Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Netzwerkprobleme - Schädling eingefangen?

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 15.06.2013, 11:44   #1
Bambaataa22
 
Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Moin,

mein Arbeitskollege hat Probleme mit seinem Rechner.
Und zwar kann Starmoney keinen Konatkt zum Starmoney-Service aufnehmen.
Dann scheitert z.B. die Lizenz-Überprüfung.
"Normales" Banking, z.B. Kontenabruf und Überweisungen funktionieren, Internet im Allgemeinen funktioniert auch.
Im Starmoney gibt es auch einen Reparatur-Modus der eine Onlineverbindung voraus setzt.
Der Download der automatisch startet wenn man die Reparatur aufruft bricht aber immer ab.

Ich hatte den Verdacht, dass es evtl. an dem Uralt-Siemens-Modem liegt, aber auf meinem Laptop funktioniert Starmoney einwandfrei in seinem Netzwerk.

Ich hab mir den Rechner angesehen und erstmal einen ganzen Sack an "Optimierern" runtergeschmissen. Darunter Norton Internet Security ComputerBildEdition, TuneUp, irgendwelche Privacy-Verbesserer, Reg-Cleaner, System-Scanner usw.

Dann hab ich diverse VPN-Geschichten deinstalliert.
Der Rechner war mal ein Heimarbeitsplatz von seiner Frau, wird aber jetzt als Wohnzimmer-PC eingesetzt.
Alles was noch an VPN- und Versicherungskram drauf ist kann runter wenn nötig.

MalwareBytes hat nichts gefunden, aber könnte sich bitte mal einer von euch die OTL-und GMER-Logs anschauen ob da irgendwas im Argen liegt?

Vielen Dank im Voraus!

MfG Bam

Code:
ATTFilter
OTL logfile created on: 14.06.2013 17:47:30 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\S. Voß HUK\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,93 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 60,03% Memory free
7,86 Gb Paging File | 6,29 Gb Available in Paging File | 80,12% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 458,87 Gb Total Space | 386,23 Gb Free Space | 84,17% Space Free | Partition Type: NTFS
Drive D: | 458,87 Gb Total Space | 456,39 Gb Free Space | 99,46% Space Free | Partition Type: NTFS
Drive K: | 931,28 Gb Total Space | 667,34 Gb Free Space | 71,66% Space Free | Partition Type: FAT32
Drive L: | 1863,01 Gb Total Space | 1793,28 Gb Free Space | 96,26% Space Free | Partition Type: NTFS
Drive M: | 931,51 Gb Total Space | 930,82 Gb Free Space | 99,93% Space Free | Partition Type: NTFS
 
Computer Name: BUERO | User Name: S. Voß HUK | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013.06.14 17:47:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\S. Voß HUK\Downloads\OTL.exe
PRC - [2013.02.13 12:38:24 | 000,844,144 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2013.02.13 12:38:14 | 001,509,232 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe
PRC - [2012.12.21 15:48:08 | 000,699,680 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) -- C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe
PRC - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.03.19 21:58:12 | 000,514,128 | ---- | M] (REINER SCT) -- C:\Windows\SysWOW64\cjpcsc.exe
PRC - [2011.05.24 10:33:30 | 001,840,128 | ---- | M] (MAGIX AG) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
PRC - [2010.04.27 11:09:52 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2010.04.20 17:13:56 | 002,104,320 | ---- | M] (AGFEO      ) -- C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe
PRC - [2010.03.26 04:29:36 | 000,563,744 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
PRC - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Programme\Acer\Acer Updater\UpdaterService.exe
PRC - [2009.12.09 11:24:16 | 000,076,320 | ---- | M] () -- C:\OEM\USBDECTION\USBS3S4Detection.exe
PRC - [2009.08.28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
PRC - [2009.01.27 19:45:38 | 000,059,392 | ---- | M] (AGFEO      ) -- C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tkmedia.exe
PRC - [2009.01.08 17:10:00 | 000,187,456 | ---- | M] (DATA BECKER GmbH & Co KG) -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe
PRC - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2013.05.16 03:07:14 | 018,022,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\1f0bb5336d1706c9b8ad2330f3642760\PresentationFramework.ni.dll
MOD - [2013.05.16 03:07:04 | 011,522,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\9b2940478ec555990b37af5448b8f509\PresentationCore.ni.dll
MOD - [2013.05.16 03:06:57 | 007,070,208 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\93a17ba6cb6753328f25466bc0bf1cb1\System.Core.ni.dll
MOD - [2013.05.16 03:06:53 | 003,883,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\a1949f57d2ec260e09768e98fecb0559\WindowsBase.ni.dll
MOD - [2013.05.16 03:06:51 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ddc3e8c2774eaec614d6775983652980\System.Configuration.ni.dll
MOD - [2013.02.14 04:18:46 | 000,221,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\7d8f6866864f78cf83d3701641c46178\System.ServiceProcess.ni.dll
MOD - [2013.01.10 04:32:15 | 001,812,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\40c7a89fe2cbf3c12a2c39e034da54cf\System.Xaml.ni.dll
MOD - [2013.01.10 04:15:01 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\fc476bbac36944e352c2f547352ffa64\System.Xml.ni.dll
MOD - [2013.01.10 04:14:55 | 009,095,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\f93dca0e4baa1dcb37cf75392b7c89da\System.ni.dll
MOD - [2013.01.10 04:14:51 | 014,416,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\6a1ccc1e1a79ce267d3d1808af382cd6\mscorlib.ni.dll
MOD - [2010.03.26 04:29:36 | 000,563,744 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
MOD - [2010.03.26 04:29:36 | 000,154,144 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2012.09.28 03:38:16 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2013.06.14 16:56:23 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.12.21 15:48:08 | 000,699,680 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Running] -- C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 8.0 OnlineUpdate)
SRV - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.11.09 12:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.03.19 21:58:12 | 000,514,128 | ---- | M] (REINER SCT) [Auto | Running] -- C:\Windows\SysWOW64\cjpcsc.exe -- (cjpcsc)
SRV - [2011.05.24 10:33:30 | 001,840,128 | ---- | M] (MAGIX AG) [Auto | Running] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2011.04.26 13:54:12 | 002,702,848 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2010.12.10 18:36:54 | 000,153,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2010.05.06 11:30:22 | 000,357,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2010.04.20 17:13:56 | 002,104,320 | ---- | M] (AGFEO      ) [Auto | Running] -- C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe -- (tksock)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.01 20:04:40 | 000,305,520 | ---- | M] (Egis Technology Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe -- (MWLService)
SRV - [2010.01.29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Programme\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2010.01.15 23:08:38 | 000,935,208 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.12.09 11:24:16 | 000,076,320 | ---- | M] () [Auto | Running] -- C:\OEM\USBDECTION\USBS3S4Detection.exe -- (USBS3S4Detection)
SRV - [2009.08.28 11:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.01.08 17:10:00 | 000,187,456 | ---- | M] (DATA BECKER GmbH & Co KG) [Auto | Running] -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe -- (DBService)
SRV - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService)
SRV - [2007.05.31 18:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007.05.31 18:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2013.02.12 06:12:06 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2012.09.28 04:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.09.28 03:12:52 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.09.20 06:35:36 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudserd.sys -- (ssudserd)
DRV:64bit: - [2012.09.20 06:35:36 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2012.09.20 06:35:36 | 000,102,368 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2012.05.14 08:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.08.07 14:56:22 | 000,116,096 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avmaudio.sys -- (avmaudio)
DRV:64bit: - [2011.06.10 14:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.03.29 10:50:26 | 000,034,672 | ---- | M] (REINER SCT) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cjusb.sys -- (cjusb)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.03.03 13:42:16 | 000,528,464 | ---- | M] (Paragon) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\Uim_IMx64.sys -- (Uim_IM)
DRV:64bit: - [2011.03.03 13:42:16 | 000,053,840 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\uimx64.sys -- (UimBus)
DRV:64bit: - [2011.03.03 13:42:14 | 000,037,456 | ---- | M] (Paragon Software Group) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hotcore3.sys -- (hotcore3)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.09.30 14:00:06 | 000,180,736 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010.09.30 14:00:06 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010.03.18 11:00:16 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2010.03.18 11:00:00 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2010.02.24 12:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11)
DRV:64bit: - [2010.01.28 03:33:38 | 000,116,736 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009.12.09 11:39:52 | 000,537,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.06.03 04:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009.06.03 04:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009.06.03 04:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2009.02.20 20:09:18 | 000,054,272 | ---- | M] (Siemens Home and Office Communication Devices GmbH & Co. KG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GigasetGenericUSB_x64.sys -- (GigasetGenericUSB_x64)
DRV:64bit: - [2009.01.14 19:55:38 | 000,092,672 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ser2pl64.sys -- (Ser2pl)
DRV - [2013.02.05 10:54:40 | 000,037,344 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2011.03.03 12:42:14 | 000,022,096 | ---- | M] (Paragon Software GmbH) [Kernel | On_Demand | Stopped] -- K:\Program Files (x86)\Paragon Software\Festplatten Manager 2011 Kompakt\bluescrn\biont_bs.sys -- (BioNT_BS)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.ewetel.de/index.htm [binary data]
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_x3950&r=173608102207pe458v135w4651v85o
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deDE392DE394
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.dmz.huk.de;*.hukvm.de;*.hukras.de;*.lan.huk-coburg.de;vtp.huk.de;vtp02.huk.de;vtp03.huk.de;vtp04.huk.de;vtp05.huk.de;vtpews.huk.de;crl1.huk-coburg.de;vtp.vrk.de;svks0009.vrk.de;sscd0040
IE - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.149.137.1:8080
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2011.05.15 13:48:50 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: K:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2011.05.15 13:48:50 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: K:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@protectdisc.com/NPPDLicenseHelper: C:\Users\S. Voß HUK\AppData\Roaming\ProtectDisc\License Helper v2\NPPDLicenseHelper.dll ( )
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101753.dll (Amazon.com, Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\passworddepot@acebit.com: C:\Program Files (x86)\AceBIT\Password Depot 5\Firefox\ [2011.04.25 09:41:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{09F060FA-566D-42D7-BF79-97AB30863433}: K:\Program Files (x86)\Steganos Privacy Suite 2012\pfplugin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{00F0643E-B367-4779-B45D-7046EBA37A88}: K:\Program Files (x86)\Steganos Privacy Suite 2012\spmplugin3
 
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: hxxp://www.google.com
CHR - Extension: YouTube = C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google-Suche = C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Google Mail = C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
 
O1 HOSTS File: ([2013.06.14 17:36:07 | 000,000,825 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Password Depot 5) - {9F79B165-70F7-4C46-B1A5-8828E2FF21F9} - C:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll (AceBIT)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-210379488-4132890845-1450444768-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] K:\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-210379488-4132890845-1450444768-1001..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-210379488-4132890845-1450444768-1001..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe (Samsung Electronics)
O4 - HKU\S-1-5-21-210379488-4132890845-1450444768-1001..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Password Depot 5 - {9F79B165-70F7-4C46-B1A5-8828E2FF21F9} - C:\Program Files (x86)\AceBIT\Password Depot 5\PasswordDepot.exe (AceBIT GmbH)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {28B66320-9687-4B13-8757-36F901887AB5} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/canvasx64.cab (CanvasX Class)
O16:64bit: - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/jordan64.cab (JordanUploader Class)
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{77E05783-9DA1-425A-BBC3-9A5C89C94808}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (K:\PROGRA~1\PARAGO~1\FESTPL~1\bluescrn\bluescrn.exe)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.05.20 08:20:03 | 000,000,000 | ---D | C] -- C:\Users\S. Voß HUK\Documents\The Lonely Hearts Murders CE
[3 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.06.14 17:50:00 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.06.14 17:50:00 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.06.14 17:42:51 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.06.14 17:42:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.06.14 17:42:36 | 3163,901,952 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.14 17:29:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.06.14 17:24:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.06.14 16:52:45 | 001,746,324 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.06.14 16:52:45 | 000,757,356 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.06.14 16:52:45 | 000,701,816 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.06.14 16:52:45 | 000,172,606 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.06.14 16:52:45 | 000,139,382 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.06.14 16:52:40 | 001,746,324 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.06.14 15:27:55 | 000,000,277 | ---- | M] () -- C:\Users\S. Voß HUK\Documents\smoney_key.rtf
[2013.06.09 13:12:22 | 000,057,399 | ---- | M] () -- C:\Windows\wininit.ini
[2013.05.23 19:17:27 | 000,460,680 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[3 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.06.14 15:27:54 | 000,000,277 | ---- | C] () -- C:\Users\S. Voß HUK\Documents\smoney_key.rtf
[2013.05.23 19:17:16 | 000,460,680 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.02.15 10:53:22 | 000,110,592 | ---- | C] () -- C:\Windows\SysWow64\FsUsbExDevice.Dll
[2013.02.15 10:53:22 | 000,037,344 | ---- | C] () -- C:\Windows\SysWow64\FsUsbExDisk.Sys
[2012.12.28 11:18:12 | 000,000,017 | ---- | C] () -- C:\Users\S. Voß HUK\AppData\Local\resmon.resmoncfg
[2012.12.25 14:16:06 | 000,000,291 | ---- | C] () -- C:\Windows\game.ini
[2012.12.18 15:24:12 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2012.09.01 13:24:27 | 000,057,399 | ---- | C] () -- C:\Windows\wininit.ini
[2012.07.10 17:23:23 | 000,167,936 | ---- | C] () -- C:\Windows\SysWow64\SerialXP.dll
[2012.07.10 17:23:23 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\win32com.dll
[2012.07.10 15:33:09 | 000,000,827 | ---- | C] () -- C:\Windows\hbcikrnl.ini
[2012.06.26 16:02:40 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012.06.26 16:02:38 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012.06.26 16:02:38 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012.06.26 16:02:38 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012.06.26 16:02:38 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012.06.11 18:50:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.06.11 18:50:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.05.05 15:44:24 | 000,017,408 | ---- | C] () -- C:\Users\S. Voß HUK\AppData\Local\WebpageIcons.db
[2012.05.02 15:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010.03.20 01:05:19 | 000,131,472 | ---- | C] () -- C:\ProgramData\FullRemove.exe
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2012.09.14 15:28:50 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\4 Friends Games
[2011.04.25 09:42:14 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\AceBIT
[2010.12.22 18:40:11 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\AGFEO
[2012.12.15 15:19:20 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Alawar Stargaze
[2013.05.26 09:02:19 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\AlawarEntertainment
[2012.09.24 17:20:28 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\aliasworlds
[2012.12.17 11:24:00 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Amazon
[2010.08.24 15:37:55 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\AntiBrowserSpy 2009
[2012.12.23 14:54:14 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Artifex Mundi
[2013.01.13 15:06:24 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Artogon
[2012.11.19 20:46:30 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Ashampoo
[2012.10.18 15:43:32 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Az-Art
[2013.03.28 07:55:26 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\BlamGames
[2013.05.23 14:47:09 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Blue Tea Games
[2013.06.09 12:16:49 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Boomzap
[2011.07.15 13:31:15 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Canon
[2013.03.02 19:29:26 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\cerasus.media
[2013.04.25 14:38:27 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\DailyMagic
[2013.04.11 14:15:38 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Deep Shadows
[2013.05.05 12:36:37 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\DriverCure
[2013.05.18 14:54:48 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Eipix
[2013.02.13 15:42:01 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\EleFun Games
[2013.05.26 15:26:47 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Elephant Games
[2012.10.06 16:23:16 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Enki Games
[2013.06.02 14:32:44 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\ERS Game Studios
[2012.12.30 14:17:36 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Fenomen Games
[2013.02.10 14:43:37 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\FOP
[2013.02.06 16:57:09 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Friday's games
[2013.04.01 15:23:12 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Frogwares
[2012.09.15 12:30:26 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Fuzzy Bug Interactive
[2012.10.21 14:44:59 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Gogii
[2013.04.28 09:22:17 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Gogii Games
[2013.01.27 16:05:21 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\GrandMA Studios
[2012.01.31 13:59:41 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\IMSIDesign
[2013.03.03 15:01:32 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\JoyBits
[2010.08.24 19:51:07 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Leadertech
[2012.10.07 14:08:37 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\LegacyGames
[2012.10.03 15:32:52 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\MA2
[2012.10.01 15:06:22 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Mad Head Games
[2013.05.20 08:20:03 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\MagicIndie
[2012.09.26 17:26:34 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\MAGIX
[2013.04.14 13:19:11 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Mariaglorum
[2012.10.28 14:33:55 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\MumboJumbo
[2010.08.15 11:38:00 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\OEM
[2013.02.17 20:13:28 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Orneon
[2012.09.24 10:27:51 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\PeaceCraft3
[2011.12.30 15:26:05 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\PlayFirst
[2010.08.15 16:51:11 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\PowerCinema
[2013.02.09 19:55:29 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\ProtectDisc
[2012.11.15 10:52:40 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Samsung
[2012.09.16 10:29:39 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\simplitec
[2012.12.16 15:30:35 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Skunk Studios
[2012.09.07 15:35:12 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\SMIGames
[2013.05.05 12:36:37 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\SpeedMaxPc
[2013.06.14 17:38:38 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Steganos
[2012.09.25 19:12:43 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\TeamViewer
[2013.02.11 15:14:39 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\TOMI3
[2012.12.25 15:58:25 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Top Evidence
[2012.12.01 18:48:26 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\TuneUp Software
[2012.11.22 15:21:05 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\URSE Games
[2013.05.20 18:39:32 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Vast Studios
[2013.03.29 20:03:01 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\VendelGAMES
[2013.04.21 13:56:08 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\Vogat Interactive
[2012.10.07 19:16:58 | 000,000,000 | ---D | M] -- C:\Users\S. Voß HUK\AppData\Roaming\World-LooM
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 155 bytes -> C:\ProgramData\Temp:195E8317
@Alternate Data Stream - 155 bytes -> C:\ProgramData\Temp:02172F27
@Alternate Data Stream - 154 bytes -> C:\ProgramData\Temp:43F5FA9D
@Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:E6B95E40
@Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:3E8A3E87
@Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:0F64164E
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:AB689DEA
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:952245B1
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:84C34762
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:FFC3922F
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:F7BF538D
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:CE506F23
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:2CB9631F
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:FCBEDCFD
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:E265ED33
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:B61767F5
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:7BFFC6A9
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:5F56E7C1
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:5ECEFF17
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:1A8854EC
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:0410A323
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:B504E4C2
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:819394CC
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:6CF828C2
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:53BA2DF6
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:244E4E3A
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:A900C3A3
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:3F266659
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:0FD8569B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:869C6B4A
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:709E81D4
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:D987CB43
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:B6D84F71
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:5FC043A8
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:32AE8659
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:94A31742
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:7254CF01
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:401CAF8F
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:164561C8
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:000D6A25
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:F817E159
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:E36F5B57
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:D7D0B4AF
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:CBAF0C30
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:AC9F291E
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:32289BE8
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:EDE28CFC
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:BD34FFC5
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:8B3C3098
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:0C2A17F2
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:E6537A16
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:BF6A2C54
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:B139DDF3
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:94B25DF5
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:5D7E5A8F
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:B4530133
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:5E73E1C2
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:2AE74FF9
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:F68CB1A4
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:93DE1838
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:798A3728
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:54403233
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:512E1728
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:44712999
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:A88BE334
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:93EB7685
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:56699AAF
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:0B9176C0
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:E1F04E8D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:AABECEFB
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:A9ABA3FF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:8C12CFCD
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:254AD2ED
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:1FA4C06F
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:DF5C005A
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:B3A5945E
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:48862C37
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:0474F714
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:F3A185AE
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:DE875C30
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:2AC146B9
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:12258D63
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:F8DE80DB
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:C82CA1C0
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:8AC20936
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:4D066AD2
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:5453E5AF
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:5133A494
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:1E942FB9
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:E402E439
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:CE3AADB7
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:A9056F42
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:1B389835
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:01F9D1B4
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:E8AEB2BF
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:A13B696A
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:97AAB7F2
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:961B84C5
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:EBF0842B
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:D621CFB8
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:4A5CFD3B
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:E11D90D0
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:8B480195
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:206470A5
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:E5AF754F
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:A73595DE
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:363E775E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:2701CA70
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:C22674B6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:AECF4772
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:A4241298
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:6BEADDC0
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:24C072FF
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:11590865
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:10CB85CA
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:6A9CA6CB
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:A4E7D25F
@Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:774A0E14
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:BF6C4AAC
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:927EC486
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:6E2D80C8
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:E5BA9ADD
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:C368C9EA
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:B21F2857
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:8318A814
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:59A6876B
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:1A5822A3

