leili1980 | 07.05.2014 05:40 | Hier die Beiden logfiles:
first
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2014
Ran by peter (administrator) on HP-WS2 on 07-05-2014 06:35:21
Running from \\SBSRV\RedirectedFolders\peter\Desktop\Virusentfernung
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\AMSP_LogServer.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(SafeNet Inc.) C:\Windows\System32\hasplms.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiSeAgnt.exe
(SHARP CORPORATION) C:\Windows\System32\spool\drivers\x64\3\SS0XRCV.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Hewlett-Packard ) C:\Program Files\IDT\WDM\beats64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
(Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\CNYHKEY.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Security Agent\TmListen.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
() C:\Program Files\Procam\Pulse\ProcamPulseServer.exe
(Farbar) \\SBSRV\RedirectedFolders\peter\Desktop\Virusentfernung\FRST64.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [219480 2011-10-17] (Trend Micro Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [489472 2010-09-27] (IDT, Inc.)
HKLM\...\Run: [SS0XRCV] => C:\Windows\system32\spool\drivers\x64\3\SS0XRCV.exe [102400 2006-10-23] (SHARP CORPORATION)
HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [37888 2010-08-15] (Hewlett-Packard )
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [664600 2010-09-28] (PDF Complete Inc)
HKLM-x32\...\Run: [LaunchHPOSIAPP] => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe [385024 2009-04-04] (Hewlett-Packard)
HKLM-x32\...\Run: [HP KEYBOARDx] => C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE [710656 2010-02-11] (Hewlett-Packard)
HKLM-x32\...\Run: [File Sanitizer] => c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [11265536 2009-12-12] (Hewlett-Packard)
HKLM-x32\...\Run: [BATINDICATOR] => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe [2068992 2009-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [ApnUpdater] => C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1644680 2013-02-08] (Ask)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/4
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM/4
URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
URLSearchHook: HKCU - (No Name) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMDTDF
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMDTDF
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMDTDF
SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMDTDF
SearchScopes: HKCU - DefaultScope {3D1F3657-449F-4370-B199-239596226E57} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=
SearchScopes: HKCU - {26D8B5A5-957F-42CF-9EFB-731C77081ECC} URL = hxxp://at.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms}
SearchScopes: HKCU - {3D1F3657-449F-4370-B199-239596226E57} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=
SearchScopes: HKCU - {4EE419FA-A1F6-4C39-854A-7FC7295A2193} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=de_US&apn_ptnrs=U3&apn_dtid=OSJ000YYAT&apn_uid=B3AC2D7D-EFC7-49B1-A0F3-EF95F6A1A4FF&apn_sauid=F35DCAA1-1E94-45E4-BF2E-72E02603BFCB
BHO: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.6.1242\6.6.1089\TmIEPlg.dll (Trend Micro Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.6.1242\6.6.1089\TmIEPlg32.dll (Trend Micro Inc.)
BHO-x32: File Sanitizer for HP ProtectTools - {3134413B-49B4-425C-98A5-893C1F195601} - c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
BHO-x32: TSToolbarBHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Security Agent\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: No Name - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File
BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM-x32 - Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Security Agent\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: HKLM-x32 {00134F72-5284-44F7-95A8-52A619F70752} https://192.168.0.10:444/officescan/console/ClientInstall/WinNTChk.cab
DPF: HKLM-x32 {9BBB3919-F518-4D06-8209-299FC243FC44} https://192.168.0.10:444/smb/console/html/root/AtxEnc.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.6.1242\6.6.1089\TmIEPlg.dll (Trend Micro Inc.)
Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - No File
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - No File
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.6.1242\6.6.1089\TmIEPlg32.dll (Trend Micro Inc.)
Handler-x32: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Security Agent\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
Handler-x32: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Security Agent\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.10
FireFox:
========
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - C:\Program Files\Trend Micro\AMSP\module\20004\FxExt\firefoxextension\
FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\module\20004\FxExt\firefoxextension\ []
FF HKLM-x32\...\Firefox\Extensions: [{22181a4d-af90-4ca3-a569-faed9118d6bc}] - C:\Program Files\Trend Micro\Security Agent\UIFramework\Toolbar\firefoxextension
FF Extension: Trend Micro Toolbar - C:\Program Files\Trend Micro\Security Agent\UIFramework\Toolbar\firefoxextension [2011-10-19]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR Extension: (YouTube) - C:\Users\peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-14]
CHR Extension: (Google-Suche) - C:\Users\peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-14]
CHR Extension: (Google Mail) - C:\Users\peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-14]
==================== Services (Whitelisted) =================
R2 hasplms; C:\Windows\system32\hasplms.exe [4180576 2010-09-27] (SafeNet Inc.)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1119768 2010-09-28] (PDF Complete Inc)
R3 TmListen; C:\Program Files\Trend Micro\Security Agent\tmlisten.exe [1017360 2011-11-16] (Trend Micro Inc.)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
S2 XobniService; C:\Program Files (x86)\Xobni\XobniService.exe [56040 2010-09-08] (Xobni Corporation)
R2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=qb -dt=60000 [X]
S4 Winmgmt; [X]
==================== Drivers (Whitelisted) ====================
S3 OxPPort; C:\Windows\system32\DRIVERS\OxPPort.sys [98304 2008-07-31] (OEM)
R2 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [90896 2011-06-23] (Trend Micro Inc.)
