fidelityhh | 11.12.2014 14:29 | Hi,
vielen Dank schon mal für die schnelle Reaktion :)))
frst.txt
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-12-2014
Ran by Monika (administrator) on MONIKA-PC on 11-12-2014 14:24:39
Running from C:\Users\Monika\Downloads
Loaded Profile: Monika (Available profiles: Monika)
Platform: Microsoft Windows 7 Professional (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Registration\GREGsvc.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PSANHost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PSUAMain.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Devices Agent\AgentSvc.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PSUAService.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(Michel Krämer) C:\Program Files\Spamihilator\spamihilator.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1594664 2009-12-10] (Synaptics Incorporated)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8493600 2010-01-29] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [715296 2010-04-23] (Acer Incorporated)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-07-26] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Run: [PSUAMain] => C:\Program Files\Panda Security\Panda Security Protection\PSUAMain.exe [37624 2014-10-16] (Panda Security, S.L.)
HKLM\...\Run: [monthly_reset_date] => C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\el\latest_version\windows_re.exe [392192 2013-09-08] ()
HKU\S-1-5-21-463495802-3663640653-2969567870-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1564016 2013-07-26] (Samsung)
HKU\S-1-5-21-463495802-3663640653-2969567870-1000\...\Run: [] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-07-26] (Samsung)
HKU\S-1-5-21-463495802-3663640653-2969567870-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-463495802-3663640653-2969567870-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-11] (Google Inc.)
HKU\S-1-5-21-463495802-3663640653-2969567870-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil32_15_0_0_246_Plugin.exe [855216 2014-12-11] (Adobe Systems Incorporated)
HKU\S-1-5-21-463495802-3663640653-2969567870-1000\...\MountPoints2: {b75edc14-c5f9-11df-a7c2-806e6f6e6963} - E:\START-BRIDGE-CD.EXE
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Spamihilator.lnk
ShortcutTarget: Spamihilator.lnk -> C:\Program Files\Spamihilator\spamihilator.exe (Michel Krämer)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=travelmate_5740&r=27051210l315l04e4z235x5712m600
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=travelmate_5740&r=27051210l315l04e4z235x5712m600
HKU\S-1-5-21-463495802-3663640653-2969567870-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=travelmate_5740&r=27051210l315l04e4z235x5712m600
HKU\S-1-5-21-463495802-3663640653-2969567870-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=travelmate_5740&r=27051210l315l04e4z235x5712m600
SearchScopes: HKLM -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKU\S-1-5-21-463495802-3663640653-2969567870-1000 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deDE409
SearchScopes: HKU\S-1-5-21-463495802-3663640653-2969567870-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deDE409
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKU\S-1-5-21-463495802-3663640653-2969567870-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 C:\Windows\system32\NLAapi.dll [51712] (Microsoft Corporation)
Winsock: Catalog5 02 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog5 03 C:\Windows\system32\winrnr.dll [20992] (Microsoft Corporation)
Winsock: Catalog5 04 C:\Windows\system32\napinsp.dll [52224] (Microsoft Corporation)
Winsock: Catalog5 05 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
Winsock: Catalog5 06 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
Winsock: Catalog9 01 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 02 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 03 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 04 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 05 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 06 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 07 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 08 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 09 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 10 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 11 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 12 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 13 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 14 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 15 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 16 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 17 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 18 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 19 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 20 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 21 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 22 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 23 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 24 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 25 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Winsock: Catalog9 26 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\4br2ipug.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-02]
Chrome:
=======
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\39.0.2171.71\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\39.0.2171.71\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\39.0.2171.71\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Profile: C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-10]
CHR Extension: (Google Wallet) - C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-06]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [735776 2010-04-23] (Acer Incorporated)
R2 GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated)
R2 NanoServiceMain; C:\Program Files\Panda Security\Panda Security Protection\PSANHost.exe [142072 2014-10-13] (Panda Security, S.L.)
R2 NTI IScheduleSvc; C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [250368 2010-03-09] (NewTech Infosystems, Inc.) [File not signed]
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144640 2009-11-06] (NewTech Infosystems, Inc.)
R2 PandaAgent; C:\Program Files\Panda Security\Panda Devices Agent\AgentSvc.exe [66808 2014-10-09] (Panda Security, S.L.)
R2 PSUAService; C:\Program Files\Panda Security\Panda Security Protection\PSUAService.exe [38136 2014-10-16] (Panda Security, S.L.)
