harald\AppData\Local\Temp\AskSLib.dll
C:\Users\harald\AppData\Local\Temp\JDSetup130509647251693530.exe
C:\Users\harald\AppData\Local\Temp\JDSetup130512265273593134.exe
C:\Users\harald\AppData\Local\Temp\JDSetup130512271351440163.exe
C:\Users\harald\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-08-27 00:44

==================== End Of Log ============================
         
--- --- ---

--- --- ---


und
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-09-2014 02
Ran by harald at 2014-09-04 23:51:44
Running from C:\Users\harald\Downloads\x
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Emsisoft Anti-Malware (Enabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
FW: Online Armor Firewall (Enabled) {BD3F5FCA-866B-1E2E-0A68-58900A751EA1}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.00 - Adobe Systems)
Bullzip PDF Printer 9.2.0.1499 (HKLM\...\Bullzip PDF Printer_is1) (Version: 9.2.0.1499 - Bullzip)
Color MF30-1 (HKLM\...\MFP-Printer Utility Color MF30-1 Installer) (Version:  - )
Color MF30-1 Scanner (HKLM-x32\...\InstallShield_{53498E29-B8FE-4B33-BD35-EB8804A45D33}) (Version:  - )
Color MF30-1 Scanner (Version: 1.00.0000 -  ) Hidden
Corel Graphics - Windows Shell Extension (HKLM-x32\...\_{8616305F-122C-4341-9C37-47A9CD322AB2}) (Version: 17.1.0.572 - Corel Corporation)
Corel Graphics - Windows Shell Extension (x32 Version: 17.1.572 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 64 Bit (Version: 17.1.572 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Capture (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Common (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Connect (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Custom Data (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - DE (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Draw (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Filters (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - FontNav (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - IPM Content (x32 Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - IPM T (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - PHOTO-PAINT (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Photozoom Plugin (x32 Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Redist (x32 Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Setup Files (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - VBA (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - VideoBrowser (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Writing Tools (x32 Version: 17.1 -  Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 (HKLM-x32\...\_{C5D9CECB-A66F-473F-B406-5C8C2DCA4DF0}) (Version: 17.1.0.572 - Corel Corporation)
CorelDRAW Graphics Suite X7 (x32 Version: 17.1 - Corel Corporation) Hidden
CutePDF Writer 2.8 (HKLM\...\CutePDF Writer Installation) (Version:  - )
Definition Update for Microsoft Office 2013 (KB2760587) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{0B79C91F-978F-4C2E-9FE4-D4B567808858}) (Version:  - Microsoft)
Emsisoft Anti-Malware (HKLM-x32\...\{BC30E5E7-047D-4232-A7E8-F2CB7CC7B2E0}_is1) (Version: 9.0 - Emsisoft GmbH)
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 8.0.2.4 - Lenovo)
Energy Management (x32 Version: 8.0.2.4 - Lenovo) Hidden
FileZilla Client 3.9.0.3 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.3 - Tim Kosse)
Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3621 - Intel Corporation)
Java 7 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.650 - Oracle)
Java Auto Updater (x32 Version: 2.1.65.20 - Oracle, Inc.) Hidden
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Microsoft Access MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft DCF MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Excel MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Groove MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft InfoPath MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Lync MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office 64-bit Components 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Korrekturhilfen 2013 - Deutsch (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office OSM MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office OSM UX MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - English (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - Italiano (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft OneNote MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Outlook MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft PowerPoint MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Publisher MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual Basic for Applications 7.1 (x86) (x32 Version: 7.1.00.00 - Microsoft Corporation) Hidden
Microsoft Visual Basic for Applications 7.1 (x86) English (x32 Version: 7.1.0.0 - Microsoft Corporation) Hidden
