08.03.2014 09:43

Win 7 Updates hängen UND Microsoft Security Essentials-Deinstallation/Installation stecken geblieben
Guten Morgen,

seit längerer Zeit versucht mein Windows 7 automatisch Updates einzuspielen und bricht das offensichtlich immer wieder ab. Ich habe ein Problem mit MSE angenommen und versucht, dies zu deinstallieren und wieder zu installieren, damit haben aber die Probleme erst richtig begonnen. Denn seither erhalte ich beim Start eine Fehlermeldung, dass Microsoft Security Essentials nicht starten konnte. Weder eine Deinstallation mit Unterstützung von Fixit noch eine Neuinstallation funktionieren. Eine im Internet gefundene Anleitung zur Registry-Bereinigung habe ich abgearbeitet, ohne Erfolg. In der Konsequenz ist mein Rechner jetzt offen und ungeschützt.

Ich füge die Logfiles an, die ich gem. Anleitung erstellt habe. Gmer ist allerdings nicht durchgelaufen, sondern Windows hat eine Meldung ausgegeben, dass das Programm "nicht mehr funktioniert". Es werde "aufgrund eines Problems geschlossen", ich würde eine Benachrichtigung erhalten, wenn eine Lösung verfügbar sei.

Falls das eine Rolle spielt: der Rechner steht inzwischen nicht mehr in Deutschland (wo es schon das Update-Problem gab), sondern ich habe ihn mit ins Ausland genommen, wo ich jetzt für einige Zeit arbeite.

Der im Addition-Log enthaltene Hinweis auf den Fehler "Objekt ist bereits vorhanden" ist aufgetreten, als ich ein Partyvideo, das mir ein Freund per wetransfer zur Verfügung gestellt hat und das ich für unvollständig benannt hielt, mit einer Dateiendung versehen wollte.

Vielen Dank im Vorhinein für die HIlfe!


Log created at 08:44 on 08/03/2014 (Konfiguration)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


FRST Logfile:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-03-2014 01
Ran by Konfiguration (administrator) on DESK on 08-03-2014 08:47:46
Running from C:\Users\Konfiguration\Downloads
Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe
(AMD) C:\Windows\system32\atieclxx.exe
() C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
( C:\Program Files\FreePDF_XP\fpassist.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieCtrl.exe
() C:\Users\Konfiguration\AppData\Local\Viber\Viber.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
() C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe
(Dropbox, Inc.) C:\Users\Konfiguration\AppData\Roaming\Dropbox\bin\Dropbox.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9288296 2010-06-14] (Realtek Semiconductor)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-10-01] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [FreePDF Assistant] - C:\Program Files\FreePDF_XP\fpassist.exe [370176 2010-06-17] (
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [HTC Sync Loader] - C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [651264 2012-04-17] ()
HKLM\...\Run: [CLMLServer] - "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
HKLM\...\Run: [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKU\S-1-5-21-1871391012-2986654079-385949586-1001\...\Run: [SandboxieControl] - C:\Program Files\Sandboxie\SbieCtrl.exe [452880 2012-04-10] (SANDBOXIE L.T.D)
HKU\S-1-5-21-1871391012-2986654079-385949586-1001\...\Run: [Viber] - C:\Users\Konfiguration\AppData\Local\Viber\Viber.exe [906240 2013-05-08] ()
HKU\S-1-5-21-1871391012-2986654079-385949586-1001\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20728480 2014-01-14] (Skype Technologies S.A.)
Startup: C:\Users\Konfiguration\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Konfiguration\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Konfiguration\AppData\Roaming\Mozilla\Firefox\Profiles\89e6vabj.default
FF Plugin: - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin: - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin:,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin:,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin:,version=1.0 - c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll No File
FF Plugin:,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin:,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin:,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin:,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: Update;version=3 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Update;version=9 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: CoolPreviews - C:\Users\Konfiguration\AppData\Roaming\Mozilla\Firefox\Profiles\89e6vabj.default\Extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}.xpi [2011-05-03]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-16]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-16]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-02-16]

CHR HomePage: hxxp://
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\32.0.1700.107\pdf.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\32.0.1700.107\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Windows Activation Technologies) - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
CHR Extension: (YouTube) - C:\Users\Konfiguration\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-04-18]
CHR Extension: (Google-Suche) - C:\Users\Konfiguration\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-04-18]
CHR Extension: (Foxtab Speed Dial) - C:\Users\Konfiguration\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchmpbaclbiioedakpcldenooikekokm [2014-01-28]
CHR Extension: (Google Wallet) - C:\Users\Konfiguration\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-08]
CHR Extension: (Google Mail) - C:\Users\Konfiguration\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-04-18]
CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\KONFIG~1\AppData\Local\foxtab_speeddial.crx [2014-01-28]
CHR HKCU\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\KONFIG~1\AppData\Local\foxtab_speeddial.crx [2014-01-28]

========================== Services (Whitelisted) =================

R2 ALDITALKVerbindungsassistent_Service; C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [358968 2013-07-27] ()
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [88576 2011-09-15] ()
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [74512 2012-04-10] (SANDBOXIE L.T.D)
S2 SystemStoreService; C:\Program Files\SoftwareUpdater\SystemStore.exe [297984 2014-03-08] ()
R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
S3 ehRecvr; %systemroot%\ehome\ehRecvr.exe [X]
S3 ehSched; %systemroot%\ehome\ehsched.exe [X]
S4 Mcx2Svc; %SystemRoot%\system32\Mcx2Svc.dll [X]
S2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [X]
S3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [X]
S2 TeamViewer6; C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe [X]
S2 WMPNetworkSvc; "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe" [X]