S2 reverse_charge_vat; C:\Windows\assembly\GAC_MSIL\dfsvc\2.0.0.0__b03f5f7f11d50a3a\postmaster\skydrive.exe [202752 2011-11-20] (Company 'gora-sah') [File not signed]
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
S2 string; C:\Windows\assembly\GAC_MSIL\dfsvc\2.0.0.0__b03f5f7f11d50a3a\postmaster\beneficiary_inn.exe [181248 2014-10-13] (Company 'gora-sah') [File not signed]
R2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
S2 to_do; C:\Windows\assembly\GAC_MSIL\dfsvc\2.0.0.0__b03f5f7f11d50a3a\postmaster\estimate_at_completion.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 A2DDA; C:\EEK\BIN\a2ddax86.sys [22056 2014-11-24] (Emsisoft GmbH)
S3 cleanhlp; C:\EEK\bin\cleanhlp32.sys [50200 2014-11-24] (Emsisoft GmbH)
R1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [88992 2014-06-04] (Panda Security, S.L.)
R1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [166816 2014-06-18] (Panda Security, S.L.)
R1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [110624 2014-06-04] (Panda Security, S.L.)
R1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [125216 2014-06-04] (Panda Security, S.L.)
R1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [40192 2014-01-16] (Panda Security, S.L.)
R1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [96160 2014-06-04] (Panda Security, S.L.)
R1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [61984 2014-06-04] (Panda Security, S.L.)
R1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [121888 2014-06-04] (Panda Security, S.L.)
R1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [288032 2014-06-04] (Panda Security, S.L.)
R1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [208800 2014-06-04] (Panda Security, S.L.)
R1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [109856 2014-06-04] (Panda Security, S.L.)
R1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [244000 2014-06-04] (Panda Security, S.L.)
R1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [96928 2014-06-04] (Panda Security, S.L.)
R2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [139536 2014-10-13] (Panda Security, S.L.)
R2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [105232 2014-10-13] (Panda Security, S.L.)
R1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [168208 2014-10-02] (Panda Security, S.L.)
R2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [113936 2014-10-02] (Panda Security, S.L.)
R2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [124688 2014-10-02] (Panda Security, S.L.)
R2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [100112 2014-10-13] (Panda Security, S.L.)
R3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [48736 2014-03-25] (Panda Security, S.L.)
S1 iukcnvyo; \??\C:\Windows\system32\drivers\iukcnvyo.sys [X]
S1 meoswwaw; \??\C:\Windows\system32\drivers\meoswwaw.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-11 14:24 - 2014-12-11 14:24 - 00000000 ____D () C:\Users\Monika\Downloads\FRST-OlderVersion
2014-12-11 13:40 - 2014-12-11 13:42 - 00000000 ____D () C:\Users\Monika\Documents\_av
2014-12-11 12:43 - 2014-12-11 12:43 - 00059888 _____ () C:\Users\Monika\Downloads\Extras.Txt
2014-12-11 12:42 - 2014-12-11 12:42 - 00090812 _____ () C:\Users\Monika\Downloads\OTL.Txt
2014-12-11 12:31 - 2014-12-11 12:31 - 00602112 _____ (OldTimer Tools) C:\Users\Monika\Downloads\OTL.exe
2014-12-09 12:15 - 2014-12-09 12:15 - 00000000 ____D () C:\Users\Monika\AppData\Roaming\Panda Security
2014-12-09 12:15 - 2014-12-09 12:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Free Antivirus
2014-12-09 12:15 - 2014-12-09 12:15 - 00000000 ____D () C:\Program Files\Panda Security
2014-12-09 12:15 - 2014-03-25 14:15 - 00048736 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\PSKMAD.sys
2014-12-09 12:14 - 2014-12-09 12:15 - 00000000 ____D () C:\ProgramData\Panda Security
2014-12-09 12:12 - 2014-12-09 12:12 - 01329312 _____ () C:\Users\Monika\Downloads\PANDAFREEAV.exe
2014-12-08 18:56 - 2014-12-08 18:56 - 00000000 ____D () C:\Program Files\ESET
2014-12-08 18:55 - 2014-12-08 18:56 - 02347384 _____ (ESET) C:\Users\Monika\Downloads\esetsmartinstaller_deu.exe
2014-12-08 18:33 - 2014-12-08 18:35 - 00000000 ____D () C:\AdwCleaner
2014-12-08 18:33 - 2014-12-08 18:33 - 00000055 _____ () C:\AdwCleanerDebug.txt
