Hi schrauber,
vielen dank für die Mühen. Die aktuellen logs anbei:
Eset (ist es normal, dass Eset fast 9h scan?): Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=d870ed720499354895e602b5fc3b9f7c
# engine=15082
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-09-11 06:31:57
# local_time=2013-09-11 08:31:57 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 86497 130510967 0 0
# scanned=148978
# found=0
# cleaned=0
# scan_time=31415 SecurityCheck: Code:
et Results of screen317's Security Check version 0.99.73
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10 ``````````````Antivirus/Firewall Check:``````````````
Norman Security Suite
Antivirus out of date! `````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
Java 7 Update 25
Adobe Flash Player 11.8.800.94
Adobe Reader XI
Mozilla Firefox (23.0.1) ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` und noch den aktuellen FRST und Addition log:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-09-2013 01
Ran by **** (ATTENTION: The logged in user is not administrator) on WPK-NB-137 on 11-09-2013 08:49:24
Running from C:\Users\****\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe
(Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe
(Dell Computer Corporation) C:\dell\DBRM\Reminder\DbrmTrayicon.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Norman ASA) C:\Program Files\Norman\Npm\Bin\zlh.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Norman ASA) C:\Program Files\Norman\Nvc\Bin\cclaw.exe
(IBM Corp) C:\Notes\NLNOTES.EXE
(IBM Corp) C:\Notes\ntaskldr.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [684016 2012-12-22] (Alps Electric Co., Ltd.)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1702912 2013-02-05] (IDT, Inc.)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [IntelPROSet] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4805936 2012-08-23] (Intel(R) Corporation)
HKLM\...\Run: [TdmNotify] - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe [370584 2012-11-09] (Wave Systems Corp.)
HKLM\...\Run: [DFEPApplication] - C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [7077432 2012-08-15] (Dell Inc.)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [DBRMTray] - C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (Authentec Inc.)
MountPoints2: {55fae774-07f4-11e3-a182-028037ec0200} - F:\pushinst.exe
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480 2012-05-30] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-12-04] (Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Norman ZANDA] - C:\Program Files\Norman\Npm\Bin\ZLH.EXE [350560 2013-02-04] (Norman ASA)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [IBM Lotus Notes Preloader] - C:\Notes\nntspreld.exe [25480 2011-09-16] (IBM Corp)
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://dell13-comm.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13-comm.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {FE07B666-117A-4A2D-80D5-48FDA96E9A5A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDRJS
SearchScopes: HKLM - {FE07B666-117A-4A2D-80D5-48FDA96E9A5A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDRJS
SearchScopes: HKLM-x32 - {FE07B666-117A-4A2D-80D5-48FDA96E9A5A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDRJS
SearchScopes: HKCU - {FE07B666-117A-4A2D-80D5-48FDA96E9A5A} URL =
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Web Check - {E155F23C-9931-47c6-A619-20E6FCA86D75} - C:\Program Files (x86)\Web Check\WebCheck.dll No File
Tcpip\..\Interfaces\{750A6C13-1E6D-445A-A112-B92A66D2FF11}: [NameServer]193.171.87.249,193.171.87.250
FireFox:
========
FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vxd8q76x.default
FF Homepage: hxxp://www.kunststofftechnik.at/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vxd8q76x.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
==================== Services (Whitelisted) =================
R2 DFEPService; C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2280504 2012-08-15] (Dell Inc.)
