| 
 Windows 7: Vermutlich Rootkit-Virus
 Hallo zusammen 
Seit ca. einem Monat bemerkte ich Veränderungen bei der Arbeit mit meinem Computer. 
Zuerst eine nervige Searchbar(buenosearch.br) in Chrome, dann öffnen von Werbeseiten und  java-Fehlermeldungsfenster. 
Kürzlich dann eine Mitteilung meines Providers, dass am 16.03.14 Viren, Würmer oder Trojaner über meinen Account versendet wurden.  
Meine Antimaleware(malewarebytes)- und Virensoftware(Norton 360) konnten zwar nichts finden, jedoch hat symantec-help eine schädliche Datei gelistet welche danach auch prompt entfernt wurde. 
Inzwischen habe ich das vom Provider empfohlene Securypack installiert (F-Secure) und den EU-cleaner HitmanPro welcher nochmals drei Dateien listete.  
Die Probleme bestehen jedoch weiterhin ausser der searchbar welche ich entfernen konnte.  
Würde mich sehr über eine Hilfe freuen.  
Freundliche Grüsse 
Walter  
HitmanPro:   Code: 
 HitmanPro 3.7.9.214www.hitmanpro.com
 
 Computer name . . . . : wstoll-PC
 Windows . . . . . . . : 6.1.1.7601.X64/4
 User name . . . . . . : wstoll-PC\wstoll
 UAC . . . . . . . . . : Enabled
 License . . . . . . . : Trial (27 days left)
 
 Scan date . . . . . . : 2014-03-27 00:19:07
 Scan mode . . . . . . : Normal
 Scan duration . . . . : 2m 57s
 Disk access mode  . . : Direct disk access (SRB)
 Cloud . . . . . . . . : Internet
 Reboot  . . . . . . . : No
 
 Threats . . . . . . . : 3
 Traces  . . . . . . . : 3
 
 Objects scanned . . . : 1'609'790
 Files scanned . . . . : 70'288
 Remnants scanned  . . : 447'539 files / 1'091'963 keys
 
 Malware remnants ____________________________________________________________
 
 buenosearch.com
 C:\Users\wstoll\AppData\Local\Google\Chrome\User Data\Default\Web Data
 
 start.mysearchdial.com
 C:\Users\wstoll\AppData\Local\Google\Chrome\User Data\Default\Web Data
 
 HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}\ (Adware.MyWebSearch) -> Deleted
 Defogger:   Code: 
 defogger_disable by jpshortstuff (23.02.10.1)Log created at 20:41 on 29/03/2014 (wstoll)
 
 Checking for autostart values...
 HKCU\~\Run values retrieved.
 HKLM\~\Run values retrieved.
 
 Checking for services/drivers...
 
 
 -=E.O.F=-
 FRST:   Code: 
 Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014Ran by wstoll (administrator) on wstoll-PC on 29-03-2014 20:06:02
 Running from C:\Users\wstoll\Desktop
 Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
 Internet Explorer Version 11
 Boot Mode: Normal
 
 The only official download link for FRST:
 Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
 Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
 Download link from any site other than Bleeping Computer is unpermitted or outdated.
 See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
 ==================== Processes (Whitelisted) =================
 
 (AMD) C:\Windows\system32\atiesrxx.exe
 (AMD) C:\Windows\system32\atieclxx.exe
 (Microsoft Corporation) C:\Windows\system32\WLANExt.exe
 (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
 (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
 (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
 (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
 (F-Secure Corporation) C:\Program Files (x86)\Internet Security Package\fshoster32.exe
 (F-Secure Corporation) C:\Program Files (x86)\Internet Security Package\apps\CCF_Reputation\fsorsp.exe
 (Acer Incorporated) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
 (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
 (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
 (F-Secure Corporation) C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Anti-Virus\FSGK32.EXE
 (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
 (Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
 (Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
 (Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
 (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
 (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe
 (Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
 (Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe
 (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
 (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
 (PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
 (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
 (Softwareentwicklung Remus - ArchiCrypt) C:\Windows\SysWOW64\STGRAMDiskHandler64.exe
 (Microsoft Corporation) C:\Windows\system32\UI0Detect.exe
 (Microsoft Corporation) C:\Windows\System32\vds.exe
 (Microsoft Corporation) C:\Windows\system32\wbengine.exe
 (Microsoft Corporation) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
 () C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe
 () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe
 (O&O Software GmbH) C:\Program Files\OO Software\DiskImage\oodiag.exe
 (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
 (Microsoft Corporation) C:\Windows\System32\vdsldr.exe
 (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
 (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
 (F-Secure Corporation) C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Common\FSMA32.EXE
 (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
 (SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
 (WiseCleaner.com) C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe
 (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
 (F-Secure Corporation) C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Common\FSHDLL64.EXE
 (O&O Software GmbH) C:\Program Files\OO Software\DiskImage\ooditray.exe
 (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
 (Logitech Inc.) C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe
 (ContentFinder Company) C:\Users\wstoll\AppData\Local\ContentFinder.exe
 (Steganos Software GmbH) C:\Program Files (x86)\Steganos Privacy Suite 14\SteganosBrowserMonitor.exe
 () C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe
 (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
 (PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
 (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
 (F-Secure Corporation) C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Anti-Virus\fssm32.exe
 (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
 () C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
 () C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
 (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
 () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe
 (F-Secure Corporation) C:\Program Files (x86)\Internet Security Package\fshoster32.exe
 (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
 (F-Secure Corporation) C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Common\FSM32.EXE
 (Steganos Software GmbH) C:\Program Files (x86)\Steganos Privacy Suite 14\SteganosHotKeyService.exe
 (Steganos Software GmbH) C:\Program Files (x86)\Steganos Privacy Suite 14\fredirstarter.exe
 (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
 (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
 (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
 (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
 (CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
 (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
 (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
 (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
 (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
 
 
 ==================== Registry (Whitelisted) ==================
 
 HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-05] (Realtek Semiconductor)
 HKLM\...\Run: [OODITRAY.EXE] - C:\Program Files\OO Software\DiskImage\ooditray.exe [4986672 2013-09-09] (O&O Software GmbH)
 HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-11-10] (Advanced Micro Devices, Inc.)
 HKLM-x32\...\Run: [Hotkey Utility] - C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe [636520 2012-02-07] ()
 HKLM-x32\...\Run: [hpqSRMon] - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
 HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
 HKLM-x32\...\Run: [] - [X]
 HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
 HKLM-x32\...\Run: [SSDMonitor] - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [105120 2012-08-21] (PC Tools)
 HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
 HKLM-x32\...\Run: [LogitechQuickCamRibbon] - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2793304 2009-10-14] ()
 HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
 HKLM-x32\...\Run: [F-Secure Hoster (43655)] - C:\Program Files (x86)\Internet Security Package\fshoster32.exe [191528 2013-12-11] (F-Secure Corporation)
 HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
 HKLM-x32\...\Run: [F-Secure Manager] - C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Common\FSM32.EXE [310312 2013-11-26] (F-Secure Corporation)
 HKLM-x32\...\Run: [Steganos HotKeys] - C:\Program Files (x86)\Steganos Privacy Suite 14\SteganosHotKeyService.exe [100864 2014-02-25] (Steganos Software GmbH)
 HKLM-x32\...\Run: [SSS14 File Redirection Starter] - C:\Program Files (x86)\Steganos Privacy Suite 14\fredirstarter.exe [17920 2014-02-25] (Steganos Software GmbH)
 HKU\S-1-5-21-149087622-1949021618-103181132-1000\...\Run: [Logitech Vid] - C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe [5458704 2009-07-16] (Logitech Inc.)
 HKU\S-1-5-21-149087622-1949021618-103181132-1000\...\Run: [ContentFinder] - C:\Users\wstoll\AppData\Local\ContentFinder.exe [160256 2014-02-21] (ContentFinder Company)
 HKU\S-1-5-21-149087622-1949021618-103181132-1000\...\Run: [SSS14 Browser Monitor] - C:\Program Files (x86)\Steganos Privacy Suite 14\SteganosBrowserMonitor.exe [70656 2014-02-25] (Steganos Software GmbH)
 HKU\S-1-5-21-149087622-1949021618-103181132-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
 Startup: C:\Users\wstoll\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
 ShortcutTarget: Logitech . Produktregistrierung.lnk -> C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (Leader Technologies/Logitech)
 
 ==================== Internet (Whitelisted) ====================
 
 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.ch/
 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
 SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 BHO: SoundFrost - {081524f7-7ed8-43ff-b01e-915c410a9cbe} - C:\Program Files (x86)\Download Free Music\SoundFrost64.dll (SoundFrost Company)
 BHO: Apps Hat - {11111111-1111-1111-1111-110411851159} -  No File
 BHO: Cablecom Online Safety - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - C:\Program Files (x86)\Internet Security Package\apps\OnlineSafety\browser\install\fs_ie_https\fs_ie_https64.dll (F-Secure Corporation)
 BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
 BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
 BHO: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files (x86)\Free Games 111\ScriptHost64.dll No File
 BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
 BHO-x32: SoundFrost - {081524f7-7ed8-43ff-b01e-915c410a9cbe} - C:\Program Files (x86)\Download Free Music\SoundFrost.dll (SoundFrost Company)
 BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
 BHO-x32: Cablecom Online Safety - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - C:\Program Files (x86)\Internet Security Package\apps\OnlineSafety\browser\install\fs_ie_https\fs_ie_https.dll (F-Secure Corporation)
 BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
 BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
 BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
 BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
 BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
 Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Privacy Suite 14\SPMIEToolbar64.dll (Steganos Software GmbH)
 Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Privacy Suite 14\SPMIEToolbar.dll (Steganos Software GmbH)
 Toolbar: HKCU - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Privacy Suite 14\SPMIEToolbar64.dll (Steganos Software GmbH)
 DPF: HKLM-x32 {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
 DPF: HKLM-x32 {644E432F-49D3-41A1-8DD5-E099162EEEC5} hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
 Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
 Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
 Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
 Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
 Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
 Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
 Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
 Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
 Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
 
 FireFox:
 ========
 FF ProfilePath: C:\Users\wstoll\AppData\Roaming\Mozilla\Firefox\Profiles\7vmmqh7q.default
 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
 FF Plugin: @microsoft.com/GENUINE - disabled No File
 FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
 FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
 FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
 FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
 FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
 FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
 FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
 FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
 FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
 FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
 FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
 FF Extension: Ghostery - C:\Users\wstoll\AppData\Roaming\Mozilla\Firefox\Profiles\7vmmqh7q.default\Extensions\firefox@ghostery.com.xpi [2014-03-27]
 FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-11-12]
 FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Privacy Suite 14\spmplugin3
 FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Privacy Suite 14\spmplugin3 [2013-12-22]
 FF HKLM-x32\...\Firefox\Extensions: [{1b6ae957-f88b-466b-beee-33112bd5b8c9}] - C:\Program Files (x86)\Internet Security Package\apps\OnlineSafety\browser\deploy\fs_firefox_https
 FF Extension: Online Safety - C:\Program Files (x86)\Internet Security Package\apps\OnlineSafety\browser\deploy\fs_firefox_https [2014-03-23]
 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-11-12]
 FF HKCU\...\Firefox\Extensions: [freegames4357@BestOffers] - C:\Users\wstoll\AppData\Roaming\Mozilla\Extensions\freegames4357@BestOffers
 FF Extension: Free Games 111 - C:\Users\wstoll\AppData\Roaming\Mozilla\Extensions\freegames4357@BestOffers [2014-03-02]
 
 ==================== Services (Whitelisted) =================
 
 R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation)
 R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation)
 R2 fshoster; C:\Program Files (x86)\Internet Security Package\fshoster32.exe [191528 2013-12-11] (F-Secure Corporation)
 R3 FSMA; C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Common\FSMA32.EXE [216104 2013-11-26] (F-Secure Corporation)
 R2 FSORSPClient; C:\Program Files (x86)\Internet Security Package\apps\CCF_Reputation\fsorsp.exe [60352 2013-06-10] (F-Secure Corporation)
 R2 GREGService; C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe [28264 2012-02-29] (Acer Incorporated)
 S2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2014-03-27] (SurfRight B.V.)
 R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
 R2 Live Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [255376 2012-02-07] (Acer Incorporated)
 R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
 S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
 R2 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
 S2 MCLIENT; C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccSvcHst.exe [143928 2012-12-05] (Symantec Corporation)
 R2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe [132504 2013-09-08] (Symantec Corporation)
 R2 OO DiskImage; C:\Program Files\OO Software\DiskImage\oodiag.exe [6258480 2013-09-09] (O&O Software GmbH)
 R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [794272 2012-08-21] (PC Tools)
 R2 Steganos Volatile Disk; C:\Windows\SysWOW64\STGRAMDiskHandler64.exe [450560 2013-07-17] (Softwareentwicklung Remus - ArchiCrypt)
 S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-12-09] (WiseCleaner.com)
 R2 WO_LiveService; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe [885096 2013-10-08] ()
 R2 WSWNDA3100v2; C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [303360 2011-12-14] ()
 S4 楗敳潂瑯獁楳瑳湡tĀ"; 㩃停潲牧浡䘠汩獥⠠㡸⤶坜獩履楗敳䌠牡㘳尵潂瑯楔敭攮數 [X]
 