2014-12-08 18:30 - 2014-12-08 18:30 - 00000000 ____D () C:\Windows\ERUNT
2014-12-08 18:29 - 2014-12-08 18:29 - 01707646 _____ (Thisisu) C:\Users\Monika\Downloads\JRT.exe
2014-12-08 18:26 - 2014-12-08 18:26 - 00004861 _____ () C:\Users\Monika\Documents\mbam-08122014.txt
2014-12-08 18:12 - 2014-12-08 19:40 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Trash-remember
2014-12-08 17:53 - 2014-12-08 17:53 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-02 21:14 - 2014-12-08 18:35 - 00000000 ___HD () C:\Users\Monika\AppData\Local\Establishment_fire
2014-12-02 13:47 - 2014-12-02 13:47 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-12-02 09:14 - 2014-12-08 18:35 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Blue-lock
2014-12-02 09:14 - 2014-12-08 18:35 - 00000000 ___HD () C:\Users\Monika\AppData\Local\Lunchstay
2014-12-01 15:51 - 2014-12-08 18:35 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Street-detailed
2014-12-01 12:41 - 2014-12-01 12:41 - 00002017 _____ () C:\Users\Monika\Documents\mbam-01122014.txt
2014-11-28 13:56 - 2014-12-02 18:38 - 00000018 _____ () C:\Windows\䌯尺䐀尺䔀尺
2014-11-27 12:24 - 2014-12-01 17:34 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Nlgvztmh
2014-11-27 11:55 - 2014-11-27 12:24 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Tsagmkr
2014-11-24 22:18 - 2014-11-24 22:18 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-11-24 22:17 - 2014-11-24 22:17 - 00004414 _____ () C:\Windows\system32\jupdate-1.7.0_71-b14.log
2014-11-24 22:17 - 2014-09-26 18:42 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-11-24 22:17 - 2014-09-26 18:36 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-11-24 22:17 - 2014-09-26 18:36 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-11-24 22:17 - 2014-09-26 18:35 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-11-24 21:25 - 2014-12-11 14:25 - 00021792 _____ () C:\Users\Monika\Downloads\FRST.txt
2014-11-24 21:21 - 2014-11-24 21:21 - 00001600 _____ () C:\EamClean.log
2014-11-24 20:32 - 2014-11-24 20:32 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-11-24 20:31 - 2014-11-24 20:39 - 00000000 ____D () C:\Users\Monika\AppData\Roaming\Opera Software
2014-11-24 20:31 - 2014-11-24 20:39 - 00000000 ____D () C:\Users\Monika\AppData\Local\Opera Software
2014-11-24 20:29 - 2014-12-11 14:24 - 00000000 ____D () C:\FRST
2014-11-24 20:27 - 2014-12-11 14:24 - 01111040 _____ (Farbar) C:\Users\Monika\Downloads\FRST.exe
2014-11-24 20:27 - 2014-11-24 21:35 - 00000000 ____D () C:\EEK
2014-11-24 19:59 - 2014-11-24 19:59 - 00000049 _____ () C:\Users\Monika\Documents\mbam-241114.txt
2014-11-24 19:47 - 2014-12-11 13:25 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-24 19:47 - 2014-12-08 17:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-24 19:46 - 2014-12-08 17:53 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-11-24 19:46 - 2014-11-24 19:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-24 19:46 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-24 19:46 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-24 19:46 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-24 19:39 - 2014-11-24 19:39 - 00000000 __SHD () C:\Windows\system32\%APPDATA%
2014-11-22 11:54 - 2014-11-24 20:46 - 00000018 _____ () C:\Windows\C˜užS
2014-11-19 09:48 - 2014-11-22 12:11 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Loader32
2014-11-19 04:31 - 2014-11-19 04:31 - 01217192 _____ (Microsoft Corporation) C:\Windows\system32\FM20.DLL
2014-11-17 13:05 - 2014-11-18 08:39 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Java
2014-11-16 14:34 - 2014-11-16 14:34 - 00000000 ____D () C:\Users\Monika\Downloads\Samsung_ChannelListPCEditor_1.10
2014-11-15 14:20 - 2014-11-15 14:51 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Brgicqxlq
2014-11-15 11:17 - 2014-11-28 14:21 - 00000000 ___HD () C:\Users\Monika\AppData\Local\Java-out
2014-11-14 20:09 - 2014-11-19 10:30 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Avira64
2014-11-14 13:34 - 2014-11-28 14:21 - 00000000 ___HD () C:\Users\Monika\AppData\Local\Loader32-out
2014-11-14 09:23 - 2014-11-28 14:21 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Run
