|   | McCallaghan | 21.01.2015 12:20 |  
 Gleich vorweg: Ich habe beim MBM leider nicht die Quarantäne gewählt, sondern die Dateien gleich entfernt... -.-  
Dazu gilt es aber zu sagen, dass das Problem beim Neustart nicht wieder auftetreten ist.  
Bericht vom ADW-Cleaner:    Code: 
 # AdwCleaner v4.108 - Bericht erstellt am 21/01/2015 um 11:40:10# Aktualisiert 17/01/2015 von Xplode
 # Database : 2015-01-18.1 [Live]
 # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
 # Benutzername : Wolfram Pallaske - ANIMUS
 # Gestartet von : C:\Users\Wolfram Pallaske\Downloads\AdwCleaner_4.108.exe
 # Option : Löschen
 
 ***** [ Dienste ] *****
 
 
 ***** [ Dateien / Ordner ] *****
 
 Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
 Ordner Gelöscht : C:\Users\Wolfram Pallaske\AppData\Local\pdfforge
 Ordner Gelöscht : C:\Users\Wolfram Pallaske\AppData\Roaming\aartemis
 Ordner Gelöscht : C:\Users\Wolfram Pallaske\AppData\Roaming\pdfforge
 Ordner Gelöscht : C:\Users\Wolfram Pallaske\AppData\Roaming\Systweak
 Ordner Gelöscht : C:\Users\Wolfram Pallaske\AppData\Roaming\UpdaterEX
 Datei Gelöscht : C:\Windows\System32\roboot64.exe
 Datei Gelöscht : C:\Users\Wolfram Pallaske\AppData\Roaming\Mozilla\Firefox\Profiles\f2m5r971.default\user.js
 
 ***** [ Tasks ] *****
 
 Task Gelöscht : UpdaterEX
 
 ***** [ Verknüpfungen ] *****
 
 
 ***** [ Registrierungsdatenbank ] *****
 
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
 Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
 Schlüssel Gelöscht : HKCU\Software\InstallCore
 Schlüssel Gelöscht : HKCU\Software\OCS
 Schlüssel Gelöscht : HKCU\Software\UpdaterEX
 Schlüssel Gelöscht : HKLM\SOFTWARE\aartemisSoftware
 Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
 
 ***** [ Browser ] *****
 
 -\\ Internet Explorer v11.0.9600.17496
 
 Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
 Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
 Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
 Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
 
 -\\ Mozilla Firefox v35.0 (x86 de)
 
 
 *************************
 
 AdwCleaner[R0].txt - [3422 octets] - [21/01/2015 11:38:34]
 AdwCleaner[S0].txt - [2464 octets] - [21/01/2015 11:40:10]
 
 ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2524 octets] ##########
 
Bericht vom JRT:    Code: 
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Junkware Removal Tool (JRT) by Thisisu
 Version: 6.4.1 (12.28.2014:1)
 OS: Windows 7 Home Premium x64
 Ran by Wolfram Pallaske on 21.01.2015 at 11:43:31,57
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
 ~~~ Services
 
 
 
 ~~~ Registry Values
 
 
 
 ~~~ Registry Keys
 
 
 
 ~~~ Files
 
 
 
 ~~~ Folders
 
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{09AFB8F5-B302-4C31-AFBB-479C8F635AB0}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{19104C36-B4E2-4B0F-A0DA-73C6826ADC50}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{20820819-BE2A-4CA2-AADB-C15C3FAE347A}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{305280F9-562B-4B00-ABAE-81AFC835A872}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{3EE76FCA-2D75-4C2F-A286-75C4F9EEFB64}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{4093F5EB-CD8A-46FF-AA72-5AC1DE39C63B}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{435393EE-1455-4595-9F3C-5B0124DB35FF}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{60662255-2AFB-4064-BC50-5DA0F356DEDD}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{6B4B263C-46B7-4E4A-9C20-56A39AB06372}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{7ED5F687-3123-4578-99A5-7105CC2809DA}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{85BF6FD0-7E00-4835-949D-AD4070A5E0B0}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{90E64026-3516-4D2E-A2CA-00A80653D0CB}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{A02E7E3D-2129-413E-B561-03323DCC833A}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{B91F5D5F-0137-48B1-B806-961D2FCDCC06}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{C17B04EE-F283-4C26-A5F5-68E265CEF065}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{C974D9D9-2ED8-43A5-84AE-963C08694333}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{E10D13B9-4B43-4A31-B0C4-27AEE6CC5E9D}
 Successfully deleted: [Empty Folder] C:\Users\Wolfram Pallaske\appdata\local\{E8132E77-6ADE-4C92-96EF-23CE283DC810}
 
 
 