 ==================== Drivers (Whitelisted) ====================
 
 R1 ccSet_MCLIENT; C:\Windows\system32\drivers\MCLIENTx64\0302020.00C\ccSetx64.sys [168096 2012-10-04] (Symantec Corporation)
 R3 F-Secure Gatekeeper; C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [203304 2014-03-20] (F-Secure Corporation)
 R1 F-Secure HIPS; C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\HIPS\drivers\fshs.sys [69480 2014-03-20] (F-Secure Corporation)
 R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [56016 2014-03-20] ()
 R3 fsni; C:\Program Files (x86)\Internet Security Package\apps\CCF_Scanning\fsni64.sys [82984 2013-11-08] (F-Secure Corporation)
 R1 fsvista; C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [13248 2013-06-24] ()
 R2 LiveTunerPM; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerProcessMonitor64.sys [12824 2011-03-08] ()
 R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
 S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
 R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
 S3 NPF; C:\Windows\System32\DRIVERS\npf.sys [47632 2010-02-03] (CACE Technologies, Inc.)
 R0 oodisr; C:\Windows\System32\DRIVERS\oodisr.sys [116936 2013-09-09] (O&O Software GmbH)
 R0 oodisrh; C:\Windows\System32\DRIVERS\oodisrh.sys [41160 2013-09-09] (O&O Software GmbH)
 R0 oodivd; C:\Windows\System32\DRIVERS\oodivd.sys [255688 2013-09-09] (O&O Software GmbH)
 R0 oodivdh; C:\Windows\System32\DRIVERS\oodivdh.sys [44744 2013-09-09] (O&O Software GmbH)
 R1 SLEE_18_DRIVER; C:\Windows\Sleen1864.sys [109144 2014-01-30] (Softwareentwicklung Remus - ArchiCrypt - )
 R1 STGMFEngine64; C:\Windows\system32\drivers\STGMFEngine64.sys [28576 2013-07-17] (Softwareentwicklung Remus - ArchiCrypt.com)
 U3 DfSdkS;
 
 ==================== NetSvcs (Whitelisted) ===================
 
 
 ==================== One Month Created Files and Folders ========
 
 2014-03-29 20:06 - 2014-03-29 20:06 - 00024458 _____ () C:\Users\wstoll\Desktop\FRST.txt
 2014-03-29 20:05 - 2014-03-29 20:06 - 00000000 ____D () C:\FRST
 2014-03-29 19:48 - 2014-03-29 19:45 - 02157056 _____ (Farbar) C:\Users\wstoll\Desktop\FRST64.exe
 2014-03-29 19:45 - 2014-03-29 19:45 - 02157056 _____ (Farbar) C:\Users\wstoll\Downloads\FRST64.exe
 2014-03-29 19:45 - 2014-03-29 19:45 - 00001150 _____ () C:\Users\wstoll\Desktop\FRST64 - Verknüpfung.lnk
 2014-03-28 00:29 - 2014-03-28 00:29 - 00275576 _____ () C:\Windows\Minidump\032814-21200-01.dmp
 2014-03-27 10:35 - 2014-03-27 10:35 - 00000000 ____D () C:\Users\wstoll\AppData\Local\Macromedia
 2014-03-27 10:04 - 2014-03-27 10:05 - 00000000 ____D () C:\Users\wstoll\AppData\Local\Mozilla
 2014-03-27 10:04 - 2014-03-27 10:04 - 00000000 ____D () C:\ProgramData\Mozilla
 2014-03-27 10:04 - 2014-03-27 10:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
 2014-03-26 11:01 - 2014-03-28 00:29 - 612103415 _____ () C:\Windows\MEMORY.DMP
 2014-03-26 11:01 - 2014-03-26 11:01 - 00275576 _____ () C:\Windows\Minidump\032614-14710-01.dmp
 2014-03-25 10:33 - 2014-03-29 20:06 - 00139475 _____ () C:\Windows\WindowsUpdate.log
 2014-03-25 10:33 - 2014-03-25 10:33 - 00098320 _____ () C:\Users\wstoll\AppData\Local\GDIPFONTCACHEV1.DAT
 2014-03-25 10:30 - 2014-03-29 20:02 - 00004540 _____ () C:\Windows\PFRO.log
 2014-03-25 10:30 - 2014-03-29 20:02 - 00001568 _____ () C:\Windows\setupact.log
 2014-03-25 10:30 - 2014-03-25 10:30 - 00000000 _____ () C:\Windows\setuperr.log
 2014-03-24 23:36 - 2014-03-24 23:36 - 09988304 _____ (SurfRight B.V.) C:\Users\wstoll\Downloads\HitmanPro.exe
 2014-03-24 23:14 - 2014-03-24 23:14 - 00098424 _____ () C:\Users\wstoll\Documents\HitmanPro_20140324_2313.log
 2014-03-24 23:13 - 2014-03-28 00:01 - 00000630 _____ () C:\Windows\system32\.crusader
 2014-03-24 23:07 - 2014-03-24 23:07 - 00000000 ____D () C:\Program Files\HitmanPro
 2014-03-24 23:05 - 2014-03-24 23:14 - 00000000 ____D () C:\ProgramData\HitmanPro
 2014-03-24 23:05 - 2014-03-24 23:05 - 10820032 _____ (SurfRight B.V.) C:\Users\wstoll\Downloads\hitmanpro_x64.exe
 2014-03-23 10:01 - 2014-03-23 10:01 - 04375224 _____ (F-Secure Corporation) C:\Users\wstoll\Downloads\F-SecureOnlineScanner.exe
 2014-03-22 00:32 - 2014-03-22 00:36 - 00000000 ____D () C:\Users\wstoll\Documents\Steganos Safe
 2014-03-22 00:21 - 2014-03-22 00:21 - 00001079 _____ () C:\Users\Public\Desktop\Privacy Suite Hauptmenü.lnk
 2014-03-21 22:17 - 2014-03-29 20:06 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
 2014-03-21 22:17 - 2014-03-27 10:34 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
 2014-03-21 22:17 - 2014-03-27 10:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
 2014-03-21 22:17 - 2014-03-27 10:34 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
 2014-03-21 00:34 - 2014-03-21 00:34 - 00037508 _____ () C:\Users\wstoll\Desktop\Monatsarbeitsplan 2014.ods
 2014-03-20 22:43 - 2014-03-20 22:43 - 00001943 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
 2014-03-20 22:43 - 2014-03-20 22:43 - 00000000 ____D () C:\Program Files\McAfee Security Scan
 2014-03-20 22:33 - 2014-03-29 18:44 - 00000618 _____ () C:\Windows\Tasks\Scheduled scanning task.job
 2014-03-20 22:33 - 2014-03-29 00:00 - 00003394 _____ () C:\Windows\System32\Tasks\Scheduled scanning task
 2014-03-20 22:25 - 2014-03-20 22:25 - 00056016 _____ () C:\Windows\system32\Drivers\fsbts.sys
 2014-03-20 22:25 - 2014-03-20 22:25 - 00020529 _____ () C:\Windows\prodsett_copy.ini
 2014-03-20 10:16 - 2014-03-20 10:16 - 09521103 _____ () C:\Users\Public\Desktop\fsdiag.zip
 2014-03-20 10:11 - 2014-03-20 22:26 - 00000000 ____D () C:\ProgramData\F-Secure
 2014-03-20 10:11 - 2014-03-20 10:16 - 00000000 ____D () C:\Program Files (x86)\Internet Security Package
 2014-03-20 10:11 - 2014-03-20 10:11 - 00002114 _____ () C:\Users\Public\Desktop\Launch pad.lnk
 2014-03-20 10:10 - 2014-03-20 10:10 - 01162176 _____ (F-Secure Corporation) C:\Users\wstoll\Downloads\Security_Installer.EXE
 2014-03-20 10:08 - 2014-03-20 10:08 - 00001991 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
 2014-03-20 08:21 - 2014-03-20 08:21 - 05730984 _____ (Symantec Corporation) C:\Users\wstoll\Downloads\SymHelp (2).exe
 2014-03-20 01:04 - 2014-03-20 01:04 - 05730984 _____ (Symantec Corporation) C:\Users\wstoll\Downloads\SymHelp (1).exe
 2014-03-20 00:00 - 2014-03-20 00:00 - 00001734 _____ () C:\ProgramData\SMRResults410.dat
 2014-03-19 23:59 - 2014-03-19 23:59 - 00000883 _____ () C:\Windows\system32\Drivers\etc\hosts.bak
 2014-03-19 23:53 - 2014-03-19 23:53 - 00000000 ____D () C:\Users\wstoll\Desktop\Bösartige Software
 2014-03-19 23:53 - 2014-03-19 23:53 - 00000000 ____D () C:\Users\wstoll\AppData\Local\Symantec Power Eraser
 2014-03-19 23:37 - 2014-03-19 23:37 - 05730984 _____ (Symantec Corporation) C:\Users\wstoll\Downloads\SymHelp.exe
 2014-03-19 10:48 - 2014-03-19 10:48 - 00546728 _____ (Symantec) C:\Users\wstoll\Downloads\Setup (1).exe
 2014-03-14 23:48 - 2014-03-14 23:48 - 01562415 _____ () C:\Users\wstoll\Downloads\tutor.zip
 2014-03-13 23:24 - 2014-03-13 23:58 - 00000000 ____D () C:\Users\wstoll\Documents\Meine Homepage
 2014-03-12 09:31 - 2014-03-01 07:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
 2014-03-12 09:31 - 2014-03-01 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
 2014-03-12 09:31 - 2014-03-01 06:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
 2014-03-12 09:31 - 2014-03-01 05:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
 2014-03-12 09:31 - 2014-03-01 05:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
 2014-03-12 09:31 - 2014-03-01 05:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
 2014-03-12 09:31 - 2014-03-01 05:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
 2014-03-12 09:31 - 2014-03-01 05:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
 2014-03-12 09:31 - 2014-03-01 05:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
 2014-03-12 09:31 - 2014-03-01 05:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
 2014-03-12 09:31 - 2014-03-01 05:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
 2014-03-12 09:31 - 2014-03-01 05:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
 2014-03-12 09:31 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
 2014-03-12 09:31 - 2014-03-01 05:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
 2014-03-12 09:31 - 2014-03-01 05:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
 2014-03-12 09:31 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
 2014-03-12 09:31 - 2014-03-01 05:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
 2014-03-12 09:31 - 2014-03-01 04:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
 2014-03-12 09:31 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
 2014-03-12 09:31 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
 2014-03-12 09:31 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
 2014-03-12 09:31 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
 2014-03-12 09:31 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
 2014-03-12 09:31 - 2014-03-01 04:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
 2014-03-12 09:31 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
 2014-03-12 09:31 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
 2014-03-12 09:31 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
 2014-03-12 09:31 - 2014-03-01 04:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
 2014-03-12 09:31 - 2014-03-01 04:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
 2014-03-12 09:31 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
 2014-03-12 09:31 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
 2014-03-12 09:31 - 2014-03-01 04:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
 2014-03-12 09:31 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
 2014-03-12 09:31 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
 2014-03-12 09:31 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
 2014-03-12 09:31 - 2014-03-01 03:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
 2014-03-12 09:31 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
 2014-03-12 09:31 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
 2014-03-12 09:31 - 2014-03-01 03:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
 2014-03-12 09:31 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
 2014-03-12 09:31 - 2014-02-07 02:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
 2014-03-12 09:31 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
 2014-03-12 09:31 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
 2014-03-12 09:31 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
 2014-03-12 09:30 - 2014-02-04 03:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
 2014-03-12 09:30 - 2014-02-04 03:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
 2014-03-12 09:30 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
 2014-03-12 09:30 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
 2014-03-12 00:27 - 2014-03-12 00:27 - 05128584 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
 2014-03-05 22:25 - 2014-03-20 10:01 - 00000000 ____D () C:\ProgramData\Screentime
 2014-03-05 22:25 - 2014-03-05 22:26 - 00000000 ____D () C:\Users\wstoll\AppData\Local\Screentime
 2014-03-05 22:24 - 2014-03-05 22:24 - 14235441 _____ () C:\Users\wstoll\Downloads\mazda6_screensaver_pc_setup.zip
 2014-03-05 12:09 - 2014-03-05 12:09 - 00003224 _____ () C:\Windows\System32\Tasks\{BA687605-3DB8-4E7A-867E-D8ECAAB8E888}
 2014-03-04 19:30 - 2014-03-04 19:30 - 00001468 _____ () C:\Users\Public\Desktop\LibreOffice 4.1.lnk
 2014-03-04 19:19 - 2014-03-04 19:21 - 216141824 _____ () C:\Users\wstoll\Downloads\LibreOffice_4.1.5_Win_x86.msi
 2014-03-04 19:19 - 2014-03-04 19:20 - 07376896 _____ () C:\Users\wstoll\Downloads\LibreOffice_4.1.5_Win_x86_helppack_de.msi
 2014-03-04 18:59 - 2014-03-04 19:00 - 00042072 _____ () C:\Users\wstoll\rpro.log
 2014-03-04 18:59 - 2014-03-04 18:59 - 00001085 _____ () C:\Users\Public\Desktop\RescuePRO Deluxe.lnk
 2014-03-04 18:59 - 2014-03-04 18:59 - 00000000 ____D () C:\Users\wstoll\licman
 2014-03-04 18:59 - 2014-03-04 18:59 - 00000000 ____D () C:\Users\wstoll\AppData\Local\LC Technology Inc
 2014-03-04 18:59 - 2014-03-04 18:59 - 00000000 ____D () C:\Program Files (x86)\RescuePRO Deluxe
 2014-03-04 10:56 - 2014-03-04 11:06 - 00002036 _____ () C:\Users\wstoll\EasyTax_0_0.log
 2014-03-04 10:56 - 2014-03-04 10:56 - 00002029 _____ () C:\Users\Public\Desktop\EasyTax 2013 AG.lnk
 2014-03-04 10:54 - 2014-03-04 10:55 - 44437016 _____ (HWI Solutions AG) C:\Users\wstoll\Downloads\EasyTax2013AG_windowsJRE_1_0.exe
 2014-03-04 10:15 - 2014-03-04 10:15 - 00000000 ____D () C:\Users\wstoll\Wandern
 2014-03-03 09:35 - 2012-11-28 10:00 - 00171520 _____ () C:\Users\wstoll\Documents\Monatsarbeitsplan 12.xls
 2014-03-02 23:54 - 2014-03-02 23:54 - 00002973 _____ () C:\Users\wstoll\Desktop\CZPBatch.lnk
 2014-03-02 23:54 - 2014-03-02 23:54 - 00002973 _____ () C:\Users\wstoll\Desktop\CombineZP.lnk
 2014-03-02 23:54 - 2014-03-02 23:54 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CombineZP
 2014-03-02 23:54 - 2014-03-02 23:54 - 00000000 ____D () C:\Program Files (x86)\Alan Hadley
 2014-03-02 23:39 - 2014-03-02 23:41 - 10320896 _____ () C:\Users\wstoll\Downloads\CombineZP.msi
 2014-03-02 23:34 - 2014-03-02 23:34 - 00001063 _____ () C:\Users\Public\Desktop\DRI Tool 2.0 .lnk
 2014-03-02 23:34 - 2014-03-02 23:34 - 00000000 ____D () C:\Program Files (x86)\Traumflieger
 2014-03-02 23:33 - 2014-03-02 23:33 - 00771175 _____ (Traumflieger ) C:\Users\wstoll\Downloads\DRI_Tool_2_setup.exe
 2014-03-02 00:44 - 2014-03-02 00:44 - 00004030 _____ () C:\Windows\System32\Tasks\LaunchApp
 2014-03-02 00:37 - 2014-03-27 10:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
 2014-03-02 00:36 - 2014-03-27 10:04 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\Mozilla
 2014-03-02 00:36 - 2014-03-11 13:42 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\PerformerSoft
 2014-03-02 00:36 - 2013-06-19 14:58 - 00019456 _____ (PerformerSoft LLC) C:\Windows\system32\roboot64.exe
 2014-03-02 00:01 - 2014-03-29 20:02 - 00000296 _____ () C:\Windows\Tasks\MySearchDial.job
 2014-03-02 00:01 - 2014-03-02 00:02 - 00003240 _____ () C:\Windows\System32\Tasks\MySearchDial
 2014-03-02 00:01 - 2014-03-02 00:01 - 00000047 _____ () C:\Users\wstoll\AppData\Roaming\WB.CFG
 2014-03-01 23:43 - 2014-03-01 23:43 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\Mp3jam
 2014-03-01 23:18 - 2014-03-02 00:38 - 00044712 _____ () C:\Users\wstoll\AppData\Local\viewer.txt
 2014-03-01 23:18 - 2014-03-01 23:32 - 00000000 ____D () C:\Users\wstoll\AppData\Local\WebPlayer
 2014-03-01 23:18 - 2014-03-01 23:18 - 00000306 __RSH () C:\Users\wstoll\ntuser.pol
 2014-03-01 23:18 - 2014-02-21 15:05 - 00160256 _____ (ContentFinder Company) C:\Users\wstoll\AppData\Local\ContentFinder.exe
 2014-03-01 23:18 - 2013-08-07 15:32 - 02598912 _____ (Digia Plc and/or its subsidiary(-ies)) C:\Users\wstoll\AppData\Local\QtCore4.dll
 2014-03-01 23:18 - 2013-06-27 11:29 - 13112320 _____ (Digia Plc and/or its subsidiary(-ies)) C:\Users\wstoll\AppData\Local\QtWebKit4.dll
 2014-03-01 23:18 - 2013-06-27 10:16 - 08581632 _____ (Digia Plc and/or its subsidiary(-ies)) C:\Users\wstoll\AppData\Local\QtGui4.dll
 2014-03-01 23:18 - 2013-06-27 10:10 - 01053696 _____ (Digia Plc and/or its subsidiary(-ies)) C:\Users\wstoll\AppData\Local\QtNetwork4.dll
 2014-03-01 23:18 - 2013-03-18 17:45 - 01122304 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\wstoll\AppData\Local\libeay32.dll
 2014-03-01 23:18 - 2013-03-18 17:45 - 00274432 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\wstoll\AppData\Local\ssleay32.dll
 2014-03-01 23:18 - 2011-06-11 00:58 - 00773968 _____ (Microsoft Corporation) C:\Users\wstoll\AppData\Local\msvcr100.dll
 2014-03-01 23:18 - 2011-06-11 00:58 - 00421200 _____ (Microsoft Corporation) C:\Users\wstoll\AppData\Local\msvcp100.dll
 2014-03-01 00:10 - 2014-03-01 00:10 - 00047782 _____ () C:\Users\wstoll\Documents\Sysinfo28.02.2014.txt
 2014-02-27 12:46 - 2014-02-27 18:28 - 00022570 _____ () C:\Users\wstoll\Desktop\Ferienplan 2014.ods
 2014-02-27 12:44 - 2014-02-27 12:44 - 00072192 _____ () C:\Users\wstoll\Downloads\kalender-urlaubsplanung.xls
 2014-02-27 12:41 - 2014-02-27 12:41 - 00051712 _____ () C:\Users\wstoll\Downloads\kalender-2014-querformat-tage-nebeneinander (1).xls
 2014-02-27 12:40 - 2014-02-27 12:40 - 00047616 _____ () C:\Users\wstoll\Downloads\kalender-2014-querformat.xls
 2014-02-27 12:37 - 2014-02-27 12:37 - 00051712 _____ () C:\Users\wstoll\Downloads\kalender-2014-querformat-tage-nebeneinander.xls
 2014-02-27 12:34 - 2014-02-27 12:34 - 01344000 _____ () C:\Users\wstoll\Downloads\kalender-2014-a4-zweiseitig.xls
 2014-02-27 12:23 - 2014-02-27 12:31 - 00000000 ____D () C:\Users\wstoll\Documents\Ferienkalender
 2014-02-27 12:23 - 2014-02-27 12:23 - 00001737 _____ () C:\Users\wstoll\Desktop\Ferienkalender Vorlagen.lnk
 2014-02-27 12:23 - 2014-02-27 12:23 - 00000000 ____D () C:\Program Files (x86)\DeltaVision
 2014-02-27 12:22 - 2014-02-27 12:22 - 02077243 _____ (DeltaVision Informatik GmbH ) C:\Users\wstoll\Downloads\dvFerienKalender_V6.4.exe
 2014-02-27 11:27 - 2014-02-27 11:27 - 00000000 ____D () C:\Users\wstoll\Documents\Fax
 2014-02-27 10:24 - 2014-02-27 10:24 - 00185344 _____ () C:\Users\wstoll\Desktop\Monatsarbeitsplan 2014b.xls
 
