Fortsetzung FRST Code:
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-09 18:55 - 2014-09-09 18:55 - 00023171 _____ () C:\Users\FS\Desktop\FRST.txt
2014-09-09 18:55 - 2014-09-09 18:54 - 00000000 ____D () C:\FRST
2014-09-09 18:52 - 2014-09-09 18:52 - 00000466 _____ () C:\Users\FS\Desktop\defogger_disable.log
2014-09-09 18:52 - 2014-09-09 18:52 - 00000000 _____ () C:\Users\FS\defogger_reenable
2014-09-09 18:52 - 2014-08-14 22:36 - 00000000 ____D () C:\Users\FS
2014-09-09 18:51 - 2014-08-14 22:42 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-838099796-3449877163-3534365744-1002
2014-09-09 18:49 - 2014-08-14 22:39 - 00002160 _____ () C:\Users\FS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk
2014-09-09 18:48 - 2014-09-09 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-09-09 18:48 - 2014-08-14 22:36 - 00000000 ____D () C:\Users\FS\AppData\Local\Pokki
2014-09-09 18:47 - 2014-06-17 10:08 - 01268574 _____ () C:\Windows\WindowsUpdate.log
2014-09-09 18:46 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-09-08 22:37 - 2014-08-14 18:30 - 00000000 ____D () C:\Users\FS\AppData\Local\CrashDumps
2014-09-08 22:28 - 2014-06-17 19:35 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2014-09-08 22:28 - 2014-06-17 19:35 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2014-09-08 22:28 - 2014-03-18 12:03 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-08 22:27 - 2014-08-20 21:10 - 00000000 ____D () C:\Program Files (x86)\WIN-CASA2013
2014-09-08 21:28 - 2014-09-08 21:28 - 00380416 _____ () C:\Users\FS\Downloads\Gmer-19357.exe
2014-09-08 21:26 - 2014-09-09 18:51 - 00050477 _____ () C:\Users\FS\Desktop\Defogger.exe
2014-09-08 21:26 - 2014-09-08 21:26 - 00050477 _____ () C:\Users\FS\Downloads\Defogger.exe
2014-09-08 21:25 - 2014-09-09 18:53 - 02105344 _____ (Farbar) C:\Users\FS\Desktop\FRST64.exe
2014-09-08 21:25 - 2014-09-08 21:25 - 02105344 _____ (Farbar) C:\Users\FS\Downloads\FRST64.exe
2014-09-08 21:20 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-09-08 21:05 - 2014-09-07 10:12 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-08 20:50 - 2014-09-08 20:50 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\FS\Downloads\revosetup95.exe
2014-09-08 20:50 - 2014-09-08 20:50 - 00001284 _____ () C:\Users\FS\Desktop\Revo Uninstaller.lnk
2014-09-08 20:50 - 2014-09-08 20:50 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-09-08 20:21 - 2014-05-16 10:16 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-09-08 20:21 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-08 20:20 - 2014-03-18 11:54 - 00016258 _____ () C:\Windows\PFRO.log
2014-09-08 20:20 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-09-08 20:13 - 2014-08-22 15:00 - 00000000 ____D () C:\Users\Public\Documents\VR-NetWorld
2014-09-07 10:33 - 2014-09-07 10:33 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-838099796-3449877163-3534365744-1005
2014-09-07 10:32 - 2014-09-07 10:26 - 00000000 ____D () C:\Users\Zweitaccount\AppData\Local\Pokki
2014-09-07 10:31 - 2014-09-07 10:31 - 00002341 _____ () C:\Users\Zweitaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2014-09-07 10:31 - 2014-09-07 10:31 - 00002170 _____ () C:\Users\Zweitaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk
2014-09-07 10:29 - 2014-09-07 10:29 - 00000000 ____D () C:\Users\Zweitaccount\PicStream
2014-09-07 10:29 - 2014-09-07 10:29 - 00000000 ____D () C:\Users\Zweitaccount\AppData\Roaming\Macromedia
2014-09-07 10:29 - 2014-09-07 10:29 - 00000000 ____D () C:\Users\Zweitaccount\AppData\Roaming\Apple Computer
2014-09-07 10:29 - 2014-09-07 10:29 - 00000000 ____D () C:\Users\Zweitaccount\AppData\Local\clear.fi
2014-09-07 10:29 - 2014-09-07 10:29 - 00000000 ____D () C:\Users\Zweitaccount\AppData\Local\AOP SDK
2014-09-07 10:29 - 2014-09-07 10:28 - 00000000 ____D () C:\Users\Zweitaccount\AppData\Local\Packages
2014-09-07 10:29 - 2014-09-07 10:26 - 00000000 ____D () C:\Users\Zweitaccount
2014-09-07 10:28 - 2014-09-07 10:28 - 00001454 _____ () C:\Users\Zweitaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-07 10:28 - 2014-09-07 10:28 - 00001276 _____ () C:\Users\Zweitaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD Audio-Manager.lnk
2014-09-07 10:28 - 2014-09-07 10:28 - 00000000 ____D () C:\Users\Zweitaccount\AppData\Roaming\Atheros
2014-09-07 10:28 - 2014-09-07 10:28 - 00000000 ____D () C:\Users\Zweitaccount\AppData\Roaming\Adobe
2014-09-07 10:28 - 2014-09-07 10:28 - 00000000 ____D () C:\Users\Zweitaccount\AppData\Local\VirtualStore
2014-09-07 10:28 - 2014-09-07 10:28 - 00000000 ____D () C:\Users\Zweitaccount\AppData\Local\iGware
2014-09-07 10:27 - 2014-09-07 10:27 - 00000020 ___SH () C:\Users\Zweitaccount\ntuser.ini
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\Vorlagen
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\Startmenü
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\Netzwerkumgebung
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\Lokale Einstellungen
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\Eigene Dateien
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\Druckumgebung
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\Documents\Eigene Musik
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\Documents\Eigene Bilder
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\AppData\Local\Verlauf
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\AppData\Local\Anwendungsdaten
2014-09-07 10:27 - 2014-09-07 10:27 - 00000000 _SHDL () C:\Users\Zweitaccount\Anwendungsdaten
2014-09-07 10:26 - 2014-08-17 10:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-07 10:26 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-09-07 10:26 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-09-07 10:12 - 2014-09-07 10:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-07 10:12 - 2014-09-07 10:12 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-07 10:12 - 2014-09-07 10:12 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-07 10:09 - 2014-09-07 10:09 - 01101648 _____ () C:\Users\FS\Downloads\Malwarebytes Anti Malware Malware Scanner - CHIP-Installer.exe
2014-09-06 16:43 - 2014-09-06 16:43 - 00089016 _____ () C:\Users\FS\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-06 16:08 - 2014-09-06 16:08 - 00000000 ____D () C:\Users\FS\AppData\Roaming\elsterformular
