hi, danke für deine schnelle antwort, hier die gewünschten Daten:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-12-2013 02
Ran by Maik (administrator) on MAIK-PC on 18-12-2013 09:05:21
Running from C:\Users\Maik\Desktop
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\core\mchost.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16613_none_6273bd8950d6cae2\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286192 2013-01-31] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe [899680 2013-02-04] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2013-03-05] (Conexant Systems, Inc.)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [RtsFT] - C:\Windows\RTFTrack.exe [6339656 2013-04-24] (Realtek semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3050736 2013-04-04] (Synaptics Incorporated)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17097200 2013-10-26] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [193008 2013-10-26] (Lenovo(beijing) Limited)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642816 2013-04-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [168464 2012-10-30] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] - C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-18] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\mcafee.com\agent\mcagent.exe [1527896 2012-06-21] (McAfee, Inc.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKU\Default\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe [52584 2013-05-15] (Lenovo)
HKU\Default User\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe [52584 2013-05-15] (Lenovo)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com/?pc=LCJB
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKLM - DefaultScope {D5D7DD23-CBE3-41F7-8C4C-596BFFF88AF2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LCJB
SearchScopes: HKLM - {D5D7DD23-CBE3-41F7-8C4C-596BFFF88AF2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LCJB
SearchScopes: HKLM-x32 - DefaultScope {D5D7DD23-CBE3-41F7-8C4C-596BFFF88AF2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LCJB
SearchScopes: HKLM-x32 - {D5D7DD23-CBE3-41F7-8C4C-596BFFF88AF2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LCJB
SearchScopes: HKCU - DefaultScope {D5D7DD23-CBE3-41F7-8C4C-596BFFF88AF2} URL =
SearchScopes: HKCU - {D5D7DD23-CBE3-41F7-8C4C-596BFFF88AF2} URL =
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
==================== Services (Whitelisted) =================
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-01-31] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-08-02] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)
S3 McAWFwk; C:\Program Files\mcafee\msc\McAWFwk.exe [332080 2012-01-26] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [383608 2012-05-22] (McAfee, Inc.)
R2 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [237920 2012-06-22] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218320 2012-06-22] (McAfee, Inc.)
R2 mfevtp; C:\WINDOWS\system32\mfevtps.exe [177144 2012-06-22] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-04-18] ()
R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2012-12-13] (Nitro PDF Software)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2013-10-26] ()
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-10-27] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3388144 2013-04-18] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-13] (Advanced Micro Devices, Inc.)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [132920 2013-04-23] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1385272 2013-04-23] (Motorola Solutions, Inc.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [69672 2012-06-22] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [169320 2012-06-22] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [300392 2012-06-22] (McAfee, Inc.)
U3 mfeavfk01; No ImagePath