 ~~~ FireFox
 
 Emptied folder: C:\Users\Wolfram Pallaske\AppData\Roaming\mozilla\firefox\profiles\f2m5r971.default\minidumps [240 files]
 
 
 
 ~~~ Event Viewer Logs were cleared
 
 
 
 
 
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 Scan was completed on 21.01.2015 at 11:47:50,51
 End of JRT log
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Bericht von MBM:    Code: 
 Malwarebytes Anti-Malwarewww.malwarebytes.org
 
 Suchlauf Datum: 21.01.2015
 Suchlauf-Zeit: 11:50:10
 Logdatei: MBM.txt
 Administrator: Ja
 
 Version: 2.00.4.1028
 Malware Datenbank: v2015.01.21.05
 Rootkit Datenbank: v2015.01.14.01
 Lizenz: Kostenlos
 Malware Schutz: Deaktiviert
 Bösartiger Webseiten Schutz: Deaktiviert
 Selbstschutz: Deaktiviert
 
 Betriebssystem: Windows 7 Service Pack 1
 CPU: x64
 Dateisystem: NTFS
 Benutzer: Wolfram Pallaske
 
 Suchlauf-Art: Bedrohungs-Suchlauf
 Ergebnis: Abgeschlossen
 Durchsuchte Objekte: 382653
 Verstrichene Zeit: 15 Min, 51 Sek
 
 Speicher: Aktiviert
 Autostart: Aktiviert
 Dateisystem: Aktiviert
 Archive: Aktiviert
 Rootkits: Deaktiviert
 Heuristik: Aktiviert
 PUP: Aktiviert
 PUM: Aktiviert
 
 Prozesse: 0
 (Keine schädliche Elemente erkannt)
 
 Module: 0
 (Keine schädliche Elemente erkannt)
 
 Registrierungsschlüssel: 2
 PUP.Optional.BuzzSearch.A, HKU\S-1-5-21-1318103975-823857753-1504678809-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{5CF5A690-C8F4-488E-9D20-F21AEF602D41}, In Quarantäne, [898035c5c5c487af7d932308cf34c937],
 PUP.Optional.BuzzSearch.A, HKU\S-1-5-21-1318103975-823857753-1504678809-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{5CF5A690-C8F4-488E-9D20-F21AEF602D41}, In Quarantäne, [898035c5c5c487af7d932308cf34c937],
 
 Registrierungswerte: 3
 PUM.UserWLoad, HKU\S-1-5-21-1318103975-823857753-1504678809-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|Load, C:\Users\WOLFRA~1\LOCALS~1\Temp\msifaauk.com, In Quarantäne, [a564f604ed9cc175d08dffc4ec170ff1]
 Trojan.Ransom, HKU\S-1-5-21-1318103975-823857753-1504678809-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|Load, C:\Users\WOLFRA~1\LOCALS~1\Temp\msifaauk.com, In Quarantäne, [bd4cd2280881f442d126c204e12240c0]
 Trojan.Agent, HKU\S-1-5-21-1318103975-823857753-1504678809-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Firewall Windows, C:\Users\Wolfram Pallaske\AppData\Roaming\Windows Firewall\csrss.exe, In Quarantäne, [8980e1197514eb4bb21edcf918eb40c0]
 
 Registrierungsdaten: 2
 Broken.OpenCommand, HKCR\scrfile\shell\open\command, NOTEPAD.EXE "Gut: ("Schlecht: (NOTEPAD.EXE "%1"),Ersetzt,[ffffffffffffffffffffffffffffffff]" /S)", %4, %5
 Broken.OpenCommand, HKCR\regfile\shell\open\command, NOTEPAD.EXE "Gut: (regedit.exe "Schlecht: (NOTEPAD.EXE "%1"),Ersetzt,[ffffffffffffffffffffffffffffffff]")", %4, %5
 
 Ordner: 0
 (Keine schädliche Elemente erkannt)
 
 Dateien: 4
 PUP.Optional.OpenCandy, C:\Users\Wolfram Pallaske\Downloads\DTLite4491-0356.exe, In Quarantäne, [23e61fdba7e2da5ccb0af2d274919c64],
 Misused.Legit.AI, C:\Users\Wolfram Pallaske\nz8xh9166a55w7\systcphelp.exe, In Quarantäne, [2adfbd3d1871d165833ce4c17e83926e],
 Trojan.Agent.Gen, C:\Users\Wolfram Pallaske\AppData\Roaming\Wolfram Pallaske-wchelper.dll, In Quarantäne, [f81108f28efbca6c880f921d0afa9b65],
 Trojan.Agent, C:\Users\Wolfram Pallaske\AppData\Roaming\Windows Firewall\csrss.exe, In Quarantäne, [8980e1197514eb4bb21edcf918eb40c0],
 
 Physische Sektoren: 0
 (Keine schädliche Elemente erkannt)
 
 
 (end)
 
Bericht von FRST:   
FRST Logfile:   Code: 
 Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2015Ran by Wolfram Pallaske (administrator) on ANIMUS on 21-01-2015 12:12:59
 Running from C:\Users\Wolfram Pallaske\Downloads
 Loaded Profiles: Wolfram Pallaske (Available profiles: Wolfram Pallaske & UpdatusUser)
 Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
 Internet Explorer Version 11 (Default browser: FF)
 Boot Mode: Normal
 Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
 ==================== Processes (Whitelisted) =================
 
 (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
 (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
 (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
 (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
 (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
 (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
 (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
 (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