2014-09-06 16:07 - 2014-09-06 16:07 - 00001249 _____ () C:\Users\Public\Desktop\ElsterFormular.lnk
2014-09-06 16:07 - 2014-09-06 16:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ElsterFormular
2014-09-06 16:07 - 2014-09-06 16:07 - 00000000 ____D () C:\ProgramData\elsterformular
2014-09-06 16:06 - 2014-09-06 16:06 - 00000000 ____D () C:\Program Files (x86)\ElsterFormular
2014-09-06 16:03 - 2014-09-06 16:01 - 150465176 _____ (Landesfinanzdirektion Thüringen) C:\Users\FS\Downloads\ElsterFormular-15.2.20140326k.exe
2014-09-03 21:31 - 2014-09-03 21:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-09-03 21:12 - 2014-08-16 17:25 - 00000000 ____D () C:\Users\FS\Documents\VRExport
2014-09-01 20:20 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2014-08-31 14:19 - 2014-08-31 14:19 - 00000000 ___RD () C:\Users\FS\AppData\Roaming\Brother
2014-08-31 14:19 - 2013-08-22 16:46 - 00026789 _____ () C:\Windows\setupact.log
2014-08-31 09:01 - 2014-08-14 22:39 - 00002331 _____ () C:\Users\FS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2014-08-29 18:45 - 2013-08-22 16:44 - 00492504 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-29 16:05 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-08-29 16:03 - 2014-05-16 10:16 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-08-28 20:18 - 2014-08-28 20:18 - 00002028 _____ () C:\Users\Public\Desktop\Acer Portal.lnk
2014-08-28 20:18 - 2014-06-17 10:37 - 00003334 _____ () C:\Windows\System32\Tasks\AcerCloud
2014-08-28 20:18 - 2014-05-16 10:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2014-08-28 20:17 - 2014-08-14 22:38 - 00000000 ____D () C:\Users\FS\AppData\Local\clear.fi
2014-08-26 21:28 - 2014-05-16 10:03 - 00002510 ____N () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games App - acer.lnk
2014-08-26 21:28 - 2014-05-16 10:03 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-08-26 21:25 - 2014-08-26 21:24 - 00000000 ____D () C:\Users\FS\AppData\Roaming\WildTangent
2014-08-26 21:24 - 2014-08-26 21:24 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-08-26 21:24 - 2014-05-16 10:02 - 00000000 ____D () C:\ProgramData\WildTangent
2014-08-26 21:24 - 2014-05-16 10:02 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
2014-08-26 18:26 - 2014-08-26 18:25 - 00002001 _____ () C:\Users\Public\Desktop\abMedia.lnk
2014-08-26 18:26 - 2014-05-16 10:02 - 00000000 ____D () C:\Program Files (x86)\Acer
2014-08-26 18:25 - 2014-08-14 22:41 - 00000000 ____D () C:\ProgramData\clear.fi
2014-08-26 18:24 - 2014-08-26 18:23 - 00002005 _____ () C:\Users\Public\Desktop\abPhoto.lnk
2014-08-24 17:04 - 2014-08-17 11:18 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Skype
2014-08-24 10:53 - 2014-08-15 10:08 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-24 10:51 - 2013-08-22 15:25 - 00000199 _____ () C:\Windows\win.ini
2014-08-23 02:42 - 2014-08-28 20:15 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 21:32 - 2014-08-15 09:56 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2014-08-22 16:10 - 2014-08-22 16:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\svnet
2014-08-22 16:10 - 2014-08-22 16:10 - 00000000 ____D () C:\Program Files (x86)\svnet
2014-08-22 16:09 - 2014-08-22 16:09 - 14086762 _____ () C:\Users\FS\Downloads\svnetSetup.exe
2014-08-22 15:05 - 2014-08-22 14:59 - 00000000 ____D () C:\Program Files (x86)\VR-NetWorld
2014-08-22 15:05 - 2014-06-17 10:04 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-22 15:03 - 2014-08-22 15:03 - 22805358 _____ (Volksbanken Raiffeisenbanken ) C:\Users\FS\Downloads\VRNetWorldSWUpdate_44412_20140303.exe
2014-08-22 15:00 - 2014-08-16 16:09 - 00001067 _____ () C:\Windows\ODBCINST.INI
2014-08-22 14:59 - 2014-08-22 14:59 - 00000832 _____ () C:\Users\Public\Desktop\VR-NetWorld.lnk
2014-08-22 14:59 - 2014-08-22 14:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VR-NetWorld
2014-08-22 13:41 - 2014-08-22 13:41 - 35962415 _____ () C:\Users\FS\Downloads\VR-NetWorld Software 4.30.zip
2014-08-20 21:13 - 2014-08-20 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firebird 2.0
2014-08-20 21:12 - 2014-08-20 21:12 - 00000970 _____ () C:\Users\Public\Desktop\Win-CASA 2013.lnk
2014-08-20 21:12 - 2014-08-20 21:12 - 00000000 ___HD () C:\ProgramData\{FA350571-F415-4138-8383-E16F3F2FAF31}
2014-08-20 21:12 - 2014-08-20 21:12 - 00000000 ____D () C:\Program Files (x86)\Firebird
2014-08-20 21:12 - 2014-08-20 21:10 - 00000000 ____D () C:\Users\FS\Documents\WINCASA
2014-08-20 21:12 - 2014-08-20 21:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Win-CASA 2013
2014-08-20 21:08 - 2014-08-20 21:08 - 00000851 _____ () C:\Users\FS\Desktop\sg mobil - Verknüpfung.lnk
2014-08-20 18:48 - 2014-08-20 18:48 - 00000000 ____D () C:\Users\FS\AppData\Local\Adobe
2014-08-20 18:30 - 2014-08-19 23:07 - 00000000 ___RD () C:\Windows\BrowserChoice
2014-08-20 18:30 - 2014-08-14 22:36 - 00000000 ____D () C:\Users\FS\AppData\Local\Packages
2014-08-19 23:07 - 2014-09-07 10:26 - 00000000 ___RD () C:\Users\Zweitaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-08-19 23:07 - 2014-09-07 10:26 - 00000000 ___RD () C:\Users\Zweitaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\setup
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\MediaViewer
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\FileManager
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Camera
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-08-19 23:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-08-19 23:07 - 2013-08-22 15:36 - 00000000 ____D () C:\Windows\system32\oobe
2014-08-19 23:04 - 2014-08-19 23:03 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-19 22:57 - 2014-09-07 10:26 - 00000000 ____D () C:\Users\Zweitaccount\AppData\Local\Microsoft Help
2014-08-19 22:57 - 2014-08-19 22:57 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-08-19 22:57 - 2014-08-19 22:57 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-08-19 20:42 - 2014-08-19 20:42 - 00000000 ____D () C:\Users\FS\AppData\Local\Macromedia
2014-08-19 19:40 - 2014-05-16 10:13 - 00000000 ____D () C:\ProgramData\Adobe
2014-08-19 18:59 - 2014-03-18 11:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-08-17 18:45 - 2014-08-17 18:45 - 00000000 ____D () C:\Users\FS\abBox
