| Thomas_Jgb |  19.01.2015 17:12 |        FRST Logfile:  
FRST Logfile:   Code:  
 Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2015 
Ran by Thomas (administrator) on THOMAS-PC on 19-01-2015 16:57:28 
Running from C:\Users\Thomas\Downloads 
Loaded Profiles: Thomas (Available profiles: Thomas & Gast) 
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland) 
Internet Explorer Version 11 (Default browser: FF) 
Boot Mode: Normal 
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/   
==================== Processes (Whitelisted) =================   
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)   
(AMD) C:\Windows\System32\atiesrxx.exe 
(AMD) C:\Windows\System32\atieclxx.exe 
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe 
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.5.0.28\ccsvchst.exe 
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe 
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe 
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe 
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe     
==================== Registry (Whitelisted) ==================   
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)   
HKU\S-1-5-21-3758458836-4203219915-3420783273-1000\...\Policies\system: [LogonHoursAction] 2 
HKU\S-1-5-21-3758458836-4203219915-3420783273-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\20.5.0.28\buShell.dll (Symantec Corporation) 
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\20.5.0.28\buShell.dll (Symantec Corporation) 
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\20.5.0.28\buShell.dll (Symantec Corporation)   
==================== Internet (Whitelisted) ====================   
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)   
HKU\S-1-5-21-3758458836-4203219915-3420783273-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp 
SearchScopes: HKLM -> DefaultScope value is missing. 
SearchScopes: HKLM-x32 -> DefaultScope value is missing. 
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\20.5.0.28\coIEPlg.dll (Symantec Corporation) 
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\20.5.0.28\IPS\IPSBHO.DLL (Symantec Corporation) 
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) 
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) 
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.5.0.28\coIEPlg.dll (Symantec Corporation) 
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1   
FireFox: 
======== 
FF ProfilePath: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\uf891wou.default-1420999219945 
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll () 
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) 
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll () 
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) 
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) 
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) 
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) 
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) 
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFF 
FF Extension: No Name - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFF [2013-10-09] 
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn 
FF Extension: No Name - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn [2014-08-13]   
Chrome:  
======= 
CHR Profile: C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default 
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-27] 
CHR Extension: (Google Wallet) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-21] 
CHR HKLM-x32\...\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files (x86)\Norton 360\Engine\20.5.0.28\Exts\Chrome.crx [Not Found]   
==================== Services (Whitelisted) =================   
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)   
R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.5.0.28\ccSvcHst.exe [144368 2013-05-20] (Symantec Corporation) 
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) 
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) 
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)   
==================== Drivers (Whitelisted) ====================   
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)   
S1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\BASHDefs\20140801.001\BHDrvx64.sys [1530160 2014-05-10] (Symantec Corporation) 
S1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1405000.01C\ccSetx64.sys [169048 2013-04-15] (Symantec Corporation) 
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [486192 2014-07-06] (Symantec Corporation) 
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\IPSDefs\20140813.001\IDSvia64.sys [525016 2014-07-17] (Symantec Corporation) 
S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [44480 2011-05-17] (hxxp://libusb-win32.sourceforge.net) 
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20140813.001\ENG64.SYS [126040 2014-08-12] (Symantec Corporation) 
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20140813.001\EX64.SYS [2099288 2014-08-12] (Symantec Corporation) 
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) 
S1 SRTSP; C:\Windows\System32\Drivers\N360x64\1405000.01C\SRTSP64.SYS [796760 2013-05-15] (Symantec Corporation) 
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1405000.01C\SRTSPX64.SYS [36952 2013-03-04] (Symantec Corporation) 
R0 SymDS; C:\Windows\System32\drivers\N360x64\1405000.01C\SYMDS64.SYS [493656 2013-05-20] (Symantec Corporation) 
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1405000.01C\SYMEFA64.SYS [1139800 2013-05-22] (Symantec Corporation) 
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-07-07] (Symantec Corporation) 
S1 SymIRON; C:\Windows\system32\drivers\N360x64\1405000.01C\Ironx64.SYS [224416 2013-03-04] (Symantec Corporation) 
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1405000.01C\SYMNETS.SYS [433752 2013-04-24] (Symantec Corporation) 
S3 VGPU; System32\drivers\rdvgkmd.sys [X]   
==================== NetSvcs (Whitelisted) ===================   
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)     
==================== One Month Created Files and Folders ========   
(If an entry is included in the fixlist, the file\folder will be moved.)   