==================== Drivers (Whitelisted) ====================

R0 amd_sata; C:\Windows\System32\DRIVERS\amd_sata.sys [62592 2010-05-14] (Advanced Micro Devices)
R0 amd_xata; C:\Windows\System32\DRIVERS\amd_xata.sys [24192 2010-05-14] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW73.sys [102416 2010-09-24] (ATI Technologies, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [135440 2012-04-10] (SANDBOXIE L.T.D)
R3 teamviewervpn; C:\Windows\System32\DRIVERS\teamviewervpn.sys [25088 2011-03-30] (TeamViewer GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\KONFIG~1\AppData\Local\Temp\catchme.sys [X]
S1 MpKsl8fa421b6; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AACD575F-A75B-4CA2-90BC-96E9B9B9C18E}\MpKsl8fa421b6.sys [X]
S3 MpNWMon; system32\DRIVERS\MpNWMon.sys [X]
S1 truecrypt; System32\drivers\truecrypt.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-03-08 08:47 - 2014-03-08 08:47 - 00013691 _____ () C:\Users\Konfiguration\Downloads\FRST.txt
2014-03-08 08:47 - 2014-03-08 08:47 - 00000000 ____D () C:\FRST
2014-03-08 08:46 - 2014-03-08 08:47 - 01145344 _____ (Farbar) C:\Users\Konfiguration\Downloads\FRST.exe
2014-03-08 08:44 - 2014-03-08 08:45 - 00000488 _____ () C:\Users\Konfiguration\Downloads\defogger_disable.log
2014-03-08 08:44 - 2014-03-08 08:44 - 00050477 _____ () C:\Users\Konfiguration\Downloads\Defogger.exe
2014-03-07 18:44 - 2014-03-07 19:12 - 633931646 _____ () C:\Users\Konfiguration\Downloads\
2014-03-07 12:57 - 2014-03-07 12:57 - 126467774 ____N () C:\Users\Konfiguration\Desktop\IMG_2717.MOV
2014-03-01 08:56 - 2014-03-01 08:56 - 185108002 _____ () C:\Users\Konfiguration\Desktop\Sicherung.reg
2014-03-01 08:54 - 2014-03-01 08:54 - 00347816 _____ (Microsoft Corporation) C:\Users\Konfiguration\Downloads\MicrosoftFixit.wu.LB.54317087158150761.2.1.Run.exe
2014-03-01 08:50 - 2014-03-01 08:50 - 11157328 _____ (Microsoft Corporation) C:\Users\Konfiguration\Downloads\mseinstall(2).exe
2014-03-01 08:46 - 2014-03-01 08:46 - 00347816 _____ (Microsoft Corporation) C:\Users\Konfiguration\Downloads\MicrosoftFixit.ProgramInstallUninstall.RNP.54317087158150761.1.1.Run.exe
2014-02-25 01:12 - 2014-02-25 01:12 - 00000000 ____D () C:\ProgramData\Oracle
2014-02-25 01:10 - 2014-02-25 01:10 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-25 01:10 - 2014-02-25 01:10 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-25 01:10 - 2014-02-25 01:10 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-25 01:10 - 2014-02-25 01:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-02-25 01:10 - 2014-02-25 01:10 - 00000000 ____D () C:\Program Files\Java
2014-02-25 01:10 - 2014-02-25 01:10 - 00000000 _____ () C:\Windows\system32\RENC5E1.tmp
2014-02-25 01:10 - 2014-02-25 01:10 - 00000000 _____ () C:\Windows\system32\RENC5E0.tmp
2014-02-25 00:55 - 2014-02-25 00:55 - 00921000 _____ (Oracle Corporation) C:\Users\Konfiguration\Downloads\jxpiinstall(2).exe
2014-02-21 07:18 - 2014-02-21 07:18 - 00002579 _____ () C:\Users\Konfiguration\Desktop\msremoval.bat
2014-02-21 07:13 - 2014-02-21 07:13 - 00347816 _____ (Microsoft Corporation) C:\Users\Konfiguration\Downloads\MicrosoftFixit.ProgramInstallUninstall.RNP.5131639033939942.1.1.Run.exe
2014-02-19 20:37 - 2014-02-19 20:37 - 11157328 _____ (Microsoft Corporation) C:\Users\Konfiguration\Downloads\mseinstall(1).exe
2014-02-17 19:27 - 2014-02-17 19:27 - 00007139 _____ () C:\Users\Konfiguration\.recently-used.xbel
2014-02-17 19:00 - 2014-02-17 19:00 - 00240308 _____ () C:\Users\Konfiguration\Desktop\script.tif
2014-02-17 18:59 - 2014-02-17 18:59 - 00008738 _____ () C:\Users\Konfiguration\Desktop\script.xcf
2014-02-17 18:24 - 2014-02-17 18:24 - 00922524 _____ () C:\Users\Konfiguration\Desktop\OoGoodVibe.tif
2014-02-16 09:15 - 2014-02-16 09:15 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-15 06:07 - 2014-02-05 09:58 - 12345344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-15 06:07 - 2014-02-05 09:56 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-15 06:07 - 2014-02-05 09:53 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-15 06:07 - 2014-02-05 09:51 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-15 06:07 - 2014-02-05 09:50 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-15 06:07 - 2014-02-05 09:49 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-15 06:07 - 2014-02-05 09:49 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-02-15 06:07 - 2014-02-05 09:48 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-15 06:07 - 2014-02-05 09:48 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-02-15 06:07 - 2014-02-05 09:48 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-15 06:07 - 2014-02-05 09:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-15 06:07 - 2014-02-05 09:48 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-15 06:07 - 2014-02-05 09:47 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-15 06:07 - 2014-02-05 09:47 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-15 06:07 - 2014-02-05 09:47 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-02-15 06:07 - 2014-02-05 09:46 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-14 07:23 - 2014-02-14 07:23 - 00000000 ____D () C:\Users\Konfiguration\AppData\Local\{331EA07D-41B0-46A5-8D63-9D780496447B}
2014-02-14 07:18 - 2014-02-14 07:18 - 00000000 ____D () C:\Users\Konfiguration\AppData\Local\Apps\2.0

==================== One Month Modified Files and Folders =======

2014-03-08 08:47 - 2014-03-08 08:47 - 00013691 _____ () C:\Users\Konfiguration\Downloads\FRST.txt
2014-03-08 08:47 - 2014-03-08 08:47 - 00000000 ____D () C:\FRST
2014-03-08 08:47 - 2014-03-08 08:46 - 01145344 _____ (Farbar) C:\Users\Konfiguration\Downloads\FRST.exe
2014-03-08 08:45 - 2014-03-08 08:44 - 00000488 _____ () C:\Users\Konfiguration\Downloads\defogger_disable.log
2014-03-08 08:44 - 2014-03-08 08:44 - 00050477 _____ () C:\Users\Konfiguration\Downloads\Defogger.exe
