Hallo Aneri,
danke für Deine Statements.
Hier nun die beiden FRST-Dateien vom Win-7-Laptop:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by GHM (administrator) on PC on 06-04-2014 09:08:03
Running from C:\Users\GHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0C5UGK8W
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(UASSOFT.COM) C:\Program Files\Silvercrest NM1005 driver\KMWDSrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\21.2.0.38\NIS.exe
(Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Data Perceptions / PowerProgrammer) C:\Windows\system32\WebUpdateSvc4.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Wistron) C:\Program Files\Launch Manager\HotkeyApp.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
(Wistron Corp.) C:\Program Files\Launch Manager\OSD.exe
(X10) C:\Program Files\Common Files\X10\Common\X10nets.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\21.2.0.38\NIS.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Wistron Corp.) C:\Program Files\Launch Manager\WButton.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(UASSOFT.COM) C:\Program Files\Silvercrest NM1005 driver\StartAutorun.exe
(UASSOFT.COM) C:\Program Files\Silvercrest NM1005 driver\KMConfig.exe
(UASSOFT.COM) C:\Program Files\Silvercrest NM1005 driver\KMProcess.exe
(Wistron Corp.) C:\Program Files\Launch Manager\WisLMSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_77_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8546848 2010-03-17] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [686624 2010-03-17] (Realtek Semiconductor)
HKLM\...\Run: [HotkeyApp] - C:\Program Files\Launch Manager\HotkeyApp.exe [200704 2009-12-14] (Wistron)
HKLM\...\Run: [LMgrVolOSD] - C:\Program Files\Launch Manager\OSD.exe [348960 2009-12-12] (Wistron Corp.)
HKLM\...\Run: [Wbutton] - C:\Program Files\Launch Manager\Wbutton.exe [413696 2010-01-13] (Wistron Corp.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1594664 2009-12-11] (Synaptics Incorporated)
HKLM\...\Run: [KMCONFIG] - C:\Program Files\Silvercrest NM1005 driver\StartAutorun.exe KMConfig.exe
AppInit_DLLs: C:\Windows\Jaksta\AC\x86\jaudcap.dll => C:\Windows\Jaksta\AC\x86\jaudcap.dll [264480 2013-10-31] (Jaksta Technologies Pty Ltd)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.medion.com
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {E5C4ECBB-88B4-40A1-B8E0-0220F5DD43A3} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - DefaultScope {C4C2BA6A-B414-4A4C-B39B-87AF0CC54637} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {57F74961-D98B-46A0-9E3F-26E321617D3B} URL = hxxp://de.wikipedia.org/w/index.php?title=Spezial:Suche&search={searchTerms}
SearchScopes: HKCU - {C4C2BA6A-B414-4A4C-B39B-87AF0CC54637} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {E5C4ECBB-88B4-40A1-B8E0-0220F5DD43A3} URL =
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\21.2.0.38\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\21.2.0.38\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\21.2.0.38\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-19]
CHR Extension: (Google Drive) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-19]
CHR Extension: (YouTube) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-19]
CHR Extension: (Google-Suche) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-19]
CHR Extension: (Google Wallet) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-19]
CHR Extension: (Google Mail) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-19]
CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files\Norton Internet Security\Engine\21.2.0.38\Exts\Chrome.crx [2014-03-22]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
R2 KMWDSERVICE; C:\Program Files\Silvercrest NM1005 driver\KMWDSrv.exe [208896 2007-06-16] (UASSOFT.COM)
R2 NIS; C:\Program Files\Norton Internet Security\Engine\21.2.0.38\NIS.exe [276376 2014-03-12] (Symantec Corporation)
S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435008 2011-12-23] (TuneUp Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1052480 2011-11-21] (TuneUp Software)
R2 WebUpdate4; C:\Windows\system32\WebUpdateSvc4.exe [262360 2009-01-08] (Data Perceptions / PowerProgrammer)
R3 WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [118560 2009-10-23] (Wistron Corp.)