Microsoft Visual Basic for Applications 7.1 (x86) German (x32 Version: 7.1.0.0 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 (HKLM-x32\...\{89ca2a32-2b52-4595-8dfd-6fe4757958d0}) (Version: 11.0.51108 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2012 Finalizer (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support  - Module linguistique Français (Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - DEU-Sprachpaket (Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - Language Pack ITA (Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - Paquete de idioma ESN (Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - 한국어 언어 팩 (Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - 日本語 Language Pack (Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support (Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x64 主控支援 - 繁體中文語言套件 (Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x64 托管支持 - 简体中文语言包 (Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - DEU-Sprachpaket (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - Language Pack ITA (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - Module linguistique Français (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - Paquete de idioma ESN (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - 한국어 언어 팩 (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - 日本語 Language Pack (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x86 主控支援 - 繁體中文語言套件 (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2012 x86 托管支持 - 简体中文语言包 (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
Microsoft Word MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
Mozilla Thunderbird 24.6.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.7 - Notepad++ Team)
Online Armor 7.0 (HKLM-x32\...\OnlineArmor_is1) (Version: 7.0 - Emsisoft GmbH)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (Version: 11.0.51108 - Microsoft Corporation) Hidden
Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - PTB (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM-x32\...\RealPlayer 12.0) (Version:  - RealNetworks)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version:  - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.9.1 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.29480 - TeamViewer)
Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version:  - Microsoft)
Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version:  - Microsoft)
Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-0018-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version:  - Microsoft)
Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-001B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version:  - Microsoft)
Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version:  - Microsoft)
Update for Microsoft Lync 2013 (KB2881070) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{35E5FACD-A5AA-46AD-93C7-F6D7969044E7}) (Version:  - Microsoft)
Update for Microsoft Lync 2013 (KB2881070) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{35E5FACD-A5AA-46AD-93C7-F6D7969044E7}) (Version:  - Microsoft)
Update for Microsoft Lync 2013 (KB2881070) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{35E5FACD-A5AA-46AD-93C7-F6D7969044E7}) (Version:  - Microsoft)
Update for Microsoft Lync 2013 (KB2881083) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4FC38705-B045-4DAC-A0B0-C573D31B8CD5}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760249) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{8C07AD38-38EB-4332-BCB3-F55A77C927DF}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760344) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{A7610F07-E844-4444-8E1D-D5BC8AD0B4C5}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2760544) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{45B7D395-EB9B-414F-9E46-5849B42326E2}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2768012) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{66421820-D3CA-450A-898C-78D7E40108E6}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817302) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{1644D7F6-90EE-4252-8884-18E4E330529D}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2817302) 32-Bit Edition (HKLM-x32\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{1644D7F6-90EE-4252-8884-18E4E330529D}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2826040) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{B7EA8070-C37F-4617-82F4-52CF3304595A}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2837644) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{9BC5FF1D-9626-44D7-BC7F-EB44BD8BDB9F}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{AD7045B8-1D75-4B4C-8120-12F045D206C7}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{AD7045B8-1D75-4B4C-8120-12F045D206C7}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2880457) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{D27F6360-AE1E-4C8C-8ECD-C0375E20B923}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2880462) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{5D6439FF-D651-4B13-B52E-2508AB9DE19D}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2880462) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{5D6439FF-D651-4B13-B52E-2508AB9DE19D}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2880478) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7C5CEE0F-6823-4BB7-A28F-76FEC14EB6AC}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2881009) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7A3EF4FF-A9C8-4F7E-8020-A45F7D319387}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{01B80B63-C638-4004-9148-75B8C8518B1E}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition (HKLM-x32\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{01B80B63-C638-4004-9148-75B8C8518B1E}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition (HKLM-x32\...