2014-03-08 08:37 - 2014-01-21 16:12 - 00000000 ___RD () C:\Users\Konfiguration\Dropbox
2014-03-08 08:37 - 2014-01-21 16:10 - 00000000 ____D () C:\Users\Konfiguration\AppData\Roaming\Dropbox
2014-03-08 08:37 - 2013-11-05 09:11 - 00000000 ____D () C:\Users\Konfiguration\AppData\Roaming\Skype
2014-03-08 08:37 - 2013-06-17 23:06 - 00000000 ____D () C:\Users\Konfiguration\AppData\Roaming\ViberPC
2014-03-08 08:37 - 2013-06-17 23:05 - 00000000 ____D () C:\Users\Konfiguration\AppData\Local\Viber
2014-03-08 08:37 - 2012-04-18 16:23 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-08 08:37 - 2011-08-30 06:52 - 00000000 ____D () C:\Users\Konfiguration\AppData\Local\Htc
2014-03-08 08:37 - 2011-04-09 14:14 - 01771125 _____ () C:\Windows\WindowsUpdate.log
2014-03-08 08:37 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-03-08 08:35 - 2009-07-14 05:34 - 00010096 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-08 08:35 - 2009-07-14 05:34 - 00010096 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-08 08:28 - 2012-04-18 10:43 - 00067317 _____ () C:\Windows\setupact.log
2014-03-08 08:28 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-08 00:41 - 2011-05-06 12:43 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-08 00:06 - 2014-01-28 22:55 - 00000314 _____ () C:\Windows\Tasks\Digital Sites.job
2014-03-08 00:06 - 2014-01-28 22:55 - 00000176 _____ () C:\Users\Konfiguration\AppData\Roaming\WB.CFG
2014-03-07 23:56 - 2012-04-18 11:46 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-07 23:55 - 2014-01-28 22:55 - 00000310 _____ () C:\Windows\Tasks\FoxTab.job
2014-03-07 23:49 - 2012-04-18 16:23 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-07 19:12 - 2014-03-07 18:44 - 633931646 _____ () C:\Users\Konfiguration\Downloads\
2014-03-07 12:57 - 2014-03-07 12:57 - 126467774 ____N () C:\Users\Konfiguration\Desktop\IMG_2717.MOV
2014-03-03 23:39 - 2012-04-18 16:12 - 00003814 _____ () C:\Windows\Sandboxie.ini
2014-03-03 23:35 - 2011-05-17 20:18 - 00000000 ____D () C:\Users\Konfiguration\AppData\Local\FreePDF_XP
2014-03-01 09:35 - 2011-04-20 08:54 - 00002122 _____ () C:\Windows\epplauncher.mif
2014-03-01 08:56 - 2014-03-01 08:56 - 185108002 _____ () C:\Users\Konfiguration\Desktop\Sicherung.reg
2014-03-01 08:54 - 2014-03-01 08:54 - 00347816 _____ (Microsoft Corporation) C:\Users\Konfiguration\Downloads\MicrosoftFixit.wu.LB.54317087158150761.2.1.Run.exe
2014-03-01 08:50 - 2014-03-01 08:50 - 11157328 _____ (Microsoft Corporation) C:\Users\Konfiguration\Downloads\mseinstall(2).exe
2014-03-01 08:46 - 2014-03-01 08:46 - 00347816 _____ (Microsoft Corporation) C:\Users\Konfiguration\Downloads\MicrosoftFixit.ProgramInstallUninstall.RNP.54317087158150761.1.1.Run.exe
2014-02-26 05:02 - 2012-06-23 22:59 - 00000000 ____D () C:\Program Files\FK_Monitor
2014-02-26 01:45 - 2009-07-14 05:53 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-25 01:12 - 2014-02-25 01:12 - 00000000 ____D () C:\ProgramData\Oracle
2014-02-25 01:10 - 2014-02-25 01:10 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-25 01:10 - 2014-02-25 01:10 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-25 01:10 - 2014-02-25 01:10 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-25 01:10 - 2014-02-25 01:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-02-25 01:10 - 2014-02-25 01:10 - 00000000 ____D () C:\Program Files\Java
2014-02-25 01:10 - 2014-02-25 01:10 - 00000000 _____ () C:\Windows\system32\RENC5E1.tmp
2014-02-25 01:10 - 2014-02-25 01:10 - 00000000 _____ () C:\Windows\system32\RENC5E0.tmp
2014-02-25 00:55 - 2014-02-25 00:55 - 00921000 _____ (Oracle Corporation) C:\Users\Konfiguration\Downloads\jxpiinstall(2).exe
2014-02-21 07:18 - 2014-02-21 07:18 - 00002579 _____ () C:\Users\Konfiguration\Desktop\msremoval.bat
2014-02-21 07:13 - 2014-02-21 07:13 - 00347816 _____ (Microsoft Corporation) C:\Users\Konfiguration\Downloads\MicrosoftFixit.ProgramInstallUninstall.RNP.5131639033939942.1.1.Run.exe
2014-02-20 20:56 - 2012-04-18 11:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-02-20 20:56 - 2012-04-18 11:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-02-19 20:37 - 2014-02-19 20:37 - 11157328 _____ (Microsoft Corporation) C:\Users\Konfiguration\Downloads\mseinstall(1).exe
2014-02-18 07:42 - 2010-07-06 21:23 - 01760044 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-17 19:27 - 2014-02-17 19:27 - 00007139 _____ () C:\Users\Konfiguration\.recently-used.xbel
2014-02-17 19:27 - 2012-04-09 08:06 - 00000000 ____D () C:\Users\Konfiguration\.gimp-2.6
2014-02-17 19:27 - 2011-04-09 14:21 - 00000000 ____D () C:\Users\Konfiguration
2014-02-17 19:00 - 2014-02-17 19:00 - 00240308 _____ () C:\Users\Konfiguration\Desktop\script.tif
2014-02-17 19:00 - 2012-04-09 08:08 - 00000000 ____D () C:\Users\Konfiguration\AppData\Roaming\gtk-2.0
2014-02-17 18:59 - 2014-02-17 18:59 - 00008738 _____ () C:\Users\Konfiguration\Desktop\script.xcf
2014-02-17 18:24 - 2014-02-17 18:24 - 00922524 _____ () C:\Users\Konfiguration\Desktop\OoGoodVibe.tif
2014-02-17 17:39 - 2011-04-20 08:53 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-02-17 07:12 - 2012-04-27 00:35 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-16 09:15 - 2014-02-16 09:15 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-15 06:13 - 2013-08-06 17:14 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-15 06:12 - 2010-07-06 22:03 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-14 20:14 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-02-14 07:23 - 2014-02-14 07:23 - 00000000 ____D () C:\Users\Konfiguration\AppData\Local\{331EA07D-41B0-46A5-8D63-9D780496447B}
2014-02-14 07:18 - 2014-02-14 07:18 - 00000000 ____D () C:\Users\Konfiguration\AppData\Local\Apps\2.0
2014-02-06 19:07 - 2013-12-01 09:32 - 00000000 ____D () C:\Users\Konfiguration\AppData\Roaming\Canon
2014-02-06 11:14 - 2013-10-27 14:56 - 00000000 ____D () C:\Users\Konfiguration\Documents\Zeltinger Str