 ==================== One Month Modified Files and Folders =======
 
 2014-03-29 20:06 - 2014-03-29 20:06 - 00024458 _____ () C:\Users\wstoll\Desktop\FRST.txt
 2014-03-29 20:06 - 2014-03-29 20:05 - 00000000 ____D () C:\FRST
 2014-03-29 20:06 - 2014-03-25 10:33 - 00139475 _____ () C:\Windows\WindowsUpdate.log
 2014-03-29 20:06 - 2014-03-21 22:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
 2014-03-29 20:03 - 2013-12-24 00:31 - 00000424 _____ () C:\Windows\Tasks\Wise Care 365.job
 2014-03-29 20:03 - 2013-12-24 00:14 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\Wise Care 365
 2014-03-29 20:03 - 2013-03-24 19:00 - 00000286 _____ () C:\Windows\Tasks\RMAutoUpdate.job
 2014-03-29 20:03 - 2013-03-18 07:38 - 00000000 ____D () C:\Program Files (x86)\PC Tools Registry Mechanic
 2014-03-29 20:02 - 2014-03-25 10:30 - 00004540 _____ () C:\Windows\PFRO.log
 2014-03-29 20:02 - 2014-03-25 10:30 - 00001568 _____ () C:\Windows\setupact.log
 2014-03-29 20:02 - 2014-03-02 00:01 - 00000296 _____ () C:\Windows\Tasks\MySearchDial.job
 2014-03-29 20:02 - 2013-12-25 17:47 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs
 2014-03-29 20:02 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
 2014-03-29 20:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
 2014-03-29 19:56 - 2012-09-26 17:19 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-149087622-1949021618-103181132-1000UA.job
 2014-03-29 19:45 - 2014-03-29 19:48 - 02157056 _____ (Farbar) C:\Users\wstoll\Desktop\FRST64.exe
 2014-03-29 19:45 - 2014-03-29 19:45 - 02157056 _____ (Farbar) C:\Users\wstoll\Downloads\FRST64.exe
 2014-03-29 19:45 - 2014-03-29 19:45 - 00001150 _____ () C:\Users\wstoll\Desktop\FRST64 - Verknüpfung.lnk
 2014-03-29 19:41 - 2009-07-14 05:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
 2014-03-29 19:41 - 2009-07-14 05:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
 2014-03-29 19:40 - 2013-03-24 19:00 - 00000418 _____ () C:\Windows\SysWOW64\AppLog.log
 2014-03-29 19:40 - 2013-03-18 07:38 - 00000286 _____ () C:\Windows\Tasks\RMSchedule.job
 2014-03-29 19:30 - 2012-09-26 20:13 - 00000000 ____D () C:\Users\wstoll\Documents\Software 2012
 2014-03-29 19:12 - 2012-10-11 00:12 - 00000000 ____D () C:\Users\wstoll\AppData\Local\CrashDumps
 2014-03-29 18:44 - 2014-03-20 22:33 - 00000618 _____ () C:\Windows\Tasks\Scheduled scanning task.job
 2014-03-29 00:00 - 2014-03-20 22:33 - 00003394 _____ () C:\Windows\System32\Tasks\Scheduled scanning task
 2014-03-28 01:20 - 2014-02-13 09:29 - 00007641 _____ () C:\Users\wstoll\AppData\Local\Resmon.ResmonCfg
 2014-03-28 00:31 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
 2014-03-28 00:29 - 2014-03-28 00:29 - 00275576 _____ () C:\Windows\Minidump\032814-21200-01.dmp
 2014-03-28 00:29 - 2014-03-26 11:01 - 612103415 _____ () C:\Windows\MEMORY.DMP
 2014-03-28 00:29 - 2012-11-25 14:05 - 00000000 ____D () C:\Windows\Minidump
 2014-03-28 00:01 - 2014-03-24 23:13 - 00000630 _____ () C:\Windows\system32\.crusader
 2014-03-27 10:35 - 2014-03-27 10:35 - 00000000 ____D () C:\Users\wstoll\AppData\Local\Macromedia
 2014-03-27 10:34 - 2014-03-21 22:17 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
 2014-03-27 10:34 - 2014-03-21 22:17 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
 2014-03-27 10:34 - 2014-03-21 22:17 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
 2014-03-27 10:06 - 2012-10-01 11:08 - 00000000 ____D () C:\Program Files (x86)\Google
 2014-03-27 10:06 - 2012-09-26 17:19 - 00000000 ____D () C:\Users\wstoll\AppData\Local\Google
 2014-03-27 10:05 - 2014-03-27 10:04 - 00000000 ____D () C:\Users\wstoll\AppData\Local\Mozilla
 2014-03-27 10:04 - 2014-03-27 10:04 - 00000000 ____D () C:\ProgramData\Mozilla
 2014-03-27 10:04 - 2014-03-27 10:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
 2014-03-27 10:04 - 2014-03-02 00:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
 2014-03-27 10:04 - 2014-03-02 00:36 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\Mozilla
 2014-03-26 11:01 - 2014-03-26 11:01 - 00275576 _____ () C:\Windows\Minidump\032614-14710-01.dmp
 2014-03-25 23:07 - 2012-09-25 17:22 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\Skype
 2014-03-25 21:56 - 2012-09-26 17:19 - 00001072 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-149087622-1949021618-103181132-1000Core.job
 2014-03-25 10:33 - 2014-03-25 10:33 - 00098320 _____ () C:\Users\wstoll\AppData\Local\GDIPFONTCACHEV1.DAT
 2014-03-25 10:30 - 2014-03-25 10:30 - 00000000 _____ () C:\Windows\setuperr.log
 2014-03-25 00:02 - 2013-12-24 00:31 - 00000404 _____ () C:\Windows\Tasks\Wise Turbo Checker.job
 2014-03-24 23:36 - 2014-03-24 23:36 - 09988304 _____ (SurfRight B.V.) C:\Users\wstoll\Downloads\HitmanPro.exe
 2014-03-24 23:14 - 2014-03-24 23:14 - 00098424 _____ () C:\Users\wstoll\Documents\HitmanPro_20140324_2313.log
 2014-03-24 23:14 - 2014-03-24 23:05 - 00000000 ____D () C:\ProgramData\HitmanPro
 2014-03-24 23:07 - 2014-03-24 23:07 - 00000000 ____D () C:\Program Files\HitmanPro
 2014-03-24 23:05 - 2014-03-24 23:05 - 10820032 _____ (SurfRight B.V.) C:\Users\wstoll\Downloads\hitmanpro_x64.exe
 2014-03-23 15:44 - 2012-10-30 00:29 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\Dropbox
 2014-03-23 15:42 - 2012-09-25 16:18 - 00000000 ___RD () C:\Users\wstoll\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
 2014-03-23 10:01 - 2014-03-23 10:01 - 04375224 _____ (F-Secure Corporation) C:\Users\wstoll\Downloads\F-SecureOnlineScanner.exe
 2014-03-23 09:56 - 2012-10-30 00:58 - 00000000 ___RD () C:\Users\wstoll\Dropbox
 2014-03-22 19:55 - 2012-09-26 17:19 - 00000000 ____D () C:\Users\wstoll\AppData\Local\Deployment
 2014-03-22 19:43 - 2012-12-20 09:48 - 00002158 _____ () C:\Windows\wininit.ini
 2014-03-22 00:36 - 2014-03-22 00:32 - 00000000 ____D () C:\Users\wstoll\Documents\Steganos Safe
 2014-03-22 00:32 - 2013-12-22 00:04 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\Steganos
 2014-03-22 00:21 - 2014-03-22 00:21 - 00001079 _____ () C:\Users\Public\Desktop\Privacy Suite Hauptmenü.lnk
 2014-03-22 00:21 - 2013-12-22 00:04 - 00000000 ____D () C:\Program Files (x86)\Steganos Privacy Suite 14
 2014-03-21 22:17 - 2012-09-25 16:20 - 00000000 ____D () C:\Users\wstoll\AppData\Local\Adobe
 2014-03-21 00:34 - 2014-03-21 00:34 - 00037508 _____ () C:\Users\wstoll\Desktop\Monatsarbeitsplan 2014.ods
 2014-03-20 23:09 - 2012-12-25 18:06 - 00000000 ____D () C:\Users\Charlie
 2014-03-20 22:43 - 2014-03-20 22:43 - 00001943 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
 2014-03-20 22:43 - 2014-03-20 22:43 - 00000000 ____D () C:\Program Files\McAfee Security Scan
 2014-03-20 22:26 - 2014-03-20 10:11 - 00000000 ____D () C:\ProgramData\F-Secure
 2014-03-20 22:25 - 2014-03-20 22:25 - 00056016 _____ () C:\Windows\system32\Drivers\fsbts.sys
 2014-03-20 22:25 - 2014-03-20 22:25 - 00020529 _____ () C:\Windows\prodsett_copy.ini
 2014-03-20 22:23 - 2012-03-29 12:41 - 00000000 ____D () C:\ProgramData\Norton
 2014-03-20 10:16 - 2014-03-20 10:16 - 09521103 _____ () C:\Users\Public\Desktop\fsdiag.zip
 2014-03-20 10:16 - 2014-03-20 10:11 - 00000000 ____D () C:\Program Files (x86)\Internet Security Package
 2014-03-20 10:11 - 2014-03-20 10:11 - 00002114 _____ () C:\Users\Public\Desktop\Launch pad.lnk
 2014-03-20 10:10 - 2014-03-20 10:10 - 01162176 _____ (F-Secure Corporation) C:\Users\wstoll\Downloads\Security_Installer.EXE
 2014-03-20 10:08 - 2014-03-20 10:08 - 00001991 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
 2014-03-20 10:08 - 2012-03-29 12:39 - 00000000 ____D () C:\ProgramData\Adobe
 2014-03-20 10:08 - 2012-03-29 12:39 - 00000000 ____D () C:\Program Files (x86)\Adobe
 2014-03-20 10:01 - 2014-03-05 22:25 - 00000000 ____D () C:\ProgramData\Screentime
 2014-03-20 10:01 - 2012-03-29 12:06 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
 2014-03-20 08:21 - 2014-03-20 08:21 - 05730984 _____ (Symantec Corporation) C:\Users\wstoll\Downloads\SymHelp (2).exe
 2014-03-20 01:04 - 2014-03-20 01:04 - 05730984 _____ (Symantec Corporation) C:\Users\wstoll\Downloads\SymHelp (1).exe
 2014-03-20 00:00 - 2014-03-20 00:00 - 00001734 _____ () C:\ProgramData\SMRResults410.dat
 2014-03-19 23:59 - 2014-03-19 23:59 - 00000883 _____ () C:\Windows\system32\Drivers\etc\hosts.bak
 2014-03-19 23:53 - 2014-03-19 23:53 - 00000000 ____D () C:\Users\wstoll\Desktop\Bösartige Software
 2014-03-19 23:53 - 2014-03-19 23:53 - 00000000 ____D () C:\Users\wstoll\AppData\Local\Symantec Power Eraser
 2014-03-19 23:37 - 2014-03-19 23:37 - 05730984 _____ (Symantec Corporation) C:\Users\wstoll\Downloads\SymHelp.exe
 2014-03-19 10:53 - 2013-08-13 23:58 - 00000000 ____D () C:\Windows\system32\MRT
 2014-03-19 10:51 - 2012-09-28 22:47 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
 2014-03-19 10:48 - 2014-03-19 10:48 - 00546728 _____ (Symantec) C:\Users\wstoll\Downloads\Setup (1).exe
 2014-03-14 23:48 - 2014-03-14 23:48 - 01562415 _____ () C:\Users\wstoll\Downloads\tutor.zip
 2014-03-13 23:58 - 2014-03-13 23:24 - 00000000 ____D () C:\Users\wstoll\Documents\Meine Homepage
 2014-03-13 22:24 - 2012-03-29 12:05 - 00000000 ___RD () C:\Program Files (x86)\Skype
 2014-03-12 22:42 - 2013-05-19 09:42 - 00003486 _____ () C:\Windows\System32\Tasks\wstoll NBAgent 5 4
 2014-03-12 22:36 - 2009-07-14 05:45 - 00390560 _____ () C:\Windows\system32\FNTCACHE.DAT
 2014-03-12 00:32 - 2012-09-25 17:06 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\SoftGrid Client
 2014-03-12 00:27 - 2014-03-12 00:27 - 05128584 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
 2014-03-11 13:42 - 2014-03-02 00:36 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\PerformerSoft
 2014-03-11 11:40 - 2013-03-11 22:28 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\fdrtools.com