R2 x10nets; C:\Program Files\Common Files\X10\Common\X10nets.exe [20480 2009-11-07] (X10)
==================== Drivers (Whitelisted) ====================
R1 BHDrvx86; C:\Program Files\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20140319.001\BHDrvx86.sys [1098968 2014-03-19] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1502000.026\ccSetx86.sys [127064 2013-09-26] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-11-23] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-11-23] (Symantec Corporation)
R1 IDSVix86; C:\Program Files\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140404.001\IDSvix86.sys [395992 2014-03-26] (Symantec Corporation)
R3 KMWDFilter; C:\Windows\System32\Drivers\KMWDFilter.SYS [17280 2007-06-13] (Windows (R) Codename Longhorn DDK provider)
S3 mod7700; C:\Windows\System32\DRIVERS\mod7700.sys [786400 2009-08-13] (DiBcom SA)
R3 NAVENG; C:\Program Files\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140405.003\NAVENG.SYS [93272 2014-02-08] (Symantec Corporation)
R3 NAVEX15; C:\Program Files\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140405.003\NAVEX15.SYS [1612376 2014-02-08] (Symantec Corporation)
S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [12288 2008-09-08] ()
R3 SRTSP; C:\Windows\System32\Drivers\NIS\1502000.026\SRTSP.SYS [664280 2014-02-13] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NIS\1502000.026\SRTSPX.SYS [32344 2013-09-10] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NIS\1502000.026\SYMDS.SYS [367704 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NIS\1502000.026\SYMEFA.SYS [936152 2014-03-04] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2013-11-24] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NIS\1502000.026\Ironx86.SYS [206936 2013-09-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NIS\1502000.026\SYMNETS.SYS [447704 2014-02-18] (Symantec Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2010-02-24] (TuneUp Software)
R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13720 2009-05-13] (X10 Wireless Technology, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27160 2009-05-13] (X10 Wireless Technology, Inc.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-06 09:07 - 2014-04-06 09:08 - 00000000 ____D () C:\FRST
2014-04-06 09:05 - 2014-04-06 09:05 - 00013895 _____ () C:\Users\GHM\Desktop\Unbenannt 1.odt
2014-04-06 08:45 - 2014-04-06 08:45 - 00013923 _____ () C:\Users\GHM\Desktop\Heutex.odt
2014-04-05 08:05 - 2014-04-05 08:05 - 00021618 _____ () C:\Users\GHM\Desktop\Katja Eichinger - Auftakt in ein neues Leben.odt
2014-04-04 08:49 - 2014-04-04 08:49 - 00016298 _____ () C:\Users\GHM\Desktop\Sara.odt
2014-04-03 17:19 - 2014-04-03 17:22 - 00017902 _____ () C:\Users\GHM\Desktop\Das „goldene Zeitalter“ Roms.odt
2014-03-24 20:38 - 2014-04-04 12:08 - 00000000 ____D () C:\Program Files\Recuva
2014-03-24 20:38 - 2014-03-24 20:38 - 00001803 _____ () C:\Users\Public\Desktop\Recuva.lnk
2014-03-24 20:27 - 2014-03-24 20:27 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-24 18:14 - 2014-03-24 18:14 - 00029068 _____ () C:\Users\GHM\Desktop\Die Wald-Kiefer.odt
2014-03-23 14:01 - 2014-03-23 14:01 - 00021348 _____ () C:\Users\GHM\Desktop\Katja Eichinger.odt
2014-03-20 22:44 - 2014-03-20 22:44 - 00016600 _____ () C:\Users\GHM\Desktop\Extinktion (Astronomie).odt
2014-03-20 21:47 - 2014-03-20 21:47 - 00024559 _____ () C:\Users\GHM\Desktop\Äquinoktium - J2000.0.odt
2014-03-19 11:33 - 2014-03-19 11:33 - 00000020 ___SH () C:\Users\DefaultAppPool\ntuser.ini
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Startmenü
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Netzwerkumgebung
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Druckumgebung
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Documents\Eigene Musik
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Documents\Eigene Bilder
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\AppData\Local\Verlauf