R2 eLoggerSvc6; C:\Program Files\Norman\Npm\Bin\elogsvc.exe [76232 2011-10-24] (Norman ASA)
R2 EmbassyService; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [225720 2012-11-20] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166432 2012-10-23] (Intel Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 LNSUSvc; C:\Notes\SUService.exe [189832 2011-09-16] (IBM Corp)
R2 Lotus Notes Diagnostics; C:\Notes\nsd.exe [4453768 2011-09-16] (IBM)
R2 Multi-user Cleanup Service; C:\Notes\ntmulti.exe [71048 2011-09-16] (IBM Corp)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272688 2012-08-23] ()
R2 NHS; C:\Program Files\Norman\Nvc\bin\nhs.exe [793520 2012-05-10] ()
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 NNFSVC; C:\Program Files\Norman\Ngs\Bin\Nnf.exe [231216 2011-11-14] (Norman ASA)
R3 Norman NJeeves; C:\Program Files\Norman\Npm\Bin\Njeeves.exe [116056 2012-02-03] ()
R2 Norman ZANDA; C:\Program Files\Norman\Npm\Bin\Zanda.exe [431320 2012-02-13] (Norman ASA)
R3 nsesvc; C:\Program Files\Norman\Nse\Bin\NSESVC.EXE [427288 2013-04-02] (Norman ASA)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 nvcoas; C:\Program Files\Norman\Nvc\Bin\nvcoas.exe [287312 2012-06-28] (Norman ASA)
R2 NVOY; C:\Program Files\Norman\npm\bin\nvoy.exe [100936 2011-10-19] (Norman ASA)
R2 O2FLASH; C:\Windows\system32\o2flash.exe [244328 2011-11-16] (O2Micro International)
R2 PbaDrvSvc_x64; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\hapi64\pbadrvsvc.exe [20480 2012-11-23] ()
R3 Scheduler; C:\Program Files\Norman\Npm\Bin\scheduler.exe [148240 2011-04-11] (Norman ASA)
S2 tcsd_win32.exe; C:\Program Files (x86)\Security Innovation\SI TSS\bin\tcsd_win32.exe [1643520 2012-05-11] ()
R2 Wave Authentication Manager Service; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [1758720 2012-11-19] (Wave Systems Corp.)
R2 WMCoreService; C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe [689560 2012-10-18] (Ericsson AB)
S2 WvPCR; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [254384 2012-11-08] (Wave Systems Corp.)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3342640 2012-08-23] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [135720 2013-07-02] (Broadcom Corporation.)
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] ()
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] ()
R3 d554gps; C:\Windows\System32\DRIVERS\d554gps64.sys [103184 2012-03-01] (Ericsson AB)
R3 d554scard; C:\Windows\System32\DRIVERS\d554scard.sys [61992 2011-01-14] (Ericsson AB)
R3 dcdbas; C:\Windows\System32\DRIVERS\dcdbas64.sys [39016 2012-09-23] (Dell Inc.)
R3 ecnssndis; C:\Windows\System32\Drivers\wwuss64.sys [26664 2011-10-05] (Ericsson AB)
R3 ecnssndisfltr; C:\Windows\System32\Drivers\wwussf64.sys [29736 2011-10-05] (Ericsson AB)
R3 Mbm3CBus; C:\Windows\System32\DRIVERS\Mbm3CBus.sys [443208 2012-10-02] (MCCI Corporation)
R3 Mbm3DevMt; C:\Windows\System32\DRIVERS\Mbm3DevMt.sys [453960 2012-10-02] (MCCI Corporation)
R3 Mbm3mdfl; C:\Windows\System32\DRIVERS\Mbm3mdfl.sys [21832 2012-10-02] (MCCI Corporation)
R3 Mbm3Mdm; C:\Windows\System32\DRIVERS\Mbm3Mdm.sys [506184 2012-10-02] (MCCI Corporation)
S3 NAL; C:\Windows\system32\Drivers\iqvw64e.sys [32936 2011-11-09] (Intel Corporation )
R1 NGS; c:\program files\norman\ngs\bin\ngs64.sys [22368 2011-07-12] (Norman ASA)
R1 NGS; c:\program files\norman\ngs\bin\ngs64.sys [22368 2011-07-12] (Norman ASA)
R2 nregsec; C:\Program Files\Norman\Ngs\Bin\nregsec64.sys [63032 2011-11-11] (Norman ASA)
R2 nregsec; C:\Program Files\Norman\Ngs\Bin\nregsec64.sys [63032 2011-11-11] (Norman ASA)
R3 NvcMFlt; C:\Windows\System32\DRIVERS\nvcv64mf.sys [57952 2012-08-16] (Norman ASA)
R3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_ACCEL.sys [68208 2012-05-21] (STMicroelectronics)
R3 usb3Hub; C:\Windows\System32\DRIVERS\usb3Hub.sys [47072 2012-10-10] (Windows (R) Win 7 DDK provider)
R3 WwanUsbServ; C:\Windows\System32\DRIVERS\WwanUsbMp64.sys [281840 2013-02-19] (Ericsson AB)
R3 XHCIPort; C:\Windows\System32\DRIVERS\XHCIPort.sys [188896 2012-10-10] (Windows (R) Win 7 DDK provider)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-10 23:50 - 2013-09-10 23:50 - 00891144 _____ C:\Users\****\Desktop\SecurityCheck.exe
2013-09-10 23:46 - 2013-09-10 23:46 - 00000000 ____D C:\Program Files (x86)\ESET
2013-09-10 23:45 - 2013-09-10 23:45 - 02347384 _____ (ESET) C:\Users\****\Desktop\esetsmartinstaller_enu.exe
