Servus Schrauber,
ok, hier das Fixlog: Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-05-2015 02
Ran by Thomas at 2015-05-17 09:20:18 Run:1
Running from C:\Users\Thomas\Downloads
Loaded Profiles: Thomas (Available profiles: Thomas)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKU\Thomas\...\RunOnce: [h7BgsM2Ns] => rundll32 "C:\Users\Thomas\AppData\Local\Temp\hG7JnB4dsPnhj5Rqew6L\gwNWQ7HbhamP01AhBowAs.dll" NjRmN2U4YTgwNWQ4YzlhNmM5ZTc1ODAxMGFjOTNiOTBf <===== ATTENTION
C:\Users\Thomas\AppData\Local\Temp\hG7JnB4dsPnhj5Rqew6L
*****************
HKU\Thomas\Software\Microsoft\Windows\CurrentVersion\RunOnce\\h7BgsM2Ns => Value not found.
"C:\Users\Thomas\AppData\Local\Temp\hG7JnB4dsPnhj5Rqew6L" => File/Directory not found.
==== End of Fixlog 09:20:19 ==== Und hier die anderen Logs:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-05-2015 02
Ran by Thomas (administrator) on THOMAS-PC on 17-05-2015 09:24:45
Running from C:\Users\Thomas\Downloads
Loaded Profiles: Thomas (Available profiles: Thomas)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\DeviceDisplayObjectProvider.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2253816567-2930413787-4049114413-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 83.169.184.161
FireFox:
========
FF ProfilePath: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\svd3mpjz.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-27] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-27] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Extension: NoScript - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\svd3mpjz.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-04-27]
FF Extension: Adblock Edge - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\svd3mpjz.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2015-04-27]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-16 14:44 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2015-05-16 14:44 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2015-05-16 14:44 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2015-05-16 14:44 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2015-05-16 14:44 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2015-05-16 14:44 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2015-05-16 14:44 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2015-05-16 14:44 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2015-05-13 22:14 - 2015-02-18 09:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2015-05-13 22:14 - 2015-02-18 09:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-13 21:41 - 2015-05-17 09:20 - 00000000 ____D () C:\Users\Thomas\Downloads\FRST-OlderVersion
2015-05-13 21:41 - 2015-05-16 15:35 - 00022019 _____ () C:\Users\Thomas\Downloads\Main.txt
2015-05-08 14:17 - 2015-05-08 14:17 - 00268848 _____ () C:\Windows\Minidump\050815-13031-01.dmp
2015-05-08 14:16 - 2015-05-08 14:17 - 00000000 ____D () C:\Windows\Minidump
2015-05-08 14:16 - 2015-05-08 14:16 - 00268848 _____ () C:\Windows\Minidump\050815-12812-01.dmp
2015-05-05 14:08 - 2015-05-05 14:08 - 14179480 _____ (Microsoft Corporation) C:\Users\Thomas\Downloads\mseinstall.exe
2015-05-05 13:13 - 2015-05-05 12:33 - 00000000 ____D () C:\Windows\Panther
2015-05-05 13:12 - 2015-05-05 13:12 - 00262144 _____ () C:\Windows\system32\config\userdiff
2015-05-05 13:04 - 2015-05-05 13:04 - 00000000 ___HD () C:\$INPLACE.~TR
2015-05-05 13:04 - 2015-05-05 12:22 - 00000000 ___HD () C:\$WINDOWS.~Q
2015-05-05 12:50 - 2012-02-17 08:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2015-05-05 12:50 - 2012-02-17 07:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2015-05-05 12:50 - 2012-02-17 06:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2015-05-05 12:50 - 2012-02-17 06:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2015-05-05 12:33 - 2015-05-05 12:33 - 00000020 ___SH () C:\Users\Thomas\ntuser.ini
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\Startmenü
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\ProgramData\Startmenü
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\ProgramData\Favoriten
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\ProgramData\Dokumente