 (Microsoft Corporation) C:\Windows\System32\wlanext.exe
 (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
 (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
 (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
 (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
 (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
 (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
 (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
 (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
 (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
 (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
 (Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
 (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
 (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
 (Microsoft Corporation) C:\Windows\System32\rundll32.exe
 (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
 (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
 (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
 (Intel Corporation) C:\Windows\System32\igfxtray.exe
 (Intel Corporation) C:\Windows\System32\hkcmd.exe
 (Intel Corporation) C:\Windows\System32\igfxpers.exe
 (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
 (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
 (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
 (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
 (TomTom) C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
 (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
 (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
 (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
 (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
 (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
 (Microsoft Corporation) C:\Windows\System32\dllhost.exe
 (McAfee, Inc.) C:\Program Files\McAfee\VirusScan\mcods.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
 (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
 (McAfee, Inc.) C:\Program Files\McAfee\MAT\McPvTray.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
 (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
 (Microsoft Corporation) C:\Windows\System32\dllhost.exe
 (Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
 ==================== Registry (Whitelisted) ==================
 
 (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
 HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
 HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2531624 2010-12-17] (Synaptics Incorporated)
 HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-09-15] (Intel(R) Corporation)
 HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
 HKLM\...\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [4384928 2012-08-27] (Dell Inc.)
 HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor)
 HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1360600 2013-10-21] (Realtek Semiconductor)
 HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-12] (Intel Corporation)
 HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
 HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated)
 HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
 HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
 HKLM-x32\...\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
 Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
 HKLM\...\Policies\Explorer: [NoFolderOptions] 0
 HKLM\...\Policies\Explorer: [NoControlPanel] 0
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\Run: [AdobeBridge] => [X]
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe [1792376 2014-10-03] (TomTom)
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2014-12-12] (Piriform Ltd)
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\RunOnce: [Uninstall C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\RunOnce: [Uninstall C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910"
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\RunOnce: [Uninstall C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811"
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\RunOnce: [Uninstall C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910_1] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910_1"
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\RunOnce: [Uninstall C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910_2\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910_2\amd64"