2013-09-10 20:03 - 2013-09-10 20:04 - 00000000 ____D C:\Users\****\Desktop\Treiber U-Book
2013-09-10 19:39 - 2013-09-10 19:39 - 00002539 _____ C:\Users\****\Desktop\Windows 7 USB DVD Download Tool.lnk
2013-09-10 19:39 - 2013-09-10 19:39 - 00000000 ____D C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
2013-09-10 19:39 - 2013-09-10 19:39 - 00000000 ____D C:\Users\****\AppData\Local\Apps\Windows 7 USB DVD Download Tool
2013-09-10 19:38 - 2013-09-10 19:38 - 02721168 _____ (Microsoft Corporation) C:\Users\****\Desktop\Windows7-USB-DVD1024-tool.exe
2013-09-10 17:33 - 2013-09-10 17:34 - 00000000 ____D C:\Users\****\Desktop\Säubern
2013-09-10 17:25 - 2013-09-10 17:25 - 00000000 ____D C:\FRST
2013-09-10 17:18 - 2013-09-10 17:18 - 00000944 _____ C:\Users\****\Desktop\AdwCleaner[S0]_umbenannt.txt
2013-09-10 17:07 - 2013-09-10 17:08 - 00000000 ____D C:\AdwCleaner
2013-09-10 17:05 - 2013-09-10 17:05 - 01949196 _____ (Farbar) C:\Users\****\Desktop\FRST64.exe
2013-09-10 17:03 - 2013-09-10 17:03 - 01037278 _____ C:\Users\****\Desktop\adwcleaner.exe
2013-09-10 17:03 - 2013-09-10 17:03 - 01029490 _____ (Thisisu) C:\Users\****\Desktop\JRT.exe
2013-09-09 15:49 - 2013-09-09 15:49 - 00000000 ____D C:\Users\****\Desktop\1
2013-09-09 12:11 - 2013-09-09 12:17 - 63621309 _____ C:\Users\****\Desktop\PartCostModel.zip
2013-09-09 09:01 - 2013-09-09 09:01 - 00035322 _____ C:\ComboFix.txt
2013-09-09 08:44 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-09-09 08:44 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-09-09 08:44 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-09-09 08:44 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-09-09 08:44 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-09-09 08:44 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-09-09 08:44 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-09-09 08:44 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-09-09 08:43 - 2013-09-09 09:01 - 00000000 ____D C:\Qoobox
2013-09-09 08:43 - 2013-09-09 09:00 - 00000000 ____D C:\Windows\erdnt
2013-09-09 08:42 - 2013-09-09 08:42 - 05124111 ____R (Swearware) C:\Users\****\Desktop\ComboFix.exe
2013-09-06 08:34 - 2013-09-06 08:34 - 00049152 _____ C:\Users\****\Desktop\130904_Arbeitsplan.xlsx
2013-09-05 17:14 - 2013-09-05 17:14 - 00023421 _____ C:\Users\****\Desktop\PPE-trocken.ogw
2013-09-05 17:14 - 2013-09-05 17:14 - 00009365 _____ C:\Users\****\Desktop\PPE-feucht.ogw
2013-09-05 09:00 - 2013-09-05 09:04 - 11970607 _____ C:\Users\****\Desktop\130904_SIM_Kriechversuche.opj
2013-09-04 21:16 - 2013-09-04 21:18 - 00000000 ____D C:\Users\****\AppData\Roaming\IrfanView
2013-08-29 10:11 - 2013-08-29 11:38 - 00000000 ____D C:\Users\****\Desktop\DMA PUR
2013-08-28 08:53 - 2013-09-09 08:49 - 00000000 ____D C:\Program Files (x86)\Web Check
2013-08-28 08:33 - 2013-08-28 08:33 - 00000000 ____D C:\Windows\system32\appmgmt
2013-08-27 20:09 - 2013-08-27 20:09 - 00000000 ____D C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2013-08-27 15:40 - 2013-08-27 15:40 - 00000000 ____D C:\Users\****\AppData\Roaming\e-academy Inc
2013-08-27 15:40 - 2013-08-27 15:40 - 00000000 ____D C:\Users\****\AppData\Local\e-academy Inc
2013-08-27 08:12 - 2013-08-27 08:12 - 00000000 ____D C:\Program Files (x86)\Dell Digital Delivery
2013-08-20 14:02 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-20 14:02 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-20 14:02 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-20 14:02 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-20 14:02 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-20 14:02 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-20 14:02 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-20 14:02 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-20 14:02 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-20 14:02 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-20 14:02 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-20 13:23 - 2013-08-20 13:23 - 00000000 ____D C:\Users\****\AppData\Roaming\2BrightSparks
2013-08-20 13:23 - 2013-08-20 13:23 - 00000000 ____D C:\Users\****\AppData\Local\2BrightSparks
2013-08-20 11:05 - 2013-08-20 11:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-19 14:56 - 2013-08-19 14:56 - 00000000 ____D C:\Program Files (x86)\CES EduPack 2013