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2014-03-01 06:35

==================== End Of Log ============================

--- --- ---


Additional scan result of Farbar Recovery Scan Tool (x86) Version: 07-03-2014 01
Ran by Konfiguration at 2014-03-08 08:48:13
Running from C:\Users\Konfiguration\Downloads
Boot Mode: Normal

==================== Security Center ========================

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

7-Zip 9.20 (HKLM\...\7-Zip) (Version:  - ) (HKLM\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM\...\Adobe AIR) (Version: - Adobe Systems Inc.)
Adobe AIR (Version: - Adobe Systems Inc.) Hidden
Adobe AIR (Version: - Adobe Systems Incorporated) Hidden
Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated)
Adobe Reader X (10.0.1) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA0000000001}) (Version: 10.0.1 - Adobe Systems Incorporated)
Adobe Reader X (10.1.9) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.9 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.5 (HKLM\...\Adobe Shockwave Player) (Version: - Adobe Systems, Inc.)
ALDI TALK Verbindungsassistent (HKLM\...\ALDITALKVerbindungsassistent) (Version: ALDI TALK 4.0 - ALDI TALK Verbindungsassistent)
Any Video Converter 3.5.3 (HKLM\...\Any Video Converter_is1) (Version:  -
ATI Catalyst Install Manager (HKLM\...\{586647DB-C4AC-6691-FD95-9A1B3B603502}) (Version: 3.0.795.0 - ATI Technologies, Inc.)
Audiograbber 1.83 SE  (HKLM\...\Audiograbber) (Version: 1.83 SE  - Audiograbber)
Audiograbber MP3-Plugin (HKLM\...\Audiograbber-Lame) (Version: 1.0 - AG)
CanoScan Toolbox Ver4.1 (HKLM\...\{BCE46757-7674-4416-BEDB-68205A60409E}) (Version:  - )
Catalyst Control Center Graphics Previews Vista (Version: 2010.0930.2237.38732 - ATI) Hidden
Catalyst Control Center InstallProxy (Version: 2010.0930.2237.38732 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (Version: 2010.0930.2237.38732 - ATI) Hidden
CCC Help Danish (Version: 2010.0930.2236.38732 - ATI) Hidden
CCC Help Dutch (Version: 2010.0930.2236.38732 - ATI) Hidden
CCC Help English (Version: 2010.0930.2236.38732 - ATI) Hidden
CCC Help Finnish (Version: 2010.0930.2236.38732 - ATI) Hidden
CCC Help French (Version: 2010.0930.2236.38732 - ATI) Hidden
CCC Help German (Version: 2010.0930.2236.38732 - ATI) Hidden
CCC Help Italian (Version: 2010.0930.2236.38732 - ATI) Hidden
CCC Help Japanese (Version: 2010.0930.2236.38732 - ATI) Hidden
CCC Help Norwegian (Version: 2010.0930.2236.38732 - ATI) Hidden
CCC Help Spanish (Version: 2010.0930.2236.38732 - ATI) Hidden
CCC Help Swedish (Version: 2010.0930.2236.38732 - ATI) Hidden
ccc-core-static (Version: 2010.0930.2237.38732 - ATI) Hidden
ccc-utility (Version: 2010.0930.2237.38732 - ATI) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.05 - Piriform)
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation)
CorelDRAW Essentials 4 - Content (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Draw (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Filters (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - ICA (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - IPM - No VBA (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang BR (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang DE (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang EN (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang ES (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang FR (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang IT (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang NL (Version: 4.0 - Uw bedrijfsnaam) Hidden
CorelDRAW Essentials 4 - PHOTO-PAINT (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Windows Shell Extension (HKLM\...\_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}) (Version:  - Corel Corporation)
CorelDRAW Essentials 4 - Windows Shell Extension (Version: 1.1 - Corel Corporation) Hidden
CorelDRAW Essentials 4 (HKLM\...\_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}) (Version:  - Corel Corporation)
CorelDRAW Essentials 4 (Version: 4.0 - Corel Corporation) Hidden
CyberLink LabelPrint (HKLM\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2515 - CyberLink Corp.)
CyberLink LabelPrint (Version: 2.5.2515 - CyberLink Corp.) Hidden
CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.)
CyberLink Power2Go (Version: 6.1.3602c - CyberLink Corp.) Hidden
CyberLink PowerDVD Copy (HKLM\...\InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}) (Version: 1.5.1306 - CyberLink Corp.)
CyberLink PowerDVD Copy (Version: 1.5.1306 - CyberLink Corp.) Hidden
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Definition update for Microsoft Office 2010 (KB982726) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2FD3FD50-4D6B-433B-9AB8-83F04675DA44}) (Version:  - Microsoft)
Dropbox (HKCU\...\Dropbox) (Version: 2.6.2 - Dropbox, Inc.)
ElsterFormular (HKLM\...\ElsterFormular) (Version: 14.3.11574 - Landesfinanzdirektion Thüringen)
FileZilla Client (HKCU\...\FileZilla Client) (Version: - FileZilla Project)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM\...\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
Fotogalerija Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Foxtab (HKLM\...\foxtab) (Version:  - FoxTab) <==== ATTENTION
Free Video Dub version (HKLM\...\Free Video Dub_is1) (Version: - DVDVideoSoft Ltd.)
FreeOCR v4.2 (HKLM\...\freeocr_is1) (Version:  - )
FreePDF (Remove only) (HKLM\...\FreePDF_XP) (Version:  - )
Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gigaset QuickSync (HKLM\...\{2c2f4c57-83a8-4790-a281-e83d306a9199}) (Version: 6.1.0822.15063 - Gigaset Communications GmbH)
GIMP 2.6.12 (HKLM\...\WinGimp-2.0_is1) (Version: 2.6.12 - The GIMP Team)
Google Chrome (HKLM\...\Google Chrome) (Version: 33.0.1750.146 - Google Inc.)
Google Update Helper (Version: - Google Inc.) Hidden
GPL Ghostscript (HKLM\...\GPL Ghostscript) (Version: 9.02 - Artifex Software Inc.)
HTC BMP USB Driver (HKLM\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
HTC Driver Installer (HKLM\...\{6D6664A9-3342-4948-9B7E-034EFE366F0F}) (Version: - HTC Corporation)
HTC Sync (HKLM\...\{AB77DFDE-9949-4AEF-B180-BE322C3E65D0}) (Version: 3.2.20 - HTC Corporation)
Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (Version: - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 24 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216024FF}) (Version: 6.0.240 - Oracle)
JoGoVEREIN (HKLM\...\{B6A6D550-53E2-49F2-AB47-2EA3262B369D}) (Version: 9.2.5 - J.G. Software)
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (HKLM\...\{CA227A9D-09BE-4BFB-9764-48FED2DA5454}) (Version: 15.4.5722.2 - Microsoft Corporation)
Medion Home Cinema (HKLM\...\InstallShield_{AB770FDE-8087-4C98-9A85-BD64262C104C}) (Version: 6.0.0000 - CyberLink Corp.)
Medion Home Cinema (Version: 6.0.0000 - CyberLink Corp.) Hidden
Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Antimalware (Version: 3.0.8107.0 - Microsoft Corporation) Hidden
Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8107.0 - Microsoft Corporation) Hidden
Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook Connector (HKLM\...\{95140000-0081-0407-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 2.0.0657.0 - Microsoft Corporation) Hidden
Microsoft Security Client DE-DE Language Pack (Version: 2.0.0657.0 - Microsoft Corporation) Hidden
Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 27.0.1 (x86 de) (HKLM\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla)
MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
MyDriveConnect (HKLM\...\MyDriveConnect) (Version: - TomTom)
Oracle VM VirtualBox 4.0.4 (HKLM\...\{408CD2E8-3977-449B-8102-76F158D4885F}) (Version: 4.0.4 - Oracle Corporation)
PlayReady PC Runtime x86 (HKLM\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Poczta usługi Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pošta Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version:  - )
Sandboxie 3.68 (32-bit) (HKLM\...\Sandboxie) (Version: 3.68 - SANDBOXIE L.T.D)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version:  - Microsoft) Hidden
Skype™ 6.13 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.13.104 - Skype Technologies S.A.)
Speccy (HKLM\...\Speccy) (Version: 1.10 - Piriform)
Spelling Dictionaries Support For Adobe Reader 9 (HKLM\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
TeamViewer 6 (HKLM\...\TeamViewer 6) (Version: 6.0.10511 - TeamViewer GmbH)
TeamViewer 8 (HKLM\...\TeamViewer 8) (Version: 8.0.20202 - TeamViewer)
TrueCrypt (HKLM\...\TrueCrypt) (Version: 7.0a - TrueCrypt Foundation)
TubeBox (HKLM\...\{60597b3f-d714-4f4e-8094-be088a31ff25}) (Version: - Freetec)
TubeBox (Version: - Freetec) Hidden
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (HKLM\...\{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2473228) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2010 (KB2202188) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{86B7A074-265D-420C-9E1E-7A920EF0ECA7}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2413186) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{556146F7-74AE-4E0A-B64F-5B8B93469F61}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2413186) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B5516874-E926-4BFD-B412-D0E70112F244}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2413186) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D6CE7280-6EE3-419A-8F47-DB111C040B1B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{B5C70C99-B109-42FD-B219-FF12CA543F19}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2493983) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{309EEC22-83CE-4109-B019-BA9392FAA322}) (Version:  - Microsoft)
Update for Microsoft Outlook Social Connector (KB2441641) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{A10DC2B7-6FDA-4C17-9DF0-6A834CAC4306}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{81812245-FC84-426A-BC02-6659C88CC7B2}) (Version:  - Microsoft)
Update for Video Converter (HKCU\...\Digital Sites) (Version:  - Update for Video Converter) <==== ATTENTION
Update für Microsoft Outlook Social Connector (KB2441641) (HKLM\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{78E1D7DA-059C-4E8D-8FAD-0EFD5BFE6779}) (Version:  - Microsoft)
Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (HKLM\...\{241E7104-937A-4366-AD57-8FDDDB003939}) (Version: 15.4.5722.2 - Microsoft Corporation)
Versandhelfer (HKLM\...\dpdhl.versandhelfer.medionpc.CDA82DC3FEDD13302C6424313D9A2999F162D21A.1) (Version: 0.9.511 - Deutsche Post AG)
Versandhelfer (Version: 0.9.511 - Deutsche Post AG) Hidden
Viber (HKCU\...\Viber) (Version: - Viber Media Inc)
Video Converter (HKCU\...\Video Converter) (Version:  - )
Video Converter Packages (HKCU\...\Video Converter Packages) (Version:  - ) <==== ATTENTION
Visual Studio C++ 10.0 Runtime (HKLM\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotoğraf Galerisi (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotótár (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (HKLM\...\{57220148-3B2B-412A-A2E0-82B9DF423696}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (HKLM\...\{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Temel Parçalar (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: - Microsoft Corp)
Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Συλλογή φωτογραφιών του Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