R2 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [146192 2011-06-23] (Trend Micro Inc.)
R2 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [69904 2011-06-23] (Trend Micro Inc.)
R1 tmlwf; C:\Windows\System32\DRIVERS\tmlwf.sys [194640 2010-09-30] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105552 2010-09-30] (Trend Micro Inc.)
R2 tmwfp; C:\Windows\System32\DRIVERS\tmwfp.sys [340560 2010-09-30] (Trend Micro Inc.)
S2 DS1410D; SYSTEM32\drivers\DS1410D.SYS [X]
S2 regi; \??\C:\Windows\system32\drivers\regi.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-07 06:35 - 2014-05-07 06:35 - 00000000 ____D () C:\FRST
2014-05-06 21:11 - 2014-05-06 21:11 - 00077850 _____ () C:\OTL.Txt
2014-05-06 14:57 - 2014-05-06 14:57 - 00000000 ____D () C:\Users\peter\AppData\Local\CrashDumps
2014-05-06 13:47 - 2014-05-06 13:47 - 00000000 ____D () C:\Users\thomasl\AppData\Local\Adobe
2014-05-06 13:07 - 2014-05-06 13:07 - 00000000 ____D () C:\Users\thomasl\AppData\Roaming\WinRAR
2014-05-06 13:06 - 2014-05-06 13:06 - 00000000 ____D () C:\Users\thomasl\AppData\Local\Google
2014-05-06 12:52 - 2014-05-06 12:52 - 00143728 _____ () C:\Users\thomasl\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-06 12:35 - 2014-05-06 13:47 - 00000000 ____D () C:\Users\thomasl\AppData\Roaming\Adobe
2014-05-06 12:24 - 2014-05-06 12:24 - 00001411 _____ () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-05-06 12:24 - 2014-05-06 12:24 - 00000000 ____D () C:\Users\thomasl\AppData\Local\PDFC
2014-05-06 12:23 - 2014-05-06 21:08 - 00000000 ____D () C:\Users\thomasl
2014-05-06 12:23 - 2014-05-06 13:11 - 00000000 ___RD () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-06 12:23 - 2014-05-06 12:24 - 00001445 _____ () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-06 12:23 - 2014-05-06 12:24 - 00000000 ___RD () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-06 12:23 - 2014-05-06 12:23 - 00000020 ___SH () C:\Users\thomasl\ntuser.ini
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Vorlagen
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Startmenü
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Netzwerkumgebung
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Lokale Einstellungen
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Eigene Dateien
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Druckumgebung
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\AppData\Local\Verlauf
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\AppData\Local\Anwendungsdaten
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Anwendungsdaten
2014-05-06 12:23 - 2011-03-25 14:37 - 00000000 ____D () C:\Users\thomasl\AppData\Local\Microsoft Help
2014-05-06 12:23 - 2011-03-17 12:49 - 00000000 ____D () C:\Users\thomasl\AppData\Roaming\Macromedia
2014-05-06 12:23 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-05-06 12:23 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-05-06 09:56 - 2014-05-06 09:57 - 00000036 _____ () C:\Users\peter\AppData\Local\housecall.guid.cache
2014-05-06 08:37 - 2014-05-06 09:04 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-05-06 07:51 - 2014-05-06 07:51 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-06 07:25 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-06 07:25 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-05-06 07:25 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-05-06 07:25 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-05-06 07:24 - 2014-05-06 07:25 - 00006055 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-06 07:24 - 2014-05-06 07:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-06 07:03 - 2014-05-06 07:03 - 00001386 _____ () C:\Windows\system32\Drivers\etc\hosts.bak
2014-05-06 06:58 - 2014-05-06 06:58 - 00000000 ____D () C:\NPE
2014-05-06 06:57 - 2014-05-06 07:06 - 00000000 ____D () C:\Users\peter\AppData\Local\NPE
2014-05-05 15:53 - 2014-04-29 13:39 - 17849344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-05 15:53 - 2014-04-29 13:15 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-05 15:53 - 2014-04-29 12:28 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-05 15:53 - 2014-04-29 12:07 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-05 13:23 - 2014-05-06 07:04 - 00000000 ____D () C:\Windows\asis
2014-05-05 13:23 - 2014-05-05 13:26 - 00000000 ____D () C:\ProgramData\ibunabeg
2014-05-05 13:23 - 2014-05-05 13:23 - 00000000 ____D () C:\Windows\axeb
2014-04-30 14:29 - 2014-04-30 14:29 - 00000000 ____D () C:\Users\peter\AppData\Roaming\SHARP
2014-04-30 14:28 - 2014-04-30 14:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC-FAX-Treiber der Reihe SHARP MX, MX-M
2014-04-30 14:27 - 2012-10-09 04:17 - 00180320 _____ () C:\Windows\_isusr32.dll
2014-04-30 14:27 - 2010-05-28 08:30 - 00032768 ____N () C:\Windows\SysWOW64\_isusr2k.dll
2014-04-30 14:25 - 2014-04-30 14:27 - 00000000 ____D () C:\Windows\SysWOW64\SCDRV
2014-04-30 14:25 - 2014-04-30 14:25 - 00000000 ____D () C:\Users\peter\AppData\Roaming\InstallShield
2014-04-09 16:14 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 16:14 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 16:14 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 16:14 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 16:14 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 16:14 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 16:14 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 16:14 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 16:14 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 16:14 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 16:14 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 16:13 - 2014-03-08 06:06 - 10926592 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-09 16:13 - 2014-03-08 05:49 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-09 16:13 - 2014-03-08 05:41 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-09 16:13 - 2014-03-08 05:40 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-09 16:13 - 2014-03-08 05:39 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-09 