2013-08-18 17:57 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-18 17:57 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-18 17:57 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-18 17:57 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-18 17:57 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-18 17:57 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-18 17:57 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-18 17:57 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-18 17:57 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-18 17:57 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-18 17:57 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-18 17:57 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-18 17:57 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-18 17:57 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-18 17:57 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-18 17:57 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-18 17:57 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-18 17:57 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-18 17:57 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-18 17:57 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-18 17:57 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-18 17:57 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-18 17:57 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-18 17:57 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-18 17:57 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-18 17:57 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-18 17:57 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-18 17:57 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-18 17:57 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-18 17:57 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-18 17:57 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-18 14:32 - 2013-08-18 14:32 - 00000000 ____D C:\Program Files (x86)\2BrightSparks
2013-08-18 13:18 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-18 13:18 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-18 13:18 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-18 13:18 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-18 13:18 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-18 13:18 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-18 13:18 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-18 13:18 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-18 13:18 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-18 13:18 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-18 13:17 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-18 13:17 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-18 13:17 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-18 13:17 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-18 13:17 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-18 13:17 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-18 13:05 - 2013-08-18 13:05 - 00000000 ____D C:\Users\****\AVM_Driver
2013-08-18 12:55 - 2013-08-18 12:55 - 00000000 ____D C:\Users\****\Documents\Bluetooth-Exchange-Ordner
2013-08-18 12:55 - 2013-08-18 12:55 - 00000000 ____D C:\Users\****\AppData\Local\Broadcom
2013-08-12 15:01 - 2013-09-10 23:42 - 00018814 _____ C:\SUService.log
2013-08-12 15:01 - 2013-08-20 11:06 - 00000000 ____D C:\Notes
2013-08-12 14:58 - 2013-08-12 14:58 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
==================== One Month Modified Files and Folders =======
2013-09-11 08:24 - 2013-07-02 05:31 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-11 08:24 - 2010-11-21 08:50 - 00696870 _____ C:\Windows\system32\perfh007.dat
2013-09-11 08:24 - 2010-11-21 08:50 - 00148134 _____ C:\Windows\system32\perfc007.dat
2013-09-11 08:24 - 2009-07-14 07:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-11 08:23 - 2013-09-11 08:23 - 00000000 ____D C:\Users\****\AppData\Roaming\smkits
2013-09-11 08:20 - 2013-07-02 05:29 - 01352533 _____ C:\Windows\WindowsUpdate.log
2013-09-10 23:50 - 2013-09-10 23:50 - 00891144 _____ C:\Users\****\Desktop\SecurityCheck.exe
2013-09-10 23:49 - 2009-07-14 06:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-10 23:49 - 2009-07-14 06:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-10 23:46 - 2013-09-10 23:46 - 00000000 ____D C:\Program Files (x86)\ESET