< End of report >
         
Code:
ATTFilter
OTL Extras logfile created on: 14.06.2013 17:47:30 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\S. Voß HUK\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,93 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 60,03% Memory free
7,86 Gb Paging File | 6,29 Gb Available in Paging File | 80,12% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 458,87 Gb Total Space | 386,23 Gb Free Space | 84,17% Space Free | Partition Type: NTFS
Drive D: | 458,87 Gb Total Space | 456,39 Gb Free Space | 99,46% Space Free | Partition Type: NTFS
Drive K: | 931,28 Gb Total Space | 667,34 Gb Free Space | 71,66% Space Free | Partition Type: FAT32
Drive L: | 1863,01 Gb Total Space | 1793,28 Gb Free Space | 96,26% Space Free | Partition Type: NTFS
Drive M: | 931,51 Gb Total Space | 930,82 Gb Free Space | 99,93% Space Free | Partition Type: NTFS
 
Computer Name: BUERO | User Name: S. Voß HUK | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [CEWE FOTOSCHAU] -- "C:\Program Files (x86)\CEWE COLOR\Mein CEWE FOTOBUCH\CEWE FOTOSCHAU.exe" -d "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Fotoschau] -- "K:\Program Files (x86)\Pixum\Pixum Fotobuch\Fotoschau.exe" -d "%1" ()
Directory [Mein CEWE FOTOBUCH] -- "C:\Program Files (x86)\CEWE COLOR\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exe" "%1" ()
Directory [Pixum Fotobuch] -- "K:\Program Files (x86)\Pixum\Pixum Fotobuch\Pixum Fotobuch.exe" "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [CEWE FOTOSCHAU] -- "C:\Program Files (x86)\CEWE COLOR\Mein CEWE FOTOBUCH\CEWE FOTOSCHAU.exe" -d "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Fotoschau] -- "K:\Program Files (x86)\Pixum\Pixum Fotobuch\Fotoschau.exe" -d "%1" ()
Directory [Mein CEWE FOTOBUCH] -- "C:\Program Files (x86)\CEWE COLOR\Mein CEWE FOTOBUCH\Mein CEWE FOTOBUCH.exe" "%1" ()
Directory [Pixum Fotobuch] -- "K:\Program Files (x86)\Pixum\Pixum Fotobuch\Pixum Fotobuch.exe" "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UacDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirstRunDisabled" = 0
"UacDisableNotify" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0CC16866-7415-4D57-9492-CB56E27C8E46}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{14BEDC3C-E871-4671-AB13-F296C8612040}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{18E49729-07DE-4079-B7D9-3B8305CCB431}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{1BD3BF3D-86ED-4CD2-A799-2CF69E883D3A}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{25254ABE-EFB1-4B50-9DC6-B0377D545553}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{278342F0-155A-4C74-825B-001D80391D3F}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{365CA878-DADF-4A77-8286-052F88F8CAF4}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{4521A7AC-A5AE-45B8-885E-25BA03AB4BEE}" = rport=137 | protocol=17 | dir=out | app=system | 
"{6A1E95F8-74C6-4347-BC3E-9A5F980208E8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{6CB9B534-53E2-40B7-A352-375713E94AF1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{719D62B5-ED15-42CC-A05A-33561FF01669}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{79CF02F3-F218-4E75-890C-AD653511B5D0}" = lport=445 | protocol=6 | dir=in | app=system | 
"{81BE7DD5-F835-4AC3-B6E0-1929B0C050CF}" = rport=138 | protocol=17 | dir=out | app=system | 
"{84A90717-5E5A-496D-A264-4C9ED7D48970}" = lport=137 | protocol=17 | dir=in | app=system | 
"{8A02ED68-8808-43E6-98DA-79BE99BD2DEE}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{9862430D-67AD-4C00-827D-41619952CC3E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{A3406086-B49B-4F47-B1AE-AF4E1710541F}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{B5017374-B68E-4B0C-8B52-AEF2D6B1C4A9}" = rport=139 | protocol=6 | dir=out | app=system | 
"{BAD45F3F-FEB5-45C7-85CD-CDE0220E072B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{BBE83C93-AD86-4E6E-BC58-44EA371B4638}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{C5502A75-443C-41C5-AB6B-EF871353945A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{C77E9F85-5E5C-4FA6-BCA4-A90DB11A8758}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | 
"{C8735A05-25E1-4D8E-896E-D6629C1AF9AD}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{C92A92BB-8DD8-45B6-835E-2BE65E80D305}" = rport=445 | protocol=6 | dir=out | app=system | 
"{E00C9ED6-D267-4D4D-AA6D-13186E0C2448}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{E0C6DAFD-9DF3-4A53-88C0-31C46E77811E}" = lport=139 | protocol=6 | dir=in | app=system | 
"{E4BAA152-A5CD-46E5-92D7-828A4328309B}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 | 
"{ED23BF2A-B863-44BC-8607-77619ED66D68}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{EFC6A029-1F83-4CB4-AADA-F9334CA9F41E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{F8640D0F-8EEB-4EF8-AD7F-09164E9E74B8}" = lport=138 | protocol=17 | dir=in | app=system | 
"{FE174412-58D4-4F73-AFE5-7F8E418EF9CC}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00BE4E82-947B-4F56-8497-A06E362A79C0}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | 
"{062EC9A7-EEA3-484A-92A1-4C9C0B0FDCED}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\homemedia\homemedia.exe | 
"{0F15739C-A145-4A16-900A-454A28BBA36D}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe | 
"{12C0DE5D-7A7A-4F27-A1A2-8D2171C12E6E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{1913DB34-DE75-4195-8440-D230D5D8E8BD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{220A4944-1ACA-4A67-87A9-5C6AA60D3E0A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{245CD60E-0F08-421E-B041-D1C88A1A4336}" = protocol=6 | dir=in | app=c:\users\s. voss huk\appdata\local\apps\2.0\5kmzqm8r.l9g\p314ae5j.zwe\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe | 
"{261A9459-637D-4F31-9E22-8082C610EBC7}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{2C75E379-2553-46A2-A6D3-C7C5FF21B7BC}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{31EEFF76-F298-40A4-8500-B970CCF04751}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{33470128-02E3-49A6-BFAD-61730CD8A596}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{35A21D43-D790-4BFF-863D-C8E5F86FF2EF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{35E2E4AD-5C55-4047-849F-6C0C340870C8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{438B7257-CBAB-4DFB-BED6-9823CDA39996}" = protocol=17 | dir=in | app=c:\users\s. voss huk\appdata\local\apps\2.0\5kmzqm8r.l9g\p314ae5j.zwe\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe | 
"{5134EFE3-948C-4220-84F4-052BC8BCD63D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{5283A62C-CD5E-4D42-A52E-DB65879389BB}" = protocol=17 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\app\starmoney.exe | 
"{59BBE1D4-F7DB-46ED-9936-1CBA97828D99}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{5A2D9600-30ED-459D-90A6-00BFA293B031}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe | 
"{80E9A385-EB72-43A1-A460-53D9386C7CD9}" = protocol=17 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\ouservice\starmoneyonlineupdate.exe | 
"{852FE4CA-E466-48C0-9EE7-502719107B6C}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe | 
"{88C58252-FB4C-4E53-9CBF-0A8F1EF96C30}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{9AFD0FFF-16DE-4A97-8F52-291BEA86BE28}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{A363DEE9-5558-4443-9F94-113890D88989}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | 
"{B55B064A-6EC2-41A1-AD23-9E9BC0962D3C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{B633BDE0-AF39-475B-90D5-B3D92F0FBC0C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B676F240-613A-4716-BF7C-34EB5038F29E}" = protocol=6 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\ouservice\starmoneyonlineupdate.exe | 
"{B8441ED8-5D1D-4D5D-91F8-95BDEEE2C742}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{B93E6A19-B3E4-452F-8230-AF2F5675AD32}" = protocol=6 | dir=out | app=system | 
"{BF6C8DF2-C3FE-4036-B898-3373BA41E620}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{C583E380-A49A-4589-A0ED-F684A568D418}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{C77EF856-6C61-4836-95A9-554F9BA2797B}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | 
"{CDACD4C6-1DFE-4185-840F-9F52673073F6}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{CEE3C10E-4758-4A63-961C-79DC6131C020}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{D256C440-8BEB-4C11-A8CA-2219A57099B1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{D30E36DC-0C3F-49AB-A2A1-284EE1BC2676}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | 
"{E6B5E6C7-49F7-4E29-9A73-159C89F968C6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{EDA85143-2B82-49C0-A1D3-BC0ADE71F1BF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{FA482814-9BC1-4E5C-99CD-7909B162B5BA}" = protocol=6 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\app\starmoney.exe | 
"{FD0145A2-C053-4B5E-92DA-E236C7E111DB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX870_series" = Canon MX870 series MP Drivers
"{12D93D02-3C15-DF08-581F-52E4A1EB0A3D}" = AMD Drag and Drop Transcoding
"{18A5D014-E9AD-DEFE-FAFE-A409612F51B4}" = AMD Media Foundation Decoders
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{1FBEA8BA-D40B-48BC-85BC-EE2D5575F27C}" = Microsoft SQL Server VSS Writer
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{50BD00DC-127E-BF00-FDD5-E1A93AB3507C}" = ccc-utility64
"{567571C7-7156-48D9-A8D0-C88B8E85F0F4}" = TMS 5.1 SP1 Client
"{57F4B170-E76D-47F9-B6BA-F3D4FB7445B6}" = MAGIX Fotos auf DVD 2013 Deluxe
"{5A2C499A-B689-4CF4-8441-DD659164B939}" = MAGIX Speed burnR (MSI)
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile-Gerätecenter
"{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}" = Bing Maps 3D
"{7C39E0D1-E138-42B1-B083-213EC2CF7692}" = Microsoft SQL Server Native Client
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A1233BA3-F715-4604-A04A-248268369B04}" = Fotos auf DVD 2013 Deluxe Update
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BB009B20-0BA0-ABDF-1947-4D56639214C7}" = AMD Accelerated Video Transcoding
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DDA8FE2D-EA67-194C-D6A5-F52BC4FDA20F}" = ATI AVIVO64 Codecs
"{E85D1C80-28C4-76B8-5A5A-2C8D8B38D5D9}" = AMD Catalyst Install Manager
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"SP6" = Logitech SetPoint 6.15
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00B52299-F42A-40C3-8232-F987B86E3FD6}_is1" = Die Legende von Pocahontas
"{028ED9C4-25EE-4DEE-9CF4-91034BC89B18}" = Microsoft SQL Server 2005 Express Edition (SQLHUK)
"{02CF7793-9F94-45E9-BB0F-E0E5FAB463E6}_is1" = Romance of Rome
"{03AEAB60-A7B3-A8DB-468B-EB30FB4B40B0}" = CCC Help German
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{162ABED6-E60C-6CFF-100E-43C16ABBC5BE}" = CCC Help Chinese Standard
"{178E1C48-ECB1-4A3D-9EB9-B6B55AEDC2F5}" = VISonline Diagnose
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1CB724FF-D18C-8FFB-E7C9-0A09CF8EC066}" = CCC Help Japanese
"{1FCBD504-AB7D-4757-9A14-850348384B08}" = StarMoney
"{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{20C14CC3-5E3B-D39A-5B37-B15E59785063}" = CCC Help Chinese Traditional
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
"{2632A2C0-ECF4-7F79-7136-9FEA4C253A4C}" = CCC Help Turkish
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{29258311-EA49-11DE-967C-005056C00008}" = Paragon Festplatten Manager™ 2011 Kompakt
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie
"{30F712DA-64FE-5DBE-AE76-3F8EA3F8223C}" = CCC Help French
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C39B3CC-4EC8-C756-AF4B-72366504FCA5}" = CCC Help Hungarian
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{44AED858-95E2-43DE-BFF2-7DB35A27AB53}" = The Curse Of Ra
"{4968622A-4D3F-489E-9ACE-5FEC4CC0BDE3}" = MediaShow Espresso
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CC9D761-A9B6-D8EA-D2A9-B74B5A90B108}" = CCC Help Norwegian
"{4D43D635-6FDA-4FA5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{54B227A6-BDBE-69FA-D450-B99609063044}" = CCC Help Greek
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5A6DB7C1-E646-4842-A562-49C5EB8F2B47}" = StarMoney
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{62F7DA7E-CCCB-439C-A760-00C3926E761F}" = Microsoft Works
"{66815B84-05B8-4FA3-AACA-3E7C434F78B8}_is1" = Password Depot 5
"{67565ee8-222f-4073-933e-a2b9ab033e49}" = Nero 9 Essentials
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6C5F8503-55D2-4398-858C-362B7A7AF51C}" = Firebird SQL Server - MAGIX Edition
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72FD9E53-73D1-4FC3-98DB-7889FD119946}_is1" = freundin - Mystery Tales 2
"{73063172-E55E-405D-8E46-B9B666604FDC}" = LWP_eToken_Client
"{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{7b7e564b-0c70-4506-9ab6-b7a2044425ab}" = Gigaset QuickSync
"{7C587778-C433-980E-F3C1-203890DC4FBE}" = CCC Help Polish
"{7DC3EABF-66A2-6D79-B485-6328525CA387}" = CCC Help Swedish
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}" = Chicken Invaders 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}" = Spin & Win
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697}" = Granny In Paradise
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}" = Dream Day First Home
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}" = Dairy Dash
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}" = Farm Frenzy 2
"{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
"{843603C6-75B7-BAB5-80DE-E76FB28DEEF2}" = CCC Help Finnish
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8D9EEAC7-42D5-3951-612A-EAA7B684C592}" = CCC Help Italian
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0407-1000-0000000FF1CE}_Office14.SingleImage_{594128C9-2CDF-43CE-8103-DC100CF013B6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{95381165-5D16-4CD4-9162-57799A3F3AB5}" = PCLinq2 High-Speed USB Bridge Cable
"{9791DAED-B734-2835-988B-157BDA087496}" = CCC Help Dutch
"{98B740C3-FAA4-C523-7478-4DBCAB7B27D1}" = Catalyst Control Center Graphics Previews Common
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A38A0A7-177F-4D21-9E86-ACDF732B1150}" = HUK-COBURG Angebotssoftware VISonline
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F0CAC6D-9B0D-A95F-CF61-6E88952D6181}" = CCC Help Thai
"{9F5FD796-86F0-4360-85F8-D54C0F5411EB}" = Steuer-Spar-Erklärung 2011
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A58E2F1D-5766-43AE-803E-37B7F99931FB}" = VIS Aktualisierung
"{A625DB70-98D5-16FD-C49D-4B8B1B2304A4}" = CCC Help Spanish
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A90214C3-3A0C-2F05-6083-E1A4BAD9E30D}" = CCC Help Danish
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA123216-6DE0-E57C-DC57-4FECEACB482F}" = CCC Help Russian
"{ABEE079E-648E-488B-8301-0C3DB48C1BCE}_is1" = Acer GameZone Console
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.02) - Deutsch
"{AE395AC2-28CB-463F-87DC-00C8059781BF}" = 7Artifacs
"{AEB61F7A-4BBA-4292-A096-7893E09034A4}" = Steuer-Spar-Erklärung 2013
"{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}" = AAVUpdateManager
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B63DFA23-5C10-44B4-881D-45EFBF4A4761}" = MAGIX Screenshare
"{B906C11A-D193-4143-9FA7-E2EE8A5A8F21}" = Acer Arcade Movie
"{BAF19BB1-7716-4F37-5C47-E9DD9A70BC0F}" = Catalyst Control Center InstallProxy
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BE5D79E8-0B8E-4E97-97E1-3CDEBAB2DEB1}" = Sven XXX - XXL
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help
"{CCD2BAD2-0919-40CB-80CC-E9538B0E4C2E}" = Steuer-Spar-Erklärung 2012
"{D0837A59-83E6-3392-1BD9-86D3445676DB}" = CCC Help Korean
"{D70AB273-113B-D7DE-5C8D-82CABA7CB0AF}" = Catalyst Control Center Localization All
"{DC8772D4-C75F-5235-63E2-BBC73F909B7A}" = CCC Help Czech
"{DCF0739A-23F1-4E7A-A538-AC4580B28F55}" = Shrek(R) SuperSlam
"{DED7FD3C-DDD2-43BB-B0F5-B07F9D0430D3}" = CCC Help Portuguese
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}" = eBay Worldwide
"{E157F2EB-E06F-B57F-9105-68F348DB2EAD}" = CCC Help English
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E2F2B987-F2BC-4969-95F2-92099486B811}" = StarMoney
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{EC36B80D-3A0B-44D2-A066-9F346FE05D54}" = TurboFLOORPLAN Garten- & Landschaftsarchitekt
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EF036F44-A287-BC23-3F6E-AAE6FDEF47EF}" = Catalyst Control Center InstallProxy
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{F902AB2B-7816-4CBD-A385-F2549F62956B}" = StarMoney
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"{FBF2527B-5904-49EE-A420-F2827AE55681}" = StarMoney 8.0 S-Edition
"{FC338210-F594-11D3-BA24-00001C3AB4DF}" = cyberJack Base Components
"3D Wohnungsplaner 10_is1" = DATA BECKER 3D Wohnungsplaner 10
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.17
"Ashampoo Burning Studio 2013_is1" = Ashampoo Burning Studio 2013 v.11.0.5
"BFG-Awakening - Das Himmelsschloss Sammleredition" = Awakening: Das Himmelsschloss Sammleredition
"BFGC" = Big Fish Games: Game Manager
"BFG-Chimeras - Melodie der Rache Sammleredition" = Chimeras: Melodie der Rache Sammleredition
"BFG-Detective Quest - Der glaeserne Schuh Sammleredition" = Detective Quest: Der gläserne Schuh Sammleredition
"BFG-Farmington Tales" = Farmington Tales
"BFG-Phantasmat - Eisiger Gipfel" = Phantasmat: Eisiger Gipfel
"BFG-Sable Maze - Sullivan River" = Sable Maze: Sullivan River
"BFG-Sacra Terra - Der Kuss des Todes" = Sacra Terra: Der Kuss des Todes
"BFG-Sacra Terra - Der Kuss des Todes Sammleredition" = Sacra Terra: Der Kuss des Todes, Sammleredition
"BFG-Spirits of Mystery - Der dunkle Minotaurus Sammleredition" = Spirits of Mystery: Der dunkle Minotaurus Sammleredition
"BFG-The Beast of Lycan Isle" = The Beast of Lycan Isle
"BFG-The Saint - Abgrund der Verzweiflung" = The Saint: Abgrund der Verzweiflung
"BFG-Time Mysteries - Das letzte Raetsel" = Time Mysteries: Das letzte Rätsel
"BFG-Time Mysteries - Das letzte Raetsel Sammleredition" = Time Mysteries: Das letzte Rätsel Sammleredition
"BFG-Toedliche Sonate - Ein Dana Knightstone-Roman" = Tödliche Sonate: Ein Dana Knightstone-Roman
"BFG-Unfinished Tales - Unsterbliche Liebe" = Unfinished Tales: Unsterbliche Liebe
"BFG-Unfinished Tales - Unsterbliche Liebe Sammleredition" = Unfinished Tales: Unsterbliche Liebe Sammleredition
"BFG-Verbotene Geheimnisse - Alien Town" = Verbotene Geheimnisse: Alien Town
"BFG-Web of Deceit - Die Schwarze Witwe Sammleredition" = Web of Deceit: Die Schwarze Witwe Sammleredition
"Briefe aus dem Jenseits" = Briefe aus dem Jenseits
"Canon MX870 series Benutzerregistrierung" = Canon MX870 series Benutzerregistrierung
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Casual Games" = Casual Games 1 
"Coffee Break PacMan" = Coffee Break PacMan
"Color Eggs II" = Color Eggs II
"Das Vermächtnis der Insel" = Das Vermächtnis der Insel
"Deep Blue Sea – Die Schatztaucherin_is1" = Deep Blue Sea – Die Schatztaucherin
"DEUTSCHLAND SPIELT Spiele Post" = DEUTSCHLAND SPIELT Spiele Post
"Diamond Drop (VOLLVERSION)" = Diamond Drop (VOLLVERSION)
"Dino & Aliens" = Dino & Aliens
"DSGPlayer" = DEUTSCHLAND SPIELT GAME CENTER
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Geheime Fälle: Die gestohlene Venus 2" = Geheime Fälle: Die gestohlene Venus 2
"HaaliMkx" = Haali Media Splitter
"Hotkey Utility" = Hotkey Utility
"Hühner-Attacke (VOLLVERSION)" = Hühner-Attacke (VOLLVERSION)
"Hühner-Rache" = Hühner-Rache
"I Have No Tomatoes" = I Have No Tomatoes v1.5
"Identity Card" = Identity Card
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{DCF0739A-23F1-4E7A-A538-AC4580B28F55}" = Shrek(R) SuperSlam
"InstallShield_{EC36B80D-3A0B-44D2-A066-9F346FE05D54}" = TurboFLOORPLAN Garten- & Landschaftsarchitekt
"Jäger des Geisterhauses_is1" = Jäger des Geisterhauses
"Kalender-Excel-8.7.1_is1" = Kalender-Excel-8.7.1
"Kalender-Excel-8.9_is1" = Kalender-Excel-8.9
"Love Over Death" = Love Over Death
"Mad Cars" = Mad Cars
"Magic Ball 2" = Magic Ball 2
"MAGIX_{57F4B170-E76D-47F9-B6BA-F3D4FB7445B6}" = MAGIX Fotos auf DVD 2013 Deluxe
"MAGIX_{5A2C499A-B689-4CF4-8441-DD659164B939}" = MAGIX Speed burnR (MSI)
"Mein CEWE FOTOBUCH" = Mein CEWE FOTOBUCH
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"MP Navigator EX 3.1" = Canon MP Navigator EX 3.1
"MyMDb_0" = MyMDb 3.6
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Pixum Fotobuch" = Pixum Fotobuch
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"Rasputins Curse" = Rasputins Curse
"Robinson Crusoe and the Cursed Pirates" = Robinson Crusoe and the Cursed Pirates
"Santa Hanta_is1" = Santa Hanta 2.4c
"Secret Diaries: Florence Ashford" = Secret Diaries: Florence Ashford
"secrets of tahiti" = secrets of tahiti
"Shadow Wolf Mysteries Bane of the Family_is1" = Shadow Wolf Mysteries Bane of the Family de
"Speed Dial Utility" = Canon Kurzwahlprogramm
"Super Puzzle" = Super Puzzle
"The Mystery of the Crystal Portal - Die versunkene Welt" = The Mystery of the Crystal Portal - Die versunkene Welt
"tksuite_tksuite_server" = AGFEO TK-Suite Server
"Tory's Shop'n' Rush" = Tory's Shop'n' Rush
"Verschleierte Wirklichkeit" = Verschleierte Wirklichkeit
"WinLiveSuite_Wave3" = Windows Live Essentials
"Wondershare Vivideo_is1" = Wondershare Vivideo(Build 2.0.0.12)
"Zoo Safari_is1" = Zoo Safari
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Protect Disc License Helper" = Protect Disc License Helper 1.0.125 (IE)
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Protect Disc License Helper" = Protect Disc License Helper 1.0.125 (IE)
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-210379488-4132890845-1450444768-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f018cf21c0452c64" = AVM FRITZ!Box USB-Fernanschluss
"MyFreeCodec" = MyFreeCodec
"Protect Disc License Helper" = Protect Disc License Helper 1.0.125 (IE)
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 25.05.2013 12:08:57 | Computer Name = Buero | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16576,
 Zeitstempel: 0x515e30fe  Name des fehlerhaften Moduls: pdIEAddOn.dll, Version: 5.3.0.0,
 Zeitstempel: 0x4d8b468d  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00004f5a  ID des fehlerhaften
 Prozesses: 0x120c  Startzeit der fehlerhaften Anwendung: 0x01ce59612a71aedb  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE  Pfad
 des fehlerhaften Moduls: C:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll
Berichtskennung:
 66de7529-c555-11e2-b5ad-90fba6e09548
 