2014-08-17 18:44 - 2014-06-17 10:28 - 00000000 ____D () C:\ProgramData\OEM
2014-08-17 16:07 - 2014-08-17 16:06 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Spotify
2014-08-17 16:06 - 2014-08-17 16:06 - 00000000 ____D () C:\Users\FS\AppData\Local\Spotify
2014-08-17 14:43 - 2014-08-15 10:26 - 00030208 ___SH () C:\Users\FS\Desktop\Thumbs.db
2014-08-17 14:40 - 2014-08-17 14:40 - 00000000 ____D () C:\Users\FS\AppData\Local\PDF24
2014-08-17 14:35 - 2014-08-17 14:35 - 00001095 _____ () C:\Users\Public\Desktop\PDF24 Creator.lnk
2014-08-17 14:35 - 2014-08-17 14:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
2014-08-17 14:35 - 2014-08-17 14:35 - 00000000 ____D () C:\Program Files (x86)\PDF24
2014-08-17 14:19 - 2014-08-17 13:46 - 00000000 ____D () C:\Program Files (x86)\Brother
2014-08-17 14:16 - 2014-08-17 14:16 - 00000000 _____ () C:\Users\FS\Sti_Trace.log
2014-08-17 13:54 - 2014-08-17 13:54 - 00000254 _____ () C:\Windows\Brpfx04a.ini
2014-08-17 13:54 - 2014-08-17 13:54 - 00000093 _____ () C:\Windows\brpcfx.ini
2014-08-17 13:54 - 2014-08-17 13:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother
2014-08-17 13:54 - 2014-08-17 11:47 - 00000000 ____D () C:\ProgramData\InstallShield
2014-08-17 13:53 - 2014-08-17 13:53 - 00000425 _____ () C:\Windows\BRWMARK.INI
2014-08-17 13:53 - 2014-08-17 13:47 - 00000050 _____ () C:\Windows\system32\bridf08b.dat
2014-08-17 13:52 - 2014-08-17 13:52 - 00000000 ____D () C:\Users\FS\AppData\Roaming\InstallShield
2014-08-17 13:45 - 2014-08-17 13:45 - 00000000 ____D () C:\Users\FS\Downloads\wlan_wiz
2014-08-17 13:45 - 2014-08-17 13:45 - 00000000 ____D () C:\Users\FS\Downloads\mflpro_c1
2014-08-17 13:45 - 2014-08-17 10:24 - 00000000 ____D () C:\Users\FS\Downloads\Installation
2014-08-17 13:42 - 2014-08-17 13:41 - 50187872 _____ (A.I.SOFT,INC.) C:\Users\FS\Downloads\MFC-295CN-inst-B1-win78.EXE
2014-08-17 13:34 - 2014-08-17 13:34 - 00000000 ____D () C:\Users\FS\AppData\Local\Scansoft
2014-08-17 11:51 - 2014-08-17 11:51 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Zeon
2014-08-17 11:51 - 2014-08-16 17:24 - 00000000 ____D () C:\Users\FS\Documents\Eigene PaperPort-Dokumente
2014-08-17 11:46 - 2014-08-17 11:46 - 00000000 ____D () C:\Program Files (x86)\ScanSoft
2014-08-17 11:43 - 2014-08-17 11:43 - 00000000 ____D () C:\ProgramData\Brother
2014-08-17 11:30 - 2014-08-17 11:30 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-08-17 11:30 - 2014-08-17 11:26 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Apple Computer
2014-08-17 11:26 - 2014-08-17 11:26 - 00001799 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-08-17 11:26 - 2014-08-17 11:26 - 00000000 ____D () C:\Users\FS\AppData\Local\Apple Computer
2014-08-17 11:26 - 2014-08-17 11:26 - 00000000 ____D () C:\Users\FS\AppData\Local\Apple
2014-08-17 11:26 - 2014-08-17 11:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-08-17 11:26 - 2014-08-17 11:26 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-08-17 11:26 - 2014-08-17 11:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-08-17 11:26 - 2014-08-17 11:26 - 00000000 ____D () C:\Program Files\iTunes
2014-08-17 11:26 - 2014-08-17 11:26 - 00000000 ____D () C:\Program Files\iPod
2014-08-17 11:26 - 2014-08-17 11:26 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-08-17 11:25 - 2014-08-17 11:25 - 00002535 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-08-17 11:25 - 2014-08-17 11:25 - 00000000 ____D () C:\ProgramData\Apple
2014-08-17 11:25 - 2014-08-17 11:25 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-08-17 11:25 - 2014-08-17 11:25 - 00000000 ____D () C:\Program Files\Bonjour
2014-08-17 11:25 - 2014-08-17 11:25 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-08-17 11:25 - 2014-08-17 11:25 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-08-17 11:23 - 2014-08-17 11:14 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro
2014-08-17 11:19 - 2014-08-17 11:19 - 00003236 _____ () C:\Windows\System32\Tasks\Optimizer Pro Schedule
2014-08-17 11:19 - 2014-08-17 11:19 - 00000000 ____D () C:\Users\FS\Documents\Optimizer Pro
2014-08-17 11:18 - 2014-08-17 11:18 - 00002533 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-08-17 11:18 - 2014-08-17 11:18 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-08-17 11:18 - 2014-08-17 11:18 - 00000000 ____D () C:\Users\FS\AppData\Local\Skype
2014-08-17 11:18 - 2014-08-17 11:18 - 00000000 ____D () C:\ProgramData\Skype
2014-08-17 11:18 - 2014-08-17 11:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-17 11:16 - 2014-08-17 11:16 - 00001194 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
2014-08-17 11:16 - 2014-08-17 11:16 - 00001182 _____ () C:\Users\Public\Desktop\TeamViewer 8.lnk
2014-08-17 11:16 - 2014-08-17 11:16 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-08-17 11:15 - 2014-08-17 11:15 - 00000000 ____D () C:\Users\FS\AppData\Roaming\FileZilla
2014-08-17 11:15 - 2014-08-17 11:14 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client
2014-08-17 11:14 - 2014-08-17 11:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet
2014-08-17 10:25 - 2014-08-17 10:25 - 00001175 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-17 10:25 - 2014-08-17 10:25 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-08-17 10:25 - 2014-08-17 10:25 - 00000000 ____D () C:\Users\FS\AppData\Local\Mozilla
2014-08-17 10:25 - 2014-08-17 10:25 - 00000000 ____D () C:\ProgramData\Mozilla
2014-08-17 10:25 - 2014-08-17 10:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-08-17 10:25 - 2014-08-15 19:18 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Mozilla
2014-08-17 10:17 - 2014-08-17 10:16 - 00000000 ____D () C:\Program Files (x86)\phase5
2014-08-17 10:16 - 2014-08-17 10:16 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Phase 5 HTML-Editor
2014-08-17 10:13 - 2014-08-17 10:13 - 16319576 _____ (Geek Software GmbH ) C:\Users\FS\Downloads\pdf24-creator-6.7.0.exe
2014-08-17 10:06 - 2014-08-17 10:04 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-08-17 10:05 - 2014-08-17 10:05 - 00000000 ____D () C:\Users\FS\AppData\Roaming\pdfforge
2014-08-17 10:05 - 2014-08-17 10:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-08-17 09:59 - 2014-08-17 09:59 - 00000000 ____D () C:\Windows\System32\Tasks\Recovery Management
2014-08-17 09:58 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\Recovery