2013-09-10 23:45 - 2013-09-10 23:45 - 02347384 _____ (ESET) C:\Users\****\Desktop\esetsmartinstaller_enu.exe
2013-09-10 23:42 - 2013-08-12 15:01 - 00018814 _____ C:\SUService.log
2013-09-10 23:42 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-10 23:42 - 2009-07-14 06:51 - 00049522 _____ C:\Windows\setupact.log
2013-09-10 20:04 - 2013-09-10 20:03 - 00000000 ____D C:\Users\****\Desktop\Treiber U-Book
2013-09-10 19:39 - 2013-09-10 19:39 - 00002539 _____ C:\Users\****\Desktop\Windows 7 USB DVD Download Tool.lnk
2013-09-10 19:39 - 2013-09-10 19:39 - 00000000 ____D C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
2013-09-10 19:39 - 2013-09-10 19:39 - 00000000 ____D C:\Users\****\AppData\Local\Apps\Windows 7 USB DVD Download Tool
2013-09-10 19:38 - 2013-09-10 19:38 - 02721168 _____ (Microsoft Corporation) C:\Users\****\Desktop\Windows7-USB-DVD1024-tool.exe
2013-09-10 17:34 - 2013-09-10 17:33 - 00000000 ____D C:\Users\****\Desktop\Säubern
2013-09-10 17:25 - 2013-09-10 17:25 - 00000000 ____D C:\FRST
2013-09-10 17:18 - 2013-09-10 17:18 - 00000944 _____ C:\Users\****\Desktop\AdwCleaner[S0]_umbenannt.txt
2013-09-10 17:08 - 2013-09-10 17:07 - 00000000 ____D C:\AdwCleaner
2013-09-10 17:05 - 2013-09-10 17:05 - 01949196 _____ (Farbar) C:\Users\****\Desktop\FRST64.exe
2013-09-10 17:03 - 2013-09-10 17:03 - 01037278 _____ C:\Users\****\Desktop\adwcleaner.exe
2013-09-10 17:03 - 2013-09-10 17:03 - 01029490 _____ (Thisisu) C:\Users\****\Desktop\JRT.exe
2013-09-09 15:49 - 2013-09-09 15:49 - 00000000 ____D C:\Users\****\Desktop\1
2013-09-09 12:17 - 2013-09-09 12:11 - 63621309 _____ C:\Users\****\Desktop\PartCostModel.zip
2013-09-09 09:01 - 2013-09-09 09:01 - 00035322 _____ C:\ComboFix.txt
2013-09-09 09:01 - 2013-09-09 08:43 - 00000000 ____D C:\Qoobox
2013-09-09 09:01 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-09-09 09:00 - 2013-09-09 08:43 - 00000000 ____D C:\Windows\erdnt
2013-09-09 08:57 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-09-09 08:50 - 2010-11-21 05:47 - 00028268 _____ C:\Windows\PFRO.log
2013-09-09 08:49 - 2013-08-28 08:53 - 00000000 ____D C:\Program Files (x86)\Web Check
2013-09-09 08:42 - 2013-09-09 08:42 - 05124111 ____R (Swearware) C:\Users\****\Desktop\ComboFix.exe
2013-09-06 10:47 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-06 08:34 - 2013-09-06 08:34 - 00049152 _____ C:\Users\****\Desktop\130904_Arbeitsplan.xlsx
2013-09-05 17:14 - 2013-09-05 17:14 - 00023421 _____ C:\Users\****\Desktop\PPE-trocken.ogw
2013-09-05 17:14 - 2013-09-05 17:14 - 00009365 _____ C:\Users\****\Desktop\PPE-feucht.ogw
2013-09-05 09:04 - 2013-09-05 09:00 - 11970607 _____ C:\Users\****\Desktop\130904_SIM_Kriechversuche.opj
2013-09-04 21:18 - 2013-09-04 21:16 - 00000000 ____D C:\Users\****\AppData\Roaming\IrfanView
2013-08-29 11:38 - 2013-08-29 10:11 - 00000000 ____D C:\Users\****\Desktop\DMA PUR
2013-08-28 10:42 - 2013-08-09 08:19 - 00000000 ____D C:\Users\****\AppData\Roaming\Swiss Academic Software
2013-08-28 09:43 - 2013-07-30 15:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-28 08:33 - 2013-08-28 08:33 - 00000000 ____D C:\Windows\system32\appmgmt
2013-08-27 20:09 - 2013-08-27 20:09 - 00000000 ____D C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2013-08-27 15:40 - 2013-08-27 15:40 - 00000000 ____D C:\Users\****\AppData\Roaming\e-academy Inc
2013-08-27 15:40 - 2013-08-27 15:40 - 00000000 ____D C:\Users\****\AppData\Local\e-academy Inc
2013-08-27 08:12 - 2013-08-27 08:12 - 00000000 ____D C:\Program Files (x86)\Dell Digital Delivery
2013-08-22 09:38 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-20 14:01 - 2013-08-09 12:12 - 00000000 ____D C:\Users\****
2013-08-20 13:23 - 2013-08-20 13:23 - 00000000 ____D C:\Users\****\AppData\Roaming\2BrightSparks
2013-08-20 13:23 - 2013-08-20 13:23 - 00000000 ____D C:\Users\****\AppData\Local\2BrightSparks
2013-08-20 11:07 - 2013-07-30 15:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-20 11:06 - 2013-08-12 15:01 - 00000000 ____D C:\Notes
2013-08-20 11:05 - 2013-08-20 11:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-19 14:56 - 2013-08-19 14:56 - 00000000 ____D C:\Program Files (x86)\CES EduPack 2013
2013-08-18 17:55 - 2013-07-31 14:27 - 00000000 ____D C:\Windows\system32\MRT
2013-08-18 17:53 - 2013-07-31 14:05 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-18 14:32 - 2013-08-18 14:32 - 00000000 ____D C:\Program Files (x86)\2BrightSparks