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2015-05-05 12:33 - 2015-05-05 12:33 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2015-05-05 12:30 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-05-05 12:30 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-05-05 12:30 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-05-05 12:30 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-05-05 12:30 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-05-05 12:30 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-05-05 12:30 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-05-05 12:30 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-05-05 12:24 - 2015-05-13 21:46 - 00967600 _____ () C:\Windows\WindowsUpdate.log
2015-05-05 12:21 - 2015-05-05 12:21 - 00022960 _____ () C:\Windows\system32\emptyregdb.dat
2015-05-05 12:16 - 2015-05-05 12:33 - 00000000 ____D () C:\Users\Thomas
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\Vorlagen
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\Startmenü
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\Netzwerkumgebung
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\Lokale Einstellungen
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\Eigene Dateien
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\Druckumgebung
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\Documents\Eigene Musik
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\Documents\Eigene Bilder
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\AppData\Local\Verlauf
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\AppData\Local\Anwendungsdaten
2015-05-05 12:16 - 2015-05-05 12:16 - 00000000 _SHDL () C:\Users\Thomas\Anwendungsdaten
2015-05-05 12:16 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 12:16 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-05 12:15 - 2015-05-05 12:15 - 00001355 _____ () C:\Windows\TSSysprep.log
2015-05-05 12:15 - 2015-05-05 12:15 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-05-05 12:15 - 2015-05-05 12:15 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-05-05 11:54 - 2015-05-05 12:21 - 00006256 _____ () C:\Windows\comsetup.log
2015-05-05 10:59 - 2015-05-05 10:59 - 00000652 _____ () C:\Windows\CompatibilityIssues.txt
2015-05-05 10:56 - 2015-05-05 11:50 - 00002544 _____ () C:\Windows\diagwrn.xml
2015-05-05 10:56 - 2015-05-05 11:50 - 00001890 _____ () C:\Windows\diagerr.xml
2015-05-02 20:21 - 2015-05-05 12:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2015-05-02 20:21 - 2015-05-05 12:18 - 00000000 ____D () C:\Program Files (x86)\CrystalDiskInfo
2015-05-02 20:21 - 2015-05-02 20:21 - 03015656 _____ (Crystal Dew World ) C:\Users\Thomas\Downloads\CrystalDiskInfo6_3_2-en.exe
2015-05-02 20:21 - 2015-05-02 20:21 - 00001190 _____ () C:\Users\Thomas\Desktop\CrystalDiskInfo.lnk
2015-04-30 11:09 - 2015-04-30 11:09 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-THOMAS-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-30 11:09 - 2015-04-30 11:09 - 00000000 ____D () C:\RegBackup
2015-04-30 11:05 - 2015-05-05 12:19 - 00000000 ____D () C:\Users\Thomas\Downloads\Tweaking.com - Windows Repair
2015-04-30 11:05 - 2015-04-30 11:05 - 10654284 _____ () C:\Users\Thomas\Downloads\tweaking.com_windows_repair_aio.zip
2015-04-28 13:52 - 2015-05-05 12:19 - 00000000 ____D () C:\Users\Thomas\Downloads\bluescreenview_v1.55
2015-04-28 13:48 - 2015-04-28 13:50 - 00067310 _____ () C:\Users\Thomas\Downloads\bluescreenview_v1.55.zip
2015-04-28 10:11 - 2015-05-05 12:18 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-04-28 10:11 - 2015-05-05 12:18 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-28 10:11 - 2015-05-05 12:18 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-28 10:11 - 2015-05-05 12:18 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-27 19:54 - 2012-06-02 16:57 - 00000003 ____N () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2015-04-27 19:12 - 2015-05-05 12:19 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\Macromedia
2015-04-27 19:12 - 2015-05-05 12:19 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\Adobe
2015-04-27 19:12 - 2015-05-05 12:18 - 00000000 ____D () C:\Users\Thomas\AppData\Local\Macromedia
2015-04-27 17:29 - 2015-05-08 14:17 - 240966187 _____ () C:\Windows\MEMORY.DMP
2015-04-27 15:56 - 2015-04-27 15:56 - 00001211 _____ () C:\Users\Thomas\Downloads\MBAM.txt
2015-04-27 15:51 - 2015-05-05 12:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-27 15:51 - 2015-05-05 12:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-27 15:51 - 2015-05-05 12:18 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-04-27 15:51 - 2015-04-27 15:51 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-27 15:51 - 2015-04-27 15:51 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-27 15:51 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-27 15:51 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-27 15:51 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-27 15:43 - 2015-04-27 15:43 - 00000778 _____ () C:\Users\Thomas\Downloads\gmer.log