\{90150000-0090-0407-0000-0000000FF1CE}_Office15.PROPLUS_{01B80B63-C638-4004-9148-75B8C8518B1E}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2883036) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{B8E73381-09B1-4895-ACD0-34385B0F526D}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2883049) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{1C6260FD-A280-49FE-89D0-CCEC647FBD8E}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2883052) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{3F3A95FF-9F40-4B19-8227-53DF683B4CF9}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2883052) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{3F3A95FF-9F40-4B19-8227-53DF683B4CF9}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-0407-0000-0000000FF1CE}_Office15.PROPLUS_{0F5FFEB6-2F66-4592-8A34-CC85FF318951}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-0409-0000-0000000FF1CE}_Office15.PROPLUS_{DA288EB3-648C-433C-88AC-71AEAAFAACF7}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-040C-0000-0000000FF1CE}_Office15.PROPLUS_{51865C36-97D4-4210-A33E-50BCC8CDDF72}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-0410-0000-0000000FF1CE}_Office15.PROPLUS_{D533D4E6-5056-487A-8F18-7FA51AF0E283}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2883062) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{EE35EB6C-7768-433F-B9A0-73C97699A08C}) (Version:  - Microsoft)
Update for Microsoft Office 2013 (KB2883062) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EE35EB6C-7768-433F-B9A0-73C97699A08C}) (Version:  - Microsoft)
Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version:  - Microsoft)
Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version:  - Microsoft)
Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version:  - Microsoft)
Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-00BA-0407-0000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version:  - Microsoft)
Update for Microsoft OneNote 2013 (KB2881082) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{CA0F0611-10FB-47D4-A642-E3BABCC73393}) (Version:  - Microsoft)
Update for Microsoft OneNote 2013 (KB2881082) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{CA0F0611-10FB-47D4-A642-E3BABCC73393}) (Version:  - Microsoft)
Update for Microsoft OneNote 2013 (KB2881082) 32-Bit Edition (HKLM-x32\...\{90150000-00A1-0407-0000-0000000FF1CE}_Office15.PROPLUS_{CA0F0611-10FB-47D4-A642-E3BABCC73393}) (Version:  - Microsoft)
Update for Microsoft Outlook 2013 (KB2880470) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{1BCA67A6-5329-48D0-A088-C097AC7A14BD}) (Version:  - Microsoft)
Update for Microsoft Outlook 2013 (KB2880470) 32-Bit Edition (HKLM-x32\...\{90150000-001A-0407-0000-0000000FF1CE}_Office15.PROPLUS_{1BCA67A6-5329-48D0-A088-C097AC7A14BD}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2013 (KB2883051) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{01923A0F-BA34-4A75-8D43-97F536E44D95}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2013 (KB2883051) 32-Bit Edition (HKLM-x32\...\{90150000-0018-0407-0000-0000000FF1CE}_Office15.PROPLUS_{01923A0F-BA34-4A75-8D43-97F536E44D95}) (Version:  - Microsoft)
Update for Microsoft Publisher 2013 (KB2880999) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7500AD77-83C6-400B-8B2F-F8E401A7B697}) (Version:  - Microsoft)
Update for Microsoft Publisher 2013 (KB2880999) 32-Bit Edition (HKLM-x32\...\{90150000-0019-0407-0000-0000000FF1CE}_Office15.PROPLUS_{7500AD77-83C6-400B-8B2F-F8E401A7B697}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{25C61889-2E44-4BE1-9E96-9364BFDCF501}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{25C61889-2E44-4BE1-9E96-9364BFDCF501}) (Version:  - Microsoft)
Update for Microsoft Word 2013 (KB2878319) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{A7CD05CC-CA85-428C-91FD-74A908D126E1}) (Version:  - Microsoft)
Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version:  - Microsoft)
Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-001A-0407-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version:  - Microsoft)
Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-001B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version:  - Microsoft)
Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version:  - Microsoft)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (06/15/2012 8.1.0.1) (HKLM\...\71BC3FD63F450BA0A957AAECBDB4A000C4F2BE42) (Version: 06/15/2012 8.1.0.1 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid  (06/19/2012 10.13.29.733) (HKLM\...\8A223E56FB1ED4F697B54E5BF96F1EB63B512684) (Version: 06/19/2012 10.13.29.733 - Lenovo)
WinRAR 5.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)
WinSpeed (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{f1f78e38}) (Version:  - 24soft) <==== ATTENTION
Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (Version: 11.0.51108 - Microsoft Corporation) Hidden
Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x86) - RUS (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-4162614285-2887739644-64261045-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)