==================== Restore Points  =========================

28-01-2014 22:15:22 TuneUp Utilities 2014 (de-DE) wird entfernt
28-01-2014 23:45:10 Windows Update
29-01-2014 20:43:59 Windows Update
29-01-2014 22:00:27 Windows Update
30-01-2014 12:22:14 Windows Update
31-01-2014 00:27:55 Windows Update
31-01-2014 09:05:20 Windows Update
31-01-2014 13:12:57 Windows Update
31-01-2014 18:11:40 Windows Update
01-02-2014 01:15:08 Windows Update
01-02-2014 10:13:33 Windows Update
01-02-2014 16:17:05 Windows Update
02-02-2014 18:03:34 Windows Modules Installer
02-02-2014 18:08:34 Windows Update
02-02-2014 20:41:44 Windows Update
06-02-2014 18:07:10 Windows Update
14-02-2014 18:11:10 Windows Modules Installer
14-02-2014 19:29:26 Windows Update
15-02-2014 05:05:11 Windows Update
16-02-2014 06:37:13 Windows Update
16-02-2014 09:20:14 Windows Update
16-02-2014 21:32:59 Windows Update
17-02-2014 06:38:29 Windows Update
17-02-2014 16:31:08 Windows Update
17-02-2014 22:21:40 Windows Update
18-02-2014 05:53:00 Windows Update
18-02-2014 06:12:22 Windows Update
18-02-2014 07:16:14 Windows Update
18-02-2014 17:36:55 Windows Update
19-02-2014 07:17:38 Windows Update
19-02-2014 16:50:39 Windows Update
19-02-2014 21:25:56 Windows Update
20-02-2014 00:55:29 Windows Update
20-02-2014 07:30:21 Windows Update
20-02-2014 22:35:07 Windows Update
21-02-2014 06:53:54 Windows Update
21-02-2014 13:28:35 Windows Update
23-02-2014 18:33:42 Windows Update
24-02-2014 04:17:55 Windows Update
24-02-2014 08:45:10 Windows Update
24-02-2014 20:17:15 Windows Update
25-02-2014 00:09:53 Installed Java 7 Update 51
25-02-2014 00:19:49 Windows Update
25-02-2014 07:26:51 Windows Update
26-02-2014 04:02:01 Windows Defender Checkpoint
26-02-2014 06:07:18 Windows Update
26-02-2014 19:48:33 Windows Update
27-02-2014 12:21:14 Windows Update
27-02-2014 23:49:23 Windows Update
28-02-2014 07:10:17 Windows Update
28-02-2014 18:57:23 Windows Update
01-03-2014 08:35:47 Windows Update
01-03-2014 23:08:16 Windows Update
02-03-2014 07:59:23 Windows Update
02-03-2014 22:10:08 Windows Update
03-03-2014 18:42:47 Windows Update
03-03-2014 19:02:48 Windows Update
03-03-2014 22:45:21 Windows Update
04-03-2014 05:33:07 Windows Update
04-03-2014 23:40:09 Windows Update
05-03-2014 06:44:16 Windows Update
06-03-2014 07:39:56 Windows Update
06-03-2014 15:35:42 Windows Update
07-03-2014 23:38:41 Windows Update

==================== Hosts content: ==========================

2009-07-14 03:04 - 2012-04-16 12:46 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts      localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {02A4927E-F99D-4F7A-B829-EF567F6D6D21} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {0579670C-53C2-4954-8DB1-598E6D33734B} - System32\Tasks\Software Updater => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe [2013-12-18] ()
Task: {0989A0F4-BEB2-4325-863F-76680E03DFBD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-18] (Google Inc.)
Task: {55684258-9A92-4DCE-B488-0CF3ABAEF3CE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-18] (Google Inc.)
Task: {7C601468-BCB5-4CD2-AC9D-5F96E38EFE9A} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {966E0B39-7D62-4DA8-AB76-7E380E140AC1} - System32\Tasks\FoxTab => C:\Users\Konfiguration\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {B8169D50-124F-44E4-8CE1-FCD50E0A3922} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-20] (Adobe Systems Incorporated)
Task: {C9DEBE93-DFFD-4C96-925C-5B2EE77651AB} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {CC90C593-8C3B-4616-B3DF-8963F1D39DC7} - System32\Tasks\Digital Sites => C:\Users\Konfiguration\AppData\Roaming\DigitalSites\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {F211C2E0-CF40-4653-83A4-F474545F8D4C} - System32\Tasks\Software Updater Ui => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe [2013-12-18] ()
Task: {FA8A40E0-41F2-4BC9-B9C5-02A9D02C828A} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2012-04-17] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Digital Sites.job => C:\Users\KONFIG~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\FoxTab.job => C:\Users\KONFIG~1\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-04-20 10:49 - 2010-06-17 20:56 - 00116224 _____ () C:\Windows\System32\redmonnt.dll
2013-07-27 13:54 - 2013-07-27 13:56 - 00358968 _____ () C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe
2011-09-15 12:06 - 2011-09-15 12:06 - 00088576 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
2012-11-29 22:59 - 2012-11-29 22:59 - 00093696 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2012-04-17 14:05 - 2012-04-17 14:05 - 00651264 _____ () C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
2012-04-17 14:05 - 2012-04-17 14:05 - 00103936 _____ () C:\Program Files\HTC\HTC Sync 3.0\OutputLog.dll
2012-04-17 14:05 - 2012-04-17 14:05 - 00516599 _____ () C:\Program Files\HTC\HTC Sync 3.0\sqlite3.dll
2012-04-17 14:05 - 2012-04-17 14:05 - 00094208 _____ () C:\Program Files\HTC\HTC Sync 3.0\fdHttpd.dll
2012-04-17 14:05 - 2012-04-17 14:05 - 00389120 _____ () C:\Program Files\HTC\HTC Sync 3.0\HtcDetect.dll
2012-04-17 14:05 - 2012-04-17 14:05 - 00151552 _____ () C:\Program Files\HTC\HTC Sync 3.0\htcDisk.dll
2012-04-17 14:05 - 2012-04-17 14:05 - 00172032 _____ () C:\Program Files\HTC\HTC Sync 3.0\htcDetectLegend.dll
2012-04-17 14:05 - 2012-04-17 14:05 - 00559244 _____ () C:\Program Files\HTC\HTC Sync 3.0\sqlite3.7.dll
2012-04-17 14:05 - 2012-04-17 14:05 - 01515520 _____ () C:\Program Files\HTC\HTC Sync 3.0\Maps\R66Api.dll
2013-06-17 23:06 - 2013-05-08 18:42 - 00906240 _____ () C:\Users\Konfiguration\AppData\Local\Viber\Viber.exe
2014-02-16 21:48 - 2014-02-16 21:48 - 14884864 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\libViber.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00729088 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\libGLESv2.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00049152 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\libEGL.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00835584 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\platforms\qwindows.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00024576 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\imageformats\qgif.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00024576 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\imageformats\qico.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00212992 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\imageformats\qjpeg.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00221184 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\imageformats\qmng.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00016384 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\imageformats\qsvg.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00016384 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\imageformats\qtga.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00278528 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\imageformats\qtiff.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00016384 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\imageformats\qwbmp.dll
2014-02-16 21:48 - 2014-02-16 21:48 - 00622592 _____ () C:\Users\Konfiguration\AppData\Local\Viber\\sqldrivers\qsqlite.dll
2013-07-27 13:54 - 2013-07-27 13:56 - 00510520 _____ () C:\Program Files\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe
2014-03-08 08:37 - 2014-03-08 08:37 - 00041984 _____ () C:\Users\Konfiguration\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp34gfgv.dll
2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\Konfiguration\AppData\Roaming\Dropbox\bin\libcef.dll
2010-10-01 07:36 - 2010-10-01 07:36 - 00270336 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2014-02-16 09:15 - 2014-02-16 09:15 - 03578992 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BsScanner => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== Disabled items from MSCONFIG ==============

==================== Faulty Device Manager Devices =============

Name: Microsoft-ISATAP-Adapter #2
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

==================== Event log errors: =========================

Application errors:
Error: (03/08/2014 08:47:50 AM) (Source: Windows Search Service) (User: )
Description: Der Index kann nicht initialisiert werden.

        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:47:50 AM) (Source: Windows Search Service) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung

        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:47:50 AM) (Source: Windows Search Service) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog

        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:37:12 AM) (Source: Windows Search Service) (User: )
Description: Der Index kann nicht initialisiert werden.

        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:37:12 AM) (Source: Windows Search Service) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung

        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:37:12 AM) (Source: Windows Search Service) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog

        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:36:50 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.

Error: (03/08/2014 08:36:49 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.

Error: (03/08/2014 08:36:49 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.

Error: (03/08/2014 08:36:46 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.

System errors:
Error: (03/08/2014 08:47:50 AM) (Source: Service Control Manager) (User: )
Description: Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 5 Mal passiert.

Error: (03/08/2014 08:47:50 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147218174.

Error: (03/08/2014 08:37:12 AM) (Source: Service Control Manager) (User: )
Description: Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 4 Mal passiert.

Error: (03/08/2014 08:37:12 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147218174.

Error: (03/08/2014 08:31:46 AM) (Source: Service Control Manager) (User: )
Description: Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert.