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\RunOnce: [Uninstall C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910_2] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Wolfram Pallaske\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910_2"
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\MountPoints2: E - Autoplay.exe -auto
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\MountPoints2: {21a71ed3-3593-11e3-90e1-806e6f6e6963} - D:\autoRcd.exe
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\MountPoints2: {5ec66181-6e28-11e4-a57d-5cf9dd3f3163} - Autoplay.exe -auto
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\MountPoints2: {cf913b48-2470-11e4-bd2d-5cf9dd3f3163} - F:\HTC_Sync_Manager_PC.exe
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\...\MountPoints2: {d989c89d-0170-11e4-991c-5cf9dd3f3163} - E:\pushinst.exe
 AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-09-12] (NVIDIA Corporation)
 AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-12] (NVIDIA Corporation)
 
 ==================== Internet (Whitelisted) ====================
 
 (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
 HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
 HKU\S-1-5-21-1318103975-823857753-1504678809-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
 SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKU\S-1-5-21-1318103975-823857753-1504678809-1000 -> {D641A2C1-1BA4-41E7-96C1-B25A238FFE81} URL = https://de.search.yahoo.com/search?fr=mcafee&type=B011DE105D20131015&p={SearchTerms}
 BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
 BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
 BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
 BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
 BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
 BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
 BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
 Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
 Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
 Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
 Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
 Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
 
 FireFox:
 ========
 FF ProfilePath: C:\Users\Wolfram Pallaske\AppData\Roaming\Mozilla\Firefox\Profiles\f2m5r971.default
 FF SearchEngineOrder.1: Sichere Suche
 FF Keyword.URL: https://de.search.yahoo.com/search?fr=mcafee&type=A111DE105&p=
 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll ()
 FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
 FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
 FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
 FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
 FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
 FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
 FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
 FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
 FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
 FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
 FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
 FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
 FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
 FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
 FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
 FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
 FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
 FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
 FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
 FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
 FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
 FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
 FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
 FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
 FF Plugin HKU\S-1-5-21-1318103975-823857753-1504678809-1000: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
 FF Plugin HKU\S-1-5-21-1318103975-823857753-1504678809-1000: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
 FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml
 FF Extension: Adblock Plus - C:\Users\Wolfram Pallaske\AppData\Roaming\Mozilla\Firefox\Profiles\f2m5r971.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-07]
 FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-17]
 FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
 FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2013-10-15]
 