 2014-03-11 11:10 - 2012-09-25 16:14 - 00000000 ___RD () C:\Users\wstoll\Eigene Bilder
 2014-03-11 00:08 - 2013-05-31 16:33 - 00001067 _____ () C:\Users\wstoll\AppData\Roaming\Microsoft\Windows\Start Menu\FixFoto.lnk
 2014-03-11 00:08 - 2013-05-31 16:33 - 00000963 _____ () C:\Users\wstoll\Desktop\FixFoto.lnk
 2014-03-11 00:08 - 2013-05-31 16:33 - 00000000 ____D () C:\Program Files (x86)\FixFoto
 2014-03-09 09:58 - 2013-01-30 22:31 - 00000450 ____H () C:\Windows\Tasks\Norton Security Scan for wstoll.job
 2014-03-09 08:29 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
 2014-03-05 22:26 - 2014-03-05 22:25 - 00000000 ____D () C:\Users\wstoll\AppData\Local\Screentime
 2014-03-05 22:24 - 2014-03-05 22:24 - 14235441 _____ () C:\Users\wstoll\Downloads\mazda6_screensaver_pc_setup.zip
 2014-03-05 12:09 - 2014-03-05 12:09 - 00003224 _____ () C:\Windows\System32\Tasks\{BA687605-3DB8-4E7A-867E-D8ECAAB8E888}
 2014-03-04 19:30 - 2014-03-04 19:30 - 00001468 _____ () C:\Users\Public\Desktop\LibreOffice 4.1.lnk
 2014-03-04 19:30 - 2013-10-29 21:25 - 00000000 ____D () C:\Program Files (x86)\LibreOffice 4
 2014-03-04 19:21 - 2014-03-04 19:19 - 216141824 _____ () C:\Users\wstoll\Downloads\LibreOffice_4.1.5_Win_x86.msi
 2014-03-04 19:20 - 2014-03-04 19:19 - 07376896 _____ () C:\Users\wstoll\Downloads\LibreOffice_4.1.5_Win_x86_helppack_de.msi
 2014-03-04 19:00 - 2014-03-04 18:59 - 00042072 _____ () C:\Users\wstoll\rpro.log
 2014-03-04 18:59 - 2014-03-04 18:59 - 00001085 _____ () C:\Users\Public\Desktop\RescuePRO Deluxe.lnk
 2014-03-04 18:59 - 2014-03-04 18:59 - 00000000 ____D () C:\Users\wstoll\licman
 2014-03-04 18:59 - 2014-03-04 18:59 - 00000000 ____D () C:\Users\wstoll\AppData\Local\LC Technology Inc
 2014-03-04 18:59 - 2014-03-04 18:59 - 00000000 ____D () C:\Program Files (x86)\RescuePRO Deluxe
 2014-03-04 18:59 - 2012-09-25 16:14 - 00000000 ____D () C:\Users\wstoll
 2014-03-04 11:06 - 2014-03-04 10:56 - 00002036 _____ () C:\Users\wstoll\EasyTax_0_0.log
 2014-03-04 10:56 - 2014-03-04 10:56 - 00002029 _____ () C:\Users\Public\Desktop\EasyTax 2013 AG.lnk
 2014-03-04 10:56 - 2013-03-16 17:37 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\EasyTax
 2014-03-04 10:56 - 2013-03-12 19:06 - 00000000 ____D () C:\Program Files (x86)\EasyTax
 2014-03-04 10:55 - 2014-03-04 10:54 - 44437016 _____ (HWI Solutions AG) C:\Users\wstoll\Downloads\EasyTax2013AG_windowsJRE_1_0.exe
 2014-03-04 10:15 - 2014-03-04 10:15 - 00000000 ____D () C:\Users\wstoll\Wandern
 2014-03-02 23:54 - 2014-03-02 23:54 - 00002973 _____ () C:\Users\wstoll\Desktop\CZPBatch.lnk
 2014-03-02 23:54 - 2014-03-02 23:54 - 00002973 _____ () C:\Users\wstoll\Desktop\CombineZP.lnk
 2014-03-02 23:54 - 2014-03-02 23:54 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CombineZP
 2014-03-02 23:54 - 2014-03-02 23:54 - 00000000 ____D () C:\Program Files (x86)\Alan Hadley
 2014-03-02 23:41 - 2014-03-02 23:39 - 10320896 _____ () C:\Users\wstoll\Downloads\CombineZP.msi
 2014-03-02 23:34 - 2014-03-02 23:34 - 00001063 _____ () C:\Users\Public\Desktop\DRI Tool 2.0 .lnk
 2014-03-02 23:34 - 2014-03-02 23:34 - 00000000 ____D () C:\Program Files (x86)\Traumflieger
 2014-03-02 23:33 - 2014-03-02 23:33 - 00771175 _____ (Traumflieger ) C:\Users\wstoll\Downloads\DRI_Tool_2_setup.exe
 2014-03-02 00:44 - 2014-03-02 00:44 - 00004030 _____ () C:\Windows\System32\Tasks\LaunchApp
 2014-03-02 00:38 - 2014-03-01 23:18 - 00044712 _____ () C:\Users\wstoll\AppData\Local\viewer.txt
 2014-03-02 00:02 - 2014-03-02 00:01 - 00003240 _____ () C:\Windows\System32\Tasks\MySearchDial
 2014-03-02 00:01 - 2014-03-02 00:01 - 00000047 _____ () C:\Users\wstoll\AppData\Roaming\WB.CFG
 2014-03-01 23:43 - 2014-03-01 23:43 - 00000000 ____D () C:\Users\wstoll\AppData\Roaming\Mp3jam
 2014-03-01 23:32 - 2014-03-01 23:18 - 00000000 ____D () C:\Users\wstoll\AppData\Local\WebPlayer
 2014-03-01 23:18 - 2014-03-01 23:18 - 00000306 __RSH () C:\Users\wstoll\ntuser.pol
 2014-03-01 23:18 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
 2014-03-01 23:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
 2014-03-01 08:54 - 2012-05-14 05:06 - 00699884 _____ () C:\Windows\system32\perfh007.dat
 2014-03-01 08:54 - 2012-05-14 05:06 - 00149766 _____ () C:\Windows\system32\perfc007.dat
 2014-03-01 08:54 - 2009-07-14 06:13 - 01622236 _____ () C:\Windows\system32\PerfStringBackup.INI
 2014-03-01 07:05 - 2014-03-12 09:31 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
 2014-03-01 06:17 - 2014-03-12 09:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
 2014-03-01 06:16 - 2014-03-12 09:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
 2014-03-01 05:58 - 2014-03-12 09:31 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
 2014-03-01 05:52 - 2014-03-12 09:31 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
 2014-03-01 05:51 - 2014-03-12 09:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
 2014-03-01 05:42 - 2014-03-12 09:31 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
 2014-03-01 05:40 - 2014-03-12 09:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
 2014-03-01 05:37 - 2014-03-12 09:31 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
 2014-03-01 05:33 - 2014-03-12 09:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
 2014-03-01 05:33 - 2014-03-12 09:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
 2014-03-01 05:32 - 2014-03-12 09:31 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
 2014-03-01 05:30 - 2014-03-12 09:31 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
 2014-03-01 05:23 - 2014-03-12 09:31 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
 2014-03-01 05:17 - 2014-03-12 09:31 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
 2014-03-01 05:11 - 2014-03-12 09:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
 2014-03-01 05:02 - 2014-03-12 09:31 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
 2014-03-01 04:54 - 2014-03-12 09:31 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
 2014-03-01 04:52 - 2014-03-12 09:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
 2014-03-01 04:51 - 2014-03-12 09:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
 2014-03-01 04:47 - 2014-03-12 09:31 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
 2014-03-01 04:43 - 2014-03-12 09:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
 2014-03-01 04:43 - 2014-03-12 09:31 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
 2014-03-01 04:42 - 2014-03-12 09:31 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
 2014-03-01 04:40 - 2014-03-12 09:31 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
 2014-03-01 04:38 - 2014-03-12 09:31 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
 2014-03-01 04:37 - 2014-03-12 09:31 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
 2014-03-01 04:35 - 2014-03-12 09:31 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
 2014-03-01 04:18 - 2014-03-12 09:31 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
 2014-03-01 04:16 - 2014-03-12 09:31 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
 2014-03-01 04:14 - 2014-03-12 09:31 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
 2014-03-01 04:10 - 2014-03-12 09:31 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
 2014-03-01 04:03 - 2014-03-12 09:31 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
 2014-03-01 04:00 - 2014-03-12 09:31 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
 2014-03-01 03:57 - 2014-03-12 09:31 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
 2014-03-01 03:38 - 2014-03-12 09:31 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
 2014-03-01 03:32 - 2014-03-12 09:31 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
 2014-03-01 03:27 - 2014-03-12 09:31 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
 2014-03-01 03:25 - 2014-03-12 09:31 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
 2014-03-01 03:25 - 2014-03-12 09:31 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
 2014-03-01 00:10 - 2014-03-01 00:10 - 00047782 _____ () C:\Users\wstoll\Documents\Sysinfo28.02.2014.txt
 2014-02-27 18:28 - 2014-02-27 12:46 - 00022570 _____ () C:\Users\wstoll\Desktop\Ferienplan 2014.ods
 2014-02-27 12:44 - 2014-02-27 12:44 - 00072192 _____ () C:\Users\wstoll\Downloads\kalender-urlaubsplanung.xls
 2014-02-27 12:41 - 2014-02-27 12:41 - 00051712 _____ () C:\Users\wstoll\Downloads\kalender-2014-querformat-tage-nebeneinander (1).xls
 2014-02-27 12:40 - 2014-02-27 12:40 - 00047616 _____ () C:\Users\wstoll\Downloads\kalender-2014-querformat.xls
 2014-02-27 12:37 - 2014-02-27 12:37 - 00051712 _____ () C:\Users\wstoll\Downloads\kalender-2014-querformat-tage-nebeneinander.xls
 2014-02-27 12:34 - 2014-02-27 12:34 - 01344000 _____ () C:\Users\wstoll\Downloads\kalender-2014-a4-zweiseitig.xls
 2014-02-27 12:31 - 2014-02-27 12:23 - 00000000 ____D () C:\Users\wstoll\Documents\Ferienkalender
 2014-02-27 12:23 - 2014-02-27 12:23 - 00001737 _____ () C:\Users\wstoll\Desktop\Ferienkalender Vorlagen.lnk
 2014-02-27 12:23 - 2014-02-27 12:23 - 00000000 ____D () C:\Program Files (x86)\DeltaVision
 2014-02-27 12:22 - 2014-02-27 12:22 - 02077243 _____ (DeltaVision Informatik GmbH ) C:\Users\wstoll\Downloads\dvFerienKalender_V6.4.exe
 2014-02-27 11:27 - 2014-02-27 11:27 - 00000000 ____D () C:\Users\wstoll\Documents\Fax
 2014-02-27 11:14 - 2012-06-16 17:26 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
 2014-02-27 10:30 - 2013-01-23 22:34 - 00000000 ____D () C:\Users\wstoll\Documents\Trachsel 2013
 2014-02-27 10:24 - 2014-02-27 10:24 - 00185344 _____ () C:\Users\wstoll\Desktop\Monatsarbeitsplan 2014b.xls
 2014-02-27 09:38 - 2013-12-29 18:52 - 00185344 _____ () C:\Users\wstoll\Desktop\Monatsarbeitsplan 2014.xls
 