==================== Restore Points  =========================

18-08-2014 14:29:35 Installed Adobe Acrobat XI Pro.
22-08-2014 07:09:14 Windows Update
26-08-2014 21:38:21 Microsoft Visual Studio Tools for Applications 2012
03-09-2014 06:41:34 Geplanter Prüfpunkt

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2014-08-18 16:42 - 00000916 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 lmlicenses.wip4.adobe.com
127.0.0.1 lm.licenses.adobe.com


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2AB4B245-1EB0-4CD3-8970-8F43AD55F11B} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4162614285-2887739644-64261045-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2011-03-29] (RealNetworks, Inc.)
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {379C9638-D709-4244-B560-A43805D64571} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation)
Task: {3A730463-D125-4F30-8404-4F89B7DDD3FA} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {444D8AB4-2001-4E7A-9A09-2FE7E1893D16} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4162614285-2887739644-64261045-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2011-03-29] (RealNetworks, Inc.)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {4B389D58-B37C-4000-822B-E314BB1FBABA} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {4B63DAD8-630E-4B6A-8687-3CE0B3CE803D} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {4C07F044-59E2-4A9A-AFEE-4014381DDF99} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {4F61FA1A-A31C-4B68-9F36-5EF5E641EA2E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {9E5FBC22-451B-4B62-A82A-41BA9B9F08FD} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A7395B5C-5140-4862-934F-8A8C654F86E3} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-08-15] (Microsoft Corporation)
Task: {A9E91544-9F2B-4F4E-A73C-4AD3B0200EF1} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D0B6ED53-6F80-49C3-A3D7-72C7298A2C37} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DF9569C7-627B-4BA6-9E65-FFAFEB2CAE0A} - System32\Tasks\AutoKMSCustom => C:\Windows\AutoKMS\AutoKMS.exe [2014-06-22] ()
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE

==================== Loaded Modules (whitelisted) =============

2014-05-12 11:49 - 2014-05-12 11:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2010-04-26 19:04 - 2010-04-26 19:04 - 00015360 _____ () C:\Windows\System32\KOBJUTAL.dll
2010-01-27 13:59 - 2010-01-27 13:59 - 00015360 _____ () C:\Windows\System32\KOBJUJAL.dll
2007-11-15 13:57 - 2007-11-15 13:57 - 00017408 _____ () C:\Windows\System32\KOBJUAAL.dll
2010-01-27 14:26 - 2010-01-27 14:26 - 00015360 _____ () C:\Windows\System32\KOBJUWAL.DLL
2014-08-15 10:45 - 2009-11-05 08:40 - 00085504 _____ () C:\Windows\System32\cpwmon64.dll
2014-07-31 00:16 - 2011-01-24 14:40 - 00041472 _____ () C:\Windows\system32\spool\PRTPROCS\x64\KOBJUAAP.DLL
2010-12-22 11:15 - 2010-12-22 11:15 - 00468992 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAC.DLL
2010-12-22 11:14 - 2010-12-22 11:14 - 03540992 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAU.DLL
2010-12-22 11:15 - 2010-12-22 11:15 - 03424768 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAR.DLL
2010-12-22 11:15 - 2010-12-22 11:15 - 00187904 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAS.DLL
2010-04-26 19:04 - 2010-04-26 19:04 - 00648704 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAO.DLL
2010-12-22 11:15 - 2010-12-22 11:15 - 02368512 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUTAD.DLL
2011-01-24 13:50 - 2011-01-24 13:50 - 00419840 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAC.DLL
2011-01-24 13:49 - 2011-01-24 13:49 - 03385344 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAU.DLL
2011-01-24 13:51 - 2011-01-24 13:51 - 03424768 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAR.DLL
2011-01-24 13:51 - 2011-01-24 13:51 - 00188416 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAS.DLL
2010-01-27 13:59 - 2010-01-27 13:59 - 00648704 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAO.DLL
2011-01-24 13:51 - 2011-01-24 13:51 - 03372544 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUJAD.DLL
2011-01-24 14:40 - 2011-01-24 14:40 - 00442368 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUAAC.DLL
2011-01-24 14:39 - 2011-01-24 14:39 - 00188416 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUAAS.DLL
2011-01-25 16:26 - 2011-01-25 16:26 - 01828352 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUWAC.DLL
2011-01-25 16:23 - 2011-01-25 16:23 - 00187392 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\KOBJUWAS.DLL
2014-07-08 21:05 - 2014-06-24 04:53 - 00600576 _____ () C:\Program Files (x86)\TrialReset\TrialReset.exe
2014-08-20 06:22 - 2014-08-20 06:22 - 04304896 _____ () C:\ProgramData\WinSpeed\WinSpeed_x64.dll
2014-05-01 21:29 - 2014-05-01 21:29 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2010-01-19 02:49 - 2010-01-19 02:49 - 00805888 _____ () C:\Windows\system32\M30-1WDV.dll
2014-07-26 13:17 - 2014-08-18 15:51 - 00746536 _____ () C:\Program Files (x86)\Emsisoft Anti-Malware\fw32.dll
2014-09-03 19:21 - 2014-09-03 19:21 - 00619008 _____ () C:\ProgramData\surfkeePita\UZaFWpjX.dll
2012-09-23 20:43 - 2012-09-23 20:43 - 00010240 _____ () C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\locale\de_de\acrotray.deu
2014-01-23 15:55 - 2014-01-23 15:55 - 01030312 _____ () C:\Program Files (x86)\Microsoft Office\Office15\ADDINS\UmOutlookAddin.dll
2014-01-23 15:55 - 2014-01-23 15:55 - 00321704 _____ () C:\Program Files (x86)\Microsoft Office\Office15\msfad.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/04/2014 09:01:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm OUTLOOK.EXE, Version 15.0.4615.1000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 137c