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 ____D () C:\Users\DefaultAppPool
2014-03-19 11:33 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-03-19 11:33 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-03-19 09:20 - 2014-03-19 09:20 - 00014304 _____ () C:\Users\GHM\Desktop\Kukident.odt
2014-03-19 08:53 - 2014-03-19 08:53 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-19 08:53 - 2013-04-04 15:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-19 08:52 - 2014-03-19 08:52 - 00012699 _____ () C:\Users\GHM\Desktop\Malwarebytes.odt
2014-03-17 15:53 - 2014-03-17 17:00 - 00017422 _____ () C:\Users\GHM\Desktop\Rühlings.odt
2014-03-17 10:23 - 2014-03-17 11:31 - 00017658 _____ () C:\Users\GHM\Desktop\Buch - Kraftort Alpen.odt
2014-03-14 09:28 - 2014-03-14 09:28 - 00025993 _____ () C:\Users\GHM\Desktop\Psychisch oder psychiatrisch.odt
2014-03-12 09:32 - 2014-03-12 09:32 - 00024528 _____ () C:\Users\GHM\Desktop\Die besten Deuserband Übungen.odt
2014-03-12 08:25 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-12 08:25 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-12 08:25 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-12 08:25 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-12 08:25 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-12 08:25 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-12 08:25 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-12 08:25 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-12 08:25 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-12 08:25 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-12 08:25 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-12 08:25 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-12 08:25 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-12 08:25 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-12 08:25 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-12 08:25 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-12 08:25 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-12 08:25 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-12 08:25 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-12 08:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-12 08:25 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-12 08:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-12 08:25 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-12 08:25 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-12 08:25 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-12 08:25 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-12 08:25 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-11 21:03 - 2014-03-11 21:03 - 05128584 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-03-10 18:27 - 2014-03-11 17:02 - 00021343 _____ () C:\Users\GHM\Desktop\Für Dr. Geberth.odt
2014-03-10 13:30 - 2014-03-10 13:46 - 00018114 _____ () C:\Users\GHM\Desktop\Alles, Was Gut Tut.odt
2014-03-10 09:00 - 2014-04-06 07:21 - 00003472 _____ () C:\Windows\setupact.log
2014-03-10 09:00 - 2014-03-10 09:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-09 12:39 - 2014-03-09 12:37 - 00014666 _____ () C:\Users\GHM\Desktop\Was soll ich künftig tun, um den PC ''sauber'' zu halten, zu reinigen.odt
==================== One Month Modified Files and Folders =======
2014-04-06 09:08 - 2014-04-06 09:07 - 00000000 ____D () C:\FRST
2014-04-06 09:05 - 2014-04-06 09:05 - 00013895 _____ () C:\Users\GHM\Desktop\Unbenannt 1.odt
2014-04-06 09:05 - 2014-02-28 20:27 - 00000000 ____D () C:\Users\GHM\Desktop\TAGTÄGLICH ROUTINE-1
2014-04-06 09:03 - 2013-11-22 18:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-06 09:03 - 2010-10-03 12:15 - 00000000 ____D () C:\Users\GHM\Desktop\Reinigung
2014-04-06 08:52 - 2010-06-11 00:37 - 01729694 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-06 08:45 - 2014-04-06 08:45 - 00013923 _____ () C:\Users\GHM\Desktop\Heutex.odt