Error: (03/08/2014 08:31:46 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147218174.

Error: (03/08/2014 08:31:15 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (03/08/2014 08:31:15 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147218174.

Error: (03/08/2014 08:30:44 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (03/08/2014 08:30:44 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147218174.

Microsoft Office Sessions:
Error: (03/08/2014 08:47:50 AM) (Source: Windows Search Service)(User: )
        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:47:50 AM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung

        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:47:50 AM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog

        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:37:12 AM) (Source: Windows Search Service)(User: )
        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:37:12 AM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung

        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:37:12 AM) (Source: Windows Search Service)(User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog

        Das Objekt, das Sie erstellen wollen, ist bereits vorhanden. Verwenden Sie einen anderen Namen.  (HRESULT : 0x80040d02) (0x80040d02)

Error: (03/08/2014 08:36:50 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: hxxp:// erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.

Error: (03/08/2014 08:36:49 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: hxxp:// erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.

Error: (03/08/2014 08:36:49 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: hxxp:// erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.

Error: (03/08/2014 08:36:46 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: hxxp:// erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.


HWiNFO32 Version 4.34-2130

DESK ----------------------------------------------------------------------

 [Current Computer]
  Computer Name:                          DESK
  Computer Brand Name:                    MEDIONPC MS-7646
 [Operating System]
  Operating System:                      Microsoft Windows 7 Home Premium Build 7601
  Service Pack:                          Service Pack 1

Central Processor(s) ------------------------------------------------------

 [CPU Unit Count]
  Number Of Processor Packages (Physical): 1
  Number Of Processors Cores:            3
  Number Of Logical Processors:          3

AMD Athlon II X3 440 ------------------------------------------------------

 [General Information]
  Processor Name:                        AMD Athlon II X3 440
  Original Processor Frequency:          3000.0 MHz
  Original Processor Frequency [MHz]:    3000
  CPU ID:                                00100F53
  Extended CPU ID:                        00100F53
  CPU Brand Name:                        AMD Athlon(tm) II X3 440 Processor
  CPU Vendor:                            AuthenticAMD
  CPU Stepping:                          BL-C3 (Bloodhound)
  CPU Code Name:                          Rana
  CPU Thermal Design Power (TDP):        94.7 W
  CPU Thermal Design Current (TDC):      75.0 A
  CPU Platform:                          Socket AM3
  Microcode Update Revision:              10000B6
  Number of CPU Cores:                    3
  Number of Logical CPUs:                3
 [Operating Points]
  CPU HFM (Maximum):                      3000.0 MHz = 15.00 x 200.0 MHz @ 1.4000 V
  CPU Current:                            3007.7 MHz = 15.00 x 200.5 MHz @ 1.4000 V
  Northbridge Maximum:                    2000.0 MHz = 10.00 x 200.0 MHz @ 1.4000 V
  Northbridge Current:                    2005.1 MHz = 10.00 x 200.5 MHz @ 1.1750 V
  CPU Bus Type:                          Hyper-Transport v3.00
  Maximum Supported Hyper-Transport Link Clock: 2000 MHz
  Current Hyper-Transport Link Clock:    2000 MHz
 [Cache and TLB]
  L1 Cache:                              Instruction: 3 x 64 KBytes, Data: 3 x 64 KBytes
  L2 Cache:                              Integrated: 3 x 512 KBytes
  Instruction TLB:                        Fully associative, 32 entries
  Data TLB:                              Fully associative, 48 entries
 [Standard Feature Flags]
  FPU on Chip                            Present
  Enhanced Virtual-86 Mode                Present
  I/O Breakpoints                        Present
  Page Size Extensions                    Present
  Time Stamp Counter                      Present
  Pentium-style Model Specific Registers  Present
  Physical Address Extension              Present
  Machine Check Exception                Present
  CMPXCHG8B Instruction                  Present
  APIC On Chip / PGE (AMD)                Present
  Fast System Call                        Present
  Memory Type Range Registers            Present
  Page Global Feature                    Present
  Machine Check Architecture              Present
  CMOV Instruction                        Present
  Page Attribute Table                    Present
  36-bit Page Size Extensions            Present
  Processor Number                        Not Present
  CLFLUSH Instruction                    Present
  Debug Trace and EMON Store              Not Present
  Internal ACPI Support                  Not Present
  MMX Technology                          Present
  Fast FP Save/Restore (IA MMX-2)        Present
  Streaming SIMD Extensions              Present
  Streaming SIMD Extensions 2            Present
  Self-Snoop                              Not Present
  Multi-Threading Capable                Present
  Automatic Clock Control                Not Present
  IA-64 Processor                        Not Present
  Signal Break on FERR                    Not Present
  Streaming SIMD Extensions 3            Present
  PCLMULQDQ Instruction Support          Not Present
  MONITOR/MWAIT Support                  Present
  Supplemental Streaming SIMD Extensions 3 Not Present
  FMA Extension                          Not Present
  CMPXCHG16B Support                      Present
  Streaming SIMD Extensions 4.1          Not Present
  Streaming SIMD Extensions 4.2          Not Present
  x2APIC                                  Not Present
  POPCNT Instruction                      Present
  AES Cryptography Support                Not Present
  XSAVE/XRSTOR/XSETBV/XGETBV Instructions Not Present
  XGETBV/XSETBV OS Enabled                Not Present
  AVX Support                            Not Present
  Half-Precision Convert (CVT16)          Not Present
 [Extended Feature Flags]
  FPU on Chip                            Present
  Enhanced Virtual-86 Mode                Present
  I/O Breakpoints                        Present
  Page Size Extensions                    Present
  Time Stamp Counter                      Present
  AMD-style Model Specific Registers      Present
  Machine Check Exception                Present
  CMPXCHG8B Instruction                  Present
  APIC On Chip                            Present
  SYSCALL and SYSRET Instructions        Present
  Memory Type Range Registers            Present
  Page Global Feature                    Present
  Machine Check Architecture              Present
  CMOV Instruction                        Present
  Page Attribute Table                    Present
  36-bit Page Size Extensions            Present
  Multi-Processing / Brand feature        Not Present
  No Execute                              Present
  MMX Technology                          Present
  MMX+ Extensions                        Present
  Fast FP Save/Restore                    Present
  Fast FP Save/Restore Optimizations      Present
  1 GB large page support                Present
  RDTSCP Instruction                      Present
  x86-64 Long Mode                        Present
  3DNow! Technology Extensions            Present
  3DNow! Technology                      Present
  LAHF/SAHF Long Mode Support            Present
  Core Multi-Processing Legacy Mode      Present
  Secure Virtual Machine                  Present
  Extended APIC Register Space            Present
  LOCK MOV CR0 Support                    Present
  Advanced Bit Manipulation              Present
  SSE4A Support                          Present
  Misaligned SSE Mode                    Present
  PREFETCH(W) Support                    Present
  OS Visible Work-around Support          Present
  Instruction Based Sampling              Present
  XOP Instruction Support                Not Present
  SKINIT, STGI, and DEV Support          Present
  Watchdog Timer Support                  Present
  TBM0 Instruction Support                Not Present
  Lightweight Profiling Support          Not Present
  FMA4 Instruction Support                Not Present
  Translation Cache Extension            Not Present
  NodeId Support                          Not Present
  Trailing Bit Manipulation              Not Present
  Topology Extensions                    Not Present
  Core Performance Counter Extensions    Not Present
  NB Performance Counter Extensions      Not Present
  Streaming Performance Monitor Architecture Not Present
  Data Breakpoint Extension              Not Present
  Performance Time-Stamp Counter          Not Present
  L2I Performance Counter Extensions      Not Present
  MWAITX/MONITORX Support                Not Present
 [Enhanced Features]
  Core Performance Boost                  Not Supported
 [Memory Ranges]
  Maximum Physical Address Size:          48-bit (256 TBytes)
  Maximum Virtual Address Size:          48-bit (256 TBytes)
  Range 0-80000000 (0MB-2048MB) Type:    Write Back (WB)
  Range 80000000-C0000000 (2048MB-3072MB) Type: Write Back (WB)
  Range C0000000-D0000000 (3072MB-3328MB) Type: Write Back (WB)