Startzeit: 01cfc8727e3cd7e8

Endzeit: 23

Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE

Berichts-ID: df3566dd-3465-11e4-8297-9cd21eec58b2

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (09/04/2014 08:45:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm OUTLOOK.EXE, Version 15.0.4615.1000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 2624

Startzeit: 01cfc86ed9a0f864

Endzeit: 36

Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE

Berichts-ID: 8a2212d9-3463-11e4-8297-9cd21eec58b2

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (09/04/2014 08:45:06 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm MSPUB.EXE, Version 15.0.4629.1000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 2574

Startzeit: 01cfc7c8a0d17e85

Endzeit: 52

Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office15\MSPUB.EXE

Berichts-ID: 927a5d66-3463-11e4-8297-9cd21eec58b2

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (09/04/2014 08:44:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm iexplore.exe, Version 11.0.9600.17239 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1294

Startzeit: 01cfc75a72708ed1

Endzeit: 786

Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe

Berichts-ID: 5c02a7f3-3463-11e4-8297-9cd21eec58b2

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (09/04/2014 08:42:17 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm IEXPLORE.EXE, Version 11.0.9600.17239 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1004

Startzeit: 01cfc75a72bcdb09

Endzeit: 666

Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Berichts-ID: 2a620dc1-3463-11e4-8297-9cd21eec58b2

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (09/04/2014 08:33:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm OUTLOOK.EXE, Version 15.0.4615.1000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 20c4

Startzeit: 01cfc7a81d565edb

Endzeit: 859

Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE

Berichts-ID: b17d48af-3461-11e4-8297-9cd21eec58b2

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (09/03/2014 08:47:43 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile  UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (09/01/2014 11:33:17 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT-AUTORITÄT)
Description: There was an error with the Windows Location Provider database

Error: (09/01/2014 08:09:15 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile  UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (08/29/2014 01:00:14 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile  UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.


System errors:
=============
Error: (09/04/2014 11:26:27 AM) (Source: DCOM) (EventID: 10010) (User: laptop)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (09/04/2014 11:22:18 AM) (Source: DCOM) (EventID: 10010) (User: laptop)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (09/04/2014 11:21:47 AM) (Source: DCOM) (EventID: 10010) (User: laptop)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (09/03/2014 10:17:57 AM) (Source: DCOM) (EventID: 10010) (User: laptop)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (09/03/2014 07:54:41 AM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden.

Error: (09/03/2014 00:35:41 AM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden.

Error: (09/03/2014 00:35:40 AM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden.

Error: (09/03/2014 00:35:40 AM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden.