2014-11-14 08:51 - 2014-11-28 14:21 - 00000000 ___HD () C:\Users\Monika\AppData\Local\Run-out
2014-11-14 08:50 - 2014-11-18 08:38 - 00000011 _____ () C:\Windows\ZL
2014-11-13 11:45 - 2014-11-15 14:20 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Qmuysugkp
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-11 14:17 - 2012-07-16 08:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-11 14:00 - 2010-12-08 15:58 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-11 13:24 - 2010-09-22 04:33 - 01226328 _____ () C:\Windows\WindowsUpdate.log
2014-12-11 12:32 - 2011-03-03 18:20 - 00000000 ____D () C:\Users\Monika\AppData\Roaming\Skype
2014-12-11 12:28 - 2009-07-14 05:34 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-11 12:28 - 2009-07-14 05:34 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-11 12:21 - 2012-07-13 11:36 - 00000000 ____D () C:\Users\Monika\AppData\Roaming\Spamihilator
2014-12-11 12:20 - 2010-12-08 15:58 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-11 12:20 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-11 12:20 - 2009-07-14 05:39 - 00093113 _____ () C:\Windows\setupact.log
2014-12-11 09:17 - 2012-07-16 08:24 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-12-11 09:17 - 2012-07-16 08:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-12-10 21:54 - 2012-02-14 14:28 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-10 13:56 - 2013-07-11 20:11 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-10 13:47 - 2012-04-10 21:08 - 109818608 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-10 13:20 - 2009-07-14 05:33 - 00370200 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-09 12:15 - 2010-12-08 21:42 - 00089528 _____ () C:\Users\Monika\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-09 12:14 - 2013-09-17 11:37 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-12-08 18:38 - 2010-09-22 04:30 - 00078914 _____ () C:\Windows\PFRO.log
2014-12-02 18:35 - 2012-04-28 11:32 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-12-01 17:34 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\TAPI
2014-11-28 14:23 - 2014-04-25 10:46 - 00000000 ____D () C:\Windows\Offline Address Books
2014-11-27 10:41 - 2014-10-19 12:07 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\System
2014-11-27 10:39 - 2014-10-20 18:05 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Win
2014-11-26 21:03 - 2011-03-03 18:22 - 00002125 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-11-24 22:18 - 2014-01-14 20:31 - 00000000 ____D () C:\ProgramData\Oracle
2014-11-24 22:17 - 2011-06-19 11:04 - 00000000 ____D () C:\Program Files\Java
2014-11-24 20:39 - 2010-12-08 21:43 - 00001413 _____ () C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-24 20:03 - 2011-03-03 18:20 - 00000000 ___RD () C:\Program Files\Skype
2014-11-24 20:03 - 2011-03-03 18:20 - 00000000 ____D () C:\ProgramData\Skype
2014-11-24 20:00 - 2014-10-13 10:10 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Wqytx
2014-11-24 20:00 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\SchCache
2014-11-24 19:40 - 2014-09-04 17:54 - 00000000 ____D () C:\ProgramData\xgepa
2014-11-24 14:04 - 2010-12-08 16:08 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-11-16 14:41 - 2010-05-11 05:29 - 01507106 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-16 10:00 - 2014-10-28 09:57 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Firefox32
2014-11-13 15:06 - 2014-10-18 23:01 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Update
2014-11-11 13:28 - 2014-10-31 14:03 - 00000000 ___HD () C:\Users\Monika\AppData\Roaming\Adtrtjmkd
Some content of TEMP:
====================
C:\Users\Monika\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\Monika\AppData\Local\Temp\Quarantine.exe
C:\Users\Monika\AppData\Local\Temp\sqlite3.dll
C:\Users\Monika\AppData\Local\Temp\{69520FAB-EA87-4483-8737-34F42E35FFC0}.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-11 09:10
==================== End Of Log ============================ --- --- ---
und die addition.txt: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-12-2014
Ran by Monika at 2014-12-11 14:25:20
Running from C:\Users\Monika\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Panda Free Antivirus (Enabled - Up to date) {3456760B-FDAA-FFFD-06C2-7BB528D2066C}