16:13 - 2014-03-08 05:38 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-04-09 16:13 - 2014-03-08 05:37 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-09 16:13 - 2014-03-08 05:34 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-04-09 16:13 - 2014-03-08 05:34 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-09 16:13 - 2014-03-08 05:33 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-09 16:13 - 2014-03-08 05:32 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-09 16:13 - 2014-03-08 05:32 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-09 16:13 - 2014-03-08 05:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-04-09 16:13 - 2014-03-08 05:24 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-09 16:13 - 2014-03-08 01:20 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-09 16:13 - 2014-03-08 01:12 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-09 16:13 - 2014-03-08 01:03 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-09 16:13 - 2014-03-08 01:02 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-09 16:13 - 2014-03-08 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-09 16:13 - 2014-03-08 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-04-09 16:13 - 2014-03-08 00:59 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-09 16:13 - 2014-03-08 00:57 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-04-09 16:13 - 2014-03-08 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-09 16:13 - 2014-03-08 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-09 16:13 - 2014-03-08 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-09 16:13 - 2014-03-08 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-09 16:13 - 2014-03-08 00:52 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-04-09 16:13 - 2014-03-08 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
==================== One Month Modified Files and Folders =======
2014-05-07 06:35 - 2014-05-07 06:35 - 00000000 ____D () C:\FRST
2014-05-07 06:28 - 2012-04-03 05:29 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-07 06:24 - 2011-03-17 12:35 - 01297691 _____ () C:\Windows\WindowsUpdate.log
2014-05-07 06:21 - 2013-02-14 18:26 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-07 06:20 - 2013-02-14 18:26 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-07 05:36 - 2009-07-14 06:45 - 00016768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-07 05:36 - 2009-07-14 06:45 - 00016768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-07 05:28 - 2011-03-25 13:29 - 00000112 _____ () C:\Windows\system32\config\netlogon.ftl
2014-05-07 05:28 - 2011-03-17 12:33 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-07 05:28 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-07 05:28 - 2009-07-14 06:51 - 00097912 _____ () C:\Windows\setupact.log
2014-05-06 21:11 - 2014-05-06 21:11 - 00077850 _____ () C:\OTL.Txt
2014-05-06 21:08 - 2014-05-06 12:23 - 00000000 ____D () C:\Users\thomasl
2014-05-06 21:08 - 2012-12-18 11:39 - 00000000 ____D () C:\Users\DefaultAppPool
2014-05-06 21:08 - 2011-10-08 01:57 - 00000000 ____D () C:\Users\administrator
2014-05-06 21:08 - 2011-03-25 13:31 - 00000000 ____D () C:\Users\peter
2014-05-06 21:08 - 2011-03-25 13:03 - 00000000 ____D () C:\Users\admin
2014-05-06 15:24 - 2011-03-25 13:34 - 00000000 ____D () C:\PTW
2014-05-06 14:57 - 2014-05-06 14:57 - 00000000 ____D () C:\Users\peter\AppData\Local\CrashDumps
2014-05-06 13:47 - 2014-05-06 13:47 - 00000000 ____D () C:\Users\thomasl\AppData\Local\Adobe
2014-05-06 13:47 - 2014-05-06 12:35 - 00000000 ____D () C:\Users\thomasl\AppData\Roaming\Adobe
2014-05-06 13:11 - 2014-05-06 12:23 - 00000000 ___RD () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-06 13:07 - 2014-05-06 13:07 - 00000000 ____D () C:\Users\thomasl\AppData\Roaming\WinRAR
2014-05-06 13:06 - 2014-05-06 13:06 - 00000000 ____D () C:\Users\thomasl\AppData\Local\Google
2014-05-06 12:52 - 2014-05-06 12:52 - 00143728 _____ () C:\Users\thomasl\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-06 12:38 - 2011-03-25 13:21 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-05-06 12:24 - 2014-05-06 12:24 - 00001411 _____ () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-05-06 12:24 - 2014-05-06 12:24 - 00000000 ____D () C:\Users\thomasl\AppData\Local\PDFC
2014-05-06 12:24 - 2014-05-06 12:23 - 00001445 _____ () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-06 12:24 - 2014-05-06 12:23 - 00000000 ___RD () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-06 12:24 - 2009-07-14 06:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-05-06 12:23 - 2014-05-06 12:23 - 00000020 ___SH () C:\Users\thomasl\ntuser.ini
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Vorlagen
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Startmenü
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Netzwerkumgebung
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Lokale Einstellungen
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Eigene Dateien
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Druckumgebung
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\AppData\Local\Verlauf
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\AppData\Local\Anwendungsdaten
2014-05-06 12:23 - 2014-05-06 12:23 - 00000000 _SHDL () C:\Users\thomasl\Anwendungsdaten
2014-05-06 10:58 - 2013-11-14 10:59 - 00000000 ____D () C:\Windows\pss
2014-05-06 09:57 - 2014-05-06 09:56 - 00000036 _____ () C:\Users\peter\AppData\Local\housecall.guid.cache
2014-05-06 09:04 - 2014-05-06 08:37 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-05-06 08:59 - 2012-09-11 04:55 - 00238128 _____ () C:\Windows\RegBootClean64.exe
2014-05-06 08:05 - 2011-03-17 12:44 - 00000000 ____D () C:\ProgramData\PDFC
2014-05-06 07:51 - 2014-05-06 07:51 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-06 07:25 - 2014-05-06 07:24 - 00006055 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-06 07:25 - 2013-06-28 06:20 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-06 07:24 - 2014-05-06 07:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-06 07:06 - 2014-05-06 06:57 - 00000000 ____D () C:\Users\peter\AppData\Local\NPE