 Files to move or delete:
 ====================
 C:\ProgramData\SMRResults410.dat
 
 
 ==================== Bamital & volsnap Check =================
 
 C:\Windows\System32\winlogon.exe => MD5 is legit
 C:\Windows\System32\wininit.exe => MD5 is legit
 C:\Windows\SysWOW64\wininit.exe => MD5 is legit
 C:\Windows\explorer.exe => MD5 is legit
 C:\Windows\SysWOW64\explorer.exe => MD5 is legit
 C:\Windows\System32\svchost.exe => MD5 is legit
 C:\Windows\SysWOW64\svchost.exe => MD5 is legit
 C:\Windows\System32\services.exe => MD5 is legit
 C:\Windows\System32\User32.dll => MD5 is legit
 C:\Windows\SysWOW64\User32.dll => MD5 is legit
 C:\Windows\System32\userinit.exe => MD5 is legit
 C:\Windows\SysWOW64\userinit.exe => MD5 is legit
 C:\Windows\System32\rpcss.dll => MD5 is legit
 C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
 
 LastRegBack: 2014-03-09 10:00
 
 ==================== End Of Log ============================
 Addition   Code: 
 Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014Ran by wstoll at 2014-03-29 20:07:10
 Running from C:\Users\wstoll\Desktop
 Boot Mode: Normal
 ==========================================================
 
 
 ==================== Security Center ========================
 
 AV: Computer Security (Enabled - Up to date) {15414183-282E-D62C-CA37-EF24860A2F17}
 AS: Computer Security (Enabled - Up to date) {AE20A067-0E14-D9A2-F087-D456FD8D65AA}
 AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
 ==================== Installed Programs ======================
 