AS: Panda Free Antivirus (Enabled - Up to date) {8F3797EF-DB90-F073-3C72-40C753554CD1}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Panda Firewall (Disabled) {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Acer Backup Manager (HKLM\...\InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}) (Version: 2.0.1.60 - NewTech Infosystems)
Acer Crystal Eye webcam (HKLM\...\{51F026FA-5146-4232-A8BA-1364740BD053}) (Version: 1.0.2.0 - Liteon)
Acer ePower Management (HKLM\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 5.00.3004 - Acer Incorporated)
Acer eRecovery Management (HKLM\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3011 - Acer Incorporated)
Acer Registration (HKLM\...\Acer Registration) (Version: 1.03.3003 - Acer Incorporated)
Acer ScreenSaver (HKLM\...\Acer Screensaver) (Version: 1.1.0203.2010 - Acer Incorporated)
Acer Updater (HKLM\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3001 - Acer Incorporated)
Acer VCM (HKLM\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3002 - Acer Incorporated)
Acrobat.com (HKLM\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.0.45.2 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Backup Manager Advance (Version: 2.0.1.60 - NewTech Infosystems) Hidden
Broadcom Gigabit NetLink Controller (HKLM\...\{A84DB02B-9C2B-4272-9D2D-A80E00A56513}) (Version: 12.52.04 - Broadcom Corporation)
eBay Worldwide (HKLM\...\{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}) (Version: 2.1.0901 - OEM)
Erfolgreich Reizen (HKLM\...\Erfolgreich Reizen) (Version: - )
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - )
eSobi v2 (HKLM\...\InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.4.000274 - esobi Inc.)
eSobi v2 (Version: 2.0.4.000274 - esobi Inc.) Hidden
Google Chrome (HKLM\...\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Grundtechniken des Alleinspiels (HKLM\...\Grundtechniken des Alleinspiels_is1) (Version: - )
Identity Card (HKLM\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2104 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.2.1001 - Intel Corporation)
InterVideo WinDVD 8 (HKLM\...\InstallShield_{5FEBF468-5AC2-4C66-AD80-DF85C085AA73}) (Version: 8.5.10.75 - InterVideo Inc.)
InterVideo WinDVD 8 (Version: 8.5.10.75 - InterVideo Inc.) Hidden
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217021FF}) (Version: 7.0.710 - Oracle)
Java(TM) 6 Update 26 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216026FF}) (Version: 6.0.260 - Oracle)
JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Launch Manager (HKLM\...\LManager) (Version: 4.0.8 - Acer Inc.)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30320 - Microsoft Corporation)
Microsoft Office 2010 (HKLM\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Home and Business 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 34.0 (x86 de) (HKLM\...\Mozilla Firefox 34.0 (x86 de)) (Version: 34.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyFreeCodec (HKU\S-1-5-21-463495802-3663640653-2969567870-1000\...\MyFreeCodec) (Version: - )
NTI Backup Now 5 (HKLM\...\InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}) (Version: 5.1.2.628 - NewTech Infosystems)
NTI Backup Now Standard (Version: 5.1.2.628 - NewTech Infosystems) Hidden
NTI Media Maker 8 (HKLM\...\InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}) (Version: 8.0.12.6630 - NewTech Infosystems)
NTI Media Maker 8 (Version: 8.0.12.6630 - NewTech Infosystems) Hidden
Panda Devices Agent (HKLM\...\Panda Devices Agent) (Version: 1.03.04 - Panda Security)
Panda Devices Agent (Version: 1.05.00 - Panda Security) Hidden
Panda Free Antivirus (HKLM\...\Panda Universal Agent Endpoint) (Version: 15.00.04.0002 - Panda Security)
Panda Free Antivirus (Version: 7.23.00.0000 - Panda Security) Hidden
Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6037 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30118 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.0.13074_14 - Samsung Electronics Co., Ltd.)
Samsung Kies (Version: 2.6.0.13074_14 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.27.0 - SAMSUNG Electronics Co., Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.9.9216 - Skype Technologies S.A.)