2015-01-19 16:57 - 2015-01-19 16:57 - 02126848 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64.exe 
2015-01-18 15:02 - 2015-01-18 15:02 - 00000000 ____D () C:\Users\Gast\AppData\Local\Paint.NET 
2015-01-16 23:37 - 2015-01-19 14:20 - 00000168 _____ () C:\Windows\setupact.log 
2015-01-16 23:37 - 2015-01-16 23:37 - 00000000 _____ () C:\Windows\setuperr.log 
2015-01-16 19:58 - 2015-01-16 19:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 
2015-01-16 19:42 - 2015-01-16 20:11 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 
2015-01-16 19:19 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 
2015-01-16 19:19 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 
2015-01-16 19:19 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 
2015-01-16 19:19 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 
2015-01-16 19:19 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 
2015-01-16 19:19 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 
2015-01-16 19:18 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 
2015-01-16 19:18 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 
2015-01-16 19:18 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 
2015-01-16 19:17 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 
2015-01-16 19:17 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 
2015-01-16 19:17 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 
2015-01-16 19:17 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 
2015-01-13 19:23 - 2015-01-13 19:23 - 00000000 __SHD () C:\Users\Thomas\AppData\Local\EmieBrowserModeList 
2015-01-11 19:08 - 2015-01-11 19:12 - 122418480 _____ (Apple Inc.) C:\Users\Thomas\Downloads\iTunes64Setup(1).exe 
2015-01-11 18:50 - 2015-01-11 18:50 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Apple Computer 
2015-01-11 18:50 - 2015-01-11 18:50 - 00000000 ____D () C:\Users\Default\AppData\Local\Apple Computer 
2015-01-11 18:50 - 2015-01-11 18:50 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Apple Computer 
2015-01-11 18:50 - 2015-01-11 18:50 - 00000000 ____D () C:\Users\Default User\AppData\Local\Apple Computer 
2015-01-11 18:40 - 2015-01-11 18:40 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk 
2015-01-11 18:39 - 2015-01-15 14:06 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1 
2015-01-11 18:37 - 2015-01-11 18:38 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 
2015-01-11 18:30 - 2015-01-11 18:29 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 
2015-01-11 18:29 - 2015-01-15 14:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 
2015-01-11 18:29 - 2015-01-11 18:29 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 
2015-01-11 18:29 - 2015-01-11 18:29 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 
2015-01-11 18:29 - 2015-01-11 18:29 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 
2015-01-11 18:29 - 2015-01-11 18:29 - 00000000 ____D () C:\Program Files (x86)\Java 
2015-01-06 10:07 - 2015-01-06 10:07 - 00000000 ____D () C:\Users\Thomas\Documents\USB-Stick 
2015-01-03 19:29 - 2015-01-07 20:10 - 00000000 ____D () C:\Users\Gast\AppData\Local\CrashDumps 
2014-12-30 14:14 - 2015-01-18 15:01 - 00068416 _____ () C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 
2014-12-26 00:16 - 2014-12-26 00:16 - 00000000 ____D () C:\Users\Gast\AppData\Local\Adobe 
2014-12-21 20:42 - 2014-12-21 20:42 - 00000842 _____ () C:\Users\Thomas\AppData\Local\recently-used.xbel 
2014-12-21 17:14 - 2014-12-21 17:14 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Macromedia 
2014-12-21 17:14 - 2014-12-21 17:14 - 00000000 ____D () C:\Users\Gast\AppData\Local\Macromedia 
2014-12-21 17:07 - 2014-12-21 17:08 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Mozilla 
2014-12-21 17:07 - 2014-12-21 17:08 - 00000000 ____D () C:\Users\Gast\AppData\Local\Mozilla   
==================== One Month Modified Files and Folders =======   
(If an entry is included in the fixlist, the file\folder will be moved.)   