2014-05-06 07:04 - 2014-05-05 13:23 - 00000000 ____D () C:\Windows\asis
2014-05-06 07:03 - 2014-05-06 07:03 - 00001386 _____ () C:\Windows\system32\Drivers\etc\hosts.bak
2014-05-06 06:58 - 2014-05-06 06:58 - 00000000 ____D () C:\NPE
2014-05-06 06:58 - 2012-11-13 05:43 - 00000000 ____D () C:\Program Files\Google
2014-05-06 06:58 - 2012-11-13 05:43 - 00000000 ____D () C:\Program Files (x86)\Google
2014-05-06 06:58 - 2011-03-17 12:32 - 00971596 _____ () C:\Windows\PFRO.log
2014-05-06 06:57 - 2011-03-17 12:50 - 00000000 ____D () C:\ProgramData\Norton
2014-05-06 06:52 - 2012-11-13 05:43 - 00000000 ____D () C:\Users\peter\AppData\Local\Google
2014-05-05 13:26 - 2014-05-05 13:23 - 00000000 ____D () C:\ProgramData\ibunabeg
2014-05-05 13:25 - 2011-10-27 15:03 - 00000000 ____D () C:\ProgramData\Sun
2014-05-05 13:23 - 2014-05-05 13:23 - 00000000 ____D () C:\Windows\axeb
2014-05-05 06:01 - 2011-07-11 05:00 - 00003186 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForpeter
2014-05-05 06:01 - 2011-07-11 05:00 - 00000332 _____ () C:\Windows\Tasks\HPCeeScheduleForpeter.job
2014-04-30 14:29 - 2014-04-30 14:29 - 00000000 ____D () C:\Users\peter\AppData\Roaming\SHARP
2014-04-30 14:28 - 2014-04-30 14:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC-FAX-Treiber der Reihe SHARP MX, MX-M
2014-04-30 14:27 - 2014-04-30 14:25 - 00000000 ____D () C:\Windows\SysWOW64\SCDRV
2014-04-30 14:25 - 2014-04-30 14:25 - 00000000 ____D () C:\Users\peter\AppData\Roaming\InstallShield
2014-04-30 14:25 - 2011-03-17 12:39 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-30 10:42 - 2011-03-25 14:17 - 00000000 ____D () C:\Program Files (x86)\lp
2014-04-29 13:39 - 2014-05-05 15:53 - 17849344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 13:15 - 2014-05-05 15:53 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 12:28 - 2014-05-05 15:53 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 12:07 - 2014-05-05 15:53 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-29 05:28 - 2012-04-03 05:29 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-29 05:28 - 2012-04-03 05:29 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-29 05:28 - 2011-05-18 06:12 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-16 05:04 - 2011-06-16 05:04 - 00003214 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForHP-WS2$
2014-04-16 05:04 - 2011-06-16 05:04 - 00000338 _____ () C:\Windows\Tasks\HPCeeScheduleForHP-WS2$.job
2014-04-14 20:13 - 2014-05-06 07:25 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-14 20:05 - 2014-05-06 07:25 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-14 20:05 - 2014-05-06 07:25 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-14 20:04 - 2014-05-06 07:25 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-09 16:15 - 2011-03-25 13:52 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-09 04:51 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
Files to move or delete:
====================
C:\ProgramData\0r7tg4j6.fee
C:\ProgramData\lsass.exe
C:\ProgramData\rjvjwbh3.fee
C:\ProgramData\wl8z17tmq9.bxx
C:\ProgramData\wl8z17tmq9.fdd
C:\ProgramData\wl8z17tmq9.fvv
C:\ProgramData\wl8z17tmq9.reg
Some content of TEMP:
====================
C:\Users\admin\AppData\Local\Temp\MSN360F.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-29 12:18
==================== End Of Log ============================ --- --- ---
--- --- ---
addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-05-2014
Ran by peter at 2014-05-07 06:36:42
Running from \\SBSRV\RedirectedFolders\peter\Desktop\Virusentfernung
Boot Mode: Normal
==========================================================
==================== Security Center ========================
==================== Installed Programs ======================
Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft)
2007 Microsoft Office system (HKLM-x32\...\PROHYBRIDR) (Version: 12.0.6612.1000 - Microsoft Corporation)
64 Bit HP CIO Components Installer (Version: 8.2.2 - Hewlett-Packard) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9130 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 1.5.3.9130 - Adobe Systems Inc.) Hidden
Adobe Flash Player 10 ActiveX 64-bit (HKLM\...\Adobe Flash Player ActiveX 64) (Version: 10.3.162.28 - Adobe Systems Incorporated)
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.206 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden
Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.15.15.0 - Ask.com) <==== ATTENTION
Ask Toolbar Updater (HKCU\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.4.36191 - Ask.com) <==== ATTENTION
AutoCAD Mechanical 2011 (HKLM\...\AutoCAD Mechanical 2011) (Version: 15.0.46.0 - Autodesk)
AutoCAD Mechanical 2011 (Version: 15.0.106.0 - Autodesk) Hidden
AutoCAD Mechanical 2011 Language Pack - Deutsch (Version: 15.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2011 Version 2 (HKLM\...\AutoCAD Mechanical 2011 Version 2) (Version: 1 - Autodesk)
Autodesk Material Library 2011 (HKLM-x32\...\{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}) (Version: 2.0.0.49 - Autodesk)
Autodesk Material Library 2011 Base Image library (HKLM-x32\...\{CD1E078C-A6B9-47DA-B035-6365C85C7832}) (Version: 2.0.0.49 - Autodesk)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Blasterball 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bounce Symphony (x32 Version: 2.2.0.95 - WildTangent) Hidden
Build-a-Lot - The Elizabethan Era (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
Canon MP Navigator EX 1.0 (HKLM-x32\...\MP Navigator EX 1.0) (Version: - )
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden
FARO LS 1.1.406.58 (HKLM-x32\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production)
FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden
File Sanitizer For HP ProtectTools (HKLM-x32\...\{6D6ADF03-B257-4EA5-BBC1-1D145AF8D514}) (Version: 5.0.1.2 - Hewlett-Packard)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.131 - Google Inc.)
Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP Auto (Version: 1.0.12494.3472 - Hewlett-Packard Company) Hidden
HP Connect Solutions (HKLM-x32\...\{BE1C9464-DEBB-4DA6-B19A-8EC634F22D73}) (Version: 1.0.0.4 - Hewlett-Packard)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden
HP Desktop Keyboard (HKLM-x32\...\HP Keyboard_is1) (Version: 1.0.0.13 - Hewlett-Packard)
HP Game Console (x32 Version: - WildTangent) Hidden
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.1.5 - WildTangent)
HP MAINSTREAM KEYBOARD (HKLM-x32\...\{B40D7926-AE5F-41EA-8AC6-56C0E2F00E9D}) (Version: 1.4.3.0 - Hewlett-Packard)
HP Managed Printing Admin (HKLM-x32\...\{7CA4F780-7AD0-417A-82A1-46EB825CFD53}) (Version: 2.5.9 - Hewlett-Packard)
HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Remote Solution (HKLM-x32\...\HP Remote Solution) (Version: 1.1.14.0 - Hewlett-Packard)
HP Remote Solution (x32 Version: 1.1.14.0 - Hewlett-Packard) Hidden
HP Setup (HKLM-x32\...\{05BA6A83-C7A7-4F85-88F1-150142305229}) (Version: 8.5.4489.3576 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard)
HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.1.6.0 - Hewlett-Packard)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6302.0 - IDT)
Insaniquarium Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
InterVideo WinDVD 8 (HKLM-x32\...\InstallShield_{5FEBF468-5AC2-4C66-AD80-DF85C085AA73}) (Version: 8.5.10.84 - InterVideo Inc.)
InterVideo WinDVD 8 (x32 Version: 8.5.10.84 - InterVideo Inc.) Hidden
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416025FF}) (Version: 6.0.250 - Oracle)
Jewel Quest II (x32 Version: 2.2.0.95 - WildTangent) Hidden
Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Hybrid 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (Version: 2.0.50728 - Microsoft Corporation) Hidden
Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NVIDIA 3D Vision Treiber 266.58 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 266.58 - NVIDIA Corporation)
NVIDIA Grafiktreiber 266.58 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 266.58 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.1.13.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.1.13.1 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.265.36.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.10.0514 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.10.0514 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.10.0514 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6658 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 266.58 (Version: 266.58 - NVIDIA Corporation) Hidden
PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.9 - PDF Complete, Inc)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.5.0 - Frank Heindörfer, Philip Chinery)
pdfforge Toolbar v5.1 (HKLM-x32\...\{782AE8DA-30DA-44bd-BA9A-9F23B8A4AC79}) (Version: 5.1 - Spigot, Inc.) <==== ATTENTION
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies (x32 Version: 2.2.0.95 - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
Recovery Manager (x32 Version: 5.5.2926 - CyberLink Corp.) Hidden
SHARP MX/MX-M Series 2 PC-Fax Driver (HKLM-x32\...\SHARP MX-2610 3110 3610 Series PC-Fax Driver) (Version: 1.00.000 - SHARP)
Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Trend Micro Worry-Free Business Security Agent (HKLM\...\Wofie) (Version: 7.0.2316 - Trend Micro Deutschland GmbH)
Trend Micro Worry-Free Business Security Agent (x32 Version: 1.0.0 - Trend Micro Inc.) Hidden
Two Worlds Pinball (HKLM-x32\...\Two Worlds Pinball) (Version: 1.00 - TopWare Interactive Inc.)
UCSetup_x64 (HKLM\...\{5CBB1682-C04D-49DF-B276-AE51351BF53E}) (Version: 1.9.935 - ProCAM Systems GmbH)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2473228) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_PROHYBRIDR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2878297) 32-Bit Edition (HKLM-x32\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{9B1DEEA3-B4ED-49F0-9EF7-4A820EEEA7F1}) (Version: - Microsoft)
Virtual Villagers - The Secret City (x32 Version: 2.2.0.95 - WildTangent) Hidden
VMware vSphere Client 4.1 (HKLM-x32\...\{A0B433B1-941D-46F5-AE59-286263534232}) (Version: 4.1.0.14766 - VMware, Inc.)
Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Small Business Server 2008 ClientAgent (HKLM\...\{E4FF4DF1-F99C-49AC-B398-BE0887432846}) (Version: 6.0.5601.6 - Microsoft Corporation)
WinRAR 4.00 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.00.0 - win.rar GmbH)
Xobni (HKLM-x32\...\XobniMain) (Version: - Xobni Corp.)
Xobni Core (x32 Version: 1.0.0 - Xobni, Inc.) Hidden
Zinio Reader 4 (HKLM-x32\...\ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1) (Version: 4.0.3184 - Zinio LLC)
Zinio Reader 4 (x32 Version: 4.0.3184 - Zinio LLC) Hidden
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
==================== Restore Points =========================
Could not list Restore Points. Check "winmgmt" service or repair WMI.
==================== Hosts content: ==========================
2009-07-14 04:34 - 2014-05-06 07:03 - 00000054 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {04363ACD-4452-4BF9-84C6-49EFC734D70A} - System32\Tasks\Microsoft\Windows\SyncCenter\S-1-5-21-1267364221-3491172544-2080735027-1151\{750FDF10-2A26-11D1-A3EA-080036587F03}\synch1 => C:\Windows\system32\mobsync.exe [2010-11-20] (Microsoft Corporation)
Task: {0937458F-66DF-4011-AAFA-991384448AFC} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2013-02-08] () <==== ATTENTION
Task: {16370226-CB61-4E93-B00C-A1456DF2CA6E} - System32\Tasks\HPCeeScheduleForHP-WS2$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
Task: {97D4E97A-9ECD-4894-9608-A51E27100ADD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-29] (Adobe Systems Incorporated)
Task: {99ED95DC-2992-4208-A9A9-4A7D1B8D8776} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-14] (Google Inc.)
Task: {99FDB315-5094-47D1-AC5D-79B8197094FB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {B83744A8-87A0-4AC4-95EE-FC6D0DC4AF41} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {D7D23873-CE8F-4B76-81C7-02B92808285D} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {E7AB5176-23BA-4D08-A3EB-98E2B813CC2D} - System32\Tasks\HPCeeScheduleForpeter => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
Task: {EEB47667-FBDF-4F79-B225-FC3A1D1F8AB1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-14] (Google Inc.)
Task: {F251DAB6-6C23-4F05-9568-2A582BC9CA52} - System32\Tasks\HPOSIAPP64 => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe [2009-02-28] ()
Task: {F8ECD179-CCD7-40FD-A676-E857FB0574D1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-09-05] (Hewlett-Packard Company)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForHP-WS2$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\Windows\Tasks\HPCeeScheduleForpeter.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Loaded Modules (whitelisted) =============
2013-11-20 12:34 - 2012-12-04 21:33 - 00065024 _____ () C:\Windows\system32\spool\PRTPROCS\x64\HP2030PP.DLL
2011-10-19 17:06 - 2009-07-08 19:03 - 00047104 _____ () C:\Program Files\Trend Micro\AMSP\boost_thread-vc80-mt-1_36.dll
2011-10-19 17:06 - 2009-07-08 19:06 - 00042496 _____ () C:\Program Files\Trend Micro\AMSP\boost_date_time-vc80-mt-1_36.dll
2011-10-19 17:06 - 2011-01-03 22:53 - 00731136 _____ () C:\Program Files\Trend Micro\AMSP\sqlite3.dll
2011-10-19 17:06 - 2011-01-03 22:53 - 01719808 _____ () C:\Program Files\Trend Micro\AMSP\libprotobuf.dll
2012-02-21 08:17 - 2011-10-05 10:16 - 00289056 _____ () C:\Program Files\Trend Micro\UniClient\plugins\LUADLL.dll
2012-02-21 08:17 - 2011-11-10 17:37 - 00691728 _____ () C:\Program Files\Trend Micro\Security Agent\plugin\plugToolbar.dll
2011-03-17 12:45 - 2009-02-28 04:13 - 00053248 _____ () C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe
2011-03-17 12:45 - 2009-07-02 23:58 - 00406016 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe
2011-10-20 07:04 - 2011-01-03 15:54 - 00047104 _____ () C:\Program Files\Trend Micro\Security Agent\boost_thread-vc80-mt-1_36.dll
2011-10-20 07:04 - 2011-01-03 15:54 - 00042496 _____ () C:\Program Files\Trend Micro\Security Agent\boost_date_time-vc80-mt-1_36.dll
2012-02-21 08:17 - 2011-11-16 14:59 - 00176640 _____ () C:\Program Files\Trend Micro\Security Agent\libTmHttpServer.dll
2012-02-21 08:17 - 2011-11-16 14:59 - 00167424 _____ () C:\Program Files\Trend Micro\Security Agent\libTmHttpClient.dll
2013-11-20 12:34 - 2012-12-04 21:33 - 02672128 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\HP2030SU.DLL
2013-11-20 12:34 - 2012-12-04 21:33 - 01236992 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\HP2030GC.dll
2013-11-20 12:34 - 2012-12-04 21:33 - 00341504 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\HP2030SD.DLL
2009-07-10 09:26 - 2009-07-10 09:26 - 01123840 _____ () C:\Program Files\Procam\Pulse\ProcamPulseServer.exe
2011-03-17 12:45 - 2009-02-20 02:22 - 00028672 _____ () C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\WMINPUT.DLL
2012-02-21 08:17 - 2011-11-10 17:37 - 00579088 _____ () C:\Program Files\Trend Micro\Security Agent\UIFramework\ToolbarHelper.dll
2012-02-21 08:17 - 2011-01-03 15:53 - 00049152 _____ () C:\Program Files\Trend Micro\Security Agent\UIFramework\boost_thread-vc80-mt-1_36.dll
2012-02-21 08:17 - 2011-01-03 15:53 - 00057344 _____ () C:\Program Files\Trend Micro\Security Agent\UIFramework\boost_date_time-vc80-mt-1_36.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== Disabled items from MSCONFIG ==============
MSCONFIG\startupreg: epqlopul => "C:\Windows\iwyh\sbahibis.exe"
MSCONFIG\startupreg: HP Remote Solution => %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
MSCONFIG\startupreg: ibyhawkb => "C:\Windows\ylij\apinavyj.exe"
MSCONFIG\startupreg: keagobomipis => C:\Users\peter\keagobomipis.exe
MSCONFIG\startupreg: okehutlb => "C:\Windows\ylij\apinavyj.exe"
MSCONFIG\startupreg: ozuhecwj => "C:\Windows\ylij\apinavyj.exe"
MSCONFIG\startupreg: ygakyckt => "C:\Windows\esof\uhekozuc.exe"
==================== Faulty Device Manager Devices =============
Could not list Devices. Check "winmgmt" service or repair WMI.