2014-04-06 07:29 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-06 07:29 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-06 07:26 - 2010-09-18 18:25 - 01244446 _____ () C:\Windows\WindowsUpdate.log
2014-04-06 07:21 - 2014-03-10 09:00 - 00003472 _____ () C:\Windows\setupact.log
2014-04-06 07:21 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-05 13:36 - 2010-06-11 19:01 - 00000000 ____D () C:\ProgramData\X10 Settings
2014-04-05 08:05 - 2014-04-05 08:05 - 00021618 _____ () C:\Users\GHM\Desktop\Katja Eichinger - Auftakt in ein neues Leben.odt
2014-04-04 12:08 - 2014-03-24 20:38 - 00000000 ____D () C:\Program Files\Recuva
2014-04-04 08:49 - 2014-04-04 08:49 - 00016298 _____ () C:\Users\GHM\Desktop\Sara.odt
2014-04-03 17:22 - 2014-04-03 17:19 - 00017902 _____ () C:\Users\GHM\Desktop\Das „goldene Zeitalter“ Roms.odt
2014-03-31 09:04 - 2010-10-02 19:55 - 00000000 ___RD () C:\Users\GHM\Desktop\Programme
2014-03-30 12:53 - 2012-12-03 10:53 - 00000000 ____D () C:\Windows\system32\Drivers\NIS
2014-03-29 18:54 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-03-28 18:54 - 2014-01-19 12:07 - 00000000 ____D () C:\AdwCleaner
2014-03-24 23:18 - 2010-09-18 18:37 - 00000000 ____D () C:\Users\GHM
2014-03-24 21:00 - 2014-02-11 22:37 - 00000000 ____D () C:\Users\GHM\Desktop\A
2014-03-24 20:38 - 2014-03-24 20:38 - 00001803 _____ () C:\Users\Public\Desktop\Recuva.lnk
2014-03-24 20:27 - 2014-03-24 20:27 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-24 18:14 - 2014-03-24 18:14 - 00029068 _____ () C:\Users\GHM\Desktop\Die Wald-Kiefer.odt
2014-03-23 14:01 - 2014-03-23 14:01 - 00021348 _____ () C:\Users\GHM\Desktop\Katja Eichinger.odt
2014-03-23 13:06 - 2011-03-14 20:32 - 00000000 ____D () C:\Users\GHM\AppData\Local\Adobe
2014-03-21 08:25 - 2013-11-22 19:44 - 00000000 ____D () C:\Users\GHM\AppData\Roaming\Applian FLV and Media Player
2014-03-20 22:44 - 2014-03-20 22:44 - 00016600 _____ () C:\Users\GHM\Desktop\Extinktion (Astronomie).odt
2014-03-20 21:47 - 2014-03-20 21:47 - 00024559 _____ () C:\Users\GHM\Desktop\Äquinoktium - J2000.0.odt
2014-03-19 11:33 - 2014-03-19 11:33 - 00000020 ___SH () C:\Users\DefaultAppPool\ntuser.ini
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Startmenü
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Netzwerkumgebung
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Druckumgebung
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Documents\Eigene Musik
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Documents\Eigene Bilder
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\AppData\Local\Verlauf
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 ____D () C:\Users\DefaultAppPool
2014-03-19 09:20 - 2014-03-19 09:20 - 00014304 _____ () C:\Users\GHM\Desktop\Kukident.odt
2014-03-19 08:53 - 2014-03-19 08:53 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-19 08:52 - 2014-03-19 08:52 - 00012699 _____ () C:\Users\GHM\Desktop\Malwarebytes.odt
2014-03-17 17:00 - 2014-03-17 15:53 - 00017422 _____ () C:\Users\GHM\Desktop\Rühlings.odt
2014-03-17 11:31 - 2014-03-17 10:23 - 00017658 _____ () C:\Users\GHM\Desktop\Buch - Kraftort Alpen.odt
2014-03-16 14:02 - 2014-03-02 12:44 - 00012821 _____ () C:\Users\GHM\Desktop\Benzo-meine Daten+Diaz.-Umrechn..odt
2014-03-15 19:26 - 2013-09-11 18:41 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-15 19:24 - 2010-06-11 19:09 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-14 09:28 - 2014-03-14 09:28 - 00025993 _____ () C:\Users\GHM\Desktop\Psychisch oder psychiatrisch.odt
2014-03-13 18:13 - 2014-02-10 13:36 - 00028859 _____ () C:\Users\GHM\Desktop\Favoriten auf anderen PC bringen.odt
2014-03-12 18:52 - 2009-07-14 06:33 - 00320496 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-12 09:32 - 2014-03-12 09:32 - 00024528 _____ () C:\Users\GHM\Desktop\Die besten Deuserband Übungen.odt