2014-08-16 18:42 - 2014-08-16 18:42 - 00282076 _____ () C:\BankCom.log
2014-08-16 18:42 - 2014-08-16 18:42 - 00217064 _____ () C:\BankContacts.log
2014-08-16 18:42 - 2014-08-16 18:40 - 00000000 ____D () C:\ProgramData\Sage
2014-08-16 18:41 - 2014-08-16 18:41 - 00002078 _____ () C:\Users\Public\Desktop\Sage GS-Buchhalter.lnk
2014-08-16 18:41 - 2014-08-16 18:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sage GS-Buchhalter
2014-08-16 18:41 - 2014-08-16 18:40 - 00000000 ____D () C:\Program Files (x86)\Sage
2014-08-16 18:16 - 2014-08-14 22:36 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Adobe
2014-08-16 18:05 - 2014-08-16 17:03 - 00000926 _____ () C:\Windows\wiso.ini
2014-08-16 17:48 - 2014-08-16 17:48 - 00002115 _____ () C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk
2014-08-16 17:48 - 2014-08-16 17:03 - 00000000 ____D () C:\Users\FS\AppData\Local\Buhl
2014-08-16 17:41 - 2014-08-16 16:56 - 00000000 ____D () C:\Program Files (x86)\WISO
2014-08-16 17:25 - 2014-08-16 17:25 - 00000000 ____D () C:\Users\FS\Documents\Youcam
2014-08-16 17:25 - 2014-08-16 17:25 - 00000000 ____D () C:\Users\FS\Documents\Steuer-Sparbuch
2014-08-16 17:25 - 2014-08-16 17:24 - 00000000 ____D () C:\Users\FS\Documents\Spanisch
2014-08-16 17:24 - 2014-08-16 17:24 - 00000000 ____D () C:\Users\FS\Documents\Meine empfangenen Dateien
2014-08-16 17:24 - 2014-08-16 17:24 - 00000000 ____D () C:\Users\FS\Documents\Lexware Sicherung
2014-08-16 17:24 - 2014-08-16 17:24 - 00000000 ____D () C:\Users\FS\Documents\Kalender-Excel-8.9
2014-08-16 17:24 - 2014-08-16 17:24 - 00000000 ____D () C:\Users\FS\Documents\Bluetooth
2014-08-16 17:10 - 2014-08-16 17:10 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Buhl
2014-08-16 17:04 - 2014-08-16 17:04 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Buhl Data Service
2014-08-16 17:04 - 2014-08-16 17:04 - 00000000 ____D () C:\Users\FS\AppData\Local\Buhl Data Service
2014-08-16 17:04 - 2014-08-16 16:54 - 00000000 ____D () C:\ProgramData\Buhl Data Service GmbH
2014-08-16 17:03 - 2014-08-16 17:03 - 00002124 _____ () C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2013.lnk
2014-08-16 16:59 - 2014-08-16 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steuern
2014-08-16 16:23 - 2014-08-14 22:36 - 00000000 ____D () C:\Users\FS\AppData\Local\VirtualStore
2014-08-16 16:11 - 2014-08-16 16:11 - 00000544 _____ () C:\Windows\DirectX.log
2014-08-16 16:10 - 2014-08-16 16:10 - 00001139 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 4.0.lnk
2014-08-16 16:09 - 2014-05-16 10:13 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-08-16 16:06 - 2014-08-16 16:06 - 00003050 _____ () C:\Windows\System32\Tasks\{EDE693E8-2F55-4E89-A200-1B18208282CB}
2014-08-16 15:51 - 2014-08-16 15:51 - 00000000 ____D () C:\Windows\Downloaded Installations
2014-08-15 22:47 - 2014-08-15 22:47 - 00001874 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Polar ProTrainer.lnk
2014-08-15 22:47 - 2014-08-15 22:47 - 00001770 _____ () C:\Users\Public\Desktop\Polar ProTrainer.lnk
2014-08-15 22:47 - 2014-08-15 22:47 - 00000000 ____D () C:\Program Files (x86)\Polar
2014-08-15 22:47 - 2014-05-16 10:14 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-08-15 19:20 - 2014-05-16 10:16 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-15 19:18 - 2014-08-15 19:18 - 00002114 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-08-15 19:18 - 2014-08-15 19:18 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Thunderbird
2014-08-15 19:18 - 2014-08-15 19:18 - 00000000 ____D () C:\Users\FS\AppData\Local\Thunderbird
2014-08-15 10:31 - 2014-08-15 10:31 - 00001686 _____ () C:\Users\FS\Desktop\Word.lnk
2014-08-15 10:30 - 2014-08-15 10:30 - 00001666 _____ () C:\Users\FS\Desktop\Ecxel.lnk
2014-08-15 10:11 - 2014-08-15 10:11 - 00000000 ____D () C:\Windows\PCHEALTH
2014-08-15 10:11 - 2014-08-15 10:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-08-15 10:11 - 2014-08-15 10:11 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio
2014-08-15 10:11 - 2014-06-17 10:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-08-15 10:08 - 2014-08-15 10:08 - 00000000 ____D () C:\Users\FS\AppData\Local\Microsoft Help
2014-08-15 10:08 - 2014-08-15 10:08 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-08-15 10:08 - 2014-03-18 11:45 - 00000000 ____D () C:\Windows\ShellNew
2014-08-15 10:07 - 2014-08-15 10:07 - 00000000 __RHD () C:\MSOCache
2014-08-15 10:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\restore
2014-08-15 09:59 - 2014-08-15 09:59 - 00000000 ____D () C:\Users\FS\Documents\Fax
2014-08-15 09:57 - 2014-08-15 09:57 - 00002575 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works.lnk
2014-08-15 09:57 - 2014-08-15 09:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works
2014-08-15 09:43 - 2014-08-15 09:41 - 00000000 ____D () C:\Users\FS\Documents\Bluetooth Folder
2014-08-15 09:41 - 2014-08-15 09:41 - 00000000 ____D () C:\Users\FS\AppData\Local\BMExplorer
2014-08-15 09:41 - 2014-06-17 10:22 - 00000000 ____D () C:\ProgramData\Atheros
2014-08-15 09:10 - 2014-08-15 09:10 - 00000000 ____D () C:\Users\FS\AppData\Local\Acer Aspire R7 Tutorial
2014-08-15 08:50 - 2013-08-22 17:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-08-15 00:10 - 2014-08-15 00:10 - 00000000 ____D () C:\Users\FS\AppData\Local\iGware
2014-08-14 23:15 - 2014-08-14 23:15 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-08-14 22:45 - 2014-08-14 22:45 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Macromedia
2014-08-14 22:43 - 2014-05-16 10:36 - 00000000 ___HD () C:\OEM
2014-08-14 22:42 - 2014-08-14 22:42 - 00000000 __SHD () C:\Users\FS\AppData\Local\EmieUserList
2014-08-14 22:42 - 2014-08-14 22:42 - 00000000 __SHD () C:\Users\FS\AppData\Local\EmieSiteList
2014-08-14 22:42 - 2014-08-14 22:42 - 00000000 ____D () C:\Users\Public\OEM
2014-08-14 22:40 - 2014-08-14 22:40 - 00000000 ____D () C:\Users\Public\Pokki
2014-08-14 22:39 - 2014-08-14 22:39 - 00000000 ____D () C:\Users\FS\AppData\Local\AOP SDK
2014-08-14 22:38 - 2014-08-14 22:38 - 00000000 ____D () C:\Users\FS\PicStream
2014-08-14 22:38 - 2014-08-14 22:38 - 00000000 ____D () C:\Users\FS\Documents\clear.fi
2014-08-14 22:38 - 2014-08-14 22:38 - 00000000 ____D () C:\Users\FS\AppData\Local\Acer