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [66712 2012-06-18] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [513456 2012-06-22] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [752672 2012-06-22] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106112 2012-06-22] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [335784 2012-06-22] (McAfee, Inc.)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3341792 2013-04-25] (Intel Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8243144 2013-04-24] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2013-04-04] (Synaptics Incorporated)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
U3 kxloypoc; \??\C:\Users\Maik\AppData\Local\Temp\kxloypoc.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-18 09:05 - 2013-12-18 09:05 - 00011722 _____ C:\Users\Maik\Desktop\FRST.txt
2013-12-18 09:04 - 2013-12-18 09:04 - 00000000 ____D C:\FRST
2013-12-18 09:03 - 2013-12-18 09:03 - 01929376 _____ (Farbar) C:\Users\Maik\Desktop\FRST64.exe
2013-12-18 05:07 - 2013-12-18 05:07 - 00000000 _____ C:\Recovery.txt
2013-12-18 01:11 - 2013-12-18 01:11 - 449531245 _____ C:\WINDOWS\MEMORY.DMP
2013-12-18 01:11 - 2013-12-18 01:11 - 00000000 ____D C:\WINDOWS\Minidump
2013-12-18 01:03 - 2013-12-18 09:01 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-151516639-3704992375-3126064996-1001
2013-12-18 00:46 - 2013-12-18 00:46 - 00001219 _____ C:\Users\Maik\Desktop\gmer_2.1.19163.bat
2013-12-18 00:35 - 2013-12-18 01:20 - 00001293 _____ C:\Users\Maik\Desktop\gmer.log
2013-12-18 00:33 - 2013-12-18 00:33 - 00000000 ____D C:\Users\Maik\AppData\Roaming\ATI
2013-12-18 00:33 - 2013-12-18 00:33 - 00000000 ____D C:\Users\Maik\AppData\Local\ATI
2013-12-18 00:33 - 2013-12-18 00:33 - 00000000 ____D C:\ProgramData\ATI
2013-12-18 00:30 - 2013-12-18 00:30 - 00377856 _____ C:\Users\Maik\Desktop\gmer_2.1.19163.exe
2013-12-18 00:28 - 2013-12-18 01:28 - 00030826 _____ C:\Users\Public\CAFADEBUG.log
2013-12-17 19:31 - 2013-12-17 19:31 - 00000000 ____D C:\Users\Maik\AppData\Roaming\Intel Corporation
2013-12-17 19:30 - 2013-12-17 19:30 - 00000000 ____D C:\Users\Maik\AppData\Roaming\Lenovo
2013-12-17 19:29 - 2013-12-17 19:29 - 00001449 _____ C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-17 19:29 - 2013-12-17 19:29 - 00000139 _____ C:\Users\Public\Desktop\eBay.url
2013-12-17 19:29 - 2013-12-17 19:29 - 00000000 ___RD C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-17 19:29 - 2013-12-17 19:29 - 00000000 ___RD C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-12-17 19:29 - 2013-12-17 19:29 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2013-12-17 19:29 - 2013-12-17 19:29 - 00000000 ____D C:\Users\Maik\AppData\Roaming\Adobe
2013-12-17 19:29 - 2013-12-17 19:29 - 00000000 ____D C:\ProgramData\eBay
2013-12-17 19:28 - 2013-12-17 19:30 - 00001133 _____ C:\Users\Maik\Desktop\Cyberlink Power2Go.lnk
2013-12-17 19:28 - 2013-12-17 19:29 - 00000000 ____D C:\Users\Maik\AppData\Local\Packages
2013-12-17 19:28 - 2013-12-17 19:28 - 00000020 ___SH C:\Users\Maik\ntuser.ini
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Vorlagen
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Startmenü
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Netzwerkumgebung
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Lokale Einstellungen
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Eigene Dateien
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Druckumgebung
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Documents\Eigene Musik
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Documents\Eigene Bilder
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\AppData\Local\Verlauf
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\AppData\Local\Anwendungsdaten
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Anwendungsdaten
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 ____D C:\Users\Maik\AppData\Roaming\Intel
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 ____D C:\Users\Maik\AppData\Local\VirtualStore