2014-03-11 22:45 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-11 21:03 - 2014-03-11 21:03 - 05128584 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-03-11 21:03 - 2013-11-22 18:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-11 21:03 - 2012-01-03 11:01 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-11 17:02 - 2014-03-10 18:27 - 00021343 _____ () C:\Users\GHM\Desktop\Für Dr. Geberth.odt
2014-03-11 09:56 - 2010-06-11 18:16 - 00000000 ____D () C:\Program Files\Launch Manager
2014-03-10 13:46 - 2014-03-10 13:30 - 00018114 _____ () C:\Users\GHM\Desktop\Alles, Was Gut Tut.odt
2014-03-10 09:00 - 2014-03-10 09:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-09 12:37 - 2014-03-09 12:39 - 00014666 _____ () C:\Users\GHM\Desktop\Was soll ich künftig tun, um den PC ''sauber'' zu halten, zu reinigen.odt
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-30 09:27
==================== End Of Log ============================ --- --- ---
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-03-2014 01
Ran by GHM at 2014-04-06 09:08:33
Running from C:\Users\GHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0C5UGK8W
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Norton Internet Security (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton Internet Security (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton Internet Security (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
==================== Installed Programs ======================
Acrobat.com (HKLM\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 MUI (HKLM\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Applian FLV and Media Player 3.1.1.12 (HKLM\...\Applian FLV and Media Player) (Version: 3.1.1.12 - Applian Technologies)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.27 - Atheros Communications Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
Cisco EAP-FAST Module (HKLM\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
CorelDRAW Essentials 4 - Content (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Draw (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Filters (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - ICA (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - IPM - No VBA (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang BR (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang DE (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang EN (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang ES (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang FR (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang IT (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang NL (Version: 4.0 - Uw bedrijfsnaam) Hidden
CorelDRAW Essentials 4 - PHOTO-PAINT (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Windows Shell Extension (HKLM\...\_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}) (Version: - Corel Corporation)
CorelDRAW Essentials 4 - Windows Shell Extension (Version: 1.1 - Corel Corporation) Hidden
CorelDRAW Essentials 4 (HKLM\...\_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}) (Version: - Corel Corporation)
CorelDRAW Essentials 4 (Version: 4.0 - Corel Corporation) Hidden
Freecorder 8 Applications (8.0.1.19) (HKLM\...\Freecorder 8 Applications) (Version: 8.0.1.19 - Applian Technologies)
Google Earth (HKLM\...\{C768790F-04FB-11E0-9B2C-001AA037B01E}) (Version: 6.0.1.2032 - Google)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2092 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.5.0.1037 - Intel Corporation)
Intel(R) TV Wizard (HKLM\...\TVWiz) (Version: - Intel Corporation)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.36 - Irfan Skiljan)
Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217021FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Launch Manager V1.5.0.8 (HKLM\...\{D0846526-66DD-4DC9-A02C-98F9A2806812}) (Version: 1.5.0.8 - Wistron Corp.)
Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Meade LPI (HKLM\...\{23484C5A-E7AE-4F59-B7DF-88D63BEF18F4}) (Version: 2.46.3.0 - )
Microsoft .NET Compact Framework 2.0 SP2 (HKLM\...\{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}) (Version: 2.0.7045 - Microsoft Corporation)
Microsoft .NET Framework 1.1 (HKLM\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [DEU] (HKLM\...\{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Text-to-Speech Engine 4.0 (English) (HKLM\...\MSTTS) (Version: - )
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden
Norton Internet Security (HKLM\...\NIS) (Version: 21.2.0.38 - Symantec Corporation)
OpenOffice 4.0.1 (HKLM\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
PL-2303 USB-to-Serial (HKLM\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: - )
PlayReady PC Runtime x86 (HKLM\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6069 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30117 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM\...\{9D3D8C60-A55F-4fed-B2B9-173F09590E16}) (Version: 1.00.0145 - REALTEK Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
Silvercrest NM1005 driver (HKLM\...\InstallShield_{1C5E457F-2009-4673-8DF4-135898ABA870}) (Version: 5.10.17 - Targa GmbH)
Silvercrest NM1005 driver (Version: 5.10.17 - Targa GmbH) Hidden
Software Update Wizard (Redist) 4.5 (HKLM\...\Software Update Wizard (Redist)) (Version: 4.5 - PowerProgrammer)
Stellarium 0.12.4 (HKLM\...\Stellarium_is1) (Version: 0.12.4 - Stellarium team)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.19.0 - Synaptics Incorporated)
TuneUp Utilities (HKLM\...\TuneUp Utilities) (Version: 9.0.6030.1 - TuneUp Software)
TuneUp Utilities (Version: 9.0.6030.1 - TuneUp Software) Hidden
TuneUp Utilities Language Pack (de-DE) (Version: 9.0.6030.1 - TuneUp Software) Hidden
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Windows Live Anmelde-Assistent (HKLM\...\{52B97218-98CB-4B8B-9283-D213C85E1AA4}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Call (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Communications Platform (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Essentials (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Mail (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Movie Maker (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Writer (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
X10 Hardware(TM) (HKLM\...\X10Hardware) (Version: - )
==================== Restore Points =========================
19-02-2014 16:33:19 Uniblue DriverScanner installation
26-02-2014 11:57:24 Windows Update
27-02-2014 08:59:11 Windows Update
07-03-2014 10:59:03 Geplanter Prüfpunkt
12-03-2014 09:15:36 Windows Update
15-03-2014 17:23:57 Windows Update
22-03-2014 19:43:19 Geplanter Prüfpunkt
30-03-2014 07:34:13 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {165C5968-C88F-4A04-BDA0-84A7702F11D7} - System32\Tasks\{0CABE388-CA3B-4C03-8834-B23EA88582D2} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {1DDC53C2-922C-4E0B-9D71-98003477A73A} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files\Norton Internet Security\Engine\21.2.0.38\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {22026F00-5371-495A-8955-B942E8F60D5A} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {22274F06-45A8-47B0-AE2F-EDB35BD03C56} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {2BE98043-7BF6-48C7-9E74-0FF27BAC3CFA} - System32\Tasks\{EE580633-7AF9-4B99-89EB-FC30E9C48A10} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {33948ED2-8750-4A4F-97A0-E6092E0D33CC} - System32\Tasks\{CACC66E8-773A-493F-B055-842E053CC2DD} => C:\Program Files\Norton Internet Security\Engine\21.1.0.18\uiStub.exe