2015-04-27 15:24 - 2015-04-27 16:27 - 00009745 _____ () C:\Users\Thomas\Downloads\Addition.txt
2015-04-27 15:23 - 2015-05-13 21:42 - 00025804 _____ () C:\Users\Thomas\Downloads\FRST.txt
2015-04-27 15:19 - 2015-05-13 21:47 - 00000000 ____D () C:\FRST
2015-04-27 15:19 - 2015-04-27 15:19 - 00000474 _____ () C:\Users\Thomas\Downloads\defogger_disable.log
2015-04-27 15:19 - 2015-04-27 15:19 - 00000000 _____ () C:\Users\Thomas\defogger_reenable
2015-04-27 15:18 - 2015-04-27 15:18 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Thomas\Downloads\mbam-setup-2.1.6.1022.exe
2015-04-27 15:17 - 2015-05-13 21:41 - 02104832 _____ (Farbar) C:\Users\Thomas\Downloads\FRST64.exe
2015-04-27 15:17 - 2015-04-27 15:17 - 00050477 _____ () C:\Users\Thomas\Downloads\Defogger.exe
2015-04-27 15:16 - 2015-04-27 15:16 - 00380416 _____ () C:\Users\Thomas\Downloads\yed4cxii.exe
2015-04-27 12:40 - 2015-04-27 12:40 - 28745120 _____ (Mozilla) C:\Users\Thomas\Downloads\Thunderbird Setup 31.6.0.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-17 09:20 - 2011-04-12 09:43 - 00643628 _____ () C:\Windows\system32\perfh007.dat
2015-05-17 09:20 - 2011-04-12 09:43 - 00126188 _____ () C:\Windows\system32\perfc007.dat
2015-05-17 09:20 - 2009-07-14 07:13 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-17 09:16 - 2009-07-14 06:45 - 00022336 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-17 09:16 - 2009-07-14 06:45 - 00022336 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-17 09:14 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-17 09:13 - 2009-07-14 06:51 - 00039764 _____ () C:\Windows\setupact.log
2015-05-05 14:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2015-05-05 13:13 - 2009-07-14 07:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2015-05-05 13:13 - 2009-07-14 07:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2015-05-05 13:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\oobe
2015-05-05 13:12 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-05-05 13:12 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-05-05 13:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Setup
2015-05-05 12:33 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2015-05-05 12:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Recovery
2015-05-05 12:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Windows NT
2015-05-05 12:30 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\restore
2015-05-05 12:25 - 2010-11-21 05:47 - 00011286 _____ () C:\Windows\PFRO.log
2015-05-05 12:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Registration
2015-05-05 12:20 - 2009-07-14 06:45 - 00275912 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-05 12:19 - 2009-07-14 06:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-05-05 12:19 - 2009-07-14 06:46 - 00005157 _____ () C:\Windows\DtcInstall.log
2015-05-05 12:19 - 2009-07-14 05:20 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-05 12:19 - 2009-07-14 05:20 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 12:19 - 2009-07-14 05:20 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-05 12:19 - 2009-07-14 05:20 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 12:18 - 2011-04-12 09:54 - 00000000 ___RD () C:\Users\Public\Recorded TV
2015-05-05 12:18 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat
2015-05-05 12:15 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 12:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sysprep
2015-04-30 11:18 - 2009-07-14 04:34 - 00000439 _____ () C:\Windows\win.ini
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-05 14:39
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-05-2015 02
Ran by Thomas at 2015-05-17 09:25:02
Running from C:\Users\Thomas\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2253816567-2930413787-4049114413-500 - Administrator - Disabled)
Gast (S-1-5-21-2253816567-2930413787-4049114413-501 - Limited - Disabled)
Thomas (S-1-5-21-2253816567-2930413787-4049114413-1000 - Administrator - Enabled) => C:\Users\Thomas
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
CrystalDiskInfo 6.3.2 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.3.2 - Crystal Dew World)
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Mozilla Firefox 37.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 de)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 37.0.2 - Mozilla)
WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
05-05-2015 12:30:06 Windows Update
05-05-2015 12:50:33 Windows Update
13-05-2015 21:46:15 Windows Update
16-05-2015 14:43:23 Windows Update
17-05-2015 09:17:29 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2015-04-30 11:18 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0E2DACE6-91A8-407A-B987-1D8BA2DF6A10} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-03-07] (Adobe Systems Incorporated)
Task: {3B092C92-3F4D-4E61-907C-839249096B0E} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {3DEBB22A-72EB-4432-BB7B-502A30F4B796} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {94FB1D75-EE74-449B-8566-1A559D53E4EF} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {D6125483-61EA-4217-9C7D-5210D18FEA78} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-27] (Adobe Systems Incorporated)
Task: {E4AFA089-81DE-45AE-972E-E8248D3F4732} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {EA2911B0-08AB-4603-801C-0CF1367AED0C} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (Whitelisted) ==============
2015-04-27 15:02 - 2015-04-27 15:02 - 00514711 _____ () C:\Windows\System32\sakuya64.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2253816567-2930413787-4049114413-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 83.169.184.161
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
FirewallRules: [{B83D6681-0807-43DF-AC3B-E3DC3DBC185B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0AC118EF-43B9-400F-9FAC-16F00AE1BD50}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Faulty Device Manager Devices =============
Name: Basissystemgerät
Description: Basissystemgerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (05/17/2015 09:22:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rundll32.exe_appraiser.dll, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc9e0
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c78c
Ausnahmecode: 0xc06d007f
Fehleroffset: 0x000000000000a49d
ID des fehlerhaften Prozesses: 0xa80
Startzeit der fehlerhaften Anwendung: 0xrundll32.exe_appraiser.dll0
Pfad der fehlerhaften Anwendung: rundll32.exe_appraiser.dll1
Pfad des fehlerhaften Moduls: rundll32.exe_appraiser.dll2
Berichtskennung: rundll32.exe_appraiser.dll3
Error: (05/17/2015 09:15:24 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/16/2015 02:47:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rundll32.exe_appraiser.dll, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc9e0
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c78c
Ausnahmecode: 0xc06d007f
Fehleroffset: 0x000000000000a49d
ID des fehlerhaften Prozesses: 0x8f8
Startzeit der fehlerhaften Anwendung: 0xrundll32.exe_appraiser.dll0
Pfad der fehlerhaften Anwendung: rundll32.exe_appraiser.dll1
Pfad des fehlerhaften Moduls: rundll32.exe_appraiser.dll2
Berichtskennung: rundll32.exe_appraiser.dll3
Error: (05/16/2015 02:41:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/13/2015 09:41:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/08/2015 02:26:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rundll32.exe_appraiser.dll, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc9e0
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c78c
Ausnahmecode: 0xc06d007f
Fehleroffset: 0x000000000000a49d
ID des fehlerhaften Prozesses: 0x844
Startzeit der fehlerhaften Anwendung: 0xrundll32.exe_appraiser.dll0
Pfad der fehlerhaften Anwendung: rundll32.exe_appraiser.dll1
Pfad des fehlerhaften Moduls: rundll32.exe_appraiser.dll2
Berichtskennung: rundll32.exe_appraiser.dll3
Error: (05/08/2015 02:19:31 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/05/2015 05:19:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/05/2015 00:34:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rundll32.exe_appraiser.dll, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc9e0
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c78c
Ausnahmecode: 0xc06d007f
Fehleroffset: 0x000000000000a49d
ID des fehlerhaften Prozesses: 0x838
Startzeit der fehlerhaften Anwendung: 0xrundll32.exe_appraiser.dll0
Pfad der fehlerhaften Anwendung: rundll32.exe_appraiser.dll1
Pfad des fehlerhaften Moduls: rundll32.exe_appraiser.dll2
Berichtskennung: rundll32.exe_appraiser.dll3
Error: (05/05/2015 00:33:43 PM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail (1324) WindowsMail0: Die Sicherung wurde abgebrochen, weil sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen wurde.