2013-12-17 19:28 - 2013-10-27 05:21 - 00000000 ___RD C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-12-17 19:28 - 2013-10-27 05:18 - 00000000 ___RD C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-12-17 19:28 - 2013-10-26 20:10 - 00000000 ____D C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2013-12-17 19:28 - 2013-10-26 20:09 - 00000000 ____D C:\Users\Maik\AppData\Roaming\Macromedia
2013-12-17 19:28 - 2013-02-04 07:18 - 00000189 _____ C:\Users\Maik\Desktop\Lenovo Telephony Start Now.url
2013-12-17 19:28 - 2012-07-26 09:13 - 00000000 ___RD C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-12-17 19:28 - 2012-07-26 09:13 - 00000000 ____D C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-12-17 19:27 - 2013-12-17 19:29 - 00000000 ____D C:\Users\Maik
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Vorlagen
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Startmenü
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Programme
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\ProgramData\Vorlagen
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\ProgramData\Startmenü
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\ProgramData\Dokumente
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Dokumente und Einstellungen
==================== One Month Modified Files and Folders =======
2013-12-18 09:05 - 2013-12-18 09:05 - 00011722 _____ C:\Users\Maik\Desktop\FRST.txt
2013-12-18 09:05 - 2013-10-26 19:27 - 01129648 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-18 09:04 - 2013-12-18 09:04 - 00000000 ____D C:\FRST
2013-12-18 09:03 - 2013-12-18 09:03 - 01929376 _____ (Farbar) C:\Users\Maik\Desktop\FRST64.exe
2013-12-18 09:01 - 2013-12-18 01:03 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-151516639-3704992375-3126064996-1001
2013-12-18 09:01 - 2013-10-27 05:12 - 00754172 _____ C:\WINDOWS\system32\perfh007.dat
2013-12-18 09:01 - 2013-10-27 05:12 - 00156362 _____ C:\WINDOWS\system32\perfc007.dat
2013-12-18 09:01 - 2013-10-26 20:15 - 00001839 _____ C:\Users\Public\Desktop\McAfee Internet Security.lnk
2013-12-18 09:01 - 2012-07-26 08:28 - 01748838 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-12-18 09:00 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\system32\sru
2013-12-18 09:00 - 2012-07-26 06:26 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2013-12-18 05:07 - 2013-12-18 05:07 - 00000000 _____ C:\Recovery.txt
2013-12-18 05:07 - 2012-07-26 09:13 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template
2013-12-18 01:33 - 2012-07-26 08:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-18 01:28 - 2013-12-18 00:28 - 00030826 _____ C:\Users\Public\CAFADEBUG.log
2013-12-18 01:20 - 2013-12-18 00:35 - 00001293 _____ C:\Users\Maik\Desktop\gmer.log
2013-12-18 01:15 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\system32\NDF
2013-12-18 01:11 - 2013-12-18 01:11 - 449531245 _____ C:\WINDOWS\MEMORY.DMP
2013-12-18 01:11 - 2013-12-18 01:11 - 00000000 ____D C:\WINDOWS\Minidump
2013-12-18 00:46 - 2013-12-18 00:46 - 00001219 _____ C:\Users\Maik\Desktop\gmer_2.1.19163.bat
2013-12-18 00:43 - 2013-10-26 20:14 - 00000000 ____D C:\ProgramData\McAfee
2013-12-18 00:33 - 2013-12-18 00:33 - 00000000 ____D C:\Users\Maik\AppData\Roaming\ATI
2013-12-18 00:33 - 2013-12-18 00:33 - 00000000 ____D C:\Users\Maik\AppData\Local\ATI
2013-12-18 00:33 - 2013-12-18 00:33 - 00000000 ____D C:\ProgramData\ATI
2013-12-18 00:30 - 2013-12-18 00:30 - 00377856 _____ C:\Users\Maik\Desktop\gmer_2.1.19163.exe
2013-12-18 00:27 - 2013-10-26 20:14 - 00000000 ____D C:\Program Files (x86)\McAfee
2013-12-17 19:31 - 2013-12-17 19:31 - 00000000 ____D C:\Users\Maik\AppData\Roaming\Intel Corporation
2013-12-17 19:30 - 2013-12-17 19:30 - 00000000 ____D C:\Users\Maik\AppData\Roaming\Lenovo
2013-12-17 19:30 - 2013-12-17 19:28 - 00001133 _____ C:\Users\Maik\Desktop\Cyberlink Power2Go.lnk
2013-12-17 19:29 - 2013-12-17 19:29 - 00001449 _____ C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-17 19:29 - 2013-12-17 19:29 - 00000139 _____ C:\Users\Public\Desktop\eBay.url