Motherboard ---------------------------------------------------------------

  Computer Brand Name:                    MEDIONPC MS-7646
  Motherboard Model:                      MEDIONPC MS-7646
  Motherboard Chipset:                    AMD 770/870 (RX780) + SP5100 (SB700)
  Motherboard Slots:                      1xPCI, 1xAGP
  USB Version Supported:                  v2.0
  BIOS Manufacturer:                      American Megatrends
  BIOS Date:                              09/23/10
  BIOS Version:                          A7646MLN.109
  EFI BIOS:                              Not Capable
  Super-IO/LPC Chip:                      Unknown

ACPI Devices --------------------------------------------------------------

AMD Processor -------------------------------------------------------------

  Device Name:                            AMD Processor

AMD Processor -------------------------------------------------------------

  Device Name:                            AMD Processor

AMD Processor -------------------------------------------------------------

  Device Name:                            AMD Processor

ACPI Fixed Feature Button -------------------------------------------------

  Device Name:                            ACPI Fixed Feature Button

Programmable interrupt controller -----------------------------------------

  Device Name:                            Programmable interrupt controller
 [Assigned Resources]
  I/O Port:                              0020 - 0021
  I/O Port:                              00A0 - 00A1
 [Alternative 1]
  I/O Port:                              0020 - 0021
  I/O Port:                              00A0 - 00A1

BIOS ----------------------------------------------------------------------

  BIOS Vendor:                            American Megatrends Inc.
  BIOS Version:                          A7646MLN.109
  BIOS Release Date:                      09/23/2010
  BIOS Start Segment:                    F000
  BIOS Size:                              1024 KBytes
  System BIOS Version:                    8.14
  ISA Support:                            Present
  MCA Support:                            Not Present
  EISA Support:                          Not Present
  PCI Support:                            Present
  PC Card (PCMCIA) Support:              Not Present
  Plug-and-Play Support:                  Present
  APM Support:                            Present
  Flash BIOS:                            Present
  BIOS Shadow:                            Present
  VL-VESA Support:                        Not Present
  ESCD Support:                          Present
  Boot from CD:                          Present
  Selectable Boot:                        Present
  BIOS ROM Socketed:                      Present
  Boot from PC Card:                      Not Present
  EDD Support:                            Present
  NEC PC-98 Support:                      Not Present
  ACPI Support:                          Present
  USB Legacy Support:                    Present
  AGP Support:                            Not Present
  I2O Boot Support:                      Not Present
  LS-120 Boot Support:                    Present
  ATAPI ZIP Drive Boot Support:          Present
  IEE1394 Boot Support:                  Not Present
  Smart Battery Support:                  Not Present
  BIOS Boot Specification Support:        Present
  Function key-initiated Network Service Boot Support: Not Present
  Targeted Content Distribution Support:  Present
  UEFI Specification Support:            Not Present

System --------------------------------------------------------------------

  System Manufacturer:                    MEDIONPC
  Product Name:                          MS-7646
  Product Version:                        1.0
  Product Serial Number:                  To Be Filled By O.E.M.
  UUID:                                  {DED77294-D826-11DD-FB81-BFB690D3298A}
  SKU Number:                            To Be Filled By O.E.M.
  Family:                                To Be Filled By O.E.M.

Mainboard -----------------------------------------------------------------

  Mainboard Manufacturer:                MEDIONPC
  Mainboard Name:                        MS-7646
  Mainboard Version:                      1.0
  Mainboard Serial Number:                To be filled by O.E.M.
  Asset Tag:                              To Be Filled By O.E.M.
  Location in chassis:                    To Be Filled By O.E.M.

System Enclosure ----------------------------------------------------------

  Manufacturer:                          MEDIONPC
  Case Type:                              Desktop
  Version:                                1.0
  Serial Number:                          To Be Filled By O.E.M.
  Asset Tag Number:                      To Be Filled By O.E.M.

Processor -----------------------------------------------------------------

  Processor Manufacturer:                AMD             
  Processor Version:                      AMD Athlon(tm) II X3 440 Processor                 
  External Clock:                        200 MHz
  Maximum Clock Supported:                3000 MHz
  Current Clock:                          3000 MHz
  CPU Socket:                            Populated
  CPU Status:                            Enabled
  Processor Type:                        Central Processor
  Processor Voltage:                      1.5 V
  Processor Upgrade:                      Unknown (1)
  Socket Designation:                    CPU 1

L1-Cache ------------------------------------------------------------------

  Socket Designation:                    L1-Cache
  Cache State:                            Enabled
  Cache Type:                            Internal
  Cache Scheme:                          Write-Through and Write-Back
  Supported SRAM Type:                    Pipeline Burst
  Current SRAM Type:                      Pipeline Burst
  Cache Speed:                            Unknown
  Error Correction Type:                 
  Maximum Cache Size:                    384 KBytes
  Installed Cache Size:                  384 KBytes
  Cache Associativity:                    4-way Set-Associative

L2-Cache ------------------------------------------------------------------

  Socket Designation:                    L2-Cache
  Cache State:                            Enabled
  Cache Type:                            Internal
  Cache Scheme:                          Write-Through and Write-Back
  Supported SRAM Type:                    Pipeline Burst
  Current SRAM Type:                      Pipeline Burst
  Cache Speed:                            Unknown
  Error Correction Type:                 
  Maximum Cache Size:                    1536 KBytes
  Installed Cache Size:                  1536 KBytes
  Cache Associativity:                    4-way Set-Associative

L3-Cache ------------------------------------------------------------------

  Socket Designation:                    L3-Cache
  Cache State:                            Disabled
  Cache Type:                            Internal
  Cache Scheme:                          Unknown
  Supported SRAM Type:                   
  Current SRAM Type:                     
  Cache Speed:                            Unknown
  Error Correction Type:                  Unknown
  Maximum Cache Size:                    0 KBytes
  Installed Cache Size:                  0 KBytes
  Cache Associativity:                    Unknown

Memory Devices ------------------------------------------------------------

Memory Controller ---------------------------------------------------------

  Error Detecting Method:                64-bit ECC
  Error Correction:                      None
  Supported Interleave:                  1-Way
  Current Interleave:                    1-Way
  Max. Memory Module Size:                512 MBytes
  Supported Memory Speed:                70 ns, 60 ns
  Supported Memory Type:                  SIMM, DIMM, SDRAM
  Supported Memory Voltage:              3.3 V
  Associated Memory Slots:                4

schrauber 12.03.2014 22:08


bitte noch nen GMER Scan machen.

SCSC 12.03.2014 23:04

Win 7 Updates hängen UND Microsoft Security Essentials-Deinstallation/Installation stecken geblieben
Danke zuerst mal dafür, dass Du (ist das ok hier, zu duzen?) Dich meiner Frage annimmst.