2015-01-19 16:57 - 2014-02-20 19:51 - 00009037 _____ () C:\Users\Thomas\Downloads\FRST.txt 
2015-01-19 16:57 - 2014-02-20 19:51 - 00000000 ____D () C:\FRST 
2015-01-19 16:57 - 2013-07-28 20:37 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 
2015-01-19 16:18 - 2013-08-16 20:33 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 
2015-01-19 16:15 - 2014-11-07 22:42 - 01206893 _____ () C:\Windows\WindowsUpdate.log 
2015-01-19 14:27 - 2009-07-14 05:45 - 00027120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
2015-01-19 14:27 - 2009-07-14 05:45 - 00027120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
2015-01-19 14:20 - 2013-08-16 20:33 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 
2015-01-19 14:20 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 
2015-01-18 15:58 - 2013-09-13 16:09 - 00000000 ____D () C:\Users\Thomas\AppData\Local\Paint.NET 
2015-01-18 15:05 - 2011-04-12 08:43 - 03749872 _____ () C:\Windows\system32\perfh007.dat 
2015-01-18 15:05 - 2011-04-12 08:43 - 01131442 _____ () C:\Windows\system32\perfc007.dat 
2015-01-18 15:05 - 2009-07-14 06:13 - 00006248 _____ () C:\Windows\system32\PerfStringBackup.INI 
2015-01-17 14:22 - 2013-08-16 20:34 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 
2015-01-16 20:12 - 2013-07-07 15:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 
2015-01-16 20:11 - 2014-02-04 17:58 - 00000000 ____D () C:\Program Files\iPod 
2015-01-16 20:11 - 2014-02-04 17:58 - 00000000 ____D () C:\Program Files (x86)\iTunes 
2015-01-16 20:10 - 2014-02-04 17:54 - 00000000 ____D () C:\Program Files\Common Files\Apple 
2015-01-16 20:05 - 2013-08-02 14:04 - 00000000 ____D () C:\Windows\Minidump 
2015-01-16 19:00 - 2013-08-02 14:21 - 00000000 ____D () C:\Windows\system32\MRT 
2015-01-15 14:15 - 2013-07-07 13:03 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 
2015-01-15 14:08 - 2013-07-07 11:11 - 00000000 ____D () C:\Users\Thomas 
2015-01-15 14:08 - 2009-07-14 05:45 - 00305120 _____ () C:\Windows\system32\FNTCACHE.DAT 
2015-01-15 14:06 - 2014-12-12 18:36 - 00000000 ____D () C:\Users\Gast 
2015-01-15 14:06 - 2014-05-13 13:02 - 00000000 ____D () C:\Windows\System32\Tasks\Norton 360 
2015-01-15 14:06 - 2013-07-10 13:16 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 
2015-01-15 14:06 - 2013-07-07 16:03 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 
2015-01-15 14:06 - 2013-07-07 16:03 - 00000000 ____D () C:\Windows\system32\Drivers\N360x64 
2015-01-15 14:06 - 2013-07-07 16:03 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared 
2015-01-15 14:06 - 2013-07-07 16:03 - 00000000 ____D () C:\Program Files (x86)\Norton 360 
2015-01-15 14:06 - 2013-07-07 15:58 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton 
2015-01-15 14:06 - 2013-07-07 15:58 - 00000000 ____D () C:\ProgramData\Norton 
2015-01-15 14:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 
2015-01-14 22:14 - 2014-12-17 11:46 - 00000000 ____D () C:\Users\Thomas\Documents\MÄCHTIG 
2015-01-11 19:08 - 2013-07-07 17:56 - 00068416 _____ () C:\Users\Thomas\AppData\Local\GDIPFONTCACHEV1.DAT 
2015-01-11 18:51 - 2014-02-04 17:58 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 
2015-01-11 18:36 - 2013-07-22 10:58 - 00000000 ____D () C:\Program Files (x86)\OpenOffice.org 3 
2015-01-11 18:32 - 2013-07-28 20:37 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 
2015-01-11 18:32 - 2013-07-10 13:16 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 