2013-12-17 19:29 - 2013-12-17 19:29 - 00000000 ___RD C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-17 19:29 - 2013-12-17 19:29 - 00000000 ___RD C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-12-17 19:29 - 2013-12-17 19:29 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2013-12-17 19:29 - 2013-12-17 19:29 - 00000000 ____D C:\Users\Maik\AppData\Roaming\Adobe
2013-12-17 19:29 - 2013-12-17 19:29 - 00000000 ____D C:\ProgramData\eBay
2013-12-17 19:29 - 2013-12-17 19:28 - 00000000 ____D C:\Users\Maik\AppData\Local\Packages
2013-12-17 19:29 - 2013-12-17 19:27 - 00000000 ____D C:\Users\Maik
2013-12-17 19:29 - 2013-10-27 06:26 - 00094019 _____ C:\WINDOWS\modules.log
2013-12-17 19:28 - 2013-12-17 19:28 - 00000020 ___SH C:\Users\Maik\ntuser.ini
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Vorlagen
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Startmenü
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Netzwerkumgebung
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Lokale Einstellungen
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Eigene Dateien
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Druckumgebung
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Documents\Eigene Musik
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Documents\Eigene Bilder
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\AppData\Local\Verlauf
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\AppData\Local\Anwendungsdaten
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 _SHDL C:\Users\Maik\Anwendungsdaten
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 ____D C:\Users\Maik\AppData\Roaming\Intel
2013-12-17 19:28 - 2013-12-17 19:28 - 00000000 ____D C:\Users\Maik\AppData\Local\VirtualStore
2013-12-17 19:28 - 2012-07-26 09:12 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2013-12-17 19:28 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\WinStore
2013-12-17 19:10 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\rescache
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Vorlagen
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Startmenü
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Programme
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\ProgramData\Vorlagen
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\ProgramData\Startmenü
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\ProgramData\Dokumente
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2013-12-17 19:08 - 2013-12-17 19:08 - 00000000 _SHDL C:\Dokumente und Einstellungen
2013-12-17 19:08 - 2012-07-26 09:12 - 00000000 ____D C:\Program Files\Windows NT
2013-12-17 19:08 - 2012-07-26 06:37 - 00000000 ___HD C:\Users\Default
2013-12-17 19:07 - 2013-03-25 22:02 - 00004616 _____ C:\WINDOWS\PFRO.log
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-03-25 22:02
==================== End Of Log ============================ --- --- ---
--- --- ---
und weil ich mir nicht sicher war ob beide datensäzte reinpassen Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-12-2013 02
Ran by Maik at 2013-12-18 09:05:46
Running from C:\Users\Maik\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: McAfee Anti-Virus und Anti-Spyware (Disabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus und Anti-Spyware (Disabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}
==================== Installed Programs ======================
Adobe AIR (x32 Version: 3.4.0.2710)
AMD Accelerated Video Transcoding (Version: 12.10.100.30425)
AMD APP SDK Runtime (Version: 10.0.1124.2)
AMD Catalyst Install Manager (Version: 8.0.911.0)
Benutzerhandbuch (x32 Version: 1.0.0.15)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center (x32 Version: 2013.0425.225.2413)
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0425.225.2413)
Catalyst Control Center InstallProxy (x32 Version: 2013.0425.225.2413)
Catalyst Control Center Localization All (x32 Version: 2013.0425.225.2413)