 6300 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
 6300_Help (x32 Version: 82.0.242.000 - Hewlett-Packard) Hidden
 6300Trb (x32 Version: 82.0.242.000 - Hewlett-Packard) Hidden
 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
 Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
 Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
 Adobe Photoshop Elements 8.0 (HKLM-x32\...\Adobe Photoshop Elements 8.0) (Version: 8.0 - Adobe Systems Incorporated)
 Adobe Photoshop Elements 8.0 (x32 Version: 8.0 - Adobe Systems Incorporated) Hidden
 Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
 AIO_CDB_ProductContext (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
 AIO_CDB_Software (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
 AIO_Scan (x32 Version: 130.0.421.000 - Hewlett-Packard) Hidden
 AMD APP SDK Runtime (Version: 10.0.831.4 - Advanced Micro Devices Inc.) Hidden
 AMD AVIVO64 Codecs (Version: 11.7.0.11109 - Advanced Micro Devices, Inc.) Hidden
 AMD Catalyst Install Manager (HKLM\...\{3F2E3651-6FF9-7D20-63F1-B41B69FD90FB}) (Version: 3.0.855.0 - Advanced Micro Devices, Inc.)
 AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
 AMD Media Foundation Decoders (Version: 1.0.61109.2218 - Advanced Micro Devices, Inc.) Hidden
 Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
 Ashampoo Burning Studio 14 v.14.0.1 (HKLM-x32\...\{91B33C97-7BCF-CDFE-4321-58EBF3E8641C}_is1) (Version: 14.0.1 - Ashampoo GmbH & Co. KG)
 Ashampoo WinOptimizer 10 v.10.2.6 (HKLM-x32\...\{4209F371-88D4-AB00-ED2B-D6520C84D9D5}_is1) (Version: 10.02.06 - Ashampoo GmbH & Co. KG)
 BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
 Capture One 7.1 (HKLM\...\CaptureOne7_is1) (Version: 7.1.5.17 - Phase One A/S)
 Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
 Catalyst Control Center (x32 Version: 2011.1109.2212.39826 - Advanced Micro Devices, Inc.) Hidden
 Catalyst Control Center InstallProxy (x32 Version: 2011.1109.2212.39826 - Advanced Micro Devices, Inc.) Hidden
 Catalyst Control Center Localization All (x32 Version: 2011.1109.2212.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Chinese Standard (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Chinese Traditional (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Czech (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Danish (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Dutch (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help English (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Finnish (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help French (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help German (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Greek (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Hungarian (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Italian (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Japanese (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Korean (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Norwegian (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Polish (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Portuguese (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Russian (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Spanish (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Swedish (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Thai (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 CCC Help Turkish (x32 Version: 2011.1109.2211.39826 - Advanced Micro Devices, Inc.) Hidden
 ccc-utility64 (Version: 2011.1109.2212.39826 - Advanced Micro Devices, Inc.) Hidden
 CombineZP (HKLM-x32\...\{8E41D2A5-C0DD-4139-8C7A-2F0E1F20ED24}) (Version: 1.0.0 - Alan Hadley)
 Computer Security 14.99.103.0 (release) (x32 Version: 14.99.103.0 - F-Secure Corporation) Hidden
 Copy (x32 Version: 130.0.428.000 - Hewlett-Packard) Hidden
 CyberLink MediaEspresso (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1720_38230 - CyberLink Corp.)
 CyberLink MediaEspresso (x32 Version: 6.5.1720_38230 - CyberLink Corp.) Hidden
 D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
 DeltaVision Ferienkalender 6.4 (HKLM-x32\...\DeltaVisionFerienkalender6_is1) (Version: 6.4 - DeltaVision Informatik GmbH)
 Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
 DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden
 Digimarc Plug-ins for Adobe® Photoshop® (HKLM-x32\...\{E670B584-4496-4086-B85B-DA63001AC096}) (Version: 4.0 - Digimarc)
 DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
 DRI Tool 2.0 (HKLM-x32\...\DRI Tool 2.0_is1) (Version: 2.0 - Traumflieger)
 Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.)
 DxO Optics Pro 8 (HKLM\...\{D3BBC6A7-B0B9-461D-8D14-DBA9A8B15228}) (Version: 8.3.1 - DxO Labs)
 EasyTax 2012 AG 1.02 (HKLM-x32\...\3785-6780-1293-3574) (Version: 1.02 - HWI Solutions AG)
 EasyTax 2013 AG 1.0 (HKLM-x32\...\4093-4123-1528-3000) (Version: 1.0 - HWI Solutions AG)
 Evernote v. 4.5.2 (HKLM-x32\...\{F77EF646-19EB-11E1-9A9E-984BE15F174E}) (Version: 4.5.2.5866 - Evernote Corp.)
 FastStone Image Viewer 4.9 (HKLM-x32\...\FastStone Image Viewer) (Version: 4.9 - FastStone Soft)
 Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden
 FDRTools Basic 2.6.1 (HKLM-x32\...\{307232B6-D24C-4F7E-A1A4-5F6EFB81CB24}) (Version: 2.6.1 - AGS Technik)
 FileViewPro (HKLM\...\FileViewPro_is1) (Version: 4.0 - stfx, Ath)
 FixFoto 3.40 (HKLM-x32\...\FixFoto_is1) (Version:  - Joachim Koopmann Software)
 Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 FreeTorrentViewer (HKLM-x32\...\FreeTorrentViewer) (Version: 1.0.0.1 - Free Torrent Viewer)
 F-Secure CCF Reputation (x32 Version: 1.1.25.2280 - F-Secure) Hidden
 F-Secure CCF Scanning 1.37.103.151 (release) (x32 Version: 1.37.103.151 - F-Secure Corporation) Hidden
 F-Secure Network CCF 1.02.134 (x32 Version: 1.02.134 - F-Secure Corporation) Hidden
 F-Secure SafeSearch 1.01.107.0 (release) (x32 Version: 1.01.107.0 - F-Secure Corporation) Hidden
 Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 GIMP 2.8.2 (HKLM\...\GIMP-2_is1) (Version: 2.8.2 - The GIMP Team)
 GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
 HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.216 - SurfRight B.V.)
 Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3510 - Packard Bell)
 HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
 HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
 HP Photosmart Essential 3.5 (HKLM\...\HP Photosmart Essential) (Version: 3.5 - HP)
 HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B (HKLM\...\{B61ED343-0B14-4241-999C-490CB1A20DA4}) (Version: 13.0 - HP)
 HP Smart Web Printing 4.51 (HKLM\...\HP Smart Web Printing) (Version: 4.51 - HP)
 HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
 HP Update (HKLM-x32\...\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.001 - Hewlett-Packard)
 HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
 HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
 HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
 HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
 HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
 HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
 Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Packard Bell)
 Imagenomic Noiseware 5.0.2 Plug-in (build 5020) (HKLM\...\ImagenomicNoisewarePlugin) (Version:  - )
 Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
 Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation)
 Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation)
 Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
 iTunes (HKLM\...\{76FF0F03-B707-4332-B5D1-A56C8303514E}) (Version: 11.0.4.4 - Apple Inc.)
 Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.510 - Oracle)
 Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
 Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Launch pad (HKLM-x32\...\F-Secure ServiceEnabler 43655) (Version: 1.99.192.0 - F-Secure Corporation)
 Launch pad (x32 Version: 1.99.192.0 - F-Secure Corporation) Hidden
 LibreOffice 4.1 Help Pack (German) (HKLM-x32\...\{2E348DF5-1C33-4E67-B45E-8A31C534A2B9}) (Version: 4.1.5.3 - The Document Foundation)
 LibreOffice 4.1.5.3 (HKLM-x32\...\{E77773E5-944A-453F-97F3-46767AE0A253}) (Version: 4.1.5.3 - The Document Foundation)
 Logitech Vid (HKLM-x32\...\{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}) (Version: 1.10.1009 - Logitech Inc.)
 Logitech Webcam Software (HKLM\...\{987FE247-4E69-4A2E-A961-D14F901FDBF6}) (Version: 12.10.1113 - Logitech Inc.)
 MAGIX Foto & Grafik Designer 7 SE (HKLM-x32\...\MAGIX_{305A1AC7-0B5C-457D-9B6F-2A889766E3A0}) (Version: 7.1.2.26041 - MAGIX AG)
 MAGIX Foto & Grafik Designer 7 SE (Version: 7.1.2.26041 - MAGIX AG) Hidden
 Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
 MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
 McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.141.11 - McAfee, Inc.)
 Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
 Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
 Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
 Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
 Microsoft Camera Codec Pack (HKLM\...\{CD01405F-BC70-4453-B7F5-00CED3903C19}) (Version: 16.4.1620.0719 - Microsoft Corporation)
 Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
 Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
 Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.5139.5005 - Microsoft Corporation)
 Microsoft Office XP Small Business (HKLM-x32\...\{91130407-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
 Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 1.0.0.0 - Microsoft Corporation)
 Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
 Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
 Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
 Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
 Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
 Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
 Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla)
 Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
 MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
 MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
 MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
 MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
 MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
 MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
 Nero BackItUp 10 (HKLM-x32\...\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.8.11100.9.100 - Nero AG)
 Nero BackItUp 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
 Nero Control Center 10 (x32 Version: 10.6.12700.0.7 - Nero AG) Hidden
 Nero ControlCenter 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
 Nero Core Components 10 (x32 Version: 2.0.19900.9.11 - Nero AG) Hidden
 Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.4.10500.1.100 - Nero AG)
 Nero DiscSpeed 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
 Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.6.10700.5.100 - Nero AG)
 Nero Express 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
 Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.6.10300 - Nero AG)
 Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{68AFA3A7-9265-4ABD-994A-ACA413E3715C}) (Version: 10.6.10400 - Nero AG)
 Nero RescueAgent 10 (HKLM-x32\...\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.6.10500.3.100 - Nero AG)
 Nero RescueAgent 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
 Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.6.10600.4.100 - Nero AG)
 Nero StartSmart 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
 Nero Update (x32 Version: 11.0.11500.28.0 - Nero AG) Hidden
 NETGEAR WNDA3100v2 wireless USB 2.0 adapter (HKLM-x32\...\{3C7839E7-21F4-49E0-B4D5-AC8ED818CCB0}) (Version: 1.03.000 - NETGEAR)
 Network64 (Version: 130.0.572.000 - Hewlett-Packard) Hidden
 Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden
 Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
 Norton Security Scan (HKLM-x32\...\NSS) (Version: 3.7.6.5 - Symantec Corporation)
 O&O DiskImage Professional (HKLM\...\{56F8EF3C-D9A0-4728-95D5-DC05A72931F5}) (Version: 7.81.6 - O&O Software GmbH)
 OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP)
 Online Safety 2.99.2287.1309 (x32 Version: 2.99.2287.1309 - F-Secure Corporation) Hidden
 Packard Bell Games (HKLM-x32\...\WildTangent packardbell Master Uninstall) (Version: 1.0.2.5 - WildTangent)
 Packard Bell Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3507 - Packard Bell)
 Packard Bell Registration (HKLM-x32\...\Packard Bell Registration) (Version: 1.04.3506 - Packard Bell)
 Packard Bell ScreenSaver (HKLM-x32\...\Packard Bell Screensaver) (Version: 1.1.0225.2011 - Packard Bell )
 Packard Bell Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3501 - Packard Bell)
 PC Tools Registry Mechanic 11.1 (HKLM-x32\...\Registry Mechanic_is1) (Version: 11.1 - PC Tools)
 Perfect Effects 8 (HKLM-x32\...\{C982ACFF-5997-4B7D-B3E1-CF7273A06FB2}) (Version: 8.1.0 - onOne Software)
 Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
 Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6521 - Realtek Semiconductor Corp.)
 RescuePRO Deluxe 5.2.3.6 (HKLM-x32\...\{38D9AAB8-116B-40BB-A801-50B71DF82D24}_is1) (Version: 5.2.3.6 - LC Technology International, Inc.)
 Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
 Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP)
 simplitec simplicheck (HKLM-x32\...\{183D780B-28F9-41BA-A2CB-605F324A5781}) (Version: 1.3.10.0 - simplitec GmbH)
 Skype Click to Call (HKLM-x32\...\{BB285C9F-C821-4770-8970-56C4AB52C87E}) (Version: 7.1.15383.6004 - Microsoft Corporation)
 Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
 SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden
 SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
 Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden
 Steganos Privacy Suite 14 (HKLM-x32\...\{9F07D3B6-3801-4C33-B20E-39CC29E63253}) (Version: 14.2.2 - Steganos Software GmbH)
 swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
 Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
 TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden
 UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden
 WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
 Welcome Center (HKLM-x32\...\Packard Bell Welcome Center) (Version: 1.02.3507 - Packard Bell)
 Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
 Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
 Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
 Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
 Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden
 Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
 Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
 Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
 Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
 Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
 Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
 Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Windows-Treiberpaket - Phase One A/S (WinUSB) USBDevice  (05/30/2013 1.12.0.68182) (HKLM\...\1D6C98F8A5FED93B7C062B26DD383655CE271976) (Version: 05/30/2013 1.12.0.68182 - Phase One A/S)
 Wise Care 365 Version 2.92 (HKLM-x32\...\{E864A1C8-EEE1-47D0-A7F8-00CC86D26D5E}_is1) (Version: 2.9.5 - WiseCleaner.com, Inc.)
 XYplorer 13.40 (HKLM-x32\...\XYplorer) (Version: 13.40 - Donald Lessau)
 Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
 Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 
 ==================== Restore Points  =========================
 
 12-03-2014 10:31:48 Windows Update
 16-03-2014 18:49:45 Windows-Sicherung
 19-03-2014 09:50:54 Windows Update
 20-03-2014 08:37:31 Removed Adobe Reader X (10.1.9) MUI.
 20-03-2014 08:59:22 Removed Bonjour
 20-03-2014 09:00:46 Removed Fooz Kids
 20-03-2014 09:01:17 Removed Fooz Kids Platform
 20-03-2014 21:39:51 Removed Apple Mobile Device Support
 20-03-2014 21:40:35 Removed Apple Software Update
 20-03-2014 21:41:07 eBay Worldwide wird entfernt
 21-03-2014 23:20:39 Installed Steganos Privacy Suite 14
 23-03-2014 19:07:46 Windows-Sicherung
 
 ==================== Hosts content: ==========================
 
 2009-07-14 03:34 - 2014-03-19 23:59 - 00000054 ____A C:\Windows\system32\Drivers\etc\hosts
 127.0.0.1       localhost
 ::1             localhost
 