2014-08-14 22:37 - 2014-08-14 22:37 - 00001276 _____ () C:\Users\FS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD Audio-Manager.lnk
2014-08-14 22:37 - 2014-08-14 22:37 - 00000000 ____D () C:\Users\FS\AppData\Roaming\Atheros
2014-08-14 22:37 - 2014-08-14 22:37 - 00000000 ____D () C:\ProgramData\OEM_YAHOO
2014-08-14 22:37 - 2014-08-14 22:37 - 00000000 ____D () C:\Program Files\Accessory Store
2014-08-14 22:37 - 2014-08-14 22:37 - 00000000 ____D () C:\Program Files (x86)\OEM
2014-08-14 22:37 - 2014-05-16 10:43 - 00000000 ____D () C:\Windows\Panther
2014-08-14 22:36 - 2014-08-14 22:36 - 00001454 _____ () C:\Users\FS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-14 22:36 - 2014-08-14 22:36 - 00000180 _____ () C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2014-08-14 22:36 - 2014-08-14 22:36 - 00000020 ___SH () C:\Users\FS\ntuser.ini
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\Vorlagen
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\Startmenü
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\Netzwerkumgebung
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\Lokale Einstellungen
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\Eigene Dateien
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\Druckumgebung
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\Documents\Eigene Musik
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\Documents\Eigene Bilder
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\AppData\Local\Verlauf
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\AppData\Local\Anwendungsdaten
2014-08-14 22:36 - 2014-08-14 22:36 - 00000000 _SHDL () C:\Users\FS\Anwendungsdaten
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Programme
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-08-14 22:16 - 2014-08-14 22:16 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2014-08-14 22:16 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows NT
2014-08-14 22:16 - 2013-08-22 15:36 - 00000000 __RHD () C:\Users\Default
2014-08-14 10:58 - 2014-08-14 10:58 - 01233920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml4.dll
2014-08-14 10:58 - 2014-08-14 10:58 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml4r.dll
2014-08-14 10:58 - 2014-08-14 10:58 - 00028160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll
Some content of TEMP:
====================
C:\Users\FS\AppData\Local\Temp\octE.tmp.exe
C:\Users\FS\AppData\Local\Temp\ose00000.exe
C:\Users\FS\AppData\Local\Temp\_is17E.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-31 12:15
==================== End Of Log ============================ Additional FRST Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-09-2014 01
Ran by FS at 2014-09-09 18:56:13
Running from C:\Users\FS\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
abDocs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.04.3004 - Acer Incorporated)
abMedia (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.05.2007.2 - Acer Incorporated)
abPhoto (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.00.2011.1 - Acer Incorporated)
Acer Docs Office AddIn (HKLM-x32\...\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.01.2001 - Acer)
Acer Explorer Agent (HKLM\...\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
Acer Launch Manager (HKLM\...\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8105 - Acer Incorporated)
Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.01.2014 - Acer Incorporated)
Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8104 - Acer Incorporated)
Acer Quick Access (HKLM\...\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.01.3012 - Acer Incorporated)
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8106 - Acer Incorporated)
Acer Remote Files (HKLM\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 1.02.2003 - Acer Incorporated)
Acer User Experience Improvement Program App Monitor Plugin (HKLM\...\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.01.3003 - Acer Incorporated)
Acer User Experience Improvement Program Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.01.3003 - Acer Incorporated)
Acer Video Player (HKLM-x32\...\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2001.4 - Acer Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.179 - Adobe Systems Incorporated)
Adobe Photoshop Elements 4.0 (HKLM-x32\...\Adobe Photoshop Elements 4) (Version: 4.0 - Adobe Systems, Inc.)
Adobe Photoshop Elements 4.0 (x32 Version: 4.0 - Adobe Systems, Inc.) Hidden
Adobe Reader XI (11.0.04) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.04 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.01.2012.1 - Acer Incorporated)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Brother MFL-Pro Suite MFC-295CN (HKLM-x32\...\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}) (Version: 2.0.0.0 - Brother Industries, Ltd.)
Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4917 - CyberLink Corp.)
CyberLink PhotoDirector 3 (x32 Version: 3.0.1.4917 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.3721 - CyberLink Corp.)
CyberLink PowerDirector 10 (x32 Version: 10.0.0.3721 - CyberLink Corp.) Hidden
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3914.57 - CyberLink Corp.)
CyberLink PowerDVD 12 (x32 Version: 12.0.3914.57 - CyberLink Corp.) Hidden
DowNlOadietKeeopp (HKLM-x32\...\{1C52B8B6-FFA2-12F6-0A5A-E8301F96A568}) (Version: - downiloadiTkeep) <==== ATTENTION
eBay Worldwide (HKLM-x32\...\{91589413-6675-4C27-8AFC-EFB9103B90A5}) (Version: 2.4.0105 - OEM)
ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 15.2.20140326 - Landesfinanzdirektion Thüringen)
FileZilla Client 3.9.0.3 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.3 - Tim Kosse)
Firebird 2.0.1 (HKLM-x32\...\FBDBServer_2_0_is1) (Version: - Firebird Project)
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Host App Service (HKCU\...\Pokki) (Version: 0.269.3.181 - Pokki)
Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.8101 - Acer Incorporated)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 1.1.165.1 - Intel Corporation)
Intel(R) Serial IO (Version: 1.1.165.1 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client (Version: 1.31.8.1 - Intel Corporation) Hidden
iTunes (HKLM\...\{77DE5105-D05E-448C-96CB-7FA381903753}) (Version: 11.3.1.2 - Apple Inc.)
Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.8100 - Acer Incorporated)
Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
McAfee LiveSafe – Internet Security (HKLM-x32\...\MSC) (Version: 12.8.988 - McAfee, Inc.)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Standard 2007 (HKLM-x32\...\STANDARDR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Standard 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works 2000 (HKLM-x32\...\{56364334-9530-11D2-BFFC-00C04FA329AA}) (Version: 1.0.0.0000 - Microsoft Corporation)
Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
Mozilla Thunderbird 31.1.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.1.0 (x86 de)) (Version: 31.1.0 - Mozilla)
Nero BackItUp (x32 Version: 12.5.11000 - Nero AG) Hidden
Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{551AC8F2-FEA2-4B45-ACF7-C98681233CC9}) (Version: 12.5.01200 - Nero AG)
Nero BackItUp Help (CHM) (x32 Version: 12.0.13000 - Nero AG) Hidden
Nero ControlCenter (x32 Version: 11.0.15900 - Nero AG) Hidden
Nero ControlCenter Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden
Nero Core Components (x32 Version: 11.0.20900 - Nero AG) Hidden
Nero Launcher (x32 Version: 12.2.7000 - Nero AG) Hidden
Nero RescueAgent (x32 Version: 12.0.3001 - Nero AG) Hidden
Nero RescueAgent Help (CHM) (x32 Version: 12.0.7000 - Nero AG) Hidden
Nero Update (x32 Version: 11.0.11800.31.0 - Nero AG) Hidden
NVIDIA Grafiktreiber 332.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.35 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden
NVIDIA Optimus 1.15.2 (Version: 1.15.2 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0927 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0927 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0927 - NVIDIA Corporation)
NVIDIA Systemsteuerung 332.35 (Version: 332.35 - NVIDIA Corporation) Hidden
NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) Hidden
PDF24 Creator 6.7.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Phase 5 HTML-Editor (HKLM-x32\...\{20B1B020-DEAE-48D1-9960-D4C3185D758B}) (Version: 5.6.2.3 - Systemberatung Schommer)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Pokki Start Menu (HKCU\...\Pokki_Start_Menu) (Version: 0.269.3.181 - )
Polar ProTrainer (HKLM-x32\...\{DF7DBA84-0A55-11D6-A0A6-6A7573736972}) (Version: 5.20.130 - )
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.318 - Qualcomm Atheros Communications)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.29 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21247 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.25.108.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7203 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Sage BankCom (x32 Version: 2.00.0000 - Sage Software GmbH) Hidden
Sage GS SAIP (x32 Version: 1.0.1.129 - Sage Software GmbH) Hidden
Sage GS-Buchhalter (HKLM-x32\...\Sage GS-Buchhalter) (Version: 2014 - Sage Software GmbH)
Sage HBCI-Kontaktverwaltung (HKLM-x32\...\{32BFD212-A55E-4D1A-9E42-DB3764B761B8}) (Version: 3.0 - Sage Software GmbH)
SageDB 5.0 (HKLM-x32\...\SageDB 5.0) (Version: - )
Sagede.Shared.Elster.Setup (x32 Version: 1.0.0.0.37 - Sage Software GmbH) Hidden
Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.)
Spielkanäle (HKLM-x32\...\WildTangentGameProvider-acer-genres) (Version: 9.2.0.11 - WildTangent, Inc.)
Spielkanäle (HKLM-x32\...\WildTangentGameProvider-acer-main) (Version: 9.2.0.11 - WildTangent, Inc.)
Spotify (HKLM-x32\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
sv.net (HKLM-x32\...\sv.net) (Version: 14.1 - ITSG GmbH)
TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.17396 - TeamViewer)
The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.32 - WildTangent) Hidden
Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_STANDARDR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_STANDARDR_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2883097) 32-Bit Edition (HKLM-x32\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{B2260BC9-D561-46EE-B33D-739CF760A2A9}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_STANDARDR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_STANDARDR_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_STANDARDR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_STANDARDR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
VR-NetWorld (HKLM-x32\...\{8815F011-43AF-4F50-BBD8-D78ED3D6F5B9}) (Version: - )
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.11.14 - WildTangent) Hidden
Win-CASA 2013 (HKLM-x32\...\Win-CASA 2013) (Version: - Software24.com GmbH)
Win-CASA 2013 (x32 Version: 10 - Software24.com GmbH) Hidden
WISO Steuer-Sparbuch 2013 (HKLM-x32\...\{D6CC2FAF-F827-4091-96A1-D32CC9B69C79}) (Version: 20.00.8137 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2014 (HKLM-x32\...\{F6E7409F-2B97-4B62-88AA-434D62FFDA89}) (Version: 21.00.8480 - Buhl Data Service GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-838099796-3449877163-3534365744-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
==================== Restore Points =========================
16-08-2014 13:51:27 Installed USB-Ir Adapter
19-08-2014 16:56:45 Windows Update
22-08-2014 12:59:27 Installiert VR-NetWorld
29-08-2014 14:05:23 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {217830A7-CC87-496F-B231-98F0591FED54} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-07-31] (Microsoft Corporation)
Task: {239B1EC0-BEDC-4265-899B-614E6707408F} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-03-17] (Acer Incorporate)
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {322A70BA-7B23-4804-8748-49D063AB98F8} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {43BE50D6-F2B3-41A8-B238-3E5F48FA16F5} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-01-24] (TODO: <Company name>)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {748E85BE-16B5-4F06-8BB5-64893B554D77} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2013-01-22] ()
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {7BF3B29E-4706-4271-BB5F-F1A97087FAC7} - System32\Tasks\Quick Access Quick Launcher => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-03-21] (Acer Incorporate)
Task: {85F3E9C1-4F9E-4B50-B7C5-853ACBEC5F5C} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-03-21] (Acer Incorporate)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {931EBB94-A693-4395-B284-0ACAA4739AA5} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe <==== ATTENTION
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {ACDD8E4B-C4A6-4E5C-9B2E-37205DC2294C} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2014-03-21] (Acer Incorporated)
Task: {B89835E3-8EE9-48B1-9313-00D1B518202D} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2013-07-08] ()
Task: {BCD057E2-D46C-4838-9B08-E94EB831985F} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2014-08-21] (Acer)
Task: {BF58E14B-1069-43E0-80DD-BB525A2FD9CD} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D08F1AB1-8F5E-4779-937E-7A750E734C77} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-03-18] (Microsoft Corporation)
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {E0258D7B-FFB8-4A8F-99AD-4AE89AD4313A} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-03-18] (Acer Incorporated)
Task: {E2ACF668-4308-4463-9ECA-B3DD4467FB01} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {E3BDCA69-0278-4D27-AE94-D673C4802877} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {FC40BF0E-9FE1-4C0C-A1D2-E0DAE10394B4} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
==================== Loaded Modules (whitelisted) =============
2005-10-03 12:04 - 2005-10-03 12:04 - 00102400 _____ () C:\Program Files (x86)\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
2014-06-17 10:30 - 2012-04-24 12:43 - 00254512 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2014-08-16 18:41 - 2011-07-18 14:55 - 05685248 _____ () C:\Program Files (x86)\Sage\SageDB 5.0\bin\mysqld-nt.exe