2013-08-18 13:14 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-08-18 13:05 - 2013-08-18 13:05 - 00000000 ____D C:\Users\****\AVM_Driver
2013-08-18 13:05 - 2013-08-09 08:03 - 00000000 ____D C:\Users\****
2013-08-18 12:55 - 2013-08-18 12:55 - 00000000 ____D C:\Users\****\Documents\Bluetooth-Exchange-Ordner
2013-08-18 12:55 - 2013-08-18 12:55 - 00000000 ____D C:\Users\****\AppData\Local\Broadcom
2013-08-12 14:58 - 2013-08-12 14:58 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-09-2013 01
Ran by **** at 2013-09-11 08:50:00
Running from C:\Users\****\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03)
CES EduPack 2013 (x32 Version: 1.1.0.0)
Cisco Systems VPN Client 5.0.07.0290 (Version: 5.0.7)
Citavi (x32 Version: 3.4.0.2)
Custom (Version: 01.00.00.002)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
Dell Backup and Recovery Manager (Version: 1.3.1)
Dell Client System Update (x32 Version: 1.3.0)
Dell Data Protection | Access (Version: 2.3.00001.021)
Dell Digital Delivery (x32 Version: 2.7.1000.0)
Dell Edoc Viewer (Version: 1.0.0)
Dell Feature Enhancement Pack (Version: 2.2.1)
Dell Mobile Broadband Manager (x32 Version: 7.1.0.2)
Dell Touchpad (Version: 8.1200.101.124)
Dell Wireless HSPA Mini-Card Drivers (x32 Version: 7.2.5.4)
DellAccess (Version: 01.03.00.046)
EMBASSY Client Core (Version: 01.03.00.092)
ERAS Connector (Version: 02.09.05.0330)
ESET Online Scanner v3 (x32)
Fotogalerie (x32 Version: 16.4.3505.0912)
Gemalto (Version: 01.64.01.0010)
GemPcCCID (Version: 2.0.1)
Intel PROSet Wireless
Intel(R) Control Center (x32 Version: 1.2.1.1008)
Intel(R) Management Engine Components (x32 Version: 8.1.20.1337)
Intel(R) Network Connections 16.8.45.00 (Version: 16.8.45.00)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2639)
Intel(R) Rapid Storage Technology (x32 Version: 11.2.0.1006)
Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.7.248)
Intel(R) WiDi (Version: 3.5.40.0)
Intel(R) Wireless Display
Intel® PROSet/Wireless WiFi-Software (Version: 15.03.1000.1637)
Intel® Trusted Connect Service Client (Version: 1.26.242.3)
IrfanView (remove only) (x32 Version: 4.36)
Java 7 Update 25 (64-bit) (Version: 7.0.250)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Junk Mail filter update (x32 Version: 16.4.3505.0912)
Lotus Notes 8.5.3 (Basic) de (x32 Version: 8.53.11287)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft ReportViewer 2010 SP1 Redistributable (KB2549864) (x32 Version: 10.0.40220)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Movie Maker (x32 Version: 16.4.3505.0912)
Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1)
Mozilla Maintenance Service (x32 Version: 23.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Norman Security Suite (Version: 7.30.0400)
Origin90 (x32 Version: 9.00.00)
PBA Driver (Version: 1.0.1.7)
PDF24 Creator 5.4.0 (x32)
Photo Gallery (x32 Version: 16.4.3505.0912)
Preboot Manager (Version: 03.05.00.026)
Private Information Manager (Version: 07.03.00.016)
rosoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition
SI TSS (Version: 2.1.41)
SPBA (WBF) 5.9 (Version: 5.9.7.7232)
ST Microelectronics 3 Axis Digital Accelerometer Solution (x32 Version: 4.10.0036)
SyncBackFree (x32 Version: 6.5.4.0)
toolkit32for64bit (x32 Version: 7.68.85.0013)
Trusted Drive Manager (Version: 5.0.0.304)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition
VLC media player 2.0.7 (x32 Version: 2.0.7)
Wave Crypto Runtime 2.0.9.0 x64 (Version: 02.00.09.0000)
Wave Crypto Runtime 2.0.9.0 x86 (x32 Version: 02.00.09.0000)
Wave Infrastructure Installer (Version: 07.68.85.0014)
Wave Support Software Installer (Version: 05.15.00.021)
Web Check (x32)
WIDCOMM Bluetooth Software (Version: 6.5.1.2410)
Windows 7 USB/DVD Download Tool (x32 Version: 1.0.30)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912)
Windows Live Essentials (x32 Version: 16.4.3505.0912)
Windows Live Family Safety (Version: 16.4.3505.0912)
Windows Live Family Safety (x32 Version: 16.4.3505.0912)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (x32 Version: 16.4.3505.0912)
Windows Live Mail (x32 Version: 16.4.3505.0912)
Windows Live MIME IFilter (Version: 16.4.3505.0912)
Windows Live Photo Common (x32 Version: 16.4.3505.0912)
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912)
Windows Live SOXE (x32 Version: 16.4.3505.0912)