 Chrome:
 =======
 
 ==================== Services (Whitelisted) =================
 
 (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
 S4 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
 R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
 S4 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-09-26] (Freemake) [File not signed]
 R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
 R2 LPDSVC; C:\Windows\system32\lpdsvc.dll [45568 2009-07-14] (Microsoft Corporation)
 S4 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
 R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
 R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
 R3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [603424 2014-09-04] (McAfee, Inc.)
 R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
 R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
 R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-08-20] (McAfee, Inc.)
 R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
 R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
 R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
 S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-09-15] ()
 R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
 R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [289496 2013-10-16] (Realtek Semiconductor)
 S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
 R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [598808 2013-06-06] (Wacom Technology, Corp.)
 
 ==================== Drivers (Whitelisted) ====================
 
 (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
 R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
 R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-11-17] (Disc Soft Ltd)
 S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
 R2 McPvDrv; C:\Windows\system32\drivers\McPvDrv.sys [74560 2013-09-09] (McAfee, Inc.)
 S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
 R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
 R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
 R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
 R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [445512 2014-08-20] (McAfee, Inc.)
 S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96592 2014-08-20] (McAfee, Inc.)
 R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
 R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [300320 2013-09-12] (NVIDIA Corporation)
 R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
 
 ==================== NetSvcs (Whitelisted) ===================
 
 (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
 ==================== One Month Created Files and Folders ========
 
 (If an entry is included in the fixlist, the file\folder will be moved.)
 
 2015-01-21 12:12 - 2015-01-21 12:12 - 00003277 _____ () C:\Users\Wolfram Pallaske\Desktop\MBM.txt
 2015-01-21 11:49 - 2015-01-21 12:11 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
 2015-01-21 11:49 - 2015-01-21 11:49 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
 2015-01-21 11:49 - 2015-01-21 11:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
 2015-01-21 11:49 - 2015-01-21 11:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
 2015-01-21 11:49 - 2015-01-21 11:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
 2015-01-21 11:49 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
 2015-01-21 11:49 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
 2015-01-21 11:49 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
 2015-01-21 11:48 - 2015-01-21 11:40 - 00002616 _____ () C:\Users\Wolfram Pallaske\Desktop\AdwCleaner[S0].txt
 2015-01-21 11:47 - 2015-01-21 11:47 - 00002888 _____ () C:\Users\Wolfram Pallaske\Desktop\JRT.txt
 2015-01-21 11:43 - 2015-01-21 11:43 - 00000000 ____D () C:\Windows\ERUNT
 2015-01-21 11:38 - 2015-01-21 11:40 - 00000000 ____D () C:\AdwCleaner
 2015-01-21 11:37 - 2015-01-21 11:37 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Wolfram Pallaske\Downloads\mbam-setup-2.0.4.1028.exe
 2015-01-21 11:37 - 2015-01-21 11:37 - 02186752 _____ () C:\Users\Wolfram Pallaske\Downloads\AdwCleaner_4.108.exe
 2015-01-21 11:37 - 2015-01-21 11:37 - 01707939 _____ (Thisisu) C:\Users\Wolfram Pallaske\Downloads\JRT.exe
 2015-01-21 09:56 - 2015-01-21 09:56 - 00001264 _____ () C:\Users\Wolfram Pallaske\Desktop\Revo Uninstaller.lnk
 2015-01-21 09:56 - 2015-01-21 09:56 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