Error - 26.05.2013 09:25:54 | Computer Name = Buero | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16576,
 Zeitstempel: 0x515e30fe  Name des fehlerhaften Moduls: pdIEAddOn.dll, Version: 5.3.0.0,
 Zeitstempel: 0x4d8b468d  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00004f5a  ID des fehlerhaften
 Prozesses: 0xea4  Startzeit der fehlerhaften Anwendung: 0x01ce5a0aacad2058  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE  Pfad
 des fehlerhaften Moduls: C:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll
Berichtskennung:
 ca1f4e87-c607-11e2-b5ad-90fba6e09548
 
Error - 26.05.2013 13:00:47 | Computer Name = Buero | Source = Windows Backup | ID = 4104
Description = 
 
Error - 30.05.2013 12:16:47 | Computer Name = Buero | Source = Application Hang | ID = 1002
Description = Programm IEXPLORE.EXE, Version 10.0.9200.16576 kann nicht mehr unter
 Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf 
in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
 zu suchen.    Prozess-ID: 23b4    Startzeit: 01ce5d4e1f317c1c    Endzeit: 15    Anwendungspfad:
 C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE    Berichts-ID:   
 
Error - 02.06.2013 08:53:11 | Computer Name = Buero | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: HauntedLegends_TheUndertakerCE_RC.exe,
 Version: 0.0.0.0, Zeitstempel: 0x51234949  Name des fehlerhaften Moduls: unknown,
 Version: 0.0.0.0, Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 
0x1c20674a  ID des fehlerhaften Prozesses: 0x3d94  Startzeit der fehlerhaften Anwendung:
 0x01ce5f8d47bea427  Pfad der fehlerhaften Anwendung: K:\Program Files (x86)\Haunted
 Legends - Der Bestatter\HauntedLegends_TheUndertakerCE_RC.exe  Pfad des fehlerhaften
 Moduls: unknown  Berichtskennung: 61244ad3-cb83-11e2-b5ad-90fba6e09548
 
Error - 02.06.2013 13:00:52 | Computer Name = Buero | Source = Windows Backup | ID = 4104
Description = 
 
Error - 05.06.2013 17:40:10 | Computer Name = Buero | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16576,
 Zeitstempel: 0x515e30fe  Name des fehlerhaften Moduls: pdIEAddOn.dll, Version: 5.3.0.0,
 Zeitstempel: 0x4d8b468d  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00004f5a  ID des fehlerhaften
 Prozesses: 0x1118  Startzeit der fehlerhaften Anwendung: 0x01ce62334908731f  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE  Pfad
 des fehlerhaften Moduls: C:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll
Berichtskennung:
 7ec8b21a-ce28-11e2-b5ad-90fba6e09548
 
Error - 06.06.2013 07:11:28 | Computer Name = Buero | Source = Application Hang | ID = 1002
Description = Programm StarMoney.exe, Version 3.0.6.31 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 47a8    Startzeit:
 01ce62a625b60d5e    Endzeit: 0    Anwendungspfad: C:\Program Files (x86)\StarMoney 8.0 
S-Edition\app\StarMoney.exe    Berichts-ID:   
 
Error - 06.06.2013 08:17:06 | Computer Name = Buero | Source = Software Protection Platform Service | ID = 8200
Description = Lizenzerwerb-Fehlerdetails.   hr=0xC004C32A
 
Error - 06.06.2013 08:17:06 | Computer Name = Buero | Source = Software Protection Platform Service | ID = 8208
Description = Fehler bei der Erfassung des authentischen Tickets (hr=0xC004C32A)
 für die Vorlagen-ID 66c92734-d682-4d71-983e-d6ec3f16059f.
 
Error - 09.06.2013 13:00:50 | Computer Name = Buero | Source = Windows Backup | ID = 4104
Description = 
 
[ Cisco AnyConnect Secure Mobility Client Events ]
Error - 14.06.2013 11:11:58 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: Directory::ReadDir File: .\Utility\Directory.cpp Line: 156
Invoked
 Function: ::FindNextFile Return Code: 18 (0x00000012) Description: Es sind keine 
weiteren Dateien vorhanden.   
 
Error - 14.06.2013 11:11:58 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: PluginLoader::QuickCreatePlugin File: c:\temp\build\thehoff\DaVinci_MR20.640871216917\DaVinci_MR2\vpn\Common\Utility/PluginLoader.h
Line:
 145 Invoked Function: PluginLoader::CreateInstance Return Code: -29294580 (0xFE41000C)
Description:
 PLUGINLOADER_ERROR_COULD_NOT_CREATE 
 
Error - 14.06.2013 11:11:58 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: PluginLoader::QuickCreatePlugin File: c:\temp\build\thehoff\DaVinci_MR20.640871216917\DaVinci_MR2\vpn\Common\Utility/PluginLoader.h
Line:
 145 Invoked Function: PluginLoader::CreateInstance Return Code: -29294580 (0xFE41000C)
Description:
 PLUGINLOADER_ERROR_COULD_NOT_CREATE 
 
Error - 14.06.2013 11:11:58 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: PluginLoader::QuickCreatePlugin File: c:\temp\build\thehoff\DaVinci_MR20.640871216917\DaVinci_MR2\vpn\Common\Utility/PluginLoader.h
Line:
 145 Invoked Function: PluginLoader::CreateInstance Return Code: -29294580 (0xFE41000C)
Description:
 PLUGINLOADER_ERROR_COULD_NOT_CREATE 
 
Error - 14.06.2013 11:12:00 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: ProfileMgr::loadProfile File: .\ProfileMgr.cpp Line: 518 Invoked
 Function: ProfileMgr::loadProfile Return Code: -33554423 (0xFE000009) Description:
 GLOBAL_ERROR_UNEXPECTED Duplicate host <vpngw3.huk-coburg.de> found in the profile
 <C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Profile\prfVTP.xml>.
 Host discarded.
 
Error - 14.06.2013 11:12:00 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: CIPv4ChangeRouteHelper::FindBestRoute File: .\IPv4ChangeRouteHelper.cpp
Line:
 2624 Invoked Function: CIPv4RouteTable::FindMatchingRoute Return Code: -33095647 
(0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 14.06.2013 11:12:00 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: CRouteMgr::UpdatePublicAddress File: .\RouteMgr.cpp Line: 
2182 Invoked Function: CChangeRouteTable::FindBestRouteInterface Return Code: -33095647
 (0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 14.06.2013 11:12:00 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::applyHostConfigForNoVpn File: .\MainThread.cpp
Line:
 8405 Invoked Function: CHostConfigMgr::DeterminePublicInterface Return Code: -33095647
 (0xFE070021) Description: ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 14.06.2013 11:12:00 | Computer Name = Buero | Source = acvpnagent | ID = 67108866
Description = Function: CMainThread::MainLoop File: .\MainThread.cpp Line: 379 Invoked
 Function: CMainThread::applyHostConfigForNoVpn Return Code: -33095647 (0xFE070021)
Description:
 ROUTETABLE_ERROR_GETBESTROUTE_FAILED 
 
Error - 14.06.2013 11:36:45 | Computer Name = Buero | Source = acvpnagent | ID = 67110873
Description = Termination reason code 7: The agent has been stopped.
 
[ System Events ]
Error - 14.06.2013 11:12:37 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:12:48 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:12:48 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:42:01 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:42:37 | Computer Name = Buero | Source = Ntfs | ID = 262281
Description = Auf dem Volume "L:" konnte der Transaktionsressourcen-Manager aufgrund
 eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in
 den Daten enthalten.
 
Error - 14.06.2013 11:42:47 | Computer Name = Buero | Source = Microsoft-Windows-BitLocker-Driver | ID = 24620
Description = Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf
 "\\?\Volume{9ae5ce6b-7702-11dc-9bbd-806e6f6e6963}" können nicht gelesen werden.
 
Error - 14.06.2013 11:42:47 | Computer Name = Buero | Source = Microsoft-Windows-BitLocker-Driver | ID = 24620
Description = Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf
 "\\?\Volume{9ae5ce6c-7702-11dc-9bbd-806e6f6e6963}" können nicht gelesen werden.
 
Error - 14.06.2013 11:43:27 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:43:38 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
Error - 14.06.2013 11:43:38 | Computer Name = Buero | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name
 Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet 
wurde:   %%1058
 
 
< End of report >
         
Code:
ATTFilter
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-06-15 12:18:47
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD10 rev.80.0 931,51GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\SDBC1~1.VOH\AppData\Local\Temp\fgldqpob.sys


---- User code sections - GMER 2.1 ----

.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[1992] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69                 0000000076ee1465 2 bytes [EE, 76]
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[1992] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155                0000000076ee14bb 2 bytes [EE, 76]
.text   ...                                                                                                                                                * 2
.text   C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe[1280] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   0000000076ee1465 2 bytes [EE, 76]
.text   C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe[1280] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  0000000076ee14bb 2 bytes [EE, 76]
.text   ...                                                                                                                                                * 2
.text   C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3244] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint                         0000000077de000c 1 byte [C3]
.text   C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3244] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin                    0000000077e6f85a 5 bytes JMP 0000000177e1d571
.text   C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe[3356] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                         0000000076ee1465 2 bytes [EE, 76]
.text   C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe[3356] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                        0000000076ee14bb 2 bytes [EE, 76]
.text   ...                                                                                                                                                * 2

---- User IAT/EAT - GMER 2.1 ----

IAT     C:\Windows\Explorer.EXE[2720] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!FreeLibraryAndExitThread]                                             [10002350] C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll
IAT     C:\Windows\Explorer.EXE[2720] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!CreateThread]                                                         [10003450] C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll
IAT     C:\Windows\Explorer.EXE[2720] @ C:\Windows\system32\SHELL32.dll[KERNEL32.dll!LoadLibraryA]                                                         [100011e0] C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll

---- Threads - GMER 2.1 ----

Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1828]                                                            0000000077e23e45
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1844]                                                            0000000077e22e25
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1928]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1932]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1936]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1940]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1944]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1948]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1952]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1964]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1968]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1972]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1196]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1244]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:1276]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2092]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2096]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2100]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2104]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2108]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2112]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2116]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2120]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2124]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2128]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2132]                                                            0000000077e23e45
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2136]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2140]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2144]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2148]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2152]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2332]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2436]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2980]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2984]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:2988]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:3984]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:3988]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:3992]                                                            0000000073be29e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [1788:3996]                                                            0000000073be29e1
Thread  C:\Windows\System32\svchost.exe [4252:792]                                                                                                         000007fef1f89688

---- EOF - GMER 2.1 ----
         

Alt 15.06.2013, 11:48   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



hi,

zusätzlich bitte noch das:

Downloade dir bitte Farbar's MiniToolBox auf deinen Desktop und starte das Tool

Setze einen Haken bei folgenden Einträgen
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset IE Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size
  • List Minidump Files
Klicke Go und poste den Inhalt der Result.txt.


Systemscan mit FRST
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Scan.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)
__________________

__________________

Alt 15.06.2013, 13:51   #3
Bambaataa22
 
Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Danke, dass du mir hilfst!

MiniToolBox:

Code:
ATTFilter
MiniToolBox by Farbar  Version:21-04-2013
Ran by S. Voß HUK (administrator) on 15-06-2013 at 14:33:16
Running from "C:\Users\S. Voß HUK\Desktop"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows-IP-Konfiguration

Der DNS-Aufl”sungscache wurde geleert.