Im Text meines ersten Postings habe ich aber schon beschrieben, dass Gmer nicht durchläuft und mit welcher Fehlermeldung ("funktioniert nicht mehr") es abbricht (und zwar obwohl es frisch installiert ist). Ich bin ja gerne bereit, etwas zu unternehmen, aber ohne irgendeinen Trick läuft Gmer also jedenfalls nicht. Sorry!

schrauber 13.03.2014 13:33


ist das ok hier, zu duzen?
Klar :)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

SCSC 13.03.2014 22:35

Win 7 Updates hängen UND Microsoft Security Essentials-Deinstallation/Installation stecken geblieben
Vielen Dank. Ich denke, die Scans habe ich hinbekommen, Hier sind die Logs:


Malwarebytes Anti-Rootkit BETA


Windows 7 Service Pack 1 x86 NTFS
Konfiguration :: DESK

13.03.2014 22:19:53
mbar-log-2014-03-13 (22-19-53).txt

 2 , 20










22:28:59.0505 5364  TDSS rootkit removing tool Feb 11 2013 18:50:42
22:29:00.0020 5364  ============================================================
22:29:00.0020 5364  Current date / time: 2014/03/13 22:29:00.0020
22:29:00.0020 5364  SystemInfo:
22:29:00.0020 5364 
22:29:00.0020 5364  OS Version: 6.1.7601 ServicePack: 1.0
22:29:00.0020 5364  Product type: Workstation
22:29:00.0020 5364  ComputerName: DESK
22:29:00.0020 5364  UserName: Konfiguration
22:29:00.0020 5364  Windows directory: C:\Windows
22:29:00.0020 5364  System windows directory: C:\Windows
22:29:00.0020 5364  Processor architecture: Intel x86
22:29:00.0020 5364  Number of processors: 3
22:29:00.0020 5364  Page size: 0x1000
22:29:00.0020 5364  Boot type: Normal boot
22:29:00.0020 5364  ============================================================
22:29:01.0143 5364  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:29:01.0159 5364  ============================================================
22:29:01.0159 5364  \Device\Harddisk0\DR0:
22:29:01.0159 5364  MBR partitions:
22:29:01.0159 5364  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
22:29:01.0159 5364  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x708D3000
22:29:01.0159 5364  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x70906000, BlocksNum 0x3C00000
22:29:01.0159 5364  ============================================================
22:29:01.0174 5364  C: <-> \Device\Harddisk0\DR0\Partition2
22:29:01.0237 5364  D: <-> \Device\Harddisk0\DR0\Partition3
22:29:01.0237 5364  ============================================================
22:29:01.0237 5364  Initialize success
22:29:01.0237 5364  ============================================================
22:29:12.0438 4596  ============================================================
22:29:12.0438 4596  Scan started
22:29:12.0438 4596  Mode: Manual; SigCheck; TDLFS;
22:29:12.0438 4596  ============================================================
Wirklich interpretieren kann ich das aber nicht...

:-) :-)


schrauber 14.03.2014 19:20

MBAR bitte nochmal, das Log ist komisch.

SCSC 15.03.2014 09:18

Als Ergebnis des Scans hat MBAR in einer Textbox angezeigt, dass nichts gefunden wurde. Ich wiederhole das aber auf jeden Fall, kein Problem. Es kann jetzt allerdings ein paar Tage dauern. Mein Vermieter hat das Internet nicht bezahlt (das laeuft hier anders als in D) und ich bin jetzt offline (poste das hier von einem anderen Rechner aus).


schrauber 15.03.2014 17:27

ok :)

SCSC 16.03.2014 00:10

"Scan finished, no malware found"

... irgendwie schon komisch, weil ich waehrend der Scan noch lief, etwas von drei infizierten Dateien (in einem Temp-Verzeichnis, Dateiname war nicht ganz sichtbar) gelesen hatte.


Malwarebytes Anti-Rootkit BETA

Database version: v2014.03.15.04

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Konfiguration :: DESK [administrator]

15.03.2014 22:35:52
mbar-log-2014-03-15 (22-35-52).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 296890
Time elapsed: 1 hour(s), 4 minute(s), 57 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)


schrauber 16.03.2014 17:50

Also Malware ist hier keine. Immer noch so Probleme?

SCSC 16.03.2014 18:19

Ja leider.

Ich habe von Anfang an nicht an ein Malware-Problem geglaubt, daher hatte ich den Fred auch unter "Windows..." begonnen. In Langform:

Es stehen immer die gleichen 9 (!) Updates an, die Windows versucht zu installieren, wenn ich den Rechner runterfahren will. Es klappt aber nicht und irgendwann geht er dann aus. Ich wollte ihn davon erloesen, indem ich die automatische Update-Funktion ausschalte, aber das hat nichts gebracht, die scheinen in einer festen Pipeline zu stehen. Ich bin auch nicht so fit, ohne Anleitung finden zu koennen, welche das genau sind.

Die Fehlermeldung bei Starten, dass eine MSE-Datei nicht da ist, ist auch noch aktuell. Und das Problem, den MSE auf normalem Wege (also mit den Windows-Funktionen dafuer) weder deinstallieren noch installieren zu koennen ist auch noch da. Mein Versuch, das mit dem Win-Tool dafuer ("Fixit" - kannte ich vorher gar nicht) in den Griff zu kriegen ist erfolglos geblieben. Und der Versuch einer manuellen Registry-Bereinigung nach einer im Internet gefundenen Anleitung hat halt auch nicht gefruchtet.

Mit Registry-Schluesseln hantiere ich sonst nicht, das uebersteigt meinen PC-Sachverstand.

Kann ich noch irgendwas machen, um die Konfiguration transparenter zu machen?


Danke fuer Deine Unterstuetzung!

schrauber 17.03.2014 10:24

Bevor wir jetzt händisch an der Kiste rummachen:

Windows DVD da?

Downloade dir bitte Windows Repair (All In One) von hier.

SCSC 17.03.2014 20:07

Die Windows DVD habe ich leider zu Hause gelassen, über 1000 km weg von hier :-(

Aber sind die benötigten Daten denn nicht auf der separaten Partition (versteckt)?

Kann ich die von Dir ausgesuchte Operation auch ohne die DVD in der Hinterhand wagen?

Vielen Dank und viele Grüße

schrauber 18.03.2014 12:03

Dann mach erstmal das Windows Repair Tool, überspring den Schritt wo nach DVD gefragt wird.

SCSC 20.03.2014 09:14

Das ist jetzt leider nicht so gut gelaufen. Im Einzelnen:

"Step 2" habe ich abgearbeitet und eine Meldung bekommen, dass und wo ein logfile abgelegt wurde.

Nach Neustart habe ich "Step 3" abgearbeitet und eine Meldung bekommen, dass Fehler gefunden und repariert wurden.

Nach Neustart sah erst alles fast normal aus (nur dass das Fenster mit der Warnmeldung, dass der MSE nicht starten konnte, verstuemmelt war: kein Text mehr, kein Button, nur noch ein geschrumpftes "Rest"-Fenster, das aber - wie zuvor die Meldung auch - sich ohne mein Zutun geschlossen hat). Nach Auswahl des Benutzerprofils zum Windows Start sah auch alles gut aus, aber dann bemerkte ich, dass der Klick auf ein Programmsymbol in der Schnellstartleiste zwar den Fokus angenommen hat, aber das Programm nicht kam. Weitere Klicks hatten gar keine Reaktion mehr. Der Windows-Button warnicht ansprechbar, auch nicht ueber die Win-Taste. Ich musste den Rechner hart ausschalten (auch bei allen nachfolgenden Aktionen). Neustart brachte keine Besserung. Neustart im abgesicherten Modus mit Netzwerktreibern brachte kein funktionierendes Windos zu Stande. Neustart mit einem anderen Benutzerprofil brachte auch nichts besseres, nur dass ploetzlich der Bidlschirmhintergrund fast komplett weg war und wieder ein defektes (textloses) Fenster ohne Button erschien. Mit der Maus suchte ich daraufhin den Bildschirm ab, um evtl. einen unsichtbaren Button zu finden. Das schien irgendwann den Speicher zu ueberfordern und wurde mit blue screen quittiert (crash dump des Speichers auf die Festplatte soll angeblich funktioniert haben). Den Fehlercode des blue screen habe ich notiert. Ein erneuter Neustart brachte wieder nur das Windows, das auf den ersten Blick i.O. aussieht, bei dem aber gar nichts funktioniert.

Unter dem Strich kann ich mit dem Rechner jetzt gar nichts mehr tun (das hier schreibe ich von einem anderen Rechner aus). Vermutlich muss ich nun doch eine Reparatur mit der CD unternehmen. Wenn ich in ein paar Monaten mal auf Besuch nach Hause fliege, werde ich sie hoffentlich finden. Es waere nett, wenn Du mir einen Tipp geben koenntest, wie ich ggf. versuchen kann, meine Daten zu retten und ob ich hier vor Ort einen Reparaturversuch mit einer anderen Windows CD unternehmen kann.

Vielen Dank