 2015-01-21 09:55 - 2015-01-21 09:55 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Wolfram Pallaske\Downloads\revosetup95.exe
 2015-01-21 09:28 - 2015-01-21 09:29 - 00033288 _____ () C:\Users\Wolfram Pallaske\Downloads\Addition.txt
 2015-01-21 09:26 - 2015-01-21 12:13 - 00022699 _____ () C:\Users\Wolfram Pallaske\Downloads\FRST.txt
 2015-01-21 09:26 - 2015-01-21 12:13 - 00000000 ____D () C:\FRST
 2015-01-21 09:24 - 2015-01-21 09:24 - 02126848 _____ (Farbar) C:\Users\Wolfram Pallaske\Downloads\FRST64.exe
 2015-01-21 08:33 - 2015-01-21 12:09 - 00007468 _____ () C:\Windows\PFRO.log
 2015-01-21 08:33 - 2015-01-21 12:09 - 00000504 _____ () C:\Windows\setupact.log
 2015-01-21 08:33 - 2015-01-21 08:33 - 00000000 _____ () C:\Windows\setuperr.log
 2015-01-21 08:31 - 2015-01-21 08:32 - 00095280 _____ () C:\Users\Wolfram Pallaske\Documents\cc_20150121_083154.reg
 2015-01-21 08:27 - 2015-01-21 08:27 - 05317104 _____ (Piriform Ltd) C:\Users\Wolfram Pallaske\Downloads\ccsetup501.exe
 2015-01-21 08:27 - 2015-01-21 08:27 - 00002794 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
 2015-01-21 08:27 - 2015-01-21 08:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
 2015-01-21 08:27 - 2015-01-21 08:27 - 00000000 ____D () C:\Program Files\CCleaner
 2015-01-21 08:22 - 2015-01-21 08:22 - 00700783 ____R (Swearware) C:\Users\Wolfram Pallaske\Downloads\dds+.exe
 2015-01-21 07:31 - 2015-01-21 07:31 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Local\PDFCreator
 2015-01-21 07:30 - 2015-01-21 08:30 - 00000000 ____D () C:\Program Files\PDFCreator
 2015-01-21 07:30 - 2015-01-21 07:30 - 00114872 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
 2015-01-21 07:30 - 2015-01-21 07:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
 2015-01-21 07:28 - 2015-01-21 07:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer
 2015-01-21 07:26 - 2015-01-21 07:27 - 17072512 _____ () C:\Program Files\PDFXVwer2.5.311.zip
 2015-01-21 07:20 - 2015-01-21 07:21 - 17072512 _____ () C:\Users\Wolfram Pallaske\Downloads\PDFXVwer2.5.311.zip
 2015-01-21 07:20 - 2015-01-21 07:20 - 00000000 __SHD () C:\Users\Wolfram Pallaske\AppData\Local\EmieBrowserModeList
 2015-01-21 07:18 - 2015-01-21 07:18 - 01191200 _____ () C:\Users\Wolfram Pallaske\Downloads\PDF XChange Viewer - CHIP-Installer.exe
 2015-01-21 07:00 - 2015-01-21 12:11 - 00003754 _____ () C:\Windows\System32\Tasks\AutoKMS
 2015-01-21 06:48 - 2015-01-21 06:48 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Roaming\PDF Architect
 2015-01-18 11:10 - 2015-01-21 09:12 - 00000000 ____D () C:\Program Files (x86)\OLYMPUS
 2015-01-18 11:10 - 2015-01-18 11:10 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Local\OLYMPUS
 2015-01-18 11:09 - 2015-01-18 11:09 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
 2015-01-18 11:07 - 2015-01-18 11:08 - 61628548 _____ () C:\Users\Wolfram Pallaske\Downloads\OMWindows.zip
 2015-01-17 17:39 - 2015-01-21 07:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
 2015-01-16 20:37 - 2015-01-16 20:40 - 27256624 _____ (pdfforge ) C:\Users\Wolfram Pallaske\Downloads\PDFCreator-2_0_1-setup.exe
 2015-01-14 09:59 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
 2015-01-14 09:59 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
 2015-01-14 09:59 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
 2015-01-14 09:59 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
 2015-01-14 09:59 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
 2015-01-14 09:59 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
 2015-01-14 09:59 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
 2015-01-14 09:59 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
 2015-01-14 09:59 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
 2015-01-14 09:59 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
 2015-01-14 09:59 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
 2015-01-14 09:59 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
 2015-01-14 09:59 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
 2015-01-13 11:47 - 2015-01-15 09:10 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Roaming\Xv
 2015-01-12 15:25 - 2015-01-12 21:14 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Roaming\.minecraft
 2015-01-12 15:25 - 2015-01-12 15:25 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Roaming\java
 2015-01-12 15:23 - 2015-01-12 15:24 - 00000000 ____D () C:\Program Files (x86)\Minecraft