========================= IE Proxy Settings: ============================== 

Proxy is not enabled.
ProxyServer: 10.149.137.1:8080

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================

#	::1             localhost

========================= IP Configuration: ================================

Realtek PCIe GBE Family Controller = LAN-Verbindung (Connected)


# ----------------------------------
# IPv4-Konfiguration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# Ende der IPv4-Konfiguration



Windows-IP-Konfiguration

   Hostname  . . . . . . . . . . . . : Buero
   Prim„res DNS-Suffix . . . . . . . : 
   Knotentyp . . . . . . . . . . . . : Hybrid
   IP-Routing aktiviert  . . . . . . : Nein
   WINS-Proxy aktiviert  . . . . . . : Nein
   DNS-Suffixsuchliste . . . . . . . : fritz.box

Ethernet-Adapter LAN-Verbindung:

   Verbindungsspezifisches DNS-Suffix: fritz.box
   Beschreibung. . . . . . . . . . . : Realtek PCIe GBE Family Controller
   Physikalische Adresse . . . . . . : 90-FB-A6-E0-95-48
   DHCP aktiviert. . . . . . . . . . : Ja
   Autokonfiguration aktiviert . . . : Ja
   Verbindungslokale IPv6-Adresse  . : fe80::7816:e8ea:2bcb:5128%10(Bevorzugt) 
   IPv4-Adresse  . . . . . . . . . . : 192.168.178.20(Bevorzugt) 
   Subnetzmaske  . . . . . . . . . . : 255.255.255.0
   Lease erhalten. . . . . . . . . . : Freitag, 14. Juni 2013 17:42:47
   Lease l„uft ab. . . . . . . . . . : Montag, 24. Juni 2013 17:42:47
   Standardgateway . . . . . . . . . : 192.168.178.1
   DHCP-Server . . . . . . . . . . . : 192.168.178.1
   DHCPv6-IAID . . . . . . . . . . . : 235728614
   DHCPv6-Client-DUID. . . . . . . . : 00-01-00-01-0E-9E-3A-02-90-FB-A6-E0-95-48
   DNS-Server  . . . . . . . . . . . : 192.168.178.1
   NetBIOS ber TCP/IP . . . . . . . : Aktiviert

Tunneladapter isatap.siemens:

   Medienstatus. . . . . . . . . . . : Medium getrennt
   Verbindungsspezifisches DNS-Suffix: 
   Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter
   Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP aktiviert. . . . . . . . . . : Nein
   Autokonfiguration aktiviert . . . : Ja

Tunneladapter Teredo Tunneling Pseudo-Interface:

   Medienstatus. . . . . . . . . . . : Medium getrennt
   Verbindungsspezifisches DNS-Suffix: 
   Beschreibung. . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP aktiviert. . . . . . . . . . : Nein
   Autokonfiguration aktiviert . . . : Ja
Server:  fritz.box
Address:  192.168.178.1

Name:    google.com
Addresses:  2a00:1450:4001:809::1008
	  173.194.113.40
	  173.194.113.41
	  173.194.113.46
	  173.194.113.32
	  173.194.113.33
	  173.194.113.34
	  173.194.113.35
	  173.194.113.36
	  173.194.113.37
	  173.194.113.38
	  173.194.113.39


Ping wird ausgefhrt fr google.com [173.194.113.40] mit 32 Bytes Daten:
Antwort von 173.194.113.40: Bytes=32 Zeit=38ms TTL=54
Antwort von 173.194.113.40: Bytes=32 Zeit=40ms TTL=54

Ping-Statistik fr 173.194.113.40:
    Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0
    (0% Verlust),
Ca. Zeitangaben in Millisek.:
    Minimum = 38ms, Maximum = 40ms, Mittelwert = 39ms
Server:  fritz.box
Address:  192.168.178.1

Name:    yahoo.com
Addresses:  98.138.253.109
	  98.139.183.24
	  206.190.36.45


Ping wird ausgefhrt fr yahoo.com [98.138.253.109] mit 32 Bytes Daten:
Antwort von 98.138.253.109: Bytes=32 Zeit=172ms TTL=49
Antwort von 98.138.253.109: Bytes=32 Zeit=167ms TTL=49

Ping-Statistik fr 98.138.253.109:
    Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0
    (0% Verlust),
Ca. Zeitangaben in Millisek.:
    Minimum = 167ms, Maximum = 172ms, Mittelwert = 169ms

Ping wird ausgefhrt fr 127.0.0.1 mit 32 Bytes Daten:
Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128
Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128

Ping-Statistik fr 127.0.0.1:
    Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0
    (0% Verlust),
Ca. Zeitangaben in Millisek.:
    Minimum = 0ms, Maximum = 0ms, Mittelwert = 0ms
===========================================================================
Schnittstellenliste
 10...90 fb a6 e0 95 48 ......Realtek PCIe GBE Family Controller
  1...........................Software Loopback Interface 1
 11...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter
 12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4-Routentabelle
===========================================================================
Aktive Routen:
     Netzwerkziel    Netzwerkmaske          Gateway    Schnittstelle Metrik
          0.0.0.0          0.0.0.0    192.168.178.1   192.168.178.20     10
        127.0.0.0        255.0.0.0   Auf Verbindung         127.0.0.1    306
        127.0.0.1  255.255.255.255   Auf Verbindung         127.0.0.1    306
  127.255.255.255  255.255.255.255   Auf Verbindung         127.0.0.1    306
    192.168.178.0    255.255.255.0   Auf Verbindung    192.168.178.20    266
   192.168.178.20  255.255.255.255   Auf Verbindung    192.168.178.20    266
  192.168.178.255  255.255.255.255   Auf Verbindung    192.168.178.20    266
        224.0.0.0        240.0.0.0   Auf Verbindung         127.0.0.1    306
        224.0.0.0        240.0.0.0   Auf Verbindung    192.168.178.20    266
  255.255.255.255  255.255.255.255   Auf Verbindung         127.0.0.1    306
  255.255.255.255  255.255.255.255   Auf Verbindung    192.168.178.20    266
===========================================================================
St„ndige Routen:
  Keine

IPv6-Routentabelle
===========================================================================
Aktive Routen:
 If Metrik Netzwerkziel             Gateway
  1    306 ::1/128                  Auf Verbindung
 10    266 fe80::/64                Auf Verbindung
 10    266 fe80::7816:e8ea:2bcb:5128/128
                                    Auf Verbindung
  1    306 ff00::/8                 Auf Verbindung
 10    266 ff00::/8                 Auf Verbindung
===========================================================================
St„ndige Routen:
  Keine
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (06/09/2013 07:00:50 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Das System kann die angegebene Datei nicht finden. (0x80070002)"

Error: (06/06/2013 02:17:06 PM) (Source: Software Protection Platform Service) (User: )
Description: Fehler bei der Erfassung des authentischen Tickets (hr=0xC004C32A) für die Vorlagen-ID 66c92734-d682-4d71-983e-d6ec3f16059f.

Error: (06/06/2013 02:17:06 PM) (Source: Software Protection Platform Service) (User: )
Description: Lizenzerwerb-Fehlerdetails. 
hr=0xC004C32A

Error: (06/06/2013 01:11:28 PM) (Source: Application Hang) (User: )
Description: Programm StarMoney.exe, Version 3.0.6.31 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 47a8

Startzeit: 01ce62a625b60d5e

Endzeit: 0

Anwendungspfad: C:\Program Files (x86)\StarMoney 8.0 S-Edition\app\StarMoney.exe

Berichts-ID:

Error: (06/05/2013 11:40:10 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16576, Zeitstempel: 0x515e30fe
Name des fehlerhaften Moduls: pdIEAddOn.dll, Version: 5.3.0.0, Zeitstempel: 0x4d8b468d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00004f5a
ID des fehlerhaften Prozesses: 0x1118
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3

Error: (06/02/2013 07:00:52 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Das System kann die angegebene Datei nicht finden. (0x80070002)"

Error: (06/02/2013 02:53:11 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: HauntedLegends_TheUndertakerCE_RC.exe, Version: 0.0.0.0, Zeitstempel: 0x51234949
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x1c20674a
ID des fehlerhaften Prozesses: 0x3d94
Startzeit der fehlerhaften Anwendung: 0xHauntedLegends_TheUndertakerCE_RC.exe0
Pfad der fehlerhaften Anwendung: HauntedLegends_TheUndertakerCE_RC.exe1
Pfad des fehlerhaften Moduls: HauntedLegends_TheUndertakerCE_RC.exe2
Berichtskennung: HauntedLegends_TheUndertakerCE_RC.exe3

Error: (05/30/2013 06:16:47 PM) (Source: Application Hang) (User: )
Description: Programm IEXPLORE.EXE, Version 10.0.9200.16576 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 23b4

Startzeit: 01ce5d4e1f317c1c

Endzeit: 15

Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Berichts-ID:

Error: (05/26/2013 07:00:47 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Das System kann die angegebene Datei nicht finden. (0x80070002)"

Error: (05/26/2013 03:25:54 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16576, Zeitstempel: 0x515e30fe
Name des fehlerhaften Moduls: pdIEAddOn.dll, Version: 5.3.0.0, Zeitstempel: 0x4d8b468d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00004f5a
ID des fehlerhaften Prozesses: 0xea4
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3


System errors:
=============
Error: (06/15/2013 01:10:18 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597 (Definition 1.151.2213.0)

Error: (06/14/2013 06:03:09 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.

Error: (06/14/2013 06:03:08 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.

Error: (06/14/2013 06:03:08 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.

Error: (06/14/2013 05:43:38 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%1058

Error: (06/14/2013 05:43:38 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%1058

Error: (06/14/2013 05:43:27 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%1058

Error: (06/14/2013 05:42:47 PM) (Source: Microsoft-Windows-BitLocker-Driver) (User: NT-AUTORITÄT)
Description: Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf "\\?\Volume{9ae5ce6c-7702-11dc-9bbd-806e6f6e6963}" können nicht gelesen werden.

Error: (06/14/2013 05:42:47 PM) (Source: Microsoft-Windows-BitLocker-Driver) (User: NT-AUTORITÄT)
Description: Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf "\\?\Volume{9ae5ce6b-7702-11dc-9bbd-806e6f6e6963}" können nicht gelesen werden.

Error: (06/14/2013 05:42:37 PM) (Source: Ntfs) (User: )
Description: Auf dem Volume "L:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.


Microsoft Office Sessions:
=========================
Error: (06/09/2013 07:00:50 PM) (Source: Windows Backup)(User: )
Description: Das System kann die angegebene Datei nicht finden. (0x80070002)

Error: (06/06/2013 02:17:06 PM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C32A66c92734-d682-4d71-983e-d6ec3f16059f

Error: (06/06/2013 02:17:06 PM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C32A00010001(0x00000000, 14:17:05:802 - hxxp://go.microsoft.com/fwlink/?LinkId=151642)
00020001(0x00000000, 14:17:05:802)
00030001(0x00000000, 14:17:05:802 - hxxp://go.microsoft.com)
00030002(0x00000000, 14:17:05:802 - 1)
00020005(0x00000000, 14:17:05:802 - 0)
0002000C(0x00000000, 14:17:05:989 - 302)
0002000E(0x00000000, 14:17:05:989 - https://validation.sls.microsoft.com/SLWGA/slwga.asmx)
00020001(0x00000000, 14:17:05:989)
00030001(0x00000000, 14:17:05:989 - https://validation.sls.microsoft.com)
00030002(0x00000000, 14:17:05:989 - 1)
00020005(0x00000000, 14:17:05:989 - 0)
0002000C(0x00000000, 14:17:06:629 - 500)
00010002(0x8004FC01, 14:17:06:629 - <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:soap="hxxp://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema"><soap:Body><soap:Fault><faultcode>soap:Server</faultcode><faultstring>SoapException</faultstring><detail><HRESULT>0xC004C32A</HRESULT><Messages><Message>553 (Validation) - [VGA: Required parameter not found in offline XML blob.  ---&gt; Parameter not found in offline XML blob - [Win7BootSectorMustExist]]</Message></Messages></detail></soap:Fault></soap:Body></soap:Envelope>)
00010003(0x8004FC01, 14:17:06:691)

Error: (06/06/2013 01:11:28 PM) (Source: Application Hang)(User: )
Description: StarMoney.exe3.0.6.3147a801ce62a625b60d5e0C:\Program Files (x86)\StarMoney 8.0 S-Edition\app\StarMoney.exe

Error: (06/05/2013 11:40:10 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.16576515e30fepdIEAddOn.dll5.3.0.04d8b468dc000000500004f5a111801ce62334908731fC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll7ec8b21a-ce28-11e2-b5ad-90fba6e09548

Error: (06/02/2013 07:00:52 PM) (Source: Windows Backup)(User: )
Description: Das System kann die angegebene Datei nicht finden. (0x80070002)

Error: (06/02/2013 02:53:11 PM) (Source: Application Error)(User: )
Description: HauntedLegends_TheUndertakerCE_RC.exe0.0.0.051234949unknown0.0.0.000000000c00000051c20674a3d9401ce5f8d47bea427K:\Program Files (x86)\Haunted Legends - Der Bestatter\HauntedLegends_TheUndertakerCE_RC.exeunknown61244ad3-cb83-11e2-b5ad-90fba6e09548

Error: (05/30/2013 06:16:47 PM) (Source: Application Hang)(User: )
Description: IEXPLORE.EXE10.0.9200.1657623b401ce5d4e1f317c1c15C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (05/26/2013 07:00:47 PM) (Source: Windows Backup)(User: )
Description: Das System kann die angegebene Datei nicht finden. (0x80070002)

Error: (05/26/2013 03:25:54 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.16576515e30fepdIEAddOn.dll5.3.0.04d8b468dc000000500004f5aea401ce5a0aacad2058C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dllca1f4e87-c607-11e2-b5ad-90fba6e09548


CodeIntegrity Errors:
===================================
  Date: 2013-02-15 09:53:34.309
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:34.216
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:32.113
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:32.021
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:29.918
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:29.789
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:27.595
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:27.501
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:25.364
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:25.286
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


=========================== Installed Programs ============================

7Artifacs (Version: 1.00.0000)
AAVUpdateManager (Version: 18.00.0000)
Acer Arcade Deluxe (Version: 4.1.7405)
Acer Arcade Movie (Version: 9.0.6205)
Acer eRecovery Management (Version: 4.05.3007)
Acer GameZone Console (Version: 6.1.0.2)
Acer Registration (Version: 1.02.3006)
Acer ScreenSaver (Version: 1.1.0318.2010)
Acer Updater (Version: 1.02.3001)
Acrobat.com (Version: 1.6.65)
Adobe AIR (Version: 3.5.0.1060)
Adobe Flash Player 11 ActiveX (Version: 11.7.700.224)
Adobe Reader XI (11.0.02) - Deutsch (Version: 11.0.02)
Advertising Center (Version: 0.0.0.2)
AGFEO TK-Suite Server (Version: )
Amazon MP3-Downloader 1.0.17 (Version: 1.0.17)
AMD Accelerated Video Transcoding (Version: 12.5.100.20928)
AMD APP SDK Runtime (Version: 10.0.1016.4)
AMD Catalyst Install Manager (Version: 8.0.891.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Media Foundation Decoders (Version: 1.0.70928.1539)
Ashampoo Burning Studio 2013 v.11.0.5 (Version: 11.0.5)
ATI AVIVO64 Codecs (Version: 10.12.0.00225)
AVM FRITZ!Box USB-Fernanschluss (Version: 2.2.1.0)
Awakening: Das Himmelsschloss Sammleredition
Big Fish Games: Game Manager (Version: 3.0.1.60)
Bing Maps 3D (Version: 4.0.903.16005)
Briefe aus dem Jenseits (Version: 1.0.0.0)
Cake Mania
Canon Easy-PhotoPrint EX
Canon Kurzwahlprogramm
Canon MP Navigator EX 3.1
Canon MX870 series Benutzerregistrierung
Canon MX870 series MP Drivers
Canon My Printer
Canon Utilities Solution Menu
Casual Games 1  (Version: 1)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (Version: 2012.0928.1532.26058)
Catalyst Control Center InstallProxy (Version: 2010.0225.1742.31671)
Catalyst Control Center InstallProxy (Version: 2012.0928.1532.26058)
Catalyst Control Center Localization All (Version: 2012.0928.1532.26058)
CCC Help Chinese Standard (Version: 2012.0928.1531.26058)
CCC Help Chinese Traditional (Version: 2012.0928.1531.26058)
CCC Help Czech (Version: 2012.0928.1531.26058)
CCC Help Danish (Version: 2012.0928.1531.26058)
CCC Help Dutch (Version: 2012.0928.1531.26058)
CCC Help English (Version: 2012.0928.1531.26058)
CCC Help Finnish (Version: 2012.0928.1531.26058)
CCC Help French (Version: 2012.0928.1531.26058)
CCC Help German (Version: 2012.0928.1531.26058)
CCC Help Greek (Version: 2012.0928.1531.26058)
CCC Help Hungarian (Version: 2012.0928.1531.26058)
CCC Help Italian (Version: 2012.0928.1531.26058)
CCC Help Japanese (Version: 2012.0928.1531.26058)
CCC Help Korean (Version: 2012.0928.1531.26058)
CCC Help Norwegian (Version: 2012.0928.1531.26058)
CCC Help Polish (Version: 2012.0928.1531.26058)
CCC Help Portuguese (Version: 2012.0928.1531.26058)
CCC Help Russian (Version: 2012.0928.1531.26058)
CCC Help Spanish (Version: 2012.0928.1531.26058)
CCC Help Swedish (Version: 2012.0928.1531.26058)
CCC Help Thai (Version: 2012.0928.1531.26058)
CCC Help Turkish (Version: 2012.0928.1531.26058)
ccc-utility64 (Version: 2012.0928.1532.26058)
Chicken Invaders 2
Chimeras: Melodie der Rache Sammleredition
Coffee Break PacMan (Version: )
Color Eggs II
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000)
cyberJack Base Components (Version: 6.10.0)
Dairy Dash
Das Vermächtnis der Insel (Version: 1.0.0.0)
DATA BECKER 3D Wohnungsplaner 10 (Version: 1.3.495.0)
Deep Blue Sea – Die Schatztaucherin
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Detective Quest: Der gläserne Schuh Sammleredition
DEUTSCHLAND SPIELT GAME CENTER (Version: 1.2010.6.23)
DEUTSCHLAND SPIELT Spiele Post (Version: 1.0.3.0)
Diamond Drop (VOLLVERSION)
Die Legende von Pocahontas
Dino & Aliens
Dream Day First Home
eBay Worldwide (Version: 2.1.0901)
eReg (Version: 1.20.138.34)
eSobi v2 (Version: 2.0.4.000274)
Farm Frenzy 2
Farmington Tales
Firebird SQL Server - MAGIX Edition (Version: 2.1.31.0)
Fotos auf DVD 2013 Deluxe Update (Version: 12.0.3.80)
freundin - Mystery Tales 2
Geheime Fälle: Die gestohlene Venus 2 (Version: 1.0.0.0)
Gigaset QuickSync (Version: 5.1.0001.14719)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.4.3607.2246)
Google Update Helper (Version: 1.3.21.145)
Granny In Paradise
Haali Media Splitter
Hotkey Utility (Version: 2.05.3003)
Hühner-Attacke (VOLLVERSION)
Hühner-Rache
HUK-COBURG Angebotssoftware VISonline (Version: 11.5.0)
I Have No Tomatoes v1.5
Identity Card (Version: 1.00.3003)
ImagXpress (Version: 7.0.74.0)
Jäger des Geisterhauses
Java Auto Updater (Version: 2.0.7.1)
Java(TM) 6 Update 31 (Version: 6.0.310)
Junk Mail filter update (Version: 14.0.8089.726)
Kalender-Excel-8.7.1 (Version: 8.7.1)
Kalender-Excel-8.9 (Version: 8.9)
Logitech SetPoint 6.15 (Version: 6.15.25)
Love Over Death (Version: 1.2.0.102)
LWP_eToken_Client (Version: 3.5.2)
Mad Cars
Magic Ball 2
MAGIX Fotos auf DVD 2013 Deluxe (Version: 12.0.0.75)
MAGIX Screenshare (Version: 4.3.6.1987)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
MediaShow Espresso (Version: 5.5.1403_23691)
Mein CEWE FOTOBUCH
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Choice Guard (Version: 2.0.48.0)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Home and Student 2010 (Version: 14.0.6029.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Office Standard Edition 2003 (Version: 11.0.8173.0)
Microsoft Office Suite Activation Assistant (Version: 2.9)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft SQL Server 2005 Express Edition (SQLHUK) (Version: 9.4.5000.00)
Microsoft SQL Server Native Client (Version: 9.00.5000.00)
Microsoft SQL Server VSS Writer (Version: 9.00.5000.00)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Works (Version: 9.7.0621)
Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0)
MSVCRT (Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0)
MyFreeCodec
MyMDb 3.6
MyWinLocker (Version: 3.1.206.0)
MyWinLocker Suite (Version: 3.1.206.0)
Nero 9 Essentials
Nero ControlCenter (Version: 9.0.0.1)
Nero DiscSpeed (Version: 5.4.13.100)
Nero DiscSpeed Help (Version: 5.4.4.100)
Nero DriveSpeed (Version: 4.4.12.100)
Nero DriveSpeed Help (Version: 4.4.4.100)
Nero Express Help (Version: 9.6.2.101)
Nero InfoTool (Version: 6.4.12.100)
Nero InfoTool Help (Version: 6.4.4.100)
Nero Installer (Version: 4.4.9.0)
Nero Online Upgrade (Version: 1.3.0.0)
Nero StartSmart (Version: 9.4.37.100)
Nero StartSmart Help (Version: 9.4.27.100)
Nero StartSmart OEM (Version: 9.16.0.100)
NeroExpress (Version: 9.4.33.100)
neroxml (Version: 1.0.0)
Paragon Festplatten Manager™ 2011 Kompakt (Version: 90.00.0003)
Password Depot 5 (Version: 5.3.0)
PCLinq2 High-Speed USB Bridge Cable
Phantasmat: Eisiger Gipfel
Pixum Fotobuch
PL-2303 USB-to-Serial (Version: 1.00.000)
Protect Disc License Helper 1.0.125 (IE) (Version: 1.0.125)
ProtectDisc Driver, Version 11 (Version: 11.0.0.14)
Rasputins Curse (Version: 1.00)
Realtek Ethernet Controller Driver (Version: 7.46.610.2011)
Realtek High Definition Audio Driver (Version: 6.0.1.5963)
Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.0.26.0)
Robinson Crusoe and the Cursed Pirates (Version: 1.00)
Romance of Rome
Sable Maze: Sullivan River
Sacra Terra: Der Kuss des Todes
Sacra Terra: Der Kuss des Todes, Sammleredition
Samsung Kies (Version: 2.3.2.12064_9)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.18.0)
Santa Hanta 2.4c
Secret Diaries: Florence Ashford (Version: 1.0.0.0)
secrets of tahiti
Shadow Wolf Mysteries Bane of the Family de (Version: de)
Shredder (Version: 2.0.5.0)
Shrek(R) SuperSlam (Version: 1.00.0000)
Skype™ 6.0 (Version: 6.0.126)
Spin & Win
Spirits of Mystery: Der dunkle Minotaurus Sammleredition
StarMoney (Version: 3.0.0.124)
StarMoney (Version: 4.0.0.203)
StarMoney 8.0 S-Edition (Version: 8.0)
Steuer-Spar-Erklärung 2011 (Version: 16.12)
Steuer-Spar-Erklärung 2012 (Version: 17.11)
Steuer-Spar-Erklärung 2013 (Version: 18.06)
Super Puzzle
Sven XXX - XXL
The Beast of Lycan Isle
The Curse Of Ra (Version: 3.3.0)
The Mystery of the Crystal Portal - Die versunkene Welt (Version: 1.00)
The Saint: Abgrund der Verzweiflung
Time Mysteries: Das letzte Rätsel
Time Mysteries: Das letzte Rätsel Sammleredition
TMS 5.1 SP1 Client (Version: 5.1.127)
Tödliche Sonate: Ein Dana Knightstone-Roman
Tory's Shop'n' Rush
TurboFLOORPLAN Garten- & Landschaftsarchitekt (Version: 12.1)
Unfinished Tales: Unsterbliche Liebe
Unfinished Tales: Unsterbliche Liebe Sammleredition
Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.5000.00)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
Verbotene Geheimnisse: Alien Town
Verschleierte Wirklichkeit (Version: 1.0.0.0)
VIS Aktualisierung (Version: 2.2.0)
VISonline Diagnose (Version: 2.0.1)
Web of Deceit: Die Schwarze Witwe Sammleredition
Welcome Center (Version: 1.00.3013)
Windows Live Anmelde-Assistent (Version: 5.000.818.5)
Windows Live Call (Version: 14.0.8064.0206)
Windows Live Communications Platform (Version: 14.0.8064.206)
Windows Live Essentials (Version: 14.0.8089.0726)
Windows Live Essentials (Version: 14.0.8089.726)
Windows Live Fotogalerie (Version: 14.0.8081.709)
Windows Live Mail (Version: 14.0.8089.0726)
Windows Live Messenger (Version: 14.0.8089.0726)
Windows Live Movie Maker (Version: 14.0.8091.0730)
Windows Live Sync (Version: 14.0.8089.726)
Windows Live Writer (Version: 14.0.8089.0726)
Windows Live-Uploadtool (Version: 14.0.8014.1029)
Windows Mobile-Gerätecenter (Version: 6.1.6965.0)
Wondershare Vivideo(Build 2.0.0.12)
Zoo Safari