 ==================== Scheduled Tasks (whitelisted) =============
 
 Task: {08392599-4B23-4F83-B7F9-7C5DEBF1ABA8} - System32\Tasks\{5AC57905-EFC8-49C7-B49F-D7366F2E96B3} => Chrome.exe hxxp://ui.skype.com/ui/0/6.1.0.129.272/de/abandoninstall?page=tsProgressBar
 Task: {0A1C8236-33D0-43DD-8E3C-D8A0B0253CB8} - System32\Tasks\Norton Security Scan for wstoll => C:\Program Files (x86)\Norton Security Scan\Engine\3.7.6.5\Nss.exe [2012-10-22] (Symantec Corporation)
 Task: {10CA6F6E-F8CA-4D26-824D-AC62550F2518} - System32\Tasks\{3A5FBC6A-1846-4211-9259-7AA2807E4F44} => Chrome.exe hxxp://ui.skype.com/ui/0/6.1.0.129.272/de/abandoninstall?page=tsProgressBar
 Task: {11E4E84E-C886-48AC-8093-DF53B728DFC9} - System32\Tasks\wstoll NBAgent 5 4 => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2012-01-16] (Nero AG)
 Task: {14A7AFAC-1423-4EC4-837C-13C8C77E7653} - System32\Tasks\{935ED428-C0A6-42B9-9141-3F8074B2C41D} => Chrome.exe
 Task: {2F87B707-B4D5-410C-9193-7BFB9985590D} - System32\Tasks\{4CF2A2EA-B862-4A3B-8678-52D8411A3C31} => Chrome.exe hxxp://ui.skype.com/ui/0/6.1.0.129.272/de/abandoninstall?page=tsProgressBar
 Task: {369A86E1-1CC2-4E6D-87D6-2D9EC510858D} - System32\Tasks\Wise Care 365 => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe [2013-12-09] (WiseCleaner.com)
 Task: {3A93DEA0-D82D-408C-8460-261B7C556FE7} - System32\Tasks\UALU notificatin => C:\Program Files\Packard Bell\Packard Bell Updater\UALU.exe [2012-02-07] (Acer Incorporated)
 Task: {3D6F8428-3ED4-407D-9588-19F87BE41C22} - System32\Tasks\Norton Management\Norton Error Processor => C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\SymErr.exe [2012-10-19] (Symantec Corporation)
 Task: {48EA2F66-DFA3-4247-BC4B-9947330A1439} - System32\Tasks\RMAutoUpdate => C:\Program Files (x86)\PC Tools Registry Mechanic\SULauncher.exe [2013-03-25] (PC Tools)
 Task: {52EEF1C7-E038-4360-9286-8BE87FBD606C} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
 Task: {5C9C02A7-35FE-44B6-B8F5-7746242D0342} - System32\Tasks\{15418A21-C049-44DE-9A4F-520384AA5B4E} => Chrome.exe hxxp://ui.skype.com/ui/0/6.1.0.129.272/de/abandoninstall?page=tsProgressBar
 Task: {6A075738-0B8D-45FF-B10F-561C1C104620} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-149087622-1949021618-103181132-1000Core => C:\Users\wstoll\AppData\Local\Google\Update\GoogleUpdate.exe
 Task: {6E8FEECD-5F55-4526-822A-76369555866F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-149087622-1949021618-103181132-1000UA => C:\Users\wstoll\AppData\Local\Google\Update\GoogleUpdate.exe
 Task: {7CD6AF2A-BDE7-4539-8D23-419C5395DD09} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-27] (Adobe Systems Incorporated)
 Task: {9D0AF1C7-FF0F-4347-86DF-489131D6774D} - System32\Tasks\{B1DD0DDD-5FDD-43B2-A598-B940BF85A0D4} => Chrome.exe hxxp://ui.skype.com/ui/0/6.1.0.129.272/de/abandoninstall?page=tsProgressBar
 Task: {B0986497-6660-4293-B716-DCF4FB9ADAA5} - System32\Tasks\Wise Turbo Checker => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe [2013-12-09] (WiseCleaner.COM)
 Task: {C05E5803-B8A0-4E41-ACCF-507D3221DDA1} - System32\Tasks\MySearchDial => C:\Users\wstoll\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
 Task: {C177DECA-110D-4E00-AEDE-422BA454DFC0} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
 Task: {D3E633C8-25DF-49E8-A572-87C464AE79BA} - System32\Tasks\wstoll Online Autobackup 5 4 => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBCore.exe [2012-01-16] (Nero AG)
 Task: {DAEC1DE5-7528-4728-A64E-B4787D044E5C} - System32\Tasks\{5B9A9A1C-63D2-4ABE-B042-61B89EFCF58C} => Chrome.exe hxxp://ui.skype.com/ui/0/6.1.0.129.272/de/abandoninstall?page=tsProgressBar
 Task: {DE46B5EA-DBD9-44C9-BA1B-9DA013F53BE7} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2011-05-20] (CyberLink)
 Task: {DFB66111-4F15-4DDA-9F04-56BB2CEE572F} - System32\Tasks\{25CA8BBC-727C-464B-A021-6C00C90B3B75} => Chrome.exe hxxp://ui.skype.com/ui/0/6.1.0.129.272/de/abandoninstall?page=tsProgressBar
 Task: {DFF1EFD8-4AED-4B9B-9378-3D4802826DAF} - System32\Tasks\Scheduled scanning task => C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Anti-Virus\fsav.exe [2013-11-26] (F-Secure Corporation)
 Task: {E90794AC-76C2-4762-BE22-E6E6673F93A8} - System32\Tasks\Norton Management\Norton Error Analyzer => C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\SymErr.exe [2012-10-19] (Symantec Corporation)
 Task: {EA913969-B248-44A1-9186-A02CEB1A8CA3} - System32\Tasks\wstoll Local Autobackup 5 4 => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBCore.exe [2012-01-16] (Nero AG)
 Task: {F444D8EC-B6EC-4C41-BD38-6733E5952C0C} - System32\Tasks\{E6D8A0C6-1C07-4ECF-BDFE-4575B7BC9D5C} => Chrome.exe hxxp://ui.skype.com/ui/0/6.1.0.129.272/de/abandoninstall?page=tsProgressBar
 Task: {F5EC3B30-FEC0-47DF-8228-EABE5194F2B3} - System32\Tasks\RMSchedule => C:\Program Files (x86)\PC Tools Registry Mechanic\RegMech.exe [2013-03-25] (PC Tools)
 Task: {FA6203C7-98A6-4F65-9551-5BD46CC0922A} - System32\Tasks\One-Click Optimizer => C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\WO10.exe [2013-10-08] (Ashampoo Development GmbH & Co. KG)
 Task: {FC6864DB-B202-4D99-B9FA-1C57365DBDD0} - System32\Tasks\NBAgent => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2012-01-16] (Nero AG)
 Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
 Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-149087622-1949021618-103181132-1000Core.job => C:\Users\wstoll\AppData\Local\Google\Update\GoogleUpdate.exe
 Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-149087622-1949021618-103181132-1000UA.job => C:\Users\wstoll\AppData\Local\Google\Update\GoogleUpdate.exe
 Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\wstoll\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
 Task: C:\Windows\Tasks\Norton Security Scan for wstoll.job => C:\PROGRA~2\NORTON~4\Engine\376~1.5\Nss.exe
 Task: C:\Windows\Tasks\One-Click Optimizer.job => C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\WO10.exe
 Task: C:\Windows\Tasks\RMAutoUpdate.job => C:\Program Files (x86)\PC Tools Registry Mechanic\SULauncher.exe
 Task: C:\Windows\Tasks\RMSchedule.job => C:\Program Files (x86)\PC Tools Registry Mechanic\RegMech.exe
 Task: C:\Windows\Tasks\Scheduled scanning task.job => C:\PROGRA~2\INTERN~2\apps\COMPUT~1\ANTI-V~1\fsav.exe
 Task: C:\Windows\Tasks\Wise Care 365.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe
 Task: C:\Windows\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe
 
 ==================== Loaded Modules (whitelisted) =============
 
 2013-12-09 01:06 - 2013-10-08 14:07 - 00885096 _____ () C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerService.exe
 2012-09-25 16:28 - 2011-12-14 16:53 - 00303360 _____ () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe
 2013-09-09 16:35 - 2013-09-09 16:35 - 00326448 _____ () C:\Program Files\OO Software\DiskImage\oodiagrs.dll
 2013-09-09 16:36 - 2013-09-09 16:36 - 00069936 _____ () C:\Program Files\OO Software\DiskImage\oodiagpsx64.dll
 2013-09-09 16:35 - 2013-09-09 16:35 - 00344880 _____ () C:\Program Files\OO Software\DiskImage\oodishrs.dll
 2013-09-09 16:35 - 2013-09-09 16:35 - 00537904 _____ () C:\Program Files\OO Software\DiskImage\ooditrrs.dll
 2012-02-07 03:17 - 2012-02-07 03:17 - 00636520 _____ () C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe
 2009-10-14 13:36 - 2009-10-14 13:36 - 02793304 _____ () C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
 2009-10-14 13:34 - 2009-10-14 13:34 - 00560472 _____ () C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
 2012-09-25 16:28 - 2011-12-14 16:55 - 08453376 _____ () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe
 2011-11-10 06:10 - 2011-11-10 06:10 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
 2011-11-09 17:55 - 2011-11-09 17:55 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
 2014-03-20 22:25 - 2013-11-26 10:58 - 00045608 _____ () C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Anti-Virus\FSAVHRES.eng
 2013-12-11 14:35 - 2013-12-11 14:35 - 00220200 _____ () C:\Program Files (x86)\Internet Security Package\daas2.dll
 2012-09-25 16:28 - 2011-12-14 09:22 - 00368640 _____ () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiLib.dll
 2009-07-16 15:34 - 2009-07-16 15:34 - 02140944 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtCore4.dll
 2009-07-16 15:34 - 2009-07-16 15:34 - 07704336 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtGui4.dll
 2009-07-16 15:34 - 2009-07-16 15:34 - 00968976 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtNetwork4.dll
 2009-07-16 15:34 - 2009-07-16 15:34 - 00475408 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtOpenGL4.dll
 2009-07-16 15:35 - 2009-07-16 15:35 - 00363792 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtXml4.dll
 2009-07-16 15:34 - 2009-07-16 15:34 - 00199952 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtSql4.dll
 2009-07-16 15:35 - 2009-07-16 15:35 - 00027408 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\SDL.dll
 2009-07-16 15:35 - 2009-07-16 15:35 - 11311888 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtWebKit4.dll
 2009-07-16 15:34 - 2009-07-16 15:34 - 00291600 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\phonon4.dll
 2009-07-16 15:36 - 2009-07-16 15:36 - 00028944 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qgif4.dll
 2009-07-16 15:36 - 2009-07-16 15:36 - 00035088 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qico4.dll
 2009-07-16 15:36 - 2009-07-16 15:36 - 00138000 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qjpeg4.dll
 2009-10-14 13:36 - 2009-10-14 13:36 - 00181592 _____ () C:\Program Files (x86)\Common Files\LogiShrd\LvApi11\LvApi11.dll
 2012-02-07 03:18 - 2012-02-07 03:18 - 00151656 _____ () C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyHook.dll
 2014-03-20 22:53 - 2014-03-20 22:53 - 00030888 _____ () C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Anti-Virus\minifilter\hashlib_x86.dll
 2014-03-20 22:25 - 2014-03-20 22:53 - 00212008 _____ () C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Spam Control\fsas.dll
 2014-03-20 22:25 - 2014-03-26 22:45 - 00949288 _____ () C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\Anti-Virus\fm4av.dll
 2012-09-25 16:28 - 2011-12-14 09:43 - 00278528 _____ () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvcLib.dll
 2014-03-20 10:11 - 2014-03-20 10:11 - 00592936 _____ () C:\Windows\WinSxS\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.482.77_none_b59ef0c311fca244\QtMultimediaKit1.dll
 2014-03-20 22:25 - 2013-11-26 10:58 - 00056360 _____ () C:\Program Files (x86)\Internet Security Package\apps\ComputerSecurity\FSGUI\fsavures.eng
 2014-02-12 23:14 - 2014-02-12 23:14 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\aa739380ca2b2fc7366d464d2f2301ac\IsdiInterop.ni.dll
 2012-06-16 17:02 - 2010-09-14 02:28 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
 2012-06-16 17:21 - 2012-02-07 10:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
 
 ==================== Alternate Data Streams (whitelisted) =========
 
 AlternateDataStreams: C:\Windows:nlsPreferences
 AlternateDataStreams: C:\ProgramData\Nalpeiron:user.ns1
 AlternateDataStreams: C:\ProgramData\Nalpeiron:user.ns2
 AlternateDataStreams: C:\ProgramData\Nalpeiron:user.ns3
 AlternateDataStreams: C:\ProgramData\Nalpeiron:user.ns4
 AlternateDataStreams: C:\ProgramData\Temp:A5B56640
 AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
 
 ==================== Safe Mode (whitelisted) ===================
 
 
 ==================== Disabled items from MSCONFIG ==============
 
 
 ==================== Faulty Device Manager Devices =============
 
 
 ==================== Event log errors: =========================
 
 Application errors:
 ==================
 Error: (03/29/2014 08:04:29 PM) (Source: WinMgmt) (User: )
 Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 Error: (03/29/2014 07:59:51 PM) (Source: Application Hang) (User: )
 Description: Programm FRST64.exe, Version 3.3.10.2 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
 
 Prozess-ID: 24c0
 
 Startzeit: 01cf4b807541db66
 
 Endzeit: 60000
 
 Anwendungspfad: C:\Users\wstoll\Desktop\FRST64.exe
 
 Berichts-ID: 2090f246-b774-11e3-b2a2-eca86b8bff00
 
 Error: (03/29/2014 07:55:42 PM) (Source: Application Hang) (User: )
 Description: Programm FRST64.exe, Version 3.3.10.2 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
 
 Prozess-ID: 2858
 
 Startzeit: 01cf4b802eed7096
 
 Endzeit: 60000
 
 Anwendungspfad: C:\Users\wstoll\Desktop\FRST64.exe
 
 Berichts-ID: 8b5e9f85-b773-11e3-b2a2-eca86b8bff00
 
 Error: (03/29/2014 07:54:27 PM) (Source: Application Hang) (User: )
 Description: Programm FRST64.exe, Version 3.3.10.2 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
 
 Prozess-ID: 2b60
 
 Startzeit: 01cf4b7f7dc655ca
 
 Endzeit: 60000
 
 Anwendungspfad: C:\Users\wstoll\Desktop\FRST64.exe
 
 Berichts-ID: 5e0b7b3f-b773-11e3-b2a2-eca86b8bff00
 
 Error: (03/29/2014 07:48:37 PM) (Source: BackItUp5) (User: )
 Description: Backup process failed.
 