Catalyst Control Center Profiles Mobile (x32 Version: 2013.0425.225.2413)
CCC Help Chinese Standard (x32 Version: 2013.0425.0224.2413)
CCC Help Chinese Traditional (x32 Version: 2013.0425.0224.2413)
CCC Help Czech (x32 Version: 2013.0425.0224.2413)
CCC Help Danish (x32 Version: 2013.0425.0224.2413)
CCC Help Dutch (x32 Version: 2013.0425.0224.2413)
CCC Help English (x32 Version: 2013.0425.0224.2413)
CCC Help Finnish (x32 Version: 2013.0425.0224.2413)
CCC Help French (x32 Version: 2013.0425.0224.2413)
CCC Help German (x32 Version: 2013.0425.0224.2413)
CCC Help Greek (x32 Version: 2013.0425.0224.2413)
CCC Help Hungarian (x32 Version: 2013.0425.0224.2413)
CCC Help Italian (x32 Version: 2013.0425.0224.2413)
CCC Help Japanese (x32 Version: 2013.0425.0224.2413)
CCC Help Korean (x32 Version: 2013.0425.0224.2413)
CCC Help Norwegian (x32 Version: 2013.0425.0224.2413)
CCC Help Polish (x32 Version: 2013.0425.0224.2413)
CCC Help Portuguese (x32 Version: 2013.0425.0224.2413)
CCC Help Russian (x32 Version: 2013.0425.0224.2413)
CCC Help Spanish (x32 Version: 2013.0425.0224.2413)
CCC Help Swedish (x32 Version: 2013.0425.0224.2413)
CCC Help Thai (x32 Version: 2013.0425.0224.2413)
CCC Help Turkish (x32 Version: 2013.0425.0224.2413)
ccc-utility64 (Version: 2013.0425.225.2413)
Conexant HD Audio (Version: 8.64.49.0)
Dolby Advanced Audio v2 (x32 Version: 7.2.8000.17)
Energy Management (x32 Version: 8.0.2.11)
Intel AppUp(SM) center (x32 Version: 3.6.1.33057.10)
Intel(R) Management Engine Components (x32 Version: 8.1.0.1281)
Intel(R) Processor Graphics (x32 Version: 9.17.10.3114)
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 15.8.0.0548)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 3.0.1327.1) (Version: 3.1.1307.0362)
Intel(R) PROSet/Wireless WiFi Software Driver (Version: 15.08.0000.0249)
Intel(R) Rapid Storage Technology (Version: 12.0.0.1083)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149)
Intel® PROSet/Wireless Software (x32 Version: 15.8.0)
Intel® PROSet/Wireless WiFi Software (Version: 15.08.0000.0172)
Intel® Trusted Connect Service Client (Version: 1.24.738.1)
Lenovo EasyCamera (x32 Version: 6.2.9200.10230)
Lenovo OneKey Recovery (Version: 8.0.0.1219)
Lenovo OneKey Recovery (x32 Version: 8.0.0.1219)
Lenovo Photos (x32 Version: 4.8.5)
Lenovo PowerDVD10 (x32 Version: 10.0.4331.52)
Lenovo Solution Center (Version: 2.1.002.00)
Lenovo VeriFace (Version: 5.0.13.5261)
Lenovo YouCam (x32 Version: 4.1.3423)
McAfee Internet Security (x32 Version: 11.6.385)
Microsoft Office (x32 Version: 15.0.4454.1510)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Nitro Pro 8 (Version: 8.0.10.7)
OEM Application Profile (x32 Version: 1.00.0000)
Power2Go (x32 Version: 5.6.0.9109)
PowerXpressHybrid (x32 Version: 1.00.0000)
PX Profile Update (x32 Version: 1.00.1.)
Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 2.1.0.16)
Realtek USB Card Reader (x32 Version: 6.2.9200.39041)
Shared C Run-time for x64 (Version: 10.0.0)
SugarSync Manager (x32 Version: 1.9.61.90905)
Synaptics Pointing Device Driver (Version: 16.5.2.0)
UserGuide (x32 Version: 1.0.0.15)
Windows-Treiberpaket - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (Version: 06/15/2012 8.1.0.1)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (Version: 06/19/2012 10.13.29.733)
==================== Restore Points =========================
==================== Hosts content: ==========================
2012-07-26 06:26 - 2012-07-26 06:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0143E0BF-4DA1-494A-B71E-1A4F3492BAFF} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Microsoft\Windows\OFFICEICON.vbs [2012-03-08] ()
Task: {154ED6CB-7411-41C5-891E-2E7BA5147FA3} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-05-15] ()
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2746672A-A0EA-4750-8234-82A33ADE417D} - System32\Tasks\Dolby Selector => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [2012-08-31] (Dolby Laboratories Inc.)