========================= Memory info: ===================================

Percentage of memory in use: 51%
Total physical RAM: 4023.11 MB
Available physical RAM: 1941.75 MB
Total Pagefile: 8044.4 MB
Available Pagefile: 5954.94 MB
Total Virtual: 4095.88 MB
Available Virtual: 3965.85 MB

========================= Partitions: =====================================

1 Drive c: (Acer) (Fixed) (Total:458.87 GB) (Free:386.05 GB) NTFS
2 Drive d: (Data) (Fixed) (Total:458.87 GB) (Free:456.39 GB) NTFS
7 Drive k: (32_00_00) (Fixed) (Total:931.28 GB) (Free:667.34 GB) FAT32
8 Drive l: (Platte2) (Fixed) (Total:1863.01 GB) (Free:1793.28 GB) NTFS
9 Drive m: (Platte1) (Fixed) (Total:931.51 GB) (Free:930.82 GB) NTFS

========================= Users: ========================================

Benutzerkonten fr \\BUERO

Administrator            Gast                     S. Voá HUK               
Der Befehl wurde erfolgreich ausgefhrt.

========================= Minidump Files ==================================

No minidump file found


**** End of log ****
         
FRST


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013
Ran by S. Voß HUK (administrator) on 15-06-2013 14:38:20
Running from C:\Users\S. Voß HUK\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe
(DATA BECKER GmbH & Co KG) C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
() C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe
(AGFEO      ) C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
() C:\OEM\USBDECTION\USBS3S4Detection.exe
(AGFEO      ) C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tkmedia.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(CANON INC.) K:\BJMYPRT.EXE
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
() C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Microsoft) C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUI.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(TeamViewer GmbH) C:\Users\SDBC1~1.VOH\AppData\Local\Temp\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Users\SDBC1~1.VOH\AppData\Local\Temp\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Users\SDBC1~1.VOH\AppData\Local\Temp\TeamViewer\Version8\tv_x64.exe
(TeamViewer GmbH) c:\users\sdbc1~1.voh\appdata\local\temp\teamviewer\version8\TeamViewer_Desktop.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe                                                                                                                                                                                                              [349552 2010-02-01] (Egis Technology Inc.)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1609296 2010-06-26] (Logitech, Inc.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [8306208 2009-10-20] (Realtek Semiconductor)
HKLM\...\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [CanonMyPrinter] K:\BJMyPrt.exe /logon [x]
HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKCU\...\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844144 2013-02-13] (Samsung)
HKCU\...\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup [578560 2013-02-06] (Samsung Electronics)
HKCU\...\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload [1509232 2013-02-13] (Samsung)
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17877168 2012-11-09] (Skype Technologies S.A.)
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-03-20] (Google Inc.)
HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKLM-x32\...\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [337264 2010-02-01] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d                                                                                                                                                                                                                    [201512 2009-12-25] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"                                                                                                                                                                                                                        [401192 2009-12-25] (Egis Technology Inc.)
HKLM-x32\...\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [563744 2010-03-26] ()
HKLM-x32\...\Run: [MDS_Menu] "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2010-04-27] (Renesas Electronics Corporation)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
Startup: C:\Users\S. Voß HUK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * K:\PROGRA~1\PARAGO~1\FESTPL~1\bluescrn\bluescrn.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_x3950&r=173608102207pe458v135w4651v85o
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.ewetel.de/index.htm
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Password Depot 5 - {9F79B165-70F7-4C46-B1A5-8828E2FF21F9} - C:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll (AceBIT)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM {28B66320-9687-4B13-8757-36F901887AB5} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/canvasx64.cab
DPF: HKLM {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/jordan64.cab
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: msdaipp - No CLSID Value - 
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msdaipp - No CLSID Value - 
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Hosts: #	::1             localhost
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

Chrome: 
=======
CHR HomePage: hxxp://www.google.com
CHR DefaultSearchURL: (Google) - {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR Extension: (YouTube) - C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0
CHR Extension: (Google Search) - C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0
CHR Extension: (Gmail) - C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0

==================== Services (Whitelisted) =================

R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [514128 2012-03-19] (REINER SCT)
R2 DBService; C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe [187456 2009-01-08] (DATA BECKER GmbH & Co KG)
R2 MSSQL$SQLHUK; C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
S4 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-02-01] (Egis Technology Inc.)
R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [244904 2010-02-03] ()
R2 StarMoney 8.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
R2 tksock; C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe [2104320 2010-04-20] (AGFEO      )
R2 USBS3S4Detection; C:\OEM\USBDECTION\USBS3S4Detection.exe [76320 2009-12-09] ()

==================== Drivers (Whitelisted) ====================

R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [116096 2011-08-07] (AVM Berlin)
S3 BioNT_BS; K:\Program Files (x86)\Paragon Software\Festplatten Manager 2011 Kompakt\bluescrn\BioNT_bs.sys [22096 2011-03-03] (Paragon Software GmbH)
S3 BioNT_BS; K:\Program Files (x86)\Paragon Software\Festplatten Manager 2011 Kompakt\bluescrn\BioNT_bs.sys [22096 2011-03-03] (Paragon Software GmbH)
R3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2011-03-29] (REINER SCT)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
S3 GigasetGenericUSB_x64; C:\Windows\System32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2009-02-20] (Siemens Home and Office Communication Devices GmbH & Co. KG)
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [37456 2011-03-03] (Paragon Software Group)
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [203104 2012-09-20] (DEVGURU Co., LTD.(www.devguru.co.kr))
R1 UimBus; C:\Windows\System32\DRIVERS\uimx64.sys [53840 2011-03-03] (Windows (R) 2000 DDK provider)
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [528464 2011-03-03] (Paragon)
S3 cpuz132; \??\C:\Users\SDBC1~1.VOH\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [x]
U3 DfSdkS; 
S3 EraserUtilDrv11220; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys [x]
S3 vpnva; system32\DRIVERS\vpnva64.sys [x]
U3 fgldqpob; \??\C:\Users\SDBC1~1.VOH\AppData\Local\Temp\fgldqpob.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-15 14:38 - 2013-06-15 14:38 - 00000000 ____D C:\FRST
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\FRST64.exe
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\FRST64.exe
2013-06-15 14:33 - 2013-06-15 14:33 - 00039343 ____A C:\Users\S. Voß HUK\Desktop\Result.txt
2013-06-15 14:32 - 2013-06-15 14:31 - 00760723 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\MiniToolBox.exe
2013-06-15 14:31 - 2013-06-15 14:31 - 00760723 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\MiniToolBox.exe
2013-06-15 12:21 - 2013-06-15 12:21 - 10285040 ____A (Malwarebytes Corporation                                    ) C:\Users\S. Voß HUK\Downloads\mbam-setup-1.75.0.1300.exe
2013-06-15 12:21 - 2013-06-15 12:21 - 00001113 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-15 12:21 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-06-15 12:19 - 2013-06-15 12:19 - 00010218 ____A C:\Users\S. Voß HUK\Desktop\gmer.txt
2013-06-14 18:35 - 2013-06-14 18:34 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Desktop\TeamViewer_Setup_de.exe
2013-06-14 18:34 - 2013-06-14 18:34 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Downloads\TeamViewer_Setup_de.exe
2013-06-14 18:05 - 2013-06-14 18:05 - 00377856 ____A C:\Users\S. Voß HUK\Downloads\gmer_2.1.19163.exe
2013-06-14 17:55 - 2013-06-14 17:55 - 00101782 ____A C:\Users\S. Voß HUK\Downloads\Extras.Txt
2013-06-14 17:54 - 2013-06-14 17:54 - 00112916 ____A C:\Users\S. Voß HUK\Downloads\OTL.Txt
2013-06-14 17:47 - 2013-06-14 17:47 - 00602112 ____A (OldTimer Tools) C:\Users\S. Voß HUK\Downloads\OTL.exe
2013-06-14 15:35 - 2013-06-14 15:38 - 182243952 ____A C:\Users\S. Voß HUK\Downloads\smoney (1).exe
2013-06-12 03:01 - 2013-05-17 03:25 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-12 03:01 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 03:01 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 03:01 - 2013-05-17 02:58 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-12 03:01 - 2013-05-14 15:14 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 03:01 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-12 03:01 - 2013-05-14 11:23 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-12 03:01 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-12 00:40 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 00:40 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 00:40 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 00:40 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 00:40 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 00:40 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 00:40 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 00:40 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 00:40 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 00:40 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 00:40 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 00:40 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 00:40 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 00:40 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 00:40 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-12 00:40 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-12 00:40 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-12 00:40 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-12 00:40 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-05-23 19:18 - 2013-05-23 19:18 - 00137488 ____A C:\Users\S. Voß HUK\AppData\Local\GDIPFONTCACHEV1.DAT
2013-05-23 19:17 - 2013-06-14 18:03 - 00002164 ____A C:\Windows\setupact.log
2013-05-23 19:17 - 2013-06-14 17:42 - 00445098 ____A C:\Windows\PFRO.log
2013-05-23 19:17 - 2013-05-23 19:17 - 00460680 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-23 19:17 - 2013-05-23 19:17 - 00000000 ____A C:\Windows\setuperr.log
2013-05-20 08:20 - 2013-05-20 08:20 - 00000000 ____D C:\Users\S. Voß HUK\Documents\The Lonely Hearts Murders CE

==================== One Month Modified Files and Folders =======

2013-06-15 14:38 - 2013-06-15 14:38 - 00000000 ____D C:\FRST
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\FRST64.exe
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\FRST64.exe
2013-06-15 14:33 - 2013-06-15 14:33 - 00039343 ____A C:\Users\S. Voß HUK\Desktop\Result.txt
2013-06-15 14:31 - 2013-06-15 14:32 - 00760723 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\MiniToolBox.exe
2013-06-15 14:31 - 2013-06-15 14:31 - 00760723 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\MiniToolBox.exe
2013-06-15 14:29 - 2013-05-04 20:10 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-15 14:24 - 2010-08-15 14:25 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-15 13:14 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-15 13:14 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-15 13:10 - 2013-05-09 10:17 - 01630112 ____A C:\Windows\WindowsUpdate.log
2013-06-15 12:21 - 2013-06-15 12:21 - 10285040 ____A (Malwarebytes Corporation                                    ) C:\Users\S. Voß HUK\Downloads\mbam-setup-1.75.0.1300.exe
2013-06-15 12:21 - 2013-06-15 12:21 - 00001113 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-15 12:19 - 2013-06-15 12:19 - 00010218 ____A C:\Users\S. Voß HUK\Desktop\gmer.txt
2013-06-14 19:24 - 2010-08-15 14:25 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-14 18:35 - 2012-09-25 19:12 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\TeamViewer
2013-06-14 18:35 - 2012-09-01 13:24 - 00057525 ____A C:\Windows\wininit.ini
2013-06-14 18:34 - 2013-06-14 18:35 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Desktop\TeamViewer_Setup_de.exe
2013-06-14 18:34 - 2013-06-14 18:34 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Downloads\TeamViewer_Setup_de.exe
2013-06-14 18:05 - 2013-06-14 18:05 - 00377856 ____A C:\Users\S. Voß HUK\Downloads\gmer_2.1.19163.exe
2013-06-14 18:04 - 2009-07-14 07:13 - 01769366 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-14 18:04 - 2007-10-10 19:26 - 00757356 ____A C:\Windows\System32\perfh007.dat
2013-06-14 18:04 - 2007-10-10 19:26 - 00172606 ____A C:\Windows\System32\perfc007.dat
2013-06-14 18:03 - 2013-05-23 19:17 - 00002164 ____A C:\Windows\setupact.log
2013-06-14 17:55 - 2013-06-14 17:55 - 00101782 ____A C:\Users\S. Voß HUK\Downloads\Extras.Txt
2013-06-14 17:54 - 2013-06-14 17:54 - 00112916 ____A C:\Users\S. Voß HUK\Downloads\OTL.Txt
2013-06-14 17:47 - 2013-06-14 17:47 - 00602112 ____A (OldTimer Tools) C:\Users\S. Voß HUK\Downloads\OTL.exe
2013-06-14 17:43 - 2012-12-28 12:40 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Skype
2013-06-14 17:42 - 2013-05-23 19:17 - 00445098 ____A C:\Windows\PFRO.log
2013-06-14 17:42 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-14 17:38 - 2012-11-13 18:34 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Steganos
2013-06-14 17:37 - 2011-09-22 07:53 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-06-14 17:37 - 2010-08-15 13:55 - 00000000 ____D C:\ProgramData\Cisco
2013-06-14 17:11 - 2013-05-09 10:25 - 00000000 ____D C:\ProgramData\Norton
2013-06-14 16:56 - 2013-05-04 20:10 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-14 16:56 - 2013-05-04 20:10 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-14 16:52 - 2010-08-15 13:55 - 01746324 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2013-06-14 15:38 - 2013-06-14 15:35 - 182243952 ____A C:\Users\S. Voß HUK\Downloads\smoney (1).exe
2013-06-12 04:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-12 03:23 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther
2013-06-12 03:05 - 2009-07-14 04:34 - 00000499 ____A C:\Windows\win.ini
2013-06-12 03:01 - 2010-09-04 17:46 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-12 01:59 - 2012-07-10 15:31 - 00000000 ____D C:\Program Files (x86)\StarMoney 8.0 S-Edition
2013-06-09 12:16 - 2012-09-01 13:24 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Boomzap
2013-06-09 12:16 - 2010-08-15 11:37 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Local\VirtualStore
2013-06-05 23:40 - 2013-05-09 13:43 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Local\CrashDumps
2013-06-02 14:32 - 2012-09-09 14:38 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\ERS Game Studios
2013-05-26 16:07 - 2013-05-09 12:49 - 00000000 ____D C:\Program Files (x86)\Grim Tales - Die Steinkoenigin Sammleredition
2013-05-26 15:26 - 2012-08-26 14:21 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Elephant Games
2013-05-26 15:26 - 2012-08-26 14:21 - 00000000 ____D C:\ProgramData\Elephant Games
2013-05-26 09:02 - 2012-09-30 14:19 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\AlawarEntertainment
2013-05-24 12:20 - 2013-05-05 12:36 - 00000000 ____D C:\ProgramData\SpeedMaxPc
2013-05-23 19:43 - 2011-03-06 16:57 - 00000000 ____D C:\Users\S. Voß HUK\Documents\MAGIX_MxTray
2013-05-23 19:18 - 2013-05-23 19:18 - 00137488 ____A C:\Users\S. Voß HUK\AppData\Local\GDIPFONTCACHEV1.DAT
2013-05-23 19:17 - 2013-05-23 19:17 - 00460680 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-23 19:17 - 2013-05-23 19:17 - 00000000 ____A C:\Windows\setuperr.log
2013-05-23 19:13 - 2012-12-01 18:47 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-05-23 14:47 - 2012-10-03 13:20 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Blue Tea Games
2013-05-20 18:39 - 2012-10-27 15:42 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Vast Studios
2013-05-20 14:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF
2013-05-20 08:20 - 2013-05-20 08:20 - 00000000 ____D C:\Users\S. Voß HUK\Documents\The Lonely Hearts Murders CE
2013-05-20 08:20 - 2013-02-24 14:45 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\MagicIndie
2013-05-19 16:20 - 2010-03-20 00:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-05-18 14:54 - 2012-10-04 22:35 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Eipix
2013-05-17 03:25 - 2013-06-12 03:01 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-05-17 03:25 - 2013-06-12 03:01 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-05-17 02:59 - 2013-06-12 03:01 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-05-17 02:59 - 2013-06-12 03:01 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-05-17 02:58 - 2013-06-12 03:01 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-05-17 02:58 - 2013-06-12 03:01 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-05-17 02:58 - 2013-06-12 03:01 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-05-17 02:58 - 2013-06-12 03:01 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-05-17 02:58 - 2013-06-12 03:01 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-05-17 02:58 - 2013-06-12 03:01 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-05-17 02:58 - 2013-06-12 03:01 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-05-17 02:58 - 2013-06-12 03:01 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-05-17 02:58 - 2013-06-12 03:01 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-05-17 02:58 - 2013-06-12 03:01 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-05-17 02:58 - 2013-06-12 03:01 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-05-17 02:58 - 2013-06-12 03:01 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-05-16 03:11 - 2010-03-20 01:13 - 00000000 ____D C:\ProgramData\Microsoft Help