Error: (09/03/2014 00:35:40 AM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden.

Error: (09/03/2014 00:35:40 AM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR10 gefunden.


Microsoft Office Sessions:
=========================
Error: (09/04/2014 09:01:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: OUTLOOK.EXE15.0.4615.1000137c01cfc8727e3cd7e823C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXEdf3566dd-3465-11e4-8297-9cd21eec58b2

Error: (09/04/2014 08:45:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: OUTLOOK.EXE15.0.4615.1000262401cfc86ed9a0f86436C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE8a2212d9-3463-11e4-8297-9cd21eec58b2

Error: (09/04/2014 08:45:06 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: MSPUB.EXE15.0.4629.1000257401cfc7c8a0d17e8552C:\Program Files (x86)\Microsoft Office\Office15\MSPUB.EXE927a5d66-3463-11e4-8297-9cd21eec58b2

Error: (09/04/2014 08:44:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe11.0.9600.17239129401cfc75a72708ed1786C:\Program Files\Internet Explorer\iexplore.exe5c02a7f3-3463-11e4-8297-9cd21eec58b2

Error: (09/04/2014 08:42:17 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17239100401cfc75a72bcdb09666C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE2a620dc1-3463-11e4-8297-9cd21eec58b2

Error: (09/04/2014 08:33:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: OUTLOOK.EXE15.0.4615.100020c401cfc7a81d565edb859C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXEb17d48af-3461-11e4-8297-9cd21eec58b2

Error: (09/03/2014 08:47:43 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"c:\program files (x86)\microsoft office\Office15\lync.exe.Manifestc:\program files (x86)\microsoft office\Office15\UccApi.DLL1

Error: (09/01/2014 11:33:17 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT-AUTORITÄT)
Description: -2147024883

Error: (09/01/2014 08:09:15 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"c:\program files (x86)\microsoft office\Office15\lync.exe.Manifestc:\program files (x86)\microsoft office\Office15\UccApi.DLL1

Error: (08/29/2014 01:00:14 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"c:\program files (x86)\microsoft office\Office15\lync.exe.Manifestc:\program files (x86)\microsoft office\Office15\UccApi.DLL1


==================== Memory info =========================== 

Processor: Intel(R) Pentium(R) CPU 2020M @ 2.40GHz
Percentage of memory in use: 59%
Total physical RAM: 3975.27 MB
Available physical RAM: 1597.4 MB
Total Pagefile: 6535.27 MB
Available Pagefile: 3211.91 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.36 GB) (Free:189.92 GB) NTFS
Drive d: () (Fixed) (Total:232.88 GB) (Free:63.17 GB) NTFS
Drive e: (WI_WIG_010) (CDROM) (Total:0.08 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: D9FA2484)

Partition: GPT Partition Type.

==================== End Of Log ============================
         
Was mir auch noch aufgefallen ist, dass sich manchmal nun auch automatisch eine weitere Seite öffnet mit der Domain: hxxp://dailysaving.me oder hxxp://p.display-trk.com

Danke
__________________

Geändert von haiflosse (04.09.2014 um 23:03 Uhr)

Alt 05.09.2014, 07:36   #4
Warlord711
/// TB-Ausbilder
 
lenovo g700 surkfeepita und winspeed deinstallieren - Standard

lenovo g700 surkfeepita und winspeed deinstallieren



Zitat:
Platform: Windows 8.1 Enterprise (X64) OS Language: Deutsch (Deutschland)

127.0.0.1 lmlicenses.wip4.adobe.com
127.0.0.1 lm.licenses.adobe.com

Task: {DF9569C7-627B-4BA6-9E65-FFAFEB2CAE0A} - System32\Tasks\AutoKMSCustom => C:\Windows\AutoKMS\AutoKMS.exe [2014-06-22] ()
Die von mir gelisteten Einträge deuten stark darauf hin, dass auf diesem Rechner Software benutzt wird, die nicht legal erworben wurde.

Ausserdem ist das Betriebsystem nicht Original.