==================== Event log errors: =========================
Application errors:
==================
Error: (05/06/2014 02:57:13 PM) (Source: Application Error) (User: ) (EventID: 1000)
Description: Name der fehlerhaften Anwendung: WSCommCntr2.exe, Version: 3.0.269.0, Zeitstempel: 0x4c0c8ae0
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000004e4e4
ID des fehlerhaften Prozesses: 0xd68
Startzeit der fehlerhaften Anwendung: 0xWSCommCntr2.exe0
Pfad der fehlerhaften Anwendung: WSCommCntr2.exe1
Pfad des fehlerhaften Moduls: WSCommCntr2.exe2
Berichtskennung: WSCommCntr2.exe3
Error: (05/06/2014 00:34:56 PM) (Source: System Restore) (User: ) (EventID: 8210)
Description: Unbekannter Fehler bei der Systemwiederherstellung: (Windows Update). Zusätzliche Informationen: 0x80070057.
Error: (05/06/2014 00:29:27 PM) (Source: System Restore) (User: ) (EventID: 8210)
Description: Unbekannter Fehler bei der Systemwiederherstellung: (Geplanter Prüfpunkt). Zusätzliche Informationen: 0x80070057.
Error: (05/06/2014 11:04:55 AM) (Source: System Restore) (User: ) (EventID: 8210)
Description: Unbekannter Fehler bei der Systemwiederherstellung: (Installiert PC-FAX-Treiber der Reihe SHARP MX). Zusätzliche Informationen: 0x80070057.
Error: (05/06/2014 09:03:16 AM) (Source: System Restore) (User: ) (EventID: 8210)
Description: Unbekannter Fehler bei der Systemwiederherstellung: (Geplanter Prüfpunkt). Zusätzliche Informationen: 0x80070057.
Error: (05/06/2014 08:58:17 AM) (Source: System Restore) (User: ) (EventID: 8210)
Description: Unbekannter Fehler bei der Systemwiederherstellung: (Installiert PC-FAX-Treiber der Reihe SHARP MX). Zusätzliche Informationen: 0x80070057.
Error: (05/06/2014 06:52:04 AM) (Source: Application Error) (User: ) (EventID: 1000)
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7a144
Name des fehlerhaften Moduls: msi.dll, Version: 5.0.7601.17514, Zeitstempel: 0x4ce7c800
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000001ebca2
ID des fehlerhaften Prozesses: 0xf94
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
Error: (05/05/2014 02:29:39 PM) (Source: Application Error) (User: ) (EventID: 1000)
Description: Name der fehlerhaften Anwendung: WSCommCntr2.exe, Version: 3.0.269.0, Zeitstempel: 0x4c0c8ae0
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000004e4e4
ID des fehlerhaften Prozesses: 0x1b68
Startzeit der fehlerhaften Anwendung: 0xWSCommCntr2.exe0
Pfad der fehlerhaften Anwendung: WSCommCntr2.exe1
Pfad des fehlerhaften Moduls: WSCommCntr2.exe2
Berichtskennung: WSCommCntr2.exe3
Error: (05/05/2014 10:02:53 AM) (Source: Application Error) (User: ) (EventID: 1000)
Description: Name der fehlerhaften Anwendung: WSCommCntr2.exe, Version: 3.0.269.0, Zeitstempel: 0x4c0c8ae0
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000004e4e4
ID des fehlerhaften Prozesses: 0x1c5c
Startzeit der fehlerhaften Anwendung: 0xWSCommCntr2.exe0
Pfad der fehlerhaften Anwendung: WSCommCntr2.exe1
Pfad des fehlerhaften Moduls: WSCommCntr2.exe2
Berichtskennung: WSCommCntr2.exe3
Error: (05/05/2014 09:38:33 AM) (Source: Application Error) (User: ) (EventID: 1000)
Description: Name der fehlerhaften Anwendung: WSCommCntr2.exe, Version: 3.0.269.0, Zeitstempel: 0x4c0c8ae0
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000004e4e4
ID des fehlerhaften Prozesses: 0xf54
Startzeit der fehlerhaften Anwendung: 0xWSCommCntr2.exe0
Pfad der fehlerhaften Anwendung: WSCommCntr2.exe1
Pfad des fehlerhaften Moduls: WSCommCntr2.exe2
Berichtskennung: WSCommCntr2.exe3
System errors:
=============
Error: (05/07/2014 06:13:11 AM) (Source: Service Control Manager) (User: ) (EventID: 7001)
Description: Der Dienst "Security Center" ist vom Dienst "Windows-Verwaltungsinstrumentation" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058
Error: (05/07/2014 06:12:41 AM) (Source: Service Control Manager) (User: ) (EventID: 7001)
Description: Der Dienst "Security Center" ist vom Dienst "Windows-Verwaltungsinstrumentation" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058
Error: (05/07/2014 05:31:37 AM) (Source: Service Control Manager) (User: ) (EventID: 7001)
Description: Der Dienst "Security Center" ist vom Dienst "Windows-Verwaltungsinstrumentation" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058