Skype™ 6.21 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
Spamihilator 1.5.0 (32-Bit) (HKLM\...\{2BBCB7D2-55AA-4156-92B7-CE870624B3AB}) (Version: 1.5.0 - Michel Krämer)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.19.0 - Synaptics Incorporated)
VLC media player 1.1.11 (HKLM\...\VLC media player) (Version: 1.1.11 - VideoLAN)
Welcome Center (HKLM\...\Acer Welcome Center) (Version: 1.01.3002 - Acer Incorporated)
Windows Live Anmelde-Assistent (HKLM\...\{52B97218-98CB-4B8B-9283-D213C85E1AA4}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-463495802-3663640653-2969567870-1000_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-463495802-3663640653-2969567870-1000_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-463495802-3663640653-2969567870-1000_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
==================== Restore Points =========================
20-11-2014 14:06:31 Windows Update
24-11-2014 07:42:29 Windows Update
24-11-2014 19:33:44 Revo Uninstaller's restore point - Ask Shopping Toolbar
24-11-2014 19:36:38 Revo Uninstaller's restore point - Ask Shopping Toolbar
24-11-2014 19:38:16 Revo Uninstaller's restore point - Google+ Auto Backup
24-11-2014 19:39:19 Revo Uninstaller's restore point - Opera Stable 26.0.1656.24
24-11-2014 21:16:21 Installed Java 7 Update 71
27-11-2014 09:44:23 Windows Update
30-11-2014 19:23:04 Windows Update
08-12-2014 17:01:35 Windows Update
10-12-2014 12:45:17 Windows Update
10-12-2014 20:47:24 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {1D2E3423-6499-45B7-B7C7-E7453E084BAF} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {249C0AC4-B749-4F15-AA5D-50EB2F5E8EF3} - \{F990E36A-3509-48BD-A0AC-60B9A2D18885} No Task File <==== ATTENTION
Task: {31E83D29-E4F7-4F5C-9928-71A39628182E} - System32\Tasks\{650F3580-5514-4B8B-90A7-B891D234228E} => C:\Program Files\Skype\\Phone\Skype.exe [2014-10-01] (Skype Technologies S.A.)
Task: {32ADEA1F-EB0C-446B-B6DC-16F8E9217207} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-11] (Adobe Systems Incorporated)
Task: {693A6BAF-05AF-420A-9AE7-6062F4F4CC9A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {AE7DAAFC-60B2-4CEB-915C-20BDB850651B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-04-12 18:23 - 2013-04-12 18:23 - 00612664 _____ () C:\Program Files\Panda Security\Panda Security Protection\SQLite3.dll
2010-03-09 01:18 - 2010-03-09 01:18 - 00465576 _____ () C:\Program Files\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2010-03-09 01:13 - 2010-03-09 01:13 - 01081600 _____ () C:\Program Files\NewTech Infosystems\Acer Backup Manager\ACE.dll
2013-08-26 08:47 - 2013-08-26 08:47 - 01902592 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\3c8c76a28c3b633e49ea9810ee3980f3\Kies.UI.ni.dll
2013-08-26 08:47 - 2013-08-26 08:47 - 00079360 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\e97a40f17def386f5b5ea1d696bc7b19\Kies.MVVM.ni.dll
2013-08-26 08:47 - 2013-08-26 08:47 - 00188416 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\7e7d735afac254a62ad7ece44afea98c\Kies.Common.DeviceServiceLib.Interface.ni.dll
2013-08-26 08:48 - 2013-08-26 08:48 - 00366592 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePhoto\d0e659fc0bcf3268411d4fda4563e2d3\DevicePhoto.ni.dll
2013-08-26 08:48 - 2013-08-26 08:48 - 00300544 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceVideo\f35619320de705124c918055c94a97a2\DeviceVideo.ni.dll
2013-08-26 08:48 - 2013-08-26 08:48 - 00616448 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePodcast\e9bd84c5084f801ce7beec9094895755\DevicePodcast.ni.dll
2013-08-26 08:48 - 2013-08-26 08:48 - 00307200 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DummyStorePlugin\fba11f594048dfcb347e0f716019286f\DummyStorePlugin.ni.dll
2013-08-26 08:48 - 2013-08-26 08:48 - 17281024 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\ed89e37e0f0d4641b68c24b53bb72a72\Kies.Theme.ni.dll
2013-08-26 08:48 - 2013-08-26 08:48 - 00581632 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\7f2688370e8d6866ea717cac42dc7662\Kies.Common.DeviceServiceLib.FileService.ni.dll
2013-08-26 08:47 - 2013-08-26 08:47 - 00046592 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\216a42533b0c2cffb4bcfefc20893e54\Kies.Common.DeviceServiceLib.FirmwareUpdate.FirmwareUpdateAgentHelper.ni.dll