Supportstopp
Lesestoff:
Cracks und Keygens
Den Kopierschutz von Software zu umgehen ist nach geltendem Recht illegal. Die Logfiles deuten stark darauf hin, dass du nicht legal erworbene Software einsetzt. Zudem sind Cracks und Patches aus dubioser Quelle sehr oft mit Schädlingen versehen, womit man sich also fast vorsätzlich infiziert.

Wir haben uns hier auf dem Board darauf geeinigt, dass wir an dieser Stelle nicht weiter bereinigen, da wir ein solches Vorgehen nicht unterstützen. Hinzu kommt, dass wir dich in unserer Anleitung und auch in diesem Wichtig-Thema unmissverständlich darauf hingewiesen haben, wie wir damit umgehen werden. Saubere, gute Software hat seinen Preis und die Softwarefirmen leben von diesen Einnahmen.

Das Thema wird erst nach Entfernung fortgeführt. Da dies eine Neuinstallation von Windows voraussetzt, ist der Support beendet.
__________________
Lerne, zurück zu schlagen und unterstütze uns!
TB Akademie | Spende | Lob & Kritik

Antwort

Themen zu lenovo g700 surkfeepita und winspeed deinstallieren
automatisch, deinstalliere, deinstallieren, ebook, emsisoft, entdeck, entdeckt, firewall, google, keine updates, lenovo, modus, notebook, passieren, programme, programmen, speed, updates, weiterhelfen, werbung, windows, windows 8



Ähnliche Themen: lenovo g700 surkfeepita und winspeed deinstallieren


  1. 'Polizei' - Trojaner auf Tablet (Lenovo)
    Log-Analyse und Auswertung - 01.06.2015 (1)
  2. Lenovo T61
    Log-Analyse und Auswertung - 24.02.2015 (2)
  3. Lenovo - Fehler bei Update auf Win 8.1
    Alles rund um Windows - 02.02.2015 (6)
  4. Bluescreen - Polizeiwarnung - Lenovo Ultrabook startet nur bis Lenovo-Symbol!
    Mülltonne - 08.10.2014 (1)
  5. Lenovo White Screen
    Log-Analyse und Auswertung - 18.07.2014 (7)
  6. lenovo g570 testen
    Plagegeister aller Art und deren Bekämpfung - 17.03.2014 (9)
  7. Lenovo X121e Bluetooth Problem
    Plagegeister aller Art und deren Bekämpfung - 03.12.2013 (1)
  8. GVU Trojaner auf lenovo notbook
    Plagegeister aller Art und deren Bekämpfung - 31.07.2013 (13)
  9. BKA-Trojaner Win 7 Lenovo-Notebook
    Log-Analyse und Auswertung - 24.06.2013 (17)
  10. Lenovo 520 Notebook
    Log-Analyse und Auswertung - 20.05.2013 (18)
  11. 4 GB RAM für Lenovo S430
    Netzwerk und Hardware - 06.01.2013 (11)
  12. GVU-Trojaner auf Lenovo IdeaPad S12
    Plagegeister aller Art und deren Bekämpfung - 02.01.2013 (22)
  13. Lenovo langsam
    Log-Analyse und Auswertung - 01.03.2012 (8)
  14. Lenovo erneut mit Trojaner-Problemen
    Nachrichten - 19.10.2010 (0)
  15. OpenSuse Auf Lenovo S10 Treiber?
    Alles rund um Mac OSX & Linux - 19.02.2010 (3)
  16. Lenovo-Laptop von meiner Mutter HJT-Log
    Mülltonne - 28.11.2008 (1)
  17. Lenovo - TR/Drop.Agent.bct
    Plagegeister aller Art und deren Bekämpfung - 09.10.2008 (6)

Zum Thema lenovo g700 surkfeepita und winspeed deinstallieren - Ich hier ein Lenovo g700 Notebook mit Windows 8 und emsisoft Schutz. Jetzt habe ich bemerkt, dass ich bei Google immer automatisch Werbung von surkfeepita bekomme. Habe dies bei meinen - lenovo g700 surkfeepita und winspeed deinstallieren...
Archiv
Du betrachtest: lenovo g700 surkfeepita und winspeed deinstallieren auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.