2014-06-17 10:08 - 2014-01-08 02:48 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-02-25 22:14 - 2014-02-25 22:14 - 00011264 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2014-02-25 22:11 - 2014-02-25 22:11 - 00086016 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll
2014-02-25 22:17 - 2014-02-25 22:17 - 00012928 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
2014-08-17 13:53 - 2012-09-25 11:26 - 01163264 ____N () C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe
2014-05-16 10:39 - 2014-03-07 18:21 - 00080312 _____ () C:\Windows\system32\igfxexps.dll
2014-07-31 12:16 - 2014-07-31 12:16 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-07-31 12:16 - 2014-07-31 12:16 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-06-17 10:10 - 2013-12-10 01:27 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-08-14 22:44 - 2014-08-14 22:44 - 00015616 _____ () C:\Windows\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
2014-08-06 16:47 - 2014-08-06 16:47 - 00013568 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
2014-07-24 18:43 - 2014-07-24 18:43 - 00279296 _____ () C:\Program Files (x86)\Acer\AcerCloud Docs\libcurl.dll
2014-08-22 18:21 - 2014-08-22 18:21 - 00203008 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
2014-08-22 18:21 - 2014-08-22 18:21 - 00630528 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
2014-08-22 18:21 - 2014-08-22 18:21 - 00654552 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
2014-08-22 18:21 - 2014-08-22 18:21 - 00119552 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
2014-08-17 13:53 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2014-07-30 05:59 - 2014-07-30 05:59 - 00569856 _____ () C:\Users\FS\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll
2014-07-30 05:59 - 2014-07-30 05:59 - 01400846 _____ () C:\Users\FS\AppData\Local\Pokki\Engine\avcodec-54.dll
2014-07-30 05:59 - 2014-07-30 05:59 - 00151054 _____ () C:\Users\FS\AppData\Local\Pokki\Engine\avutil-51.dll
2014-07-30 05:59 - 2014-07-30 05:59 - 00222734 _____ () C:\Users\FS\AppData\Local\Pokki\Engine\avformat-54.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/08/2014 10:37:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BackgroundAgent.exe, Version: 1.0.1.5, Zeitstempel: 0x53e1eb8b
Name des fehlerhaften Moduls: MSVCR90.dll, Version: 9.0.30729.8387, Zeitstempel: 0x51ea24a5
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00056b1d
ID des fehlerhaften Prozesses: 0x14cc
Startzeit der fehlerhaften Anwendung: 0xBackgroundAgent.exe0
Pfad der fehlerhaften Anwendung: BackgroundAgent.exe1
Pfad des fehlerhaften Moduls: BackgroundAgent.exe2
Berichtskennung: BackgroundAgent.exe3
Vollständiger Name des fehlerhaften Pakets: BackgroundAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BackgroundAgent.exe5
Error: (09/08/2014 10:33:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm GSBuchhalter.exe, Version 2014.6.10.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 16c8
Startzeit: 01cfcba3a08d3b34
Endzeit: 4294967295
Anwendungspfad: C:\Program Files (x86)\Sage\GSBuchhalter\GSBuchhalter.exe
Berichts-ID: 72dd36d2-3797-11e4-8267-f8a9639de364
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (09/08/2014 10:18:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm WINWORD.EXE, Version 12.0.6700.5000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 291c
Startzeit: 01cfcba1e8045aa1
Endzeit: 55538
Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
Berichts-ID: 2ea93a66-3795-11e4-8267-f8a9639de364
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (09/08/2014 09:19:36 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Explorer.EXE, Version 6.3.9600.17039 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 7f0
Startzeit: 01cfcb91b4322627
Endzeit: 12173
Anwendungspfad: C:\Windows\Explorer.EXE
Berichts-ID: ebcb0e2e-378c-11e4-8267-f8a9639de364
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (09/08/2014 08:31:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: eRecoveryUI.exe, Version: 6.0.3020.0, Zeitstempel: 0x5316bf9c
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.3.9600.17055, Zeitstempel: 0x532954fb
Ausnahmecode: 0xe0434352
Fehleroffset: 0x0000000000005bf8
ID des fehlerhaften Prozesses: 0x1a8c
Startzeit der fehlerhaften Anwendung: 0xeRecoveryUI.exe0
Pfad der fehlerhaften Anwendung: eRecoveryUI.exe1
Pfad des fehlerhaften Moduls: eRecoveryUI.exe2
Berichtskennung: eRecoveryUI.exe3
Vollständiger Name des fehlerhaften Pakets: eRecoveryUI.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: eRecoveryUI.exe5
Error: (09/08/2014 08:31:36 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: eRecoveryUI.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.ComponentModel.Win32Exception
Stapel:
bei System.Diagnostics.Process.Kill()
bei eRecoveryUI.App.CloseProcess(System.String)
bei eRecoveryUI.App.RunWindow(System.String[] ByRef, eRecoveryUI.App ByRef)
bei eRecoveryUI.App.Main(System.String[])
Error: (09/07/2014 05:24:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BackgroundAgent.exe, Version: 1.0.1.5, Zeitstempel: 0x53e1eb8b
Name des fehlerhaften Moduls: MSVCR90.dll, Version: 9.0.30729.8387, Zeitstempel: 0x51ea24a5
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00056b1d
ID des fehlerhaften Prozesses: 0xaac
Startzeit der fehlerhaften Anwendung: 0xBackgroundAgent.exe0
Pfad der fehlerhaften Anwendung: BackgroundAgent.exe1
Pfad des fehlerhaften Moduls: BackgroundAgent.exe2
Berichtskennung: BackgroundAgent.exe3
Vollständiger Name des fehlerhaften Pakets: BackgroundAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BackgroundAgent.exe5
Error: (09/07/2014 05:24:17 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1688
Error: (09/07/2014 05:24:17 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1688
Error: (09/07/2014 05:24:17 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
System errors:
=============
Error: (09/08/2014 10:25:11 PM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
Error: (09/08/2014 09:54:30 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus lautet: 802.
Error: (09/08/2014 09:54:30 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus lautet: 1106.
Error: (09/08/2014 08:56:37 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252.
Error: (09/08/2014 08:56:37 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252.
Error: (09/08/2014 08:48:22 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252.
Error: (09/08/2014 08:21:32 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Performance Optimizer erreicht.
Error: (09/07/2014 04:46:18 PM) (Source: DCOM) (EventID: 10005) (User: NT-AUTORITÄT)
Description: 1053mcpltsvcNicht verfügbar{20966775-18A4-4299-B8E3-772C336B52A7}
Error: (09/07/2014 04:46:18 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee Platform Services" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (09/07/2014 04:46:18 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst McAfee Platform Services erreicht.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz
Percentage of memory in use: 26%
Total physical RAM: 8083.27 MB
Available physical RAM: 5935.27 MB
Total Pagefile: 9363.27 MB
Available Pagefile: 6198.61 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:718.92 GB) (Free:629.81 GB) NTFS
Drive e: (Daten) (Fixed) (Total:195.31 GB) (Free:173.75 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: B0C4A045)
Partition: GPT Partition Type.
==================== End Of Log ============================ es folgen weitere
GMER Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-09-09 19:09:27
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002f WDC_WD10JPVX-22JC3T0 rev.01.01A01 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\FS\AppData\Local\Temp\uwloakow.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff960000bd700 15 bytes [40, B5, F7, 01, 80, 39, 70, ...]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 16 fffff960000bd710 11 bytes [00, 15, FC, FF, 00, 27, C3, ...]