Task: {343D5FFE-FC8D-4C67-AEB1-4D0045F7E59C} - System32\Tasks\{525B7F42-104F-452E-8957-6B83CBA039FD} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {43216073-228E-406F-B21E-5007D7B8260D} - System32\Tasks\{AE4EFF61-1333-44E0-B8A5-1533F4C293FF} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {442A651C-0FCE-469A-A5A0-D35DB52ACAC4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {52D95DE6-BB7F-45BF-86C1-543BA77E24E0} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files\Norton Internet Security\Engine\21.2.0.38\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {5A965C5C-5429-4807-8939-6FA4C156E1AC} - System32\Tasks\{8981FB4E-AAEE-4A83-9B59-FD049634C066} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {62138DA7-CEED-482E-A53E-C53E167ECE4D} - System32\Tasks\{B9144F3B-BFC7-4043-A6BE-3D103109A325} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {6E995A92-5164-4362-8F9E-EBA604138AB2} - System32\Tasks\{941B04B0-B4A7-4E2C-AA4B-EB18D11FE7BD} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {78B0D134-4F5F-4303-9BA9-A26B416CA8B3} - System32\Tasks\{2F8AE86D-C16B-494B-B128-C3AF00304684} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {7D8473E7-3D1E-4218-958C-7A86982BE9C6} - System32\Tasks\{534F2751-BBB0-498C-B0BA-2FCACBD716E4} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {8618C71B-1EFB-4A13-89C7-D5864FB04BAD} - System32\Tasks\{E5897B04-E0FD-4FF9-8028-D57EB918290F} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {88938DD2-E6E5-42C7-AC74-5F8B762D46E5} - System32\Tasks\{53766444-4A8D-4CAC-A3F3-769521C26451} => C:\Program Files\Norton Internet Security\Engine\21.1.0.18\uiStub.exe
Task: {98800D62-F8B1-47C7-8718-0EF972BD62BF} - System32\Tasks\{873D580C-0E2D-45E2-A2C2-55A355D235B5} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {A560798D-0BE2-4A4E-A957-952851F616BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-21] (Adobe Systems Incorporated)
Task: {AF6A920F-FD88-42B3-9F5A-144272260B12} - System32\Tasks\{06D416FB-73D1-4AA9-AAFB-69E84EF27B2F} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {B4DB4241-A5D0-4465-BEA8-12B6F8B3531E} - System32\Tasks\{D983DC3F-81BD-4C64-9ECC-4C2AFAEB299B} => C:\Medion\Fix Windows Update.exe [2009-11-26] ()
Task: {BF5946C2-EA02-42C6-8E4C-EC490016A363} - System32\Tasks\{29542231-EC11-4FEF-804B-18989C576D63} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {C0DD792B-584D-445A-A4E1-28A0A30D97E8} - System32\Tasks\{1DB9D2CE-0CB9-4C4F-9468-EAB0EB7066BD} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {CCDCEA17-158D-4666-9B1A-6D8208F0D014} - System32\Tasks\{6E87E417-7283-4E75-A527-F31AD12A67CD} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {D80FF8E1-CFB4-4FB2-BB03-5895864A56D5} - System32\Tasks\{B5D4B8AF-20FC-48AD-9F57-7BB6AB1F2452} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {DE0A6413-ED46-4AE0-9FA9-31267632DC87} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Internet Security\Engine\21.2.0.38\WSCStub.exe [2014-03-12] (Symantec Corporation)
Task: {E8A9C5A7-997A-40B0-8961-1C99079F08D1} - System32\Tasks\{0A1C68F5-34E2-4CE4-A9AB-7C52159B7D80} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {F64CFA7A-E036-402D-88C1-61A835B612EA} - System32\Tasks\{E00BD7CB-9D61-44B1-A5DC-B723F3FC94F2} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {F9709670-1930-4A84-997D-7A5680FF8F6E} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2010\OneClick.exe [2011-11-21] (TuneUp Software)
Task: {F9E26035-D75C-4594-AC4D-850BDD3E5A1D} - System32\Tasks\{CCB33391-B9A7-4A99-A584-62895F17BE98} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: {FEC8420A-B8BC-4ADF-B894-6B92558D1476} - System32\Tasks\{25D0679D-17AA-4042-9FC4-59ACC6A628FF} => C:\Program Files\Meade\AutostarSuite\UNWISE.EXE [2001-09-28] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2010-06-11 18:01 - 2009-10-02 22:18 - 00058880 _____ () C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2007-03-29 13:17 - 2007-03-29 13:17 - 00106496 _____ () C:\Program Files\Silvercrest NM1005 driver\keydll.dll
2005-05-04 20:12 - 2005-05-04 20:12 - 00028672 _____ () C:\Program Files\Silvercrest NM1005 driver\MouseHook.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BsScanner => ""="Service"
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/05/2014 00:55:26 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"1".
Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/04/2014 09:22:22 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"1".
Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/03/2014 09:10:14 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"1".
Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/02/2014 03:37:33 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"1".
Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/02/2014 08:25:06 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 11.0.9600.16521, Zeitstempel: 0x53114399
Name des fehlerhaften Moduls: AcroRd32.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x518aacc2
Ausnahmecode: 0xc0000005
Fehleroffset: 0x5c89dcb1
ID des fehlerhaften Prozesses: 0xe08
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
Error: (04/01/2014 07:49:59 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"1".
Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (03/31/2014 09:29:45 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"1".
Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (03/30/2014 09:28:39 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"1".
Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (03/29/2014 11:27:15 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"1".
Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (03/28/2014 03:03:46 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"1".
Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
System errors:
=============
Error: (04/05/2014 06:36:25 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (04/05/2014 06:36:25 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (04/05/2014 06:35:43 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (04/05/2014 06:35:43 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (04/05/2014 09:57:32 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (04/05/2014 09:57:32 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (03/30/2014 00:14:18 PM) (Source: DCOM) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Error: (03/27/2014 09:51:25 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (03/27/2014 09:51:25 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (03/27/2014 09:51:25 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Microsoft Office Sessions:
=========================
Error: (04/05/2014 00:55:26 AM) (Source: SideBySide)(User: )
Description: UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"c:\program files\windows live\messenger\wlcsdk.exe
Error: (04/04/2014 09:22:22 AM) (Source: SideBySide)(User: )
Description: UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"c:\program files\windows live\messenger\wlcsdk.exe
Error: (04/03/2014 09:10:14 AM) (Source: SideBySide)(User: )
Description: UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"c:\program files\windows live\messenger\wlcsdk.exe
Error: (04/02/2014 03:37:33 PM) (Source: SideBySide)(User: )
Description: UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"c:\program files\windows live\messenger\wlcsdk.exe
Error: (04/02/2014 08:25:06 AM) (Source: Application Error)(User: )
Description: iexplore.exe11.0.9600.1652153114399AcroRd32.dll_unloaded0.0.0.0518aacc2c00000055c89dcb1e0801cf4e3afd0f7b8bC:\Program Files\Internet Explorer\iexplore.exeAcroRd32.dll87cd8790-ba2f-11e3-bc19-00262df85f3b
Error: (04/01/2014 07:49:59 AM) (Source: SideBySide)(User: )
Description: UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"c:\program files\windows live\messenger\wlcsdk.exe
Error: (03/31/2014 09:29:45 AM) (Source: SideBySide)(User: )
Description: UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"c:\program files\windows live\messenger\wlcsdk.exe
Error: (03/30/2014 09:28:39 AM) (Source: SideBySide)(User: )
Description: UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"c:\program files\windows live\messenger\wlcsdk.exe
Error: (03/29/2014 11:27:15 AM) (Source: SideBySide)(User: )
Description: UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"c:\program files\windows live\messenger\wlcsdk.exe
Error: (03/28/2014 03:03:46 AM) (Source: SideBySide)(User: )
Description: UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"c:\program files\windows live\messenger\wlcsdk.exe
==================== Memory info ===========================
Percentage of memory in use: 35%
Total physical RAM: 3510.6 MB
Available physical RAM: 2248.63 MB
Total Pagefile: 7019.49 MB
Available Pagefile: 5672.91 MB
Total Virtual: 2047.88 MB
Available Virtual: 1906.03 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:424.66 GB) (Free:388.02 GB) NTFS
Drive d: (Recover) (Fixed) (Total:40 GB) (Free:21.32 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=425 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=40 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
==================== End Of Log ============================ --- --- --- |