2015-01-11 18:32 - 2013-07-10 13:16 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 
2015-01-11 18:23 - 2014-03-11 20:46 - 00000000 ____D () C:\Program Files\GIMP 2 
2015-01-11 18:21 - 2013-07-30 09:42 - 00000000 ____D () C:\Program Files (x86)\Secunia 
2015-01-06 15:15 - 2013-08-02 14:07 - 00000000 ____D () C:\Users\Thomas\AppData\Local\CrashDumps 
2015-01-01 17:57 - 2013-08-17 17:18 - 00000000 ____D () C:\Users\Thomas\Documents\Schule 
2014-12-26 00:16 - 2014-12-12 18:39 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Adobe 
2014-12-21 20:42 - 2013-10-21 23:02 - 00000000 ____D () C:\Users\Thomas\.gimp-2.8   
==================== Files in the root of some directories ======= 
2014-12-21 20:42 - 2014-12-21 20:42 - 0000842 _____ () C:\Users\Thomas\AppData\Local\recently-used.xbel   
==================== Bamital & volsnap Check =================   
(There is no automatic fix for files that do not pass verification.)   
C:\Windows\System32\winlogon.exe => File is digitally signed 
C:\Windows\System32\wininit.exe => File is digitally signed 
C:\Windows\SysWOW64\wininit.exe => File is digitally signed 
C:\Windows\explorer.exe => File is digitally signed 
C:\Windows\SysWOW64\explorer.exe => File is digitally signed 
C:\Windows\System32\svchost.exe => File is digitally signed 
C:\Windows\SysWOW64\svchost.exe => File is digitally signed 
C:\Windows\System32\services.exe => File is digitally signed 
C:\Windows\System32\User32.dll => File is digitally signed 
C:\Windows\SysWOW64\User32.dll => File is digitally signed 
C:\Windows\System32\userinit.exe => File is digitally signed 
C:\Windows\SysWOW64\userinit.exe => File is digitally signed 
C:\Windows\System32\rpcss.dll => File is digitally signed 
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed     
LastRegBack: 2015-01-17 22:10   
==================== End Of Log ============================   --- --- ---  
--- --- ---     Code:  
 Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-01-2015 
Ran by Thomas at 2015-01-19 17:10:03 
Running from C:\Users\Thomas\Desktop 
Boot Mode: Normal 
==========================================================     
==================== Security Center ========================   
(If an entry is included in the fixlist, it will be removed.)   
AV: Norton 360 (Disabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} 
AS: Norton 360 (Disabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466} 
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
FW: Norton 360 (Disabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}   
==================== Installed Programs ======================   
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)   
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version:  - ) 
Adobe Flash Player 11 ActiveX (HKLM-x32\...\{4CFE23CC-779D-4572-A76F-AB60A958BC79}) (Version: 11.8.800.94 - Adobe Systems Incorporated) 
Adobe Flash Player 16 NPAPI (HKLM-x32\...\{61F2FFE4-56BA-4F5E-91FB-BD34F92E44CE}) (Version: 16.0.0.235 - Adobe Systems Incorporated) 
Adobe Reader XI (11.0.03) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated) 
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) 
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.) 
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) 
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) 
CCleaner (HKLM\...\CCleaner) (Version: 4.03 - Piriform) 
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team) 
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.99 - Google Inc.) 