Files to move or delete:
====================
C:\ProgramData\FullRemove.exe
C:\ProgramData\ntuser.dat

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-13 19:40

==================== End Of Log ============================
         
--- --- ---


Addition.txt

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-06-2013
Ran by S. Voß HUK at 2013-06-15 14:38:43 Run:
Running from C:\Users\S. Voß HUK\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

7Artifacs (Version: 1.00.0000)
AAVUpdateManager (Version: 18.00.0000)
Acer Arcade Deluxe (Version: 4.1.7405)
Acer Arcade Movie (Version: 9.0.6205)
Acer eRecovery Management (Version: 4.05.3007)
Acer GameZone Console (Version: 6.1.0.2)
Acer Registration (Version: 1.02.3006)
Acer ScreenSaver (Version: 1.1.0318.2010)
Acer Updater (Version: 1.02.3001)
Acrobat.com (Version: 1.6.65)
Adobe AIR (Version: 3.5.0.1060)
Adobe Flash Player 11 ActiveX (Version: 11.7.700.224)
Adobe Reader XI (11.0.02) - Deutsch (Version: 11.0.02)
Advertising Center (Version: 0.0.0.2)
AGFEO TK-Suite Server (Version: )
Amazon MP3-Downloader 1.0.17 (Version: 1.0.17)
AMD Accelerated Video Transcoding (Version: 12.5.100.20928)
AMD APP SDK Runtime (Version: 10.0.1016.4)
AMD Catalyst Install Manager (Version: 8.0.891.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Media Foundation Decoders (Version: 1.0.70928.1539)
Ashampoo Burning Studio 2013 v.11.0.5 (Version: 11.0.5)
ATI AVIVO64 Codecs (Version: 10.12.0.00225)
AVM FRITZ!Box USB-Fernanschluss (Version: 2.2.1.0)
Awakening: Das Himmelsschloss Sammleredition
Big Fish Games: Game Manager (Version: 3.0.1.60)
Bing Maps 3D (Version: 4.0.903.16005)
Briefe aus dem Jenseits (Version: 1.0.0.0)
Cake Mania
Canon Easy-PhotoPrint EX
Canon Kurzwahlprogramm
Canon MP Navigator EX 3.1
Canon MX870 series Benutzerregistrierung
Canon MX870 series MP Drivers
Canon My Printer
Canon Utilities Solution Menu
Casual Games 1  (Version: 1)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (Version: 2012.0928.1532.26058)
Catalyst Control Center InstallProxy (Version: 2010.0225.1742.31671)
Catalyst Control Center InstallProxy (Version: 2012.0928.1532.26058)
Catalyst Control Center Localization All (Version: 2012.0928.1532.26058)
CCC Help Chinese Standard (Version: 2012.0928.1531.26058)
CCC Help Chinese Traditional (Version: 2012.0928.1531.26058)
CCC Help Czech (Version: 2012.0928.1531.26058)
CCC Help Danish (Version: 2012.0928.1531.26058)
CCC Help Dutch (Version: 2012.0928.1531.26058)
CCC Help English (Version: 2012.0928.1531.26058)
CCC Help Finnish (Version: 2012.0928.1531.26058)
CCC Help French (Version: 2012.0928.1531.26058)
CCC Help German (Version: 2012.0928.1531.26058)
CCC Help Greek (Version: 2012.0928.1531.26058)
CCC Help Hungarian (Version: 2012.0928.1531.26058)
CCC Help Italian (Version: 2012.0928.1531.26058)
CCC Help Japanese (Version: 2012.0928.1531.26058)
CCC Help Korean (Version: 2012.0928.1531.26058)
CCC Help Norwegian (Version: 2012.0928.1531.26058)
CCC Help Polish (Version: 2012.0928.1531.26058)
CCC Help Portuguese (Version: 2012.0928.1531.26058)
CCC Help Russian (Version: 2012.0928.1531.26058)
CCC Help Spanish (Version: 2012.0928.1531.26058)
CCC Help Swedish (Version: 2012.0928.1531.26058)
CCC Help Thai (Version: 2012.0928.1531.26058)
CCC Help Turkish (Version: 2012.0928.1531.26058)
ccc-utility64 (Version: 2012.0928.1532.26058)
Chicken Invaders 2
Chimeras: Melodie der Rache Sammleredition
Coffee Break PacMan (Version: )
Color Eggs II
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000)
cyberJack Base Components (Version: 6.10.0)
Dairy Dash
Das Vermächtnis der Insel (Version: 1.0.0.0)
DATA BECKER 3D Wohnungsplaner 10 (Version: 1.3.495.0)
Deep Blue Sea – Die Schatztaucherin
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Detective Quest: Der gläserne Schuh Sammleredition
DEUTSCHLAND SPIELT GAME CENTER (Version: 1.2010.6.23)
DEUTSCHLAND SPIELT Spiele Post (Version: 1.0.3.0)
Diamond Drop (VOLLVERSION)
Die Legende von Pocahontas
Dino & Aliens
Dream Day First Home
eBay Worldwide (Version: 2.1.0901)
eReg (Version: 1.20.138.34)
eSobi v2 (Version: 2.0.4.000274)
Farm Frenzy 2
Farmington Tales
Firebird SQL Server - MAGIX Edition (Version: 2.1.31.0)
Fotos auf DVD 2013 Deluxe Update (Version: 12.0.3.80)
freundin - Mystery Tales 2
Geheime Fälle: Die gestohlene Venus 2 (Version: 1.0.0.0)
Gigaset QuickSync (Version: 5.1.0001.14719)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.4.3607.2246)
Google Update Helper (Version: 1.3.21.145)
Granny In Paradise
Haali Media Splitter
Hotkey Utility (Version: 2.05.3003)
Hühner-Attacke (VOLLVERSION)
Hühner-Rache
HUK-COBURG Angebotssoftware VISonline (Version: 11.5.0)
I Have No Tomatoes v1.5
Identity Card (Version: 1.00.3003)
ImagXpress (Version: 7.0.74.0)
Jäger des Geisterhauses
Java Auto Updater (Version: 2.0.7.1)
Java(TM) 6 Update 31 (Version: 6.0.310)
Junk Mail filter update (Version: 14.0.8089.726)
Kalender-Excel-8.7.1 (Version: 8.7.1)
Kalender-Excel-8.9 (Version: 8.9)
Logitech SetPoint 6.15 (Version: 6.15.25)
Love Over Death (Version: 1.2.0.102)
LWP_eToken_Client (Version: 3.5.2)
Mad Cars
Magic Ball 2
MAGIX Fotos auf DVD 2013 Deluxe (Version: 12.0.0.75)
MAGIX Screenshare (Version: 4.3.6.1987)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
MediaShow Espresso (Version: 5.5.1403_23691)
Mein CEWE FOTOBUCH
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Choice Guard (Version: 2.0.48.0)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Home and Student 2010 (Version: 14.0.6029.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Office Standard Edition 2003 (Version: 11.0.8173.0)
Microsoft Office Suite Activation Assistant (Version: 2.9)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft SQL Server 2005 Express Edition (SQLHUK) (Version: 9.4.5000.00)
Microsoft SQL Server Native Client (Version: 9.00.5000.00)
Microsoft SQL Server VSS Writer (Version: 9.00.5000.00)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Works (Version: 9.7.0621)
Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0)
MSVCRT (Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0)
MyFreeCodec
MyMDb 3.6
MyWinLocker (Version: 3.1.206.0)
MyWinLocker Suite (Version: 3.1.206.0)
Nero 9 Essentials
Nero ControlCenter (Version: 9.0.0.1)
Nero DiscSpeed (Version: 5.4.13.100)
Nero DiscSpeed Help (Version: 5.4.4.100)
Nero DriveSpeed (Version: 4.4.12.100)
Nero DriveSpeed Help (Version: 4.4.4.100)
Nero Express Help (Version: 9.6.2.101)
Nero InfoTool (Version: 6.4.12.100)
Nero InfoTool Help (Version: 6.4.4.100)
Nero Installer (Version: 4.4.9.0)
Nero Online Upgrade (Version: 1.3.0.0)
Nero StartSmart (Version: 9.4.37.100)
Nero StartSmart Help (Version: 9.4.27.100)
Nero StartSmart OEM (Version: 9.16.0.100)
NeroExpress (Version: 9.4.33.100)
neroxml (Version: 1.0.0)
Paragon Festplatten Manager™ 2011 Kompakt (Version: 90.00.0003)
Password Depot 5 (Version: 5.3.0)
PCLinq2 High-Speed USB Bridge Cable
Phantasmat: Eisiger Gipfel
Pixum Fotobuch
PL-2303 USB-to-Serial (Version: 1.00.000)
Protect Disc License Helper 1.0.125 (IE) (Version: 1.0.125)
ProtectDisc Driver, Version 11 (Version: 11.0.0.14)
Rasputins Curse (Version: 1.00)
Realtek Ethernet Controller Driver (Version: 7.46.610.2011)
Realtek High Definition Audio Driver (Version: 6.0.1.5963)
Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.0.26.0)
Robinson Crusoe and the Cursed Pirates (Version: 1.00)
Romance of Rome
Sable Maze: Sullivan River
Sacra Terra: Der Kuss des Todes
Sacra Terra: Der Kuss des Todes, Sammleredition
Samsung Kies (Version: 2.3.2.12064_9)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.18.0)
Santa Hanta 2.4c
Secret Diaries: Florence Ashford (Version: 1.0.0.0)
secrets of tahiti
Shadow Wolf Mysteries Bane of the Family de (Version: de)
Shredder (Version: 2.0.5.0)
Shrek(R) SuperSlam (Version: 1.00.0000)
Skype™ 6.0 (Version: 6.0.126)
Spin & Win
Spirits of Mystery: Der dunkle Minotaurus Sammleredition
StarMoney (Version: 3.0.0.124)
StarMoney (Version: 4.0.0.203)
StarMoney 8.0 S-Edition (Version: 8.0)
Steuer-Spar-Erklärung 2011 (Version: 16.12)
Steuer-Spar-Erklärung 2012 (Version: 17.11)
Steuer-Spar-Erklärung 2013 (Version: 18.06)
Super Puzzle
Sven XXX - XXL
The Beast of Lycan Isle
The Curse Of Ra (Version: 3.3.0)
The Mystery of the Crystal Portal - Die versunkene Welt (Version: 1.00)
The Saint: Abgrund der Verzweiflung
Time Mysteries: Das letzte Rätsel
Time Mysteries: Das letzte Rätsel Sammleredition
TMS 5.1 SP1 Client (Version: 5.1.127)
Tödliche Sonate: Ein Dana Knightstone-Roman
Tory's Shop'n' Rush
TurboFLOORPLAN Garten- & Landschaftsarchitekt (Version: 12.1)
Unfinished Tales: Unsterbliche Liebe
Unfinished Tales: Unsterbliche Liebe Sammleredition
Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.5000.00)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
Verbotene Geheimnisse: Alien Town
Verschleierte Wirklichkeit (Version: 1.0.0.0)
VIS Aktualisierung (Version: 2.2.0)
VISonline Diagnose (Version: 2.0.1)
Web of Deceit: Die Schwarze Witwe Sammleredition
Welcome Center (Version: 1.00.3013)
Windows Live Anmelde-Assistent (Version: 5.000.818.5)
Windows Live Call (Version: 14.0.8064.0206)
Windows Live Communications Platform (Version: 14.0.8064.206)
Windows Live Essentials (Version: 14.0.8089.0726)
Windows Live Essentials (Version: 14.0.8089.726)
Windows Live Fotogalerie (Version: 14.0.8081.709)
Windows Live Mail (Version: 14.0.8089.0726)
Windows Live Messenger (Version: 14.0.8089.0726)
Windows Live Movie Maker (Version: 14.0.8091.0730)
Windows Live Sync (Version: 14.0.8089.726)
Windows Live Writer (Version: 14.0.8089.0726)
Windows Live-Uploadtool (Version: 14.0.8014.1029)
Windows Mobile-Gerätecenter (Version: 6.1.6965.0)
Wondershare Vivideo(Build 2.0.0.12)
Zoo Safari

==================== Restore Points  =========================

23-05-2013 17:11:49 TuneUp Utilities 2012 wird entfernt
23-05-2013 17:13:38 TuneUp Utilities Language Pack (de-DE) wird entfernt
26-05-2013 17:00:09 Windows-Sicherung
02-06-2013 17:00:09 Windows-Sicherung
09-06-2013 17:00:10 Windows-Sicherung
12-06-2013 01:00:15 Windows Update
14-06-2013 14:47:48 Windows Update
14-06-2013 15:36:49 Removed Cisco AnyConnect Secure Mobility Client
14-06-2013 15:40:33 eTokenEnroll wird entfernt
14-06-2013 15:41:02 Removed eToken PKI Client 5.1 SP1

==================== Faulty Device Manager Devices =============

Name: H:\
Description: Flash Reader    
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Multiple
Service: WUDFRd
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. 

Name: Standardtastatur (PS/2)
Description: Standardtastatur (PS/2)
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardtastaturen)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: UFOS
Description: USB Flash Disk  
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: BUFFALO 
Service: WUDFRd
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. 

Name: Microsoft PS/2-Maus
Description: Microsoft PS/2-Maus
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/09/2013 07:00:50 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Das System kann die angegebene Datei nicht finden. (0x80070002)"

Error: (06/06/2013 02:17:06 PM) (Source: Software Protection Platform Service) (User: )
Description: Fehler bei der Erfassung des authentischen Tickets (hr=0xC004C32A) für die Vorlagen-ID 66c92734-d682-4d71-983e-d6ec3f16059f.

Error: (06/06/2013 02:17:06 PM) (Source: Software Protection Platform Service) (User: )
Description: Lizenzerwerb-Fehlerdetails. 
hr=0xC004C32A

Error: (06/06/2013 01:11:28 PM) (Source: Application Hang) (User: )
Description: Programm StarMoney.exe, Version 3.0.6.31 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 47a8

Startzeit: 01ce62a625b60d5e

Endzeit: 0

Anwendungspfad: C:\Program Files (x86)\StarMoney 8.0 S-Edition\app\StarMoney.exe

Berichts-ID:

Error: (06/05/2013 11:40:10 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16576, Zeitstempel: 0x515e30fe
Name des fehlerhaften Moduls: pdIEAddOn.dll, Version: 5.3.0.0, Zeitstempel: 0x4d8b468d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00004f5a
ID des fehlerhaften Prozesses: 0x1118
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3

Error: (06/02/2013 07:00:52 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Das System kann die angegebene Datei nicht finden. (0x80070002)"

Error: (06/02/2013 02:53:11 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: HauntedLegends_TheUndertakerCE_RC.exe, Version: 0.0.0.0, Zeitstempel: 0x51234949
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x1c20674a
ID des fehlerhaften Prozesses: 0x3d94
Startzeit der fehlerhaften Anwendung: 0xHauntedLegends_TheUndertakerCE_RC.exe0
Pfad der fehlerhaften Anwendung: HauntedLegends_TheUndertakerCE_RC.exe1
Pfad des fehlerhaften Moduls: HauntedLegends_TheUndertakerCE_RC.exe2
Berichtskennung: HauntedLegends_TheUndertakerCE_RC.exe3

Error: (05/30/2013 06:16:47 PM) (Source: Application Hang) (User: )
Description: Programm IEXPLORE.EXE, Version 10.0.9200.16576 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 23b4

Startzeit: 01ce5d4e1f317c1c

Endzeit: 15

Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Berichts-ID:

Error: (05/26/2013 07:00:47 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Das System kann die angegebene Datei nicht finden. (0x80070002)"

Error: (05/26/2013 03:25:54 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16576, Zeitstempel: 0x515e30fe
Name des fehlerhaften Moduls: pdIEAddOn.dll, Version: 5.3.0.0, Zeitstempel: 0x4d8b468d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00004f5a
ID des fehlerhaften Prozesses: 0xea4
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3


System errors:
=============
Error: (06/15/2013 01:10:18 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597 (Definition 1.151.2213.0)

Error: (06/14/2013 06:03:09 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.

Error: (06/14/2013 06:03:08 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.