2013-08-26 08:48 - 2013-08-26 08:48 - 00998912 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceCommonLib\8c788eba8c342bd4c56f6f2a9199d33a\DeviceCommonLib.ni.dll
2013-08-26 08:48 - 2013-08-26 08:48 - 00232960 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\52207264bac5068c2de665b3f41e8964\ASF_cSharpAPI.ni.dll
2014-02-18 11:48 - 2014-02-18 11:48 - 00060416 _____ () C:\Program Files\Spamihilator\zlib1.dll
2014-02-18 11:48 - 2014-02-18 11:48 - 00279040 _____ () C:\Program Files\Spamihilator\sqlite3.dll
2013-01-10 12:44 - 2013-01-10 12:44 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\9e5dc5d1c75de12100f8c1d8c65de002\IsdiInterop.ni.dll
2010-05-11 05:42 - 2010-04-13 17:52 - 00058880 _____ () C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2014-12-02 13:47 - 2014-12-02 13:47 - 03758192 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: avira64-process => C:\Users\Monika\AppData\Local\Avira64\avira64-process.exe
MSCONFIG\startupreg: BackupManagerTray => "C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
MSCONFIG\startupreg: ehpzjsuj => C:\Users\Monika\AppData\Local\Qqebdjkdo\jlvmmnjsuj.exe
MSCONFIG\startupreg: Google+ Auto Backup => "C:\Users\Monika\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart
MSCONFIG\startupreg: javasecure => C:\Users\Monika\AppData\Local\Java\javasecure.exe
MSCONFIG\startupreg: LManager => C:\Program Files\Launch Manager\LManager.exe
MSCONFIG\startupreg: loader32option => C:\Users\Monika\AppData\Local\Loader32\loader32option.exe
MSCONFIG\startupreg: run-rundll64 => C:\Users\Monika\AppData\Roaming\Run\run-rundll64.exe
MSCONFIG\startupreg: runoutput32 => C:\Users\Monika\AppData\Local\Run\runoutput32.exe
MSCONFIG\startupreg: runsecure => C:\Users\Monika\AppData\Local\Run\runsecure.exe
MSCONFIG\startupreg: swg => "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: system32timer64 => C:\Users\Monika\AppData\Roaming\System32\system32timer64.exe
MSCONFIG\startupreg: systemrundll => C:\Users\Monika\AppData\Roaming\System\systemrundll.exe
MSCONFIG\startupreg: update-memory64 => C:\Users\Monika\AppData\Local\Temp\Update\update-memory64.exe
MSCONFIG\startupreg: winnetware => C:\Users\Monika\AppData\Roaming\Win\winnetware.exe
MSCONFIG\startupreg: wkislhan => C:\Users\Monika\AppData\Local\Temp\Syxg\oyqslhan.exe
========================= Accounts: ==========================
Administrator (S-1-5-21-463495802-3663640653-2969567870-500 - Administrator - Disabled)
Gast (S-1-5-21-463495802-3663640653-2969567870-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-463495802-3663640653-2969567870-1002 - Limited - Enabled)
Monika (S-1-5-21-463495802-3663640653-2969567870-1000 - Administrator - Enabled) => C:\Users\Monika
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (12/11/2014 09:16:32 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (12/11/2014 09:11:35 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error: (12/11/2014 08:52:14 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OUTLOOK.EXE, Version: 14.0.7113.5000, Zeitstempel: 0x527d636c
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000001
ID des fehlerhaften Prozesses: 0x8b0
Startzeit der fehlerhaften Anwendung: 0xOUTLOOK.EXE0
Pfad der fehlerhaften Anwendung: OUTLOOK.EXE1
Pfad des fehlerhaften Moduls: OUTLOOK.EXE2
Berichtskennung: OUTLOOK.EXE3
Error: (12/10/2014 09:43:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OUTLOOK.EXE, Version: 14.0.7113.5000, Zeitstempel: 0x527d636c
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000001
ID des fehlerhaften Prozesses: 0x1c50
Startzeit der fehlerhaften Anwendung: 0xOUTLOOK.EXE0
Pfad der fehlerhaften Anwendung: OUTLOOK.EXE1
Pfad des fehlerhaften Moduls: OUTLOOK.EXE2
Berichtskennung: OUTLOOK.EXE3
Error: (12/08/2014 09:33:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AcroRd32.exe, Version: 11.0.9.29, Zeitstempel: 0x5412b4b3
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7600.17206, Zeitstempel: 0x50e65f4f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000b06d
ID des fehlerhaften Prozesses: 0x15f0
Startzeit der fehlerhaften Anwendung: 0xAcroRd32.exe0
Pfad der fehlerhaften Anwendung: AcroRd32.exe1
Pfad des fehlerhaften Moduls: AcroRd32.exe2
Berichtskennung: AcroRd32.exe3