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912)
Windows Live UX Platform (x32 Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912)
Windows Live Writer (x32 Version: 16.4.3505.0912)
Windows Live Writer Resources (x32 Version: 16.4.3505.0912)
==================== Restore Points =========================
Could not list Restore Points.
==================== Hosts content: ==========================
2009-07-14 04:34 - 2013-09-09 08:57 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ?
==================== Loaded Modules (whitelisted) =============
2009-07-14 02:18 - 2009-07-14 03:38 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\imaadp32.acm
2009-07-14 02:18 - 2009-07-14 03:38 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\msg711.acm
2009-07-14 02:18 - 2009-07-14 03:38 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\msgsm32.acm
2009-07-14 02:18 - 2009-07-14 03:38 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\msadp32.acm
2009-07-14 02:22 - 2009-07-14 03:38 - 00081408 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\System32\l3codeca.acm
2012-11-09 06:39 - 2012-11-09 06:39 - 00135584 _____ (Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll
2013-04-04 01:09 - 2013-04-04 01:09 - 04300432 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2013-07-02 07:11 - 2012-05-18 05:38 - 00113048 _____ (Alps Electric Co., Ltd.) C:\Windows\system32\Vxdif.dll
2013-07-02 07:11 - 2013-02-05 12:59 - 00674304 ____N (IDT, Inc.) C:\Windows\system32\stapi64.dll
2013-07-02 07:12 - 2012-02-01 20:41 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrDEU.lrc
2013-07-02 07:11 - 2012-02-01 20:34 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-08-23 23:03 - 2012-08-23 23:03 - 00174896 _____ (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\PsRegApi.dll
2012-08-28 22:34 - 2012-08-28 22:34 - 00196912 _____ (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\LangResources\DEU\FrWrkDEU.dll
2012-08-23 23:03 - 2012-08-23 23:03 - 05670704 _____ (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\FrameworkPlugins\ConnMgr.dll
2012-08-28 22:34 - 2012-08-28 22:34 - 00682800 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\LangResources\DEU\IntWADEU.dll
2012-08-23 23:03 - 2012-08-23 23:03 - 00299312 _____ (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\TraceAPI.DLL
2012-08-23 23:04 - 2012-08-23 23:04 - 00555312 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\MurocApi.dll
2012-08-23 23:04 - 2012-08-23 23:04 - 00111920 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\IntStngs.dll
2012-08-23 23:04 - 2012-08-23 23:04 - 00027952 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\S24MUDLL.dll
2012-08-23 23:04 - 2012-08-23 23:04 - 01058608 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\PfMgrApi.dll
2012-08-23 23:03 - 2012-08-23 23:03 - 00109360 _____ (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\DbEngine.dll
2013-07-02 07:08 - 2011-03-08 23:52 - 00073728 _____ (Dell Computer Corporation) C:\dell\DBRM\Reminder\de\DBRM_Toaster.resources.dll
2013-07-02 07:08 - 2011-03-08 23:52 - 00180224 _____ (Dell Computer Corporation) C:\dell\DBRM\Reminder\de-DE\DBRM_Toaster.resources.dll
2009-07-14 02:09 - 2009-07-14 03:38 - 00425984 _____ (Microsoft Corporation) C:\Windows\system32\irprops.cpl
2012-08-15 23:28 - 2012-08-15 23:28 - 02503736 _____ (Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DellFrameworkLibrary.dll
2012-08-15 23:34 - 2012-08-15 23:34 - 02252856 _____ (Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DellSmartSettingsSys.dll
2012-08-15 23:34 - 2012-08-15 23:34 - 00250936 _____ (Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DellSmartSettingsExt.dll
2013-07-02 07:11 - 2012-05-18 05:38 - 00113048 _____ (Alps Electric Co., Ltd.) C:\Windows\system32\VXDIF.DLL
==================== Alternate Data Streams (whitelisted) ==========
==================== Faulty Device Manager Devices =============
Name: Cisco Systems VPN Adapter for 64-bit Windows
Description: Cisco Systems VPN Adapter for 64-bit Windows