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden 
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) 
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) 
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) 
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) 
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) 
Mozilla Firefox 35.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0 (x86 de)) (Version: 35.0 - Mozilla) 
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) 
Mozilla Thunderbird 31.3.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.3.0 (x86 de)) (Version: 31.3.0 - Mozilla) 
Mp3tag v2.58 (HKLM-x32\...\Mp3tag) (Version: v2.58 - Florian Heidenreich) 
Norton 360 (HKLM-x32\...\N360) (Version: 20.5.0.28 - Symantec Corporation) 
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) 
Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC) 
Secunia PSI (3.0.0.7011) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.7011 - Secunia) 
Windows Installer Clean Up (HKLM-x32\...\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}) (Version: 3.00.00.0000 - Microsoft Corporation) 
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)   
==================== Custom CLSID (selected items): ==========================   
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)   
CustomCLSID: HKU\S-1-5-21-3758458836-4203219915-3420783273-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Thomas\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File   
==================== Restore Points  =========================   
19-12-2014 14:41:03 Geplanter Prüfpunkt 
19-12-2014 23:57:53 Windows Update 
27-12-2014 14:28:30 Geplanter Prüfpunkt 
10-01-2015 18:41:00 Geplanter Prüfpunkt 
11-01-2015 18:57:00 Removed iTunes 
11-01-2015 19:00:58 Removed iTunes 
11-01-2015 19:15:51 Installed iTunes 
15-01-2015 14:13:18 Windows Update 
16-01-2015 19:01:01 Windows Modules Installer 
16-01-2015 19:04:02 Windows Modules Installer 
16-01-2015 19:05:04 Windows Modules Installer 
16-01-2015 19:07:05 Windows Modules Installer 
16-01-2015 19:08:08 Windows Modules Installer 
16-01-2015 19:41:02 Installed iTunes 
16-01-2015 20:09:23 Removed iTunes 
16-01-2015 20:13:58 Windows Update   
==================== Hosts content: ==========================   
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)   
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts   
==================== Scheduled Tasks (whitelisted) =============   
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)   
Task: {0779348D-4630-4419-A140-B6FF0391D1C6} - System32\Tasks\{27E5A356-1E54-4709-A314-F5491600715B} => pcalua.exe -a E:\sp52131.exe -d E:\ 
Task: {2D62EDA4-05B1-4DA5-B3BE-8D538233A937} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\20.5.0.28\SymErr.exe [2013-06-03] (Symantec Corporation) 
Task: {336DB0D7-BDD0-4B74-BA6E-CA350D074F9F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-16] (Google Inc.) 
Task: {408ED1E8-2BCC-47D7-BD17-71CFF46FFCBE} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\20.5.0.28\SymErr.exe [2013-06-03] (Symantec Corporation) 
Task: {54B603A9-155F-470A-BD89-7D2B14069971} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) 
Task: {621226D0-152E-4DD1-9CF3-0376C12E3F33} - \PC Performer No Task File <==== ATTENTION 
Task: {6B490DE3-63C0-44C5-982C-A6E9741CB757} - System32\Tasks\{DC0C40CF-F53E-437F-BA6E-A53322979C50} => pcalua.exe -a C:\Users\Thomas\Downloads\JRT.exe -d C:\Users\Thomas\Downloads 
Task: {7C1D89D6-0C0D-4A34-BDAE-7F3787440513} - System32\Tasks\{6725FB60-F913-41D2-A0C6-7E5A1A1AEA6C} => pcalua.exe -a E:\sp51604.exe -d E:\ 
Task: {81129083-5A32-4067-9338-FA814D3C058D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-11] (Adobe Systems Incorporated) 
Task: {83AC4C34-2AC6-4F17-B0F3-420FD77E44A1} - \EPUpdater No Task File <==== ATTENTION 
Task: {8B637F26-EEEB-4AAD-9EFB-B50141F593C7} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\20.5.0.28\WSCStub.exe [2014-04-29] (Symantec Corporation) 
Task: {B9CD4ACF-02CD-4F6A-9DF7-766C764D41C4} - System32\Tasks\{A0FEDEFE-C7AA-4017-9A1E-3D54CAA92DC2} => pcalua.exe -a C:\Users\Thomas\Downloads\JRT(1).exe -d C:\Users\Thomas\Downloads 
Task: {C0EBC3A2-F61E-4B8F-8C4A-4450B2FC587A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-16] (Google Inc.) 