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\lsass.exe[808] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bec20430
.text C:\Windows\system32\svchost.exe[876] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bec20430
.text C:\Windows\system32\svchost.exe[908] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bea10430
.text C:\Windows\System32\svchost.exe[524] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bea10430
.text C:\Windows\system32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bea10430
.text C:\Windows\system32\svchost.exe[644] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bec20430
.text C:\Windows\System32\svchost.exe[1060] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bea10430
.text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bec20430
.text C:\Windows\System32\spoolsv.exe[1552] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bea10430
.text C:\Windows\system32\svchost.exe[1592] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bea10430
.text C:\Windows\system32\mfevtps.exe[2804] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 506 00007fffbe5c169a 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\system32\mfevtps.exe[2804] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 514 00007fffbe5c16a2 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\system32\mfevtps.exe[2804] C:\Windows\system32\psapi.dll!QueryWorkingSet + 118 00007fffbe5c181a 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\system32\mfevtps.exe[2804] C:\Windows\system32\psapi.dll!QueryWorkingSet + 142 00007fffbe5c1832 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\system32\svchost.exe[3012] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bec20430
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[1020] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007fffbe5c169a 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[1020] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007fffbe5c16a2 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[1020] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007fffbe5c181a 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[1020] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007fffbe5c1832 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\system32\svchost.exe[3804] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bea10430
.text C:\Windows\system32\svchost.exe[4640] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bec20430
.text C:\Windows\System32\svchost.exe[4884] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bec20430
.text C:\Windows\system32\DllHost.exe[5616] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bec20430
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[5716] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007fffbe5c169a 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[5716] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007fffbe5c16a2 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[5716] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007fffbe5c181a 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[5716] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007fffbe5c1832 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[6788] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bea10430
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[6788] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007fffb33e1f6a 4 bytes [3E, B3, FF, 7F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[6788] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007fffb33e1f82 4 bytes [3E, B3, FF, 7F]
.text C:\Windows\system32\rundll32.exe[10544] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000be9b0430
.text C:\Windows\system32\nvvsvc.exe[2656] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007fffbe5c169a 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\system32\nvvsvc.exe[2656] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007fffbe5c16a2 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\system32\nvvsvc.exe[2656] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007fffbe5c181a 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\system32\nvvsvc.exe[2656] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007fffbe5c1832 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[10396] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 506 00007fffbe5c169a 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[10396] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 514 00007fffbe5c16a2 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[10396] C:\Windows\system32\psapi.dll!QueryWorkingSet + 118 00007fffbe5c181a 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[10396] C:\Windows\system32\psapi.dll!QueryWorkingSet + 142 00007fffbe5c1832 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\Explorer.EXE[9332] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000be9d0430
.text C:\Windows\Explorer.EXE[9332] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 506 00007fffbe5c169a 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\Explorer.EXE[9332] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 514 00007fffbe5c16a2 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\Explorer.EXE[9332] C:\Windows\system32\psapi.dll!QueryWorkingSet + 118 00007fffbe5c181a 4 bytes [5C, BE, FF, 7F]
.text C:\Windows\Explorer.EXE[9332] C:\Windows\system32\psapi.dll!QueryWorkingSet + 142 00007fffbe5c1832 4 bytes [5C, BE, FF, 7F]
.text C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe[7772] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007fffb33e1f6a 4 bytes [3E, B3, FF, 7F]
.text C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe[7772] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007fffb33e1f82 4 bytes [3E, B3, FF, 7F]
.text C:\Windows\system32\DllHost.exe[9572] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 00007fffbef6cd44 7 bytes JMP 00008000bec20430
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [8628:9804] fffff960008fdb90
---- Processes - GMER 2.1 ----
Library C:\Users\FS\AppData\Local\Pokki\Engine\libPokki.dll (*** suspicious ***) @ C:\Users\FS\AppData\Local\Pokki\Engine\HostAppService.exe [10768] (Chromium/The Chromium Authors)(2014-08-29 23:36:46) 000000005c240000
Library C:\Users\FS\AppData\Local\Pokki\Engine\icudt.dll (*** suspicious ***) @ C:\Users\FS\AppData\Local\Pokki\Engine\HostAppService.exe [10768] (ICU Data DLL/The ICU Project)(2014-07-30 03:59:38) 000000006af70000
Library C:\Users\FS\AppData\Local\Pokki\Engine\libPokki.dll (*** suspicious ***) @ C:\Users\FS\AppData\Local\Pokki\Engine\HostAppService.exe [10540] (Chromium/The Chromium Authors)(2014-08-29 23:36:46) 000000005c240000
Library C:\Users\FS\AppData\Local\Pokki\Engine\icudt.dll (*** suspicious ***) @ C:\Users\FS\AppData\Local\Pokki\Engine\HostAppService.exe [10540] (ICU Data DLL/The ICU Project)(2014-07-30 03:59:38) 000000006af70000
Library C:\Users\FS\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll (*** suspicious ***) @ C:\Users\FS\AppData\Local\Pokki\Engine\HostAppService.exe [10540](2014-07-30 03:59:38) 0000000066170000
Library C:\Users\FS\AppData\Local\Pokki\Engine\avcodec-54.dll (*** suspicious ***) @ C:\Users\FS\AppData\Local\Pokki\Engine\HostAppService.exe [10540](2014-07-30 03:59:38) 0000000065f70000
Library C:\Users\FS\AppData\Local\Pokki\Engine\avutil-51.dll (*** suspicious ***) @ C:\Users\FS\AppData\Local\Pokki\Engine\HostAppService.exe [10540](2014-07-30 03:59:38) 000000006d390000
Library C:\Users\FS\AppData\Local\Pokki\Engine\avformat-54.dll (*** suspicious ***) @ C:\Users\FS\AppData\Local\Pokki\Engine\HostAppService.exe [10540](2014-07-30 03:59:38) 0000000068c90000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- MalWarebytes mit Befund Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 07.09.2014
Suchlauf-Zeit: 10:12:41
Logdatei: MalwarebytesSuchlauf070914.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.09.07.01
Rootkit Datenbank: v2014.08.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: FS
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 352191
Verstrichene Zeit: 11 Min, 42 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 3
PUP.Optional.Booster.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5F189DF5-2D05-472B-9091-84D9848AE48B}{892cc6a3}, In Quarantäne, [e3ea8b5f0972d2648e00c63cdf247c84],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-838099796-3449877163-3534365744-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [527b638796e5ff375f8874b2847fde22],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-838099796-3449877163-3534365744-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [e3ea48a280fbb581ea5ee756ca3aae52],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-838099796-3449877163-3534365744-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, zr2X2X1G1S1F2V1S2Q0V, In Quarantäne, [e3ea48a280fbb581ea5ee756ca3aae52]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 3
PUP.Optional.MultiPlug, C:\$Recycle.Bin\S-1-5-21-838099796-3449877163-3534365744-1002\$RSWDUP4\N.dll, In Quarantäne, [ad205f8b6615e94d5f8630836a97f907],
PUP.Optional.MultiPlug, C:\$Recycle.Bin\S-1-5-21-838099796-3449877163-3534365744-1002\$RSWDUP4\N.exe, In Quarantäne, [0cc145a51d5e55e1f9edd0e361a004fc],
PUP.Optional.MultiPlug, C:\$Recycle.Bin\S-1-5-21-838099796-3449877163-3534365744-1002\$RSWDUP4\N.x64.dll, In Quarantäne, [5e6f73776714082ef1f403b0768b9868],
Physische Sektoren: 0
(No malicious items detected)
(end) Willst Du auch Malwarebytes vom 08.09 ohne Befund? Bei McAffee finde ich leider keine LogFiles.
Danke schon mal
Sandra |