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: CVirtA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (09/10/2013 11:46:29 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (09/10/2013 11:46:09 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (09/10/2013 11:46:09 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (09/10/2013 11:45:38 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (09/10/2013 11:45:37 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (09/10/2013 11:42:22 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/10/2013 07:32:38 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/10/2013 05:09:44 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/10/2013 08:26:17 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/09/2013 03:39:44 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: DllHost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bca54
Name des fehlerhaften Moduls: igdumd64.dll, Version: 8.15.10.2639, Zeitstempel: 0x4f29a5e5
Ausnahmecode: 0xc000041d
Fehleroffset: 0x000000000030e0b6
ID des fehlerhaften Prozesses: 0x126c
Startzeit der fehlerhaften Anwendung: 0xDllHost.exe0
Pfad der fehlerhaften Anwendung: DllHost.exe1
Pfad des fehlerhaften Moduls: DllHost.exe2
Berichtskennung: DllHost.exe3
System errors:
=============
Error: (09/10/2013 11:42:19 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WvPCR" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%0
Error: (09/10/2013 11:42:19 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SI TSS v1.2.1.41 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%0
Error: (09/10/2013 07:32:18 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WvPCR" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%0
Error: (09/10/2013 07:32:18 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SI TSS v1.2.1.41 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%0
Error: (09/10/2013 05:09:42 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WvPCR" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%0
Error: (09/10/2013 05:09:42 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SI TSS v1.2.1.41 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%0
Error: (09/10/2013 08:26:16 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "System Store" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (09/10/2013 08:26:16 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WvPCR" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%0
Error: (09/10/2013 08:26:16 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SI TSS v1.2.1.41 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%0
Error: (09/09/2013 09:04:30 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "System Store" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Microsoft Office Sessions:
=========================
Error: (09/10/2013 11:46:29 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\****\Desktop\esetsmartinstaller_enu.exe
Error: (09/10/2013 11:46:09 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\****\Desktop\esetsmartinstaller_enu.exe
Error: (09/10/2013 11:46:09 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\****\Desktop\esetsmartinstaller_enu.exe
Error: (09/10/2013 11:45:38 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\****\Desktop\esetsmartinstaller_enu.exe
Error: (09/10/2013 11:45:37 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\****\Desktop\esetsmartinstaller_enu.exe
Error: (09/10/2013 11:42:22 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/10/2013 07:32:38 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/10/2013 05:09:44 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/10/2013 08:26:17 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/09/2013 03:39:44 PM) (Source: Application Error)(User: )
Description: DllHost.exe6.1.7600.163854a5bca54igdumd64.dll8.15.10.26394f29a5e5c000041d000000000030e0b6126c01cead6206e5fc50C:\Windows\system32\DllHost.exeC:\Windows\system32\igdumd64.dll48a2c088-1955-11e3-8eb9-f01faf20aff0
CodeIntegrity Errors:
===================================
Date: 2013-09-09 08:49:32.346
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-09-09 08:49:32.314
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 31%
Total physical RAM: 8065.8 MB
Available physical RAM: 5525.59 MB
Total Pagefile: 16129.79 MB
Available Pagefile: 13237.64 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:150 GB) (Free:93.98 GB) NTFS
Drive d: (Daten) (Fixed) (Total:305.43 GB) (Free:271.24 GB) NTFS
Drive f: (Datentransfer) (Fixed) (Total:111.79 GB) (Free:53.07 GB) NTFS
==================== MBR & Partition Table ==================
==================== End Of Log ============================ Greetz
Hßbb3s |