 Error: (03/29/2014 07:46:26 PM) (Source: BackItUp5) (User: )
 Description: Backup process failed.
 
 Error: (03/29/2014 07:30:51 PM) (Source: BackItUp5) (User: )
 Description: Backup process failed.
 
 Error: (03/29/2014 07:12:43 PM) (Source: Application Error) (User: )
 Description: Name der fehlerhaften Anwendung: ContentFinder.exe, Version: 2.2.5.0, Zeitstempel: 0x53074f09
 Name des fehlerhaften Moduls: QtCore4.dll, Version: 4.8.5.0, Zeitstempel: 0x51cbf354
 Ausnahmecode: 0xc0000005
 Fehleroffset: 0x0010eeb1
 ID des fehlerhaften Prozesses: 0x1518
 Startzeit der fehlerhaften Anwendung: 0xContentFinder.exe0
 Pfad der fehlerhaften Anwendung: ContentFinder.exe1
 Pfad des fehlerhaften Moduls: ContentFinder.exe2
 Berichtskennung: ContentFinder.exe3
 
 Error: (03/29/2014 06:55:16 PM) (Source: BackItUp5) (User: )
 Description: Backup process failed.
 
 Error: (03/29/2014 06:55:16 PM) (Source: BackItUp5) (User: )
 Description: Job execution failed because the selected target for job does not exist.
 
 
 System errors:
 =============
 Error: (03/29/2014 08:02:50 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "Net.Pipe Listener Adapter" ist von folgendem Dienst abhängig: was. Dieser Dienst ist eventuell nicht installiert.
 
 Error: (03/29/2014 08:02:50 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "Net.Msmq Listener Adapter" ist von folgendem Dienst abhängig: msmq. Dieser Dienst ist eventuell nicht installiert.
 
 Error: (03/29/2014 08:02:50 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "Norton Management" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1.
 
 Error: (03/29/2014 08:02:10 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst Steganos Volatile Disk konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
 
 Error: (03/29/2014 06:44:30 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "Net.Pipe Listener Adapter" ist von folgendem Dienst abhängig: was. Dieser Dienst ist eventuell nicht installiert.
 
 Error: (03/29/2014 06:44:30 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "Net.Msmq Listener Adapter" ist von folgendem Dienst abhängig: msmq. Dieser Dienst ist eventuell nicht installiert.
 
 Error: (03/29/2014 06:44:30 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "Norton Management" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1.
 
 Error: (03/29/2014 00:57:31 AM) (Source: Service Control Manager) (User: )
 Description: Der Dienst Steganos Volatile Disk konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
 
 Error: (03/29/2014 00:12:04 AM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "楗敳䈠潯⁴獁楳瑳湡t" wurde aufgrund folgenden Fehlers nicht gestartet:
 %%2
 
 Error: (03/28/2014 10:12:03 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "楗敳䈠潯⁴獁楳瑳湡t" wurde aufgrund folgenden Fehlers nicht gestartet:
 %%2
 
 
 Microsoft Office Sessions:
 =========================
 Error: (03/29/2014 08:04:29 PM) (Source: WinMgmt)(User: )
 Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 Error: (03/29/2014 07:59:51 PM) (Source: Application Hang)(User: )
 Description: FRST64.exe3.3.10.224c001cf4b807541db6660000C:\Users\wstoll\Desktop\FRST64.exe2090f246-b774-11e3-b2a2-eca86b8bff00
 
 Error: (03/29/2014 07:55:42 PM) (Source: Application Hang)(User: )
 Description: FRST64.exe3.3.10.2285801cf4b802eed709660000C:\Users\wstoll\Desktop\FRST64.exe8b5e9f85-b773-11e3-b2a2-eca86b8bff00
 
 Error: (03/29/2014 07:54:27 PM) (Source: Application Hang)(User: )
 Description: FRST64.exe3.3.10.22b6001cf4b7f7dc655ca60000C:\Users\wstoll\Desktop\FRST64.exe5e0b7b3f-b773-11e3-b2a2-eca86b8bff00
 
 Error: (03/29/2014 07:48:37 PM) (Source: BackItUp5)(User: )
 Description: Sicherung ist fehlgeschlagen.
 
 Error: (03/29/2014 07:46:26 PM) (Source: BackItUp5)(User: )
 Description: Sicherung ist fehlgeschlagen.
 
 Error: (03/29/2014 07:30:51 PM) (Source: BackItUp5)(User: )
 Description: Sicherung ist fehlgeschlagen.
 
 Error: (03/29/2014 07:12:43 PM) (Source: Application Error)(User: )
 Description: ContentFinder.exe2.2.5.053074f09QtCore4.dll4.8.5.051cbf354c00000050010eeb1151801cf4b76cd669e4dC:\Users\wstoll\AppData\Local\ContentFinder.exeC:\Users\wstoll\AppData\Local\QtCore4.dllb89057f0-b76d-11e3-b2a2-eca86b8bff00
 
 Error: (03/29/2014 06:55:16 PM) (Source: BackItUp5)(User: )
 Description: Sicherung ist fehlgeschlagen.
 
 Error: (03/29/2014 06:55:16 PM) (Source: BackItUp5)(User: )
 Description: Die Ausführung des Jobs ist fehlgeschlagen, da das gewählte Ziel (G:\) für Job (wstoll Local Autobackup) nicht existiert oder nicht darauf zugegriffen werden kann.
 
 
 ==================== Memory info ===========================
 
 Percentage of memory in use: 31%
 Total physical RAM: 8156.43 MB
 Available physical RAM: 5616.06 MB
 Total Pagefile: 16311.04 MB
 Available Pagefile: 13592.2 MB
 Total Virtual: 8192 MB
 Available Virtual: 8191.81 MB
 
 ==================== Drives ================================
 
 Drive c: (Packard Bell) (Fixed) (Total:456.45 GB) (Free:301.47 GB) NTFS
 Drive d: (DATA) (Fixed) (Total:456.96 GB) (Free:148.64 GB) NTFS
 
 ==================== MBR & Partition Table ==================
 
 ========================================================
 Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 8AB7CC55)
 Partition 1: (Not Active) - (Size=18 GB) - (Type=27)
 Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
 Partition 3: (Not Active) - (Size=456 GB) - (Type=07 NTFS)
 Partition 4: (Not Active) - (Size=457 GB) - (Type=07 NTFS)
 Could not read MBR for disk 2.
 
 ==================== End Of Log ============================
 Gmer:   Code: 
 GMER 2.1.19357 - hxxp://www.gmer.netRootkit scan 2014-03-29 21:16:26
 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST1000DM rev.CC4B 931.51GB
 Running: Gmer-19357.exe; Driver: C:\Users\wstoll\AppData\Local\Temp\fwriipob.sys
 
 
 ---- Kernel code sections - GMER 2.1 ----
 
 .text  C:\Windows\System32\win32k.sys!W32pServiceTable                                                                                                        fffff96000143f00 7 bytes [00, 98, F3, FF, 01, A6, F0]
 .text  C:\Windows\System32\win32k.sys!W32pServiceTable + 8                                                                                                    fffff96000143f08 3 bytes [C0, 06, 02]
 
 ---- User code sections - GMER 2.1 ----
 
 .text  C:\Program Files (x86)\Internet Security Package\apps\CCF_Reputation\fsorsp.exe[2204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69          0000000075611465 2 bytes [61, 75]
 .text  C:\Program Files (x86)\Internet Security Package\apps\CCF_Reputation\fsorsp.exe[2204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155         00000000756114bb 2 bytes [61, 75]
 .text  ...                                                                                                                                                    * 2
 .text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[3028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   0000000075611465 2 bytes [61, 75]
 .text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[3028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  00000000756114bb 2 bytes [61, 75]
 .text  ...                                                                                                                                                    * 2
 .text  C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe[3188] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 35                                             0000000073cf11a8 2 bytes [CF, 73]
 .text  C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe[3188] C:\Windows\SysWOW64\ksuser.dll!KsCreateAllocator + 21                                       0000000073cf13a8 2 bytes [CF, 73]
 .text  C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe[3188] C:\Windows\SysWOW64\ksuser.dll!KsCreateClock + 21                                           0000000073cf1422 2 bytes [CF, 73]
 .text  C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe[3188] C:\Windows\SysWOW64\ksuser.dll!KsCreateTopologyNode + 19                                    0000000073cf1498 2 bytes [CF, 73]
 .text  C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe[3188] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 195                         0000000073ce1b41 2 bytes [CE, 73]
 .text  C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe[3188] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 362                         0000000073ce1be8 2 bytes [CE, 73]
 .text  C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe[3188] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 418                         0000000073ce1c20 2 bytes [CE, 73]
 .text  C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe[3188] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 596                         0000000073ce1cd2 2 bytes [CE, 73]
 .text  C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe[3188] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 628                         0000000073ce1cf2 2 bytes [CE, 73]
 .text  C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe[3188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                     0000000075611465 2 bytes [61, 75]
 .text  C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe[3188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                    00000000756114bb 2 bytes [61, 75]
 .text  ...                                                                                                                                                    * 2
 .text  C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                               0000000075611465 2 bytes [61, 75]
 .text  C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                              00000000756114bb 2 bytes [61, 75]
 .text  ...                                                                                                                                                    * 2
 .text  C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe[3748] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                 0000000075611465 2 bytes [61, 75]
 .text  C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe[3748] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                00000000756114bb 2 bytes [61, 75]
 .text  ...                                                                                                                                                    * 2
 .text  C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe[4044] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                     0000000075611465 2 bytes [61, 75]
 .text  C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe[4044] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                    00000000756114bb 2 bytes [61, 75]
 .text  ...                                                                                                                                                    * 2
 .text  C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[3208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                               0000000075611465 2 bytes [61, 75]
 .text  C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[3208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                              00000000756114bb 2 bytes [61, 75]
 .text  ...                                                                                                                                                    * 2
 .text  C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe[4448] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                      0000000075611465 2 bytes [61, 75]
 .text  C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe[4448] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                     00000000756114bb 2 bytes [61, 75]
 .text  ...                                                                                                                                                    * 2
 .text  C:\Program Files\OO Software\DiskImage\oodiag.exe[4724] C:\Windows\system32\kernel32.dll!SetUnhandledExceptionFilter                                   0000000077859b80 13 bytes {MOV R11, 0x13fc96cf8; JMP R11}
 ?      C:\Windows\system32\mssprxy.dll [5268] entry point in ".rdata" section                                                                                 00000000710771e6
 .text  C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   0000000075611465 2 bytes [61, 75]
 .text  C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  00000000756114bb 2 bytes [61, 75]
 .text  ...                                                                                                                                                    * 2
 |