System errors:
=============
Error: (05/17/2015 09:18:34 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {752073A1-23F2-4396-85F0-8FDB879ED0ED}
Error: (05/17/2015 09:17:21 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2978668)
Error: (05/17/2015 09:17:21 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB3035126)
Error: (05/17/2015 09:17:21 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Update für Windows 7 für x64-basierte Systeme (KB2852386)
Error: (05/17/2015 09:17:21 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB2862152)
Error: (05/17/2015 09:17:21 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework 3.5.1 unter Windows 7 und Windows Server 2008 R2 SP1 für x64-basierte Systeme (KB2736422)
Error: (05/17/2015 09:17:21 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB3031432)
Error: (05/17/2015 09:17:21 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-Systeme (KB2698365)
Error: (05/17/2015 09:17:21 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Update für Microsoft .NET Framework 3.5.1 unter Windows 7 und Windows Server 2008 R2 SP1 für x64-basierte Systeme (KB2836943)
Error: (05/17/2015 09:17:21 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Windows 7 für x64-basierte Systeme (KB3006226)
Microsoft Office Sessions:
=========================
Error: (05/17/2015 09:22:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: rundll32.exe_appraiser.dll6.1.7600.163854a5bc9e0KERNELBASE.dll6.1.7601.175144ce7c78cc06d007f000000000000a49da8001d0907234523a60C:\Windows\system32\rundll32.exeC:\Windows\system32\KERNELBASE.dll7649e24c-fc65-11e4-a94b-08002710536d
Error: (05/17/2015 09:15:24 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/16/2015 02:47:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rundll32.exe_appraiser.dll6.1.7600.163854a5bc9e0KERNELBASE.dll6.1.7601.175144ce7c78cc06d007f000000000000a49d8f801d08fd67fba91e3C:\Windows\system32\rundll32.exeC:\Windows\system32\KERNELBASE.dllc3478993-fbc9-11e4-ae78-08002710536d
Error: (05/16/2015 02:41:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/13/2015 09:41:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/08/2015 02:26:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rundll32.exe_appraiser.dll6.1.7600.163854a5bc9e0KERNELBASE.dll6.1.7601.175144ce7c78cc06d007f000000000000a49d84401d0898a2b61fb2dC:\Windows\system32\rundll32.exeC:\Windows\system32\KERNELBASE.dll6e0ed5d1-f57d-11e4-a30b-08002710536d
Error: (05/08/2015 02:19:31 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/05/2015 05:19:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/05/2015 00:34:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: rundll32.exe_appraiser.dll6.1.7600.163854a5bc9e0KERNELBASE.dll6.1.7601.175144ce7c78cc06d007f000000000000a49d83801d0871f0e5bafecC:\Windows\system32\rundll32.exeC:\Windows\system32\KERNELBASE.dll524340f8-f312-11e4-88c7-08002710536d
Error: (05/05/2015 00:33:43 PM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail1324WindowsMail0:
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7 CPU 970 @ 3.20GHz
Percentage of memory in use: 41%
Total physical RAM: 4095.55 MB
Available physical RAM: 2395.24 MB
Total Pagefile: 8189.31 MB
Available Pagefile: 6332.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:119.9 GB) (Free:96.17 GB) NTFS
Drive d: (GSP1RMCHPXFRER_DE_DVD) (CDROM) (Total:3.04 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 120 GB) (Disk ID: 4D8E3977)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=119.9 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Die Probleme sind noch da, der Rechner wollte sich nach dem FRST-Durchlauf wegen Updates neu starten => Bluescreen.
Viele Grüße
Thomas |