 2015-01-12 15:23 - 2015-01-12 15:23 - 00000961 _____ () C:\Users\Public\Desktop\Minecraft.lnk
 2015-01-12 15:23 - 2015-01-12 15:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
 2015-01-12 15:22 - 2015-01-12 15:22 - 02318336 _____ () C:\Users\Wolfram Pallaske\Downloads\MinecraftInstaller.msi
 2015-01-09 14:41 - 2015-01-09 15:14 - 1600265736 _____ () C:\Users\Wolfram Pallaske\Downloads\hih13566-1080p.mp4
 2015-01-09 14:21 - 2015-01-09 14:35 - 825340126 _____ () C:\Users\Wolfram Pallaske\Downloads\hih13616-1080p.mp4
 2015-01-08 07:58 - 2015-01-20 22:34 - 00000000 ____D () C:\Users\Wolfram Pallaske\Desktop\Zettelwirtschaft
 2015-01-06 08:57 - 2015-01-06 08:57 - 00001456 _____ () C:\Users\Wolfram Pallaske\AppData\Local\Adobe Für Web speichern 13.0 Prefs
 2014-12-25 15:13 - 2014-12-27 00:28 - 00000000 ____D () C:\Users\Wolfram Pallaske\Desktop\von Papa
 
 ==================== One Month Modified Files and Folders =======
 
 (If an entry is included in the fixlist, the file\folder will be moved.)
 
 2015-01-21 12:14 - 2013-10-15 14:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
 2015-01-21 12:12 - 2013-10-15 14:22 - 00000000 __RSD () C:\Users\Wolfram Pallaske\Documents\McAfee-Tresore
 2015-01-21 12:10 - 2014-05-08 22:39 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf6b05edc3a848.job
 2015-01-21 12:09 - 2013-10-15 13:46 - 00000000 ____D () C:\ProgramData\NVIDIA
 2015-01-21 12:09 - 2013-10-15 13:16 - 02050154 _____ () C:\Windows\WindowsUpdate.log
 2015-01-21 12:09 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
 2015-01-21 12:08 - 2005-09-05 08:11 - 00000000 _RSHD () C:\Users\Wolfram Pallaske\AppData\Roaming\Windows Firewall
 2015-01-21 12:06 - 2014-03-01 11:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
 2015-01-21 12:02 - 2013-12-05 02:22 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cef1586b0a9169.job
 2015-01-21 11:47 - 2009-07-14 05:45 - 00028128 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
 2015-01-21 11:47 - 2009-07-14 05:45 - 00028128 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
 2015-01-21 11:45 - 2013-10-15 23:10 - 00699666 _____ () C:\Windows\system32\perfh007.dat
 2015-01-21 11:45 - 2013-10-15 23:10 - 00149774 _____ () C:\Windows\system32\perfc007.dat
 2015-01-21 11:45 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
 2015-01-21 11:41 - 2013-10-15 14:22 - 00000000 ____D () C:\Program Files (x86)\McAfee
 2015-01-21 11:41 - 2013-10-15 14:14 - 00000000 ____D () C:\ProgramData\McAfee
 2015-01-21 11:38 - 2013-10-15 17:40 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Roaming\vlc
 2015-01-21 09:20 - 2013-11-08 10:34 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Roaming\Notepad++
 2015-01-21 09:20 - 2013-11-08 10:34 - 00000000 ____D () C:\Program Files (x86)\Notepad++
 2015-01-21 09:19 - 2013-10-15 21:13 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
 2015-01-21 09:19 - 2013-10-15 18:20 - 00000000 ____D () C:\Program Files (x86)\Steam
 2015-01-21 09:09 - 2014-02-06 17:45 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Local\CrashDumps
 2015-01-21 09:09 - 2013-10-15 14:22 - 00000000 ____D () C:\Program Files\McAfee
 2015-01-21 09:09 - 2013-10-15 14:21 - 00074703 _____ () C:\Windows\SysWOW64\mfc45.dat
 2015-01-21 09:07 - 2013-10-15 13:24 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
 2015-01-21 09:06 - 2013-12-21 18:47 - 00000000 ____D () C:\Program Files (x86)\Epson Software
 2015-01-21 09:06 - 2013-12-21 18:41 - 00000000 ____D () C:\Program Files (x86)\epson
 2015-01-21 09:04 - 2013-12-21 18:42 - 00000000 ____D () C:\ProgramData\EPSON
 2015-01-21 09:03 - 2013-12-21 18:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
 2015-01-21 09:01 - 2013-12-21 18:47 - 00000000 ____D () C:\Program Files\EpsonNet
 2015-01-21 08:30 - 2014-06-18 21:33 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Roaming\DAEMON Tools Lite
 2015-01-21 08:29 - 2013-10-15 23:12 - 00000000 ____D () C:\Windows\Panther
 2015-01-21 07:28 - 2013-10-18 20:43 - 00000000 ____D () C:\Program Files\Tracker Software
 2015-01-21 07:18 - 2014-08-24 23:07 - 00000000 ___RD () C:\Program Files (x86)\Skype
 2015-01-21 07:18 - 2013-11-18 20:37 - 00000000 ____D () C:\ProgramData\Skype
 2015-01-21 06:30 - 2013-10-15 14:51 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Local\Adobe
 2015-01-20 22:37 - 2014-12-15 09:35 - 10506240 _____ () C:\Users\Wolfram Pallaske\Documents\Modellphotographie.indd