Error: (05/07/2014 05:31:07 AM) (Source: Service Control Manager) (User: ) (EventID: 7001)
Description: Der Dienst "Security Center" ist vom Dienst "Windows-Verwaltungsinstrumentation" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058
Error: (05/07/2014 05:31:05 AM) (Source: Service Control Manager) (User: ) (EventID: 7001)
Description: Der Dienst "Security Center" ist vom Dienst "Windows-Verwaltungsinstrumentation" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058
Error: (05/07/2014 05:30:37 AM) (Source: Service Control Manager) (User: ) (EventID: 7001)
Description: Der Dienst "Security Center" ist vom Dienst "Windows-Verwaltungsinstrumentation" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058
Error: (05/07/2014 05:30:35 AM) (Source: Service Control Manager) (User: ) (EventID: 7001)
Description: Der Dienst "Security Center" ist vom Dienst "Windows-Verwaltungsinstrumentation" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058
Error: (05/07/2014 05:29:31 AM) (Source: Service Control Manager) (User: ) (EventID: 7000)
Description: Der Dienst "XobniService" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (05/07/2014 05:29:31 AM) (Source: Service Control Manager) (User: ) (EventID: 7009)
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst XobniService erreicht.
Error: (05/07/2014 05:29:14 AM) (Source: Microsoft-Windows-GroupPolicy) (User: KEPP) (EventID: 1065)
Description: Fehler bei der Verarbeitung der Gruppenrichtlinie. Der WMI-Filter (Windows Management Instrumentation) für das Gruppenrichtlinienobjekt "CN={FE6033C2-2B81-4B7D-8134-4C47A4F05689},CN=POLICIES,CN=SYSTEM,DC=KEPP,DC=LOCAL" konnte nicht ausgewertet werden. Dies kann darauf zurückzuführen sein, dass RSoP deaktiviert ist, oder dass der WMI-Dienst deaktiviert oder angehalten wurde, bzw. andere WMI-Fehler aufgetreten sind. Stellen Sie sicher, dass der WMI-Dienst gestartet ist und dass der Starttyp auf automatischen Start festgelegt ist. Neue Gruppenrichtlinienobjekte oder -einstellungen werden nicht verarbeitet, bis dieses Ereignis behoben wurde.
Microsoft Office Sessions:
=========================
Error: (10/20/2011 07:08:26 AM) (Source: Microsoft Office 12 Sessions) (User: ) (EventID: 7001)
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 6714 seconds with 960 seconds of active time. This session ended with a crash.
Error: (09/21/2011 10:12:10 AM) (Source: Microsoft Office 12 Sessions) (User: ) (EventID: 7001)
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 19001 seconds with 1080 seconds of active time. This session ended with a crash.
Error: (08/02/2011 05:50:56 AM) (Source: Microsoft Office 12 Sessions) (User: ) (EventID: 7001)
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 3442 seconds with 120 seconds of active time. This session ended with a crash.
Error: (07/21/2011 07:33:19 AM) (Source: Microsoft Office 12 Sessions) (User: ) (EventID: 7001)
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 9504 seconds with 900 seconds of active time. This session ended with a crash.
Error: (06/04/2011 10:24:54 AM) (Source: Microsoft Office 12 Sessions) (User: ) (EventID: 7001)
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 240 seconds with 60 seconds of active time. This session ended with a crash.
Error: (05/30/2011 05:40:04 AM) (Source: Microsoft Office 12 Sessions) (User: ) (EventID: 7001)
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 153 seconds with 60 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Percentage of memory in use: 41%
Total physical RAM: 4078.54 MB
Available physical RAM: 2391.63 MB
Total Pagefile: 8155.27 MB
Available Pagefile: 6204.75 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:918.45 GB) (Free:846.68 GB) NTFS
Drive d: (HP_RECOVERY) (Fixed) (Total:12.96 GB) (Free:1.59 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive p: (Daten) (Network) (Total:441.99 GB) (Free:128.23 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 2B0F2E58)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=918 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=13 GB) - (Type=07 NTFS)
==================== End Of Log ============================ besten Dank für die rasche Antwort. Ich hoffe so kann damit gearbeitet werden
mfg
Thomas |