Task: {4A1AF8D0-7E91-4A44-8D4A-7066DEEBE1C0} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe [2013-05-15] (Lenovo)
Task: {5023BBAC-10DF-4455-B6AE-795CE7E80654} - System32\Tasks\Microsoft\WINRE\WinRE-Repair => C:\Windows\System32\ReAgentc.exe [2012-10-24] (Microsoft Corporation)
Task: {68D76E1D-DF05-41E8-A315-B533C2C6E729} - System32\Tasks\Lenovo\LSC\Time72Task => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe [2013-05-15] (Lenovo)
Task: {8842C160-0BA9-4367-9104-14EF08E35D6E} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2013-05-15] (Lenovo)
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {D876E4E8-A921-43F0-8D07-AED326D30736} - System32\Tasks\Lenovo\LSC\RebootCountTask => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe [2013-05-15] (Lenovo)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {F8E9F306-F34A-402E-A5B7-FB560F72E779} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup
==================== Loaded Modules (whitelisted) =============
2013-04-26 07:25 - 2013-04-18 00:59 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-10-26 19:41 - 2012-07-18 05:55 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (12/18/2013 00:28:41 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: ZeroConfigService.exe, Version: 15.8.0.0, Zeitstempel: 0x51709701
Name des fehlerhaften Moduls: MurocApi.dll, Version: 15.8.0.0, Zeitstempel: 0x5170961c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000026990
ID des fehlerhaften Prozesses: 0x74c
Startzeit der fehlerhaften Anwendung: 0xZeroConfigService.exe0
Pfad der fehlerhaften Anwendung: ZeroConfigService.exe1
Pfad des fehlerhaften Moduls: ZeroConfigService.exe2
Berichtskennung: ZeroConfigService.exe3
Vollständiger Name des fehlerhaften Pakets: ZeroConfigService.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ZeroConfigService.exe5
System errors:
=============
Error: (12/18/2013 01:33:13 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 18.12.2013 um 01:11:26 unerwartet heruntergefahren.
Error: (12/18/2013 01:11:29 AM) (Source: BugCheck) (User: )
Description: 0x00000109 (0xa3a039d89cf1a4e8, 0xb3b7465eef7151a4, 0xfffff803ad712080, 0x0000000000000002)C:\WINDOWS\MEMORY.DMP
Error: (12/18/2013 01:11:29 AM) (Source: BugCheck) (User: )
Description:
Error: (12/18/2013 01:11:26 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 18.12.2013 um 00:52:05 unerwartet heruntergefahren.
Error: (12/18/2013 00:29:03 AM) (Source: Service Control Manager) (User: )
Description: Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (12/18/2013 00:27:05 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 17.12.2013 um 19:26:35 unerwartet heruntergefahren.
Error: (12/18/2013 00:26:38 AM) (Source: Microsoft-Windows-Kernel-Boot) (User: NT-AUTORITÄT)
Description: 32212256841119104
Error: (12/17/2013 07:31:49 PM) (Source: DCOM) (User: Maik-Pc)
Description: Microsoft.WindowsLive.Platform.Service.RemoteProcess
Error: (12/17/2013 07:07:22 PM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.
Microsoft Office Sessions:
=========================
Error: (12/18/2013 00:28:41 AM) (Source: Application Error)(User: )
Description: ZeroConfigService.exe15.8.0.051709701MurocApi.dll15.8.0.05170961cc0000005000000000002699074c01cefb7f98aa31c5C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exeC:\Program Files\Intel\WiFi\bin\MurocApi.dllf63832a4-6772-11e3-be76-0cd2927a2db1
==================== Memory info ===========================
Percentage of memory in use: 29%
Total physical RAM: 3993.77 MB
Available physical RAM: 2804.06 MB
Total Pagefile: 8089.77 MB
Available Pagefile: 6477.91 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:891.91 GB) (Free:862.42 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:24.9 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 0F2F7574)
Partition: GPT Partition Type
==================== End Of Log ============================ |