Error: (12/08/2014 09:09:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc100
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7600.16915, Zeitstempel: 0x4ec49caf
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00046194
ID des fehlerhaften Prozesses: 0x804
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Error: (12/08/2014 06:54:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7600.16768, Zeitstempel: 0x4d6878c3
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x02240218
ID des fehlerhaften Prozesses: 0x148
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
System errors:
=============
Error: (12/11/2014 00:21:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "contact_list" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (12/11/2014 00:21:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "service_order_line" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (12/11/2014 00:21:49 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (12/11/2014 08:48:32 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "contact_list" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (12/11/2014 08:48:32 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "region" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (12/11/2014 08:48:32 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (12/10/2014 09:43:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "contact_list" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (12/10/2014 09:41:56 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (12/10/2014 01:44:37 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Volumeschattenkopie" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (12/10/2014 01:44:37 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Volumeschattenkopie erreicht.
Microsoft Office Sessions:
=========================
Error: (12/11/2014 09:16:32 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"c:\program files\Samsung\Kies\External\firmwareupdate\gt-i8160p\DeviceController64.exec:\program files\Samsung\Kies\External\firmwareupdate\gt-i8160p\Microsoft.VC90.CRT.MANIFEST11
Error: (12/11/2014 09:11:35 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3
Error: (12/11/2014 08:52:14 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: OUTLOOK.EXE14.0.7113.5000527d636cunknown0.0.0.000000000c0000005000000018b001d015175a81d68aC:\Program Files\Microsoft Office\Office14\OUTLOOK.EXEunknown9e637e7c-810a-11e4-9910-88ae1d9e5e7b
Error: (12/10/2014 09:43:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: OUTLOOK.EXE14.0.7113.5000527d636cunknown0.0.0.000000000c0000005000000011c5001d014b9e684ed14C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXEunknown2e495593-80ad-11e4-8b4c-88ae1d9e5e7b
Error: (12/08/2014 09:33:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AcroRd32.exe11.0.9.295412b4b3KERNELBASE.dll6.1.7600.1720650e65f4fc00000050000b06d15f001d013263d3d1b52C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exeC:\Windows\system32\KERNELBASE.dll7bd08bad-7f19-11e4-87a6-88ae1d9e5e7b
Error: (12/08/2014 09:09:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.1.7600.163854a5bc100ntdll.dll6.1.7600.169154ec49cafc00000050004619480401d01316c283e55eC:\Windows\system32\svchost.exeC:\Windows\SYSTEM32\ntdll.dll269874b0-7f16-11e4-87a6-88ae1d9e5e7b
Error: (12/08/2014 06:54:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.1.7600.167684d6878c3unknown0.0.0.000000000c00000050224021814801d0130ff05a60d1C:\Windows\Explorer.EXEunknown416ec38d-7f03-11e4-8c11-88ae1d9e5e7b
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Percentage of memory in use: 56%
Total physical RAM: 1782.71 MB
Available physical RAM: 772.72 MB
Total Pagefile: 3565.42 MB
Available Pagefile: 1808.57 MB
Total Virtual: 2047.88 MB
Available Virtual: 1861.88 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:138.95 GB) (Free:94.06 GB) NTFS
Drive d: (DATA) (Fixed) (Total:139.04 GB) (Free:138.83 GB) NTFS
Drive e: (EIN2009) (CDROM) (Total:0.55 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 299F7FD8)
Partition 1: (Not Active) - (Size=20 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=139 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=139 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Vielen Dank und beste Grüße,
Jan |