Error: (06/14/2013 06:03:08 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR6 gefunden.

Error: (06/14/2013 05:43:38 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%1058

Error: (06/14/2013 05:43:38 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%1058

Error: (06/14/2013 05:43:27 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%1058

Error: (06/14/2013 05:42:47 PM) (Source: Microsoft-Windows-BitLocker-Driver) (User: NT-AUTORITÄT)
Description: Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf "\\?\Volume{9ae5ce6c-7702-11dc-9bbd-806e6f6e6963}" können nicht gelesen werden.

Error: (06/14/2013 05:42:47 PM) (Source: Microsoft-Windows-BitLocker-Driver) (User: NT-AUTORITÄT)
Description: Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf "\\?\Volume{9ae5ce6b-7702-11dc-9bbd-806e6f6e6963}" können nicht gelesen werden.

Error: (06/14/2013 05:42:37 PM) (Source: Ntfs) (User: )
Description: Auf dem Volume "L:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.


Microsoft Office Sessions:
=========================
Error: (06/09/2013 07:00:50 PM) (Source: Windows Backup)(User: )
Description: Das System kann die angegebene Datei nicht finden. (0x80070002)

Error: (06/06/2013 02:17:06 PM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C32A66c92734-d682-4d71-983e-d6ec3f16059f

Error: (06/06/2013 02:17:06 PM) (Source: Software Protection Platform Service)(User: )
Description: hr=0xC004C32A00010001(0x00000000, 14:17:05:802 - hxxp://go.microsoft.com/fwlink/?LinkId=151642)
00020001(0x00000000, 14:17:05:802)
00030001(0x00000000, 14:17:05:802 - hxxp://go.microsoft.com)
00030002(0x00000000, 14:17:05:802 - 1)
00020005(0x00000000, 14:17:05:802 - 0)
0002000C(0x00000000, 14:17:05:989 - 302)
0002000E(0x00000000, 14:17:05:989 - https://validation.sls.microsoft.com/SLWGA/slwga.asmx)
00020001(0x00000000, 14:17:05:989)
00030001(0x00000000, 14:17:05:989 - https://validation.sls.microsoft.com)
00030002(0x00000000, 14:17:05:989 - 1)
00020005(0x00000000, 14:17:05:989 - 0)
0002000C(0x00000000, 14:17:06:629 - 500)
00010002(0x8004FC01, 14:17:06:629 - <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:soap="hxxp://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema"><soap:Body><soap:Fault><faultcode>soap:Server</faultcode><faultstring>SoapException</faultstring><detail><HRESULT>0xC004C32A</HRESULT><Messages><Message>553 (Validation) - [VGA: Required parameter not found in offline XML blob.  ---&gt; Parameter not found in offline XML blob - [Win7BootSectorMustExist]]</Message></Messages></detail></soap:Fault></soap:Body></soap:Envelope>)
00010003(0x8004FC01, 14:17:06:691)

Error: (06/06/2013 01:11:28 PM) (Source: Application Hang)(User: )
Description: StarMoney.exe3.0.6.3147a801ce62a625b60d5e0C:\Program Files (x86)\StarMoney 8.0 S-Edition\app\StarMoney.exe

Error: (06/05/2013 11:40:10 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.16576515e30fepdIEAddOn.dll5.3.0.04d8b468dc000000500004f5a111801ce62334908731fC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll7ec8b21a-ce28-11e2-b5ad-90fba6e09548

Error: (06/02/2013 07:00:52 PM) (Source: Windows Backup)(User: )
Description: Das System kann die angegebene Datei nicht finden. (0x80070002)

Error: (06/02/2013 02:53:11 PM) (Source: Application Error)(User: )
Description: HauntedLegends_TheUndertakerCE_RC.exe0.0.0.051234949unknown0.0.0.000000000c00000051c20674a3d9401ce5f8d47bea427K:\Program Files (x86)\Haunted Legends - Der Bestatter\HauntedLegends_TheUndertakerCE_RC.exeunknown61244ad3-cb83-11e2-b5ad-90fba6e09548

Error: (05/30/2013 06:16:47 PM) (Source: Application Hang)(User: )
Description: IEXPLORE.EXE10.0.9200.1657623b401ce5d4e1f317c1c15C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (05/26/2013 07:00:47 PM) (Source: Windows Backup)(User: )
Description: Das System kann die angegebene Datei nicht finden. (0x80070002)

Error: (05/26/2013 03:25:54 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE10.0.9200.16576515e30fepdIEAddOn.dll5.3.0.04d8b468dc000000500004f5aea401ce5a0aacad2058C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dllca1f4e87-c607-11e2-b5ad-90fba6e09548


CodeIntegrity Errors:
===================================
  Date: 2013-02-15 09:53:34.309
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:34.216
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:32.113
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:32.021
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:29.918
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:29.789
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:27.595
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:27.501
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:25.364
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-15 09:53:25.286
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info =========================== 

Percentage of memory in use: 52%
Total physical RAM: 4023.11 MB
Available physical RAM: 1893.3 MB
Total Pagefile: 8044.4 MB
Available Pagefile: 5911.27 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:458.87 GB) (Free:385.93 GB) NTFS (Disk=0 Partition=3)
Drive d: (Data) (Fixed) (Total:458.87 GB) (Free:456.39 GB) NTFS (Disk=0 Partition=4)
Drive k: (32_00_00) (Fixed) (Total:931.28 GB) (Free:667.34 GB) FAT32 (Disk=3 Partition=1)
Drive l: (Platte2) (Fixed) (Total:1863.01 GB) (Free:1793.28 GB) NTFS (Disk=2 Partition=1)
Drive m: (Platte1) (Fixed) (Total:931.51 GB) (Free:930.82 GB) NTFS (Disk=1 Partition=1)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: A95C0492)
Partition 1: (Not Active) - (Size=14 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=459 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=459 GB) - (Type=07 NTFS)

========================================================
Disk: 3 (MBR Code: Windows XP) (Size: 932 GB) (Disk ID: 20152E0E)
Partition 1: (Active) - (Size=932 GB) - (Type=0C)

==================== End Of Log ============================
         
__________________

Alt 15.06.2013, 14:52   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Hi,

IPv6 deaktivieren in den Netzwerkeinstellungen.

Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 15.06.2013, 17:01   #5
Bambaataa22
 
Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Hi, kann es sein, dass ComboFix alle Programme schließt oder die Netzwerkverbindungen unterbricht?

Weil ich kann nur per Teamviewer auf den PC zugreifen und die Verbindung ist bei der Installation von Combofix abgebrochen und ich kann mich auch nicht neu verbinden...

Das hätt ich dir wohl vorher sagen sollen :-(

LG Bam


Alt 15.06.2013, 17:57   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Ja hättest Du

Teamviewer wird immer beendet.
__________________
--> Netzwerkprobleme - Schädling eingefangen?

Alt 25.06.2013, 16:34   #7
Bambaataa22
 
Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Moin, hier das ComboFix-Log:

Code:
ATTFilter
ComboFix 13-06-15.01 - S. Voß HUK 15.06.2013  17:56:52.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.4023.1884 [GMT 2:00]
ausgeführt von:: c:\users\S. Vo¯ HUK\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
c:\programdata\ntuser.dat
c:\windows\SysWow64\muzapp.exe
c:\windows\wininit.ini
c:\users\S. Voß HUK\Documents\TurboFLOORPLAN Garten- & Landschaftsarchitekt  . . . . Nicht in der Lage zu löschen
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-05-25 bis 2013-06-25  ))))))))))))))))))))))))))))))
.
.
2013-06-15 16:02 . 2013-06-15 16:02	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-06-15 12:38 . 2013-06-15 12:38	--------	d-----w-	C:\FRST
2013-06-15 10:21 . 2013-06-15 10:21	--------	d-----w-	c:\users\S. Voß HUK\AppData\Roaming\Malwarebytes
2013-06-15 10:21 . 2013-06-15 10:21	--------	d-----w-	c:\programdata\Malwarebytes
2013-06-15 10:21 . 2013-06-15 10:21	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware
2013-06-15 10:21 . 2013-04-04 12:50	25928	----a-w-	c:\windows\system32\drivers\mbam.sys
2013-06-11 22:40 . 2013-05-08 06:39	1910632	----a-w-	c:\windows\system32\drivers\tcpip.sys
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-14 14:56 . 2013-05-04 18:10	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-14 14:56 . 2013-05-04 18:10	692104	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-12 01:01 . 2010-09-04 15:46	75825640	----a-w-	c:\windows\system32\MRT.exe
2013-05-07 18:05 . 2013-05-07 18:05	719360	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll
2013-05-07 18:05 . 2013-05-07 18:05	523264	----a-w-	c:\windows\SysWow64\vbscript.dll
2013-05-07 18:05 . 2013-05-07 18:05	226304	----a-w-	c:\windows\system32\elshyph.dll
2013-05-07 18:05 . 2013-05-07 18:05	185344	----a-w-	c:\windows\SysWow64\elshyph.dll
2013-05-07 18:05 . 2013-05-07 18:05	158720	----a-w-	c:\windows\SysWow64\msls31.dll
2013-05-07 18:05 . 2013-05-07 18:05	150528	----a-w-	c:\windows\SysWow64\iexpress.exe
2013-05-07 18:05 . 2013-05-07 18:05	138752	----a-w-	c:\windows\SysWow64\wextract.exe
2013-05-07 18:05 . 2013-05-07 18:05	1054720	----a-w-	c:\windows\system32\MsSpellCheckingFacility.exe
2013-05-07 18:05 . 2013-05-07 18:05	97280	----a-w-	c:\windows\system32\mshtmled.dll
2013-05-07 18:05 . 2013-05-07 18:05	92160	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2013-05-07 18:05 . 2013-05-07 18:05	905728	----a-w-	c:\windows\system32\mshtmlmedia.dll
2013-05-07 18:05 . 2013-05-07 18:05	81408	----a-w-	c:\windows\system32\icardie.dll
2013-05-07 18:05 . 2013-05-07 18:05	77312	----a-w-	c:\windows\system32\tdc.ocx
2013-05-07 18:05 . 2013-05-07 18:05	762368	----a-w-	c:\windows\system32\ieapfltr.dll
2013-05-07 18:05 . 2013-05-07 18:05	73728	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2013-05-07 18:05 . 2013-05-07 18:05	62976	----a-w-	c:\windows\system32\pngfilt.dll
2013-05-07 18:05 . 2013-05-07 18:05	61952	----a-w-	c:\windows\SysWow64\tdc.ocx
2013-05-07 18:05 . 2013-05-07 18:05	599552	----a-w-	c:\windows\system32\vbscript.dll
2013-05-07 18:05 . 2013-05-07 18:05	52224	----a-w-	c:\windows\system32\msfeedsbs.dll
2013-05-07 18:05 . 2013-05-07 18:05	51200	----a-w-	c:\windows\system32\imgutil.dll
2013-05-07 18:05 . 2013-05-07 18:05	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2013-05-07 18:05 . 2013-05-07 18:05	48640	----a-w-	c:\windows\system32\mshtmler.dll
2013-05-07 18:05 . 2013-05-07 18:05	452096	----a-w-	c:\windows\system32\dxtmsft.dll
2013-05-07 18:05 . 2013-05-07 18:05	441856	----a-w-	c:\windows\system32\html.iec
2013-05-07 18:05 . 2013-05-07 18:05	38400	----a-w-	c:\windows\SysWow64\imgutil.dll
2013-05-07 18:05 . 2013-05-07 18:05	361984	----a-w-	c:\windows\SysWow64\html.iec
2013-05-07 18:05 . 2013-05-07 18:05	281600	----a-w-	c:\windows\system32\dxtrans.dll
2013-05-07 18:05 . 2013-05-07 18:05	27648	----a-w-	c:\windows\system32\licmgr10.dll
2013-05-07 18:05 . 2013-05-07 18:05	270848	----a-w-	c:\windows\system32\iedkcs32.dll
2013-05-07 18:05 . 2013-05-07 18:05	247296	----a-w-	c:\windows\system32\webcheck.dll
2013-05-07 18:05 . 2013-05-07 18:05	235008	----a-w-	c:\windows\system32\url.dll
2013-05-07 18:05 . 2013-05-07 18:05	23040	----a-w-	c:\windows\SysWow64\licmgr10.dll
2013-05-07 18:05 . 2013-05-07 18:05	216064	----a-w-	c:\windows\system32\msls31.dll
2013-05-07 18:05 . 2013-05-07 18:05	197120	----a-w-	c:\windows\system32\msrating.dll
2013-05-07 18:05 . 2013-05-07 18:05	173568	----a-w-	c:\windows\system32\ieUnatt.exe
2013-05-07 18:05 . 2013-05-07 18:05	167424	----a-w-	c:\windows\system32\iexpress.exe
2013-05-07 18:05 . 2013-05-07 18:05	1509376	----a-w-	c:\windows\system32\inetcpl.cpl
2013-05-07 18:05 . 2013-05-07 18:05	149504	----a-w-	c:\windows\system32\occache.dll
2013-05-07 18:05 . 2013-05-07 18:05	144896	----a-w-	c:\windows\system32\wextract.exe
2013-05-07 18:05 . 2013-05-07 18:05	1441280	----a-w-	c:\windows\SysWow64\inetcpl.cpl
2013-05-07 18:05 . 2013-05-07 18:05	1400416	----a-w-	c:\windows\system32\ieapfltr.dat
2013-05-07 18:05 . 2013-05-07 18:05	13824	----a-w-	c:\windows\system32\mshta.exe
2013-05-07 18:05 . 2013-05-07 18:05	137216	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2013-05-07 18:05 . 2013-05-07 18:05	136192	----a-w-	c:\windows\system32\iepeers.dll
2013-05-07 18:05 . 2013-05-07 18:05	135680	----a-w-	c:\windows\system32\IEAdvpack.dll
2013-05-07 18:05 . 2013-05-07 18:05	12800	----a-w-	c:\windows\SysWow64\mshta.exe
2013-05-07 18:05 . 2013-05-07 18:05	12800	----a-w-	c:\windows\system32\msfeedssync.exe
2013-05-07 18:05 . 2013-05-07 18:05	110592	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2013-05-07 18:05 . 2013-05-07 18:05	102912	----a-w-	c:\windows\system32\inseng.dll
2013-05-02 00:06 . 2010-08-15 14:31	278800	------w-	c:\windows\system32\MpSigStub.exe
2013-04-13 05:49 . 2013-05-15 10:32	135168	----a-w-	c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-15 10:32	350208	----a-w-	c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-15 10:32	308736	----a-w-	c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-15 10:32	111104	----a-w-	c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-15 10:32	474624	----a-w-	c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-15 10:32	2176512	----a-w-	c:\windows\apppatch\AcGenral.dll
2013-04-12 14:45 . 2013-04-23 20:35	1656680	----a-w-	c:\windows\system32\drivers\ntfs.sys
2013-04-10 06:01 . 2013-05-15 10:32	265064	----a-w-	c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 06:01 . 2013-05-15 10:32	983400	----a-w-	c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 03:46 . 2013-05-07 07:59	9317456	------w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{9AFA303B-6235-4B97-97DC-181DE1913BEA}\mpengine.dll
2013-04-10 03:30 . 2013-05-15 10:32	3153920	----a-w-	c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-02-01 18:03	120176	----a-w-	c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2013-02-06 578560]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2013-02-13 1509232]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-11-09 17877168]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-19 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-02-01 337264]
"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2009-12-25 201512]
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2009-12-25 401192]
"Hotkey Utility"="c:\program files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" [2010-03-26 563744]
"MDS_Menu"="c:\program files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
.
c:\users\S. Voß HUK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2013-1-8 228448]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute	REG_MULTI_SZ   	autocheck autochk *\0k:\progra~1\PARAGO~1\FESTPL~1\bluescrn\bluescrn.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 BioNT_BS;BioNT_BS;k:\program files (x86)\Paragon Software\Festplatten Manager 2011 Kompakt\bluescrn\BioNT_bs.sys;k:\program files (x86)\Paragon Software\Festplatten Manager 2011 Kompakt\bluescrn\BioNT_bs.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 EraserUtilDrv11220;EraserUtilDrv11220;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\SysWOW64\FsUsbExDisk.SYS;c:\windows\SysWOW64\FsUsbExDisk.SYS [x]
R3 GigasetGenericUSB_x64;GigasetGenericUSB_x64;c:\windows\system32\DRIVERS\GigasetGenericUSB_x64.sys;c:\windows\SYSNATIVE\DRIVERS\GigasetGenericUSB_x64.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssudserd.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [x]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys;c:\windows\SYSNATIVE\DRIVERS\hotcore3.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
S2 AAV UpdateService;AAV UpdateService;c:\program files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe;c:\program files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys;c:\windows\SYSNATIVE\drivers\acedrv11.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 cjpcsc;cyberJack PC/SC COM Service ;c:\windows\SysWOW64\cjpcsc.exe;c:\windows\SysWOW64\cjpcsc.exe [x]
S2 DBService;DATA BECKER Update Service;c:\program files (x86)\Common Files\DATA BECKER Shared\DBService.exe;c:\program files (x86)\Common Files\DATA BECKER Shared\DBService.exe [x]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [x]
S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe;c:\program files (x86)\Acer\Registration\GregHSRW.exe [x]
S2 MSSQL$SQLHUK;SQL Server (SQLHUK);c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe;c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [x]
S2 StarMoney 8.0 OnlineUpdate;StarMoney 8.0 OnlineUpdate;c:\program files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe;c:\program files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [x]
S2 tksock;TK-Suite Server;c:\program files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe;c:\program files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe [x]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
S2 USBS3S4Detection;USBS3S4Detection;c:\oem\USBDECTION\USBS3S4Detection.exe;c:\oem\USBDECTION\USBS3S4Detection.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 avmaudio;AVM Audio;c:\windows\system32\DRIVERS\avmaudio.sys;c:\windows\SYSNATIVE\DRIVERS\avmaudio.sys [x]
S3 cjusb;REINER SCT cyberJack USB Driver;c:\windows\system32\DRIVERS\cjusb.sys;c:\windows\SYSNATIVE\DRIVERS\cjusb.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2013-06-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-04 14:56]
.
2013-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-15 12:25]
.
2013-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-15 12:25]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-02-01 18:06	137584	----a-w-	c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-02-01 349552]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-06-26 1609296]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-20 8306208]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_x3950&r=173608102207pe458v135w4651v85o
uLocal Page = c:\windows\system32\blank.htm
uInternet Settings,ProxyOverride = *.dmz.huk.de;*.hukvm.de;*.hukras.de;*.lan.huk-coburg.de;vtp.huk.de;vtp02.huk.de;vtp03.huk.de;vtp04.huk.de;vtp05.huk.de;vtpews.huk.de;crl1.huk-coburg.de;vtp.vrk.de;svks0009.vrk.de;sscd0040
TCP: DhcpNameServer = 192.168.178.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-CanonMyPrinter - K:\BJMyPrt.exe
AddRemove-3D Wohnungsplaner 10_is1 - k:\program files (x86)\DATA BECKER\3D Wohnungsplaner 10\unins000.exe
AddRemove-Ashampoo Burning Studio 2013_is1 - k:\program files (x86)\Ashampoo\Ashampoo Burning Studio 2013\unins000.exe
AddRemove-BFG-Awakening - Das Himmelsschloss Sammleredition - k:\program files (x86)\Awakening - Das Himmelsschloss Sammleredition\Uninstall.exe
AddRemove-BFG-Chimeras - Melodie der Rache Sammleredition - k:\program files (x86)\Chimeras - Melodie der Rache Sammleredition\Uninstall.exe
AddRemove-BFG-Farmington Tales - k:\program files (x86)\Farmington Tales\Uninstall.exe
AddRemove-BFG-Sable Maze - Sullivan River - k:\program files (x86)\Sable Maze - Sullivan River\Uninstall.exe
AddRemove-BFG-Sacra Terra - Der Kuss des Todes Sammleredition - k:\program files (x86)\Sacra Terra - Der Kuss des Todes Sammleredition\Uninstall.exe
AddRemove-BFG-Spirits of Mystery - Der dunkle Minotaurus Sammleredition - k:\program files (x86)\Spirits of Mystery - Der dunkle Minotaurus Sammleredition\Uninstall.exe
AddRemove-BFG-The Saint - Abgrund der Verzweiflung - k:\program files (x86)\The Saint - Abgrund der Verzweiflung\Uninstall.exe
AddRemove-BFG-Time Mysteries - Das letzte Raetsel Sammleredition - k:\program files (x86)\Time Mysteries - Das letzte Raetsel Sammleredition\Uninstall.exe
AddRemove-BFG-Toedliche Sonate - Ein Dana Knightstone-Roman - k:\program files (x86)\Toedliche Sonate - Ein Dana Knightstone-Roman\Uninstall.exe
AddRemove-BFG-Unfinished Tales - Unsterbliche Liebe - k:\program files (x86)\Unfinished Tales - Unsterbliche Liebe\Uninstall.exe
AddRemove-BFG-Unfinished Tales - Unsterbliche Liebe Sammleredition - k:\program files (x86)\Unfinished Tales - Unsterbliche Liebe Sammleredition\Uninstall.exe
AddRemove-BFG-Verbotene Geheimnisse - Alien Town - k:\program files (x86)\Verbotene Geheimnisse - Alien Town\Uninstall.exe
AddRemove-BFG-Web of Deceit - Die Schwarze Witwe Sammleredition - k:\program files (x86)\Web of Deceit - Die Schwarze Witwe Sammleredition\Uninstall.exe
AddRemove-CanonMyPrinter - K:\uninst.exe
AddRemove-Coffee Break PacMan - k:\coffee break pacman\uninstall.exe
AddRemove-Deep Blue Sea – Die Schatztaucherin_is1 - k:\program files (x86)\rondomedia\Deep Blue Sea – Die Schatztaucherin\unins000.exe
AddRemove-Easy-PhotoPrint EX - k:\program files\Canon\Easy-PhotoPrint EX\uninst.exe
AddRemove-I Have No Tomatoes - k:\i have no tomatoes\Uninstall.exe
AddRemove-Jäger des Geisterhauses_is1 - k:\program files (x86)\eGames\Geisterhaus\unins000.exe
AddRemove-Kalender-Excel-8.7.1_is1 - k:\users\S. Voß HUK\Documents\Kalender-Excel-8.7.1\unins000.exe
AddRemove-Kalender-Excel-8.9_is1 - k:\users\S. Voß HUK\Documents\Kalender-Excel-8.9\unins000.exe
AddRemove-Love Over Death - k:\program files (x86)\Love Over Death\Uninstall.exe
AddRemove-MyMDb_0 - k:\program files (x86)mymdb\Uninstall.exe
AddRemove-Pixum Fotobuch - k:\program files (x86)\Pixum\Pixum Fotobuch\uninstall.exe
AddRemove-Rasputins Curse - k:\program files (x86)\Rasputins Curse\de\uninst.exe
AddRemove-Robinson Crusoe and the Cursed Pirates - k:\program files (x86)\Robinson Crusoe and the Cursed Pirates\de\uninst.exe
AddRemove-Santa Hanta_is1 - k:\program files (x86)\Santa Hanta\unins000.exe
AddRemove-secrets of tahiti - k:\program files (x86)\Alawar\TahitiHiddenPearls\Uninstall.exe
AddRemove-The Mystery of the Crystal Portal - Die versunkene Welt - k:\program files (x86)\The Mystery of the Crystal Portal - Die versunkene Welt\de\uninst.exe
AddRemove-Tory's Shop'n' Rush - k:\progra~1\PURPLE~1\TORY'S~1\UNWISE.EXE
AddRemove-Wondershare Vivideo_is1 - k:\program files (x86)\Wondershare\Vivideo\unins000.exe
AddRemove-Zoo Safari_is1 - k:\program files (x86)\rondomedia\Zoo Safari\unins000.exe
AddRemove-{00B52299-F42A-40C3-8232-F987B86E3FD6}_is1 - k:\program files (x86)\Green Pepper\Die Legende von Pocahontas\unins000.exe
AddRemove-{02CF7793-9F94-45E9-BB0F-E0E5FAB463E6}_is1 - k:\program files (x86)\Romance of Rome\unins000.exe
AddRemove-{72FD9E53-73D1-4FC3-98DB-7889FD119946}_is1 - k:\program files (x86)\freundin-Games\Mystery Tales 2\unins000.exe
AddRemove-MyFreeCodec - k:\program files (x86)\MyFree Codec\1.0b beta\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Cyberlink\Shared files\RichVideo.exe
c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files (x86)\AGFEO\Tk-Suite\tkserver\tkmedia.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-06-25  17:24:20 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2013-06-25 15:24
.
Vor Suchlauf: 17 Verzeichnis(se), 414.229.327.872 Bytes frei
Nach Suchlauf: 23 Verzeichnis(se), 412.810.612.736 Bytes frei
.
- - End Of File - - 1F709E32F627B53CC9D10AEC5304943E
D41D8CD98F00B204E9800998ECF8427E
         