 2015-01-18 10:57 - 2013-10-18 13:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
 2015-01-17 01:25 - 2013-10-29 14:39 - 00011730 _____ () C:\Users\Wolfram Pallaske\.heldEinstellungen4_1.xml
 2015-01-16 20:07 - 2013-10-29 14:39 - 00000268 _____ () C:\Users\Wolfram Pallaske\.dsa4.properties
 2015-01-15 09:19 - 2013-10-20 16:57 - 00000000 ____D () C:\Windows\system32\MRT
 2015-01-15 08:43 - 2013-10-20 16:57 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
 2015-01-14 13:06 - 2014-03-01 11:17 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
 2015-01-14 13:06 - 2013-10-15 14:52 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
 2015-01-14 13:06 - 2013-10-15 14:52 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
 2015-01-07 14:36 - 2013-10-16 15:27 - 00000000 ____D () C:\Users\Wolfram Pallaske\Documents\Usenet.nl
 2015-01-07 14:34 - 2013-10-16 15:27 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Roaming\Usenet.nl
 2015-01-06 08:57 - 2013-10-15 14:52 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Roaming\Adobe
 2015-01-06 04:36 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
 2015-01-05 14:31 - 2013-12-08 18:17 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Local\Audible
 2014-12-31 23:01 - 2014-03-05 00:04 - 00000000 ____D () C:\Users\Wolfram Pallaske\AppData\Local\Amazon Cloud Player
 2014-12-30 00:52 - 2013-10-15 13:20 - 00000000 ____D () C:\Users\Wolfram Pallaske
 2014-12-26 18:40 - 2013-10-22 14:14 - 00000000 ____D () C:\temp
 
 ==================== Files in the root of some directories =======
 2015-01-21 07:26 - 2015-01-21 07:27 - 17072512 _____ () C:\Program Files\PDFXVwer2.5.311.zip
 2014-04-23 10:15 - 2014-12-14 21:47 - 0000132 _____ () C:\Users\Wolfram Pallaske\AppData\Roaming\Adobe BMP-Format CC - Voreinstellungen
 2013-11-07 19:57 - 2013-11-19 15:40 - 0000132 _____ () C:\Users\Wolfram Pallaske\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen
 2014-06-19 08:12 - 2014-07-17 10:30 - 0000034 _____ () C:\Users\Wolfram Pallaske\AppData\Roaming\AdobeWLCMCache.dat
 2013-12-19 00:35 - 2014-02-26 01:00 - 0000145 _____ () C:\Users\Wolfram Pallaske\AppData\Roaming\WB.CFG
 2014-02-03 19:47 - 2014-02-03 19:47 - 158099492 _____ () C:\Users\Wolfram Pallaske\AppData\Local\ACCCx2_4_0_348.zip.aamdownload
 2014-02-03 19:47 - 2014-02-03 19:47 - 0001943 _____ () C:\Users\Wolfram Pallaske\AppData\Local\ACCCx2_4_0_348.zip.aamdownload.aamd
 2015-01-06 08:57 - 2015-01-06 08:57 - 0001456 _____ () C:\Users\Wolfram Pallaske\AppData\Local\Adobe Für Web speichern 13.0 Prefs
 2013-10-21 23:53 - 2013-10-21 23:59 - 0003584 _____ () C:\Users\Wolfram Pallaske\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 2013-11-19 16:12 - 2013-11-19 16:12 - 0005335 _____ () C:\Users\Wolfram Pallaske\AppData\Local\recently-used.xbel
 2014-01-06 14:53 - 2014-12-18 09:19 - 0000287 _____ () C:\Users\Wolfram Pallaske\AppData\Local\VersionChecker_17.xml
 2014-05-23 21:29 - 2014-06-23 11:39 - 0000287 _____ () C:\Users\Wolfram Pallaske\AppData\Local\VersionChecker_19.xml
 2014-08-08 09:30 - 2014-08-08 09:30 - 0000000 _____ () C:\Users\Wolfram Pallaske\AppData\Local\{63241142-0D9A-4749-B3DF-89EF41C4A705}
 
 Some content of TEMP:
 ====================
 C:\Users\Wolfram Pallaske\AppData\Local\Temp\Quarantine.exe
 C:\Users\Wolfram Pallaske\AppData\Local\Temp\sqlite3.dll
 
 
 ==================== Bamital & volsnap Check =================
 
 (There is no automatic fix for files that do not pass verification.)
 
 C:\Windows\System32\winlogon.exe => File is digitally signed
 C:\Windows\System32\wininit.exe => File is digitally signed
 C:\Windows\SysWOW64\wininit.exe => File is digitally signed
 C:\Windows\explorer.exe => File is digitally signed
 C:\Windows\SysWOW64\explorer.exe => File is digitally signed
 C:\Windows\System32\svchost.exe => File is digitally signed
 C:\Windows\SysWOW64\svchost.exe => File is digitally signed
 C:\Windows\System32\services.exe => File is digitally signed
 C:\Windows\System32\User32.dll => File is digitally signed
 C:\Windows\SysWOW64\User32.dll => File is digitally signed
 C:\Windows\System32\userinit.exe => File is digitally signed
 C:\Windows\SysWOW64\userinit.exe => File is digitally signed
 C:\Windows\System32\rpcss.dll => File is digitally signed
 C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
 LastRegBack: 2015-01-15 10:24
 
 ==================== End Of Log ============================
 --- --- ---  |