Task: {F3202622-2F7F-4AF7-BA1C-43A964F59B24} - System32\Tasks\{A603B5C8-F408-4C0E-AC66-3CE8ECA00DB8} => pcalua.exe -a E:\sp51096.exe -d E:\ 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe   
==================== Loaded Modules (whitelisted) =============   
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 
2015-01-16 19:58 - 2015-01-16 19:58 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 
2014-12-02 17:31 - 2014-12-02 17:31 - 03339376 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll 
2014-12-02 17:31 - 2014-12-02 17:31 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 
2014-12-02 17:31 - 2014-12-02 17:31 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll   
==================== Alternate Data Streams (whitelisted) =========   
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)     
==================== Safe Mode (whitelisted) ===================   
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)     
==================== EXE Association (whitelisted) =============   
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)     
==================== MSCONFIG/TASK MANAGER disabled items =========   
(Currently there is no automatic fix for this section.)   
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk => C:\Windows\pss\Secunia PSI Tray.lnk.CommonStartup 
MSCONFIG\startupfolder: C:^Users^Thomas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup 
MSCONFIG\startupfolder: C:^Users^Thomas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk => C:\Windows\pss\OpenOffice.org 3.4.1.lnk.Startup 
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" 
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" 
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"   
========================= Accounts: ==========================   
Administrator (S-1-5-21-3758458836-4203219915-3420783273-500 - Administrator - Disabled) 
Gast (S-1-5-21-3758458836-4203219915-3420783273-501 - Limited - Enabled) => C:\Users\Gast 
HomeGroupUser$ (S-1-5-21-3758458836-4203219915-3420783273-1002 - Limited - Enabled) 
Thomas (S-1-5-21-3758458836-4203219915-3420783273-1000 - Administrator - Enabled) => C:\Users\Thomas   
==================== Faulty Device Manager Devices =============   
Name: Symantec Iron Driver 
Description: Symantec Iron Driver 
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} 
Manufacturer:  
Service: SymIRON 
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) 
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. 
Devices stay in this state if they have been prepared for removal. 
After you remove the device, this error disappears.Remove the device, and this error should be resolved.   
Name: BHDrvx64 
Description: BHDrvx64 
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} 
Manufacturer:  
Service: BHDrvx64 
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) 
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. 
Devices stay in this state if they have been prepared for removal. 
After you remove the device, this error disappears.Remove the device, and this error should be resolved.   
Name: Norton 360 Settings Manager 
Description: Norton 360 Settings Manager 
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} 
Manufacturer:  
Service: ccSet_N360 
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) 
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. 
Devices stay in this state if they have been prepared for removal. 
After you remove the device, this error disappears.Remove the device, and this error should be resolved.     
==================== Event log errors: =========================   
Application errors: 
================== 
Error: (01/19/2015 02:21:41 PM) (Source: WinMgmt) (EventID: 10) (User: ) 
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003   
Error: (01/18/2015 03:58:03 PM) (Source: Application Hang) (EventID: 1002) (User: ) 
Description: Programm PaintDotNet.exe, Version 3.511.4977.23448 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.   
Prozess-ID: f64   
Startzeit: 01d033279740de41   
Endzeit: 132   
Anwendungspfad: C:\Program Files\Paint.NET\PaintDotNet.exe   
Berichts-ID: 310128dc-9f22-11e4-aed2-78acc056c305   
Error: (01/18/2015 03:05:18 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) 
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich.   
Error: (01/18/2015 03:05:18 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) 
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.   
Error: (01/18/2015 03:05:18 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) 
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.   
Error: (01/18/2015 03:03:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) 
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich.   
Error: (01/18/2015 03:03:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) 
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.   
Error: (01/18/2015 03:03:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) 
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.   