Alt 25.06.2013, 19:12   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST Log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 25.06.2013, 19:58   #9
Bambaataa22
 
Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Hi, hier die neuen Logs.
FRST hat nur 1 File erstellt, keine Addition.txt

Code:
ATTFilter
# AdwCleaner v2.303 - Datei am 25/06/2013 um 20:28:41 erstellt
# Aktualisiert am 08/06/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : S. Voß HUK - BUERO
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\S. Voß HUK\Desktop\AdwCleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk
Ordner Gelöscht : C:\Program Files (x86)\Wondershare
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\SpeedMaxPc
Ordner Gelöscht : C:\Users\S. Voß HUK\AppData\Roaming\DriverCure
Ordner Gelöscht : C:\Users\S. Voß HUK\AppData\Roaming\SpeedMaxPc

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\SpeedMaxPC
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : HKLM\Software\SpeedMaxPC
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}

***** [Internet Browser] *****

-\\ Internet Explorer v10.0.9200.16611

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [2080 octets] - [25/06/2013 20:27:45]
AdwCleaner[S1].txt - [2015 octets] - [25/06/2013 20:28:41]

########## EOF - C:\AdwCleaner[S1].txt - [2075 octets] ##########
         
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by S. Voá HUK on 25.06.2013 at 20:43:36,18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\big fish games"
Successfully deleted: [Folder] "C:\ProgramData\simplitec"
Successfully deleted: [Folder] "C:\Users\S. Voá HUK\AppData\Roaming\simplitec"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.06.2013 at 20:46:11,83
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2013 01
Ran by S. Voß HUK (administrator) on 25-06-2013 20:50:41
Running from C:\Users\S. Voß HUK\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe
(DATA BECKER GmbH & Co KG) C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
() C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe
(AGFEO      ) C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe
(AGFEO      ) C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tkmedia.exe
() C:\OEM\USBDECTION\USBS3S4Detection.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
() C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Microsoft) C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUI.exe
(TeamViewer GmbH) C:\Users\SDBC1~1.VOH\AppData\Local\Temp\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Users\SDBC1~1.VOH\AppData\Local\Temp\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Users\SDBC1~1.VOH\AppData\Local\Temp\TeamViewer\Version8\tv_x64.exe
(TeamViewer GmbH) c:\users\sdbc1~1.voh\appdata\local\temp\teamviewer\version8\TeamViewer_Desktop.exe
(Farbar) C:\Users\S. Voß HUK\Desktop\FRST64 (1).exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe                                                                                                                                                                                                              [349552 2010-02-01] (Egis Technology Inc.)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1609296 2010-06-26] (Logitech, Inc.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [8306208 2009-10-20] (Realtek Semiconductor)
HKLM\...\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [CanonMyPrinter] K:\BJMyPrt.exe /logon [x]
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKCU\...\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup [578560 2013-02-06] (Samsung Electronics)
HKCU\...\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload [1509232 2013-02-13] (Samsung)
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17877168 2012-11-09] (Skype Technologies S.A.)
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-03-20] (Google Inc.)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [337264 2010-02-01] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d                                                                                                                                                                                                                    [201512 2009-12-25] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"                                                                                                                                                                                                                        [401192 2009-12-25] (Egis Technology Inc.)
HKLM-x32\...\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [563744 2010-03-26] ()
HKLM-x32\...\Run: [MDS_Menu] "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2010-04-27] (Renesas Electronics Corporation)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
Startup: C:\Users\S. Voß HUK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * K:\PROGRA~1\PARAGO~1\FESTPL~1\bluescrn\bluescrn.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_x3950&r=173608102207pe458v135w4651v85o
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Password Depot 5 - {9F79B165-70F7-4C46-B1A5-8828E2FF21F9} - C:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll (AceBIT)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM {28B66320-9687-4B13-8757-36F901887AB5} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/canvasx64.cab
DPF: HKLM {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/jordan64.cab
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: msdaipp - No CLSID Value - 
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msdaipp - No CLSID Value - 
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

Chrome: 
=======
CHR HomePage: hxxp://www.google.com
CHR DefaultSearchURL: (Google) - {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR Extension: (YouTube) - C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0
CHR Extension: (Google Search) - C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0
CHR Extension: (Gmail) - C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0

==================== Services (Whitelisted) =================

R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [514128 2012-03-19] (REINER SCT)
R2 DBService; C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe [187456 2009-01-08] (DATA BECKER GmbH & Co KG)
R2 MSSQL$SQLHUK; C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
S4 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-02-01] (Egis Technology Inc.)
R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [244904 2010-02-03] ()
R2 StarMoney 8.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
R2 tksock; C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe [2104320 2010-04-20] (AGFEO      )
R2 USBS3S4Detection; C:\OEM\USBDECTION\USBS3S4Detection.exe [76320 2009-12-09] ()

==================== Drivers (Whitelisted) ====================

R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [116096 2011-08-07] (AVM Berlin)
R3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2011-03-29] (REINER SCT)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
S3 GigasetGenericUSB_x64; C:\Windows\System32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2009-02-20] (Siemens Home and Office Communication Devices GmbH & Co. KG)
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [37456 2011-03-03] (Paragon Software Group)
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [203104 2012-09-20] (DEVGURU Co., LTD.(www.devguru.co.kr))
R1 UimBus; C:\Windows\System32\DRIVERS\uimx64.sys [53840 2011-03-03] (Windows (R) 2000 DDK provider)
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [528464 2011-03-03] (Paragon)
S3 BioNT_BS; \??\K:\Program Files (x86)\Paragon Software\Festplatten Manager 2011 Kompakt\bluescrn\BioNT_bs.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 cpuz132; \??\C:\Users\SDBC1~1.VOH\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [x]
U3 DfSdkS; 
S3 EraserUtilDrv11220; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys [x]
S3 vpnva; system32\DRIVERS\vpnva64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-25 20:49 - 2013-06-25 20:49 - 01931854 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\FRST64 (1).exe
2013-06-25 20:49 - 2013-06-25 20:49 - 01931854 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\FRST64 (1).exe
2013-06-25 20:47 - 2013-06-25 20:48 - 00000000 ____D C:\Users\S. Voß HUK\Desktop\tools
2013-06-25 20:43 - 2013-06-25 20:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-25 20:43 - 2013-06-25 20:43 - 00000000 ____D C:\JRT
2013-06-25 20:41 - 2013-06-25 20:41 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\S. Voß HUK\Downloads\JRT.exe
2013-06-25 20:28 - 2013-06-25 20:28 - 00002142 ____A C:\AdwCleaner[S1].txt
2013-06-25 20:27 - 2013-06-25 20:27 - 00002080 ____A C:\AdwCleaner[R1].txt
2013-06-25 20:25 - 2013-06-25 20:25 - 00648201 ____A C:\Users\S. Voß HUK\Downloads\AdwCleaner.exe
2013-06-25 17:31 - 2013-06-25 20:34 - 00000262 ____A C:\Windows\wininit.ini
2013-06-25 17:25 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-25 17:25 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-25 17:25 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-25 17:25 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-25 17:25 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-25 17:25 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-25 17:25 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-25 17:25 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-25 17:25 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-25 17:25 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-25 17:25 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-25 17:25 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-25 17:24 - 2013-06-25 17:24 - 00028371 ____A C:\ComboFix.txt
2013-06-25 17:19 - 2013-06-25 17:19 - 1191829032 ____A C:\Windows\MEMORY.DMP
2013-06-25 17:19 - 2013-06-25 17:19 - 00455784 ____A C:\Windows\Minidump\062513-18688-01.dmp
2013-06-15 17:55 - 2013-06-25 17:24 - 00000000 ____D C:\Qoobox
2013-06-15 17:55 - 2013-06-25 17:23 - 00000000 ____D C:\Windows\erdnt
2013-06-15 17:55 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe
2013-06-15 17:55 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe
2013-06-15 17:55 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-06-15 17:55 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-06-15 17:55 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-06-15 17:55 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe
2013-06-15 17:55 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe
2013-06-15 17:55 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe
2013-06-15 17:54 - 2013-06-15 17:55 - 05080151 ____A (Swearware) C:\Users\S. Voß HUK\Downloads\ComboFix.exe
2013-06-15 14:38 - 2013-06-15 14:38 - 00000000 ____D C:\FRST
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\FRST64.exe
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\FRST64.exe
2013-06-15 14:31 - 2013-06-15 14:31 - 00760723 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\MiniToolBox.exe
2013-06-15 12:21 - 2013-06-15 12:21 - 10285040 ____A (Malwarebytes Corporation                                    ) C:\Users\S. Voß HUK\Downloads\mbam-setup-1.75.0.1300.exe
2013-06-15 12:21 - 2013-06-15 12:21 - 00001113 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-15 12:21 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-06-14 18:35 - 2013-06-14 18:34 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Desktop\TeamViewer_Setup_de.exe
2013-06-14 18:34 - 2013-06-14 18:34 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Downloads\TeamViewer_Setup_de.exe
2013-06-14 18:05 - 2013-06-14 18:05 - 00377856 ____A C:\Users\S. Voß HUK\Downloads\gmer_2.1.19163.exe
2013-06-14 17:55 - 2013-06-14 17:55 - 00101782 ____A C:\Users\S. Voß HUK\Downloads\Extras.Txt
2013-06-14 17:54 - 2013-06-14 17:54 - 00112916 ____A C:\Users\S. Voß HUK\Downloads\OTL.Txt
2013-06-14 17:47 - 2013-06-14 17:47 - 00602112 ____A (OldTimer Tools) C:\Users\S. Voß HUK\Downloads\OTL.exe
2013-06-14 15:35 - 2013-06-14 15:38 - 182243952 ____A C:\Users\S. Voß HUK\Downloads\smoney (1).exe
2013-06-12 03:01 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-12 03:01 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 03:01 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 03:01 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-12 03:01 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-12 03:01 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-12 00:40 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 00:40 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 00:40 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 00:40 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 00:40 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 00:40 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 00:40 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 00:40 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 00:40 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 00:40 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 00:40 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 00:40 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 00:40 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 00:40 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 00:40 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-12 00:40 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-12 00:40 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-12 00:40 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-12 00:40 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll

==================== One Month Modified Files and Folders =======

2013-06-25 20:49 - 2013-06-25 20:49 - 01931854 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\FRST64 (1).exe
2013-06-25 20:49 - 2013-06-25 20:49 - 01931854 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\FRST64 (1).exe
2013-06-25 20:48 - 2013-06-25 20:47 - 00000000 ____D C:\Users\S. Voß HUK\Desktop\tools
2013-06-25 20:43 - 2013-06-25 20:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-25 20:43 - 2013-06-25 20:43 - 00000000 ____D C:\JRT
2013-06-25 20:43 - 2012-12-28 12:40 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Skype
2013-06-25 20:41 - 2013-06-25 20:41 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\S. Voß HUK\Downloads\JRT.exe
2013-06-25 20:37 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-25 20:37 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-25 20:34 - 2013-06-25 17:31 - 00000262 ____A C:\Windows\wininit.ini
2013-06-25 20:34 - 2010-08-15 14:25 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-25 20:30 - 2013-05-23 19:17 - 00002332 ____A C:\Windows\setupact.log
2013-06-25 20:30 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-25 20:29 - 2013-05-09 10:17 - 01689973 ____A C:\Windows\WindowsUpdate.log
2013-06-25 20:29 - 2013-05-04 20:10 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-25 20:28 - 2013-06-25 20:28 - 00002142 ____A C:\AdwCleaner[S1].txt
2013-06-25 20:27 - 2013-06-25 20:27 - 00002080 ____A C:\AdwCleaner[R1].txt
2013-06-25 20:25 - 2013-06-25 20:25 - 00648201 ____A C:\Users\S. Voß HUK\Downloads\AdwCleaner.exe
2013-06-25 20:24 - 2010-08-15 14:25 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-25 17:24 - 2013-06-25 17:24 - 00028371 ____A C:\ComboFix.txt
2013-06-25 17:24 - 2013-06-15 17:55 - 00000000 ____D C:\Qoobox
2013-06-25 17:24 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default
2013-06-25 17:23 - 2013-06-15 17:55 - 00000000 ____D C:\Windows\erdnt
2013-06-25 17:21 - 2012-07-10 15:31 - 00000000 ____D C:\Program Files (x86)\StarMoney 8.0 S-Edition
2013-06-25 17:20 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini
2013-06-25 17:19 - 2013-06-25 17:19 - 1191829032 ____A C:\Windows\MEMORY.DMP
2013-06-25 17:19 - 2013-06-25 17:19 - 00455784 ____A C:\Windows\Minidump\062513-18688-01.dmp
2013-06-25 17:19 - 2013-05-23 19:17 - 00445650 ____A C:\Windows\PFRO.log
2013-06-25 17:19 - 2010-11-22 18:57 - 00000000 ____D C:\Windows\Minidump
2013-06-15 17:55 - 2013-06-15 17:54 - 05080151 ____A (Swearware) C:\Users\S. Voß HUK\Downloads\ComboFix.exe