Error: (01/18/2015 04:11:54 AM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledSPRetry 16474   
Error: (01/18/2015 04:11:54 AM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledEvent 16474     
System errors: 
============= 
Error: (01/19/2015 04:53:02 PM) (Source: atikmdag) (EventID: 10261) (User: ) 
Description: Display is not active   
Error: (01/19/2015 04:52:36 PM) (Source: atikmdag) (EventID: 10261) (User: ) 
Description: Display is not active   
Error: (01/19/2015 03:59:48 PM) (Source: atikmdag) (EventID: 10261) (User: ) 
Description: Display is not active   
Error: (01/19/2015 02:20:29 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) 
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:  
BHDrvx64 
ccSet_N360 
SRTSP 
SymIRON   
Error: (01/19/2015 02:20:08 PM) (Source: atikmdag) (EventID: 10261) (User: ) 
Description: Display is not active   
Error: (01/19/2015 02:20:08 PM) (Source: atikmdag) (EventID: 19468) (User: ) 
Description: CPLIB :: General - Invalid Parameter   
Error: (01/19/2015 02:19:50 PM) (Source: SRTSP) (EventID: 4) (User: ) 
Description: Error loading virus definitions.   
Error: (01/19/2015 02:20:11 PM) (Source: EventLog) (EventID: 6008) (User: ) 
Description: Das System wurde zuvor am 18.01.2015 um 22:18:50 unerwartet heruntergefahren.   
Error: (01/18/2015 07:51:57 PM) (Source: atikmdag) (EventID: 10261) (User: ) 
Description: Display is not active   
Error: (01/18/2015 07:34:19 PM) (Source: DCOM) (EventID: 10016) (User: Thomas-PC) 
Description: AnwendungsspezifischLokalAktivierung{8BC3F05E-D86B-11D0-A075-00C04FB68820}{8BC3F05E-D86B-11D0-A075-00C04FB68820}Thomas-PCGastS-1-5-21-3758458836-4203219915-3420783273-501LocalHost (unter Verwendung von LRPC)     
Microsoft Office Sessions: 
========================= 
Error: (01/19/2015 02:21:41 PM) (Source: WinMgmt) (EventID: 10) (User: ) 
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003   
Error: (01/18/2015 03:58:03 PM) (Source: Application Hang) (EventID: 1002) (User: ) 
Description: PaintDotNet.exe3.511.4977.23448f6401d033279740de41132C:\Program Files\Paint.NET\PaintDotNet.exe310128dc-9f22-11e4-aed2-78acc056c305   
Error: (01/18/2015 03:05:18 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) 
Description: WmiApRplWmiApRpl8F20300004D070000   
Error: (01/18/2015 03:05:18 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) 
Description: Performance1637070000000000000000000009030000   
Error: (01/18/2015 03:05:18 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) 
Description: Performance1637070000000000000000000009030000   
Error: (01/18/2015 03:03:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) 
Description: WmiApRplWmiApRpl8F20300004D070000   
Error: (01/18/2015 03:03:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) 
Description: Performance1637070000000000000000000009030000   
Error: (01/18/2015 03:03:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) 
Description: Performance1637070000000000000000000009030000   
Error: (01/18/2015 04:11:54 AM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledSPRetry 16474   
Error: (01/18/2015 04:11:54 AM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledEvent 16474     
==================== Memory info ===========================    
Processor: AMD V140 Processor 
Percentage of memory in use: 65% 
Total physical RAM: 1786.9 MB 
Available physical RAM: 620.05 MB 
Total Pagefile: 3573.8 MB 
Available Pagefile: 2054.07 MB 
Total Virtual: 8192 MB 
Available Virtual: 8191.85 MB   
==================== Drives ================================   
Drive c: () (Fixed) (Total:232.79 GB) (Free:173.84 GB) NTFS   
==================== MBR & Partition Table ==================   
======================================================== 
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 31D2810F) 
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) 
Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS)   
==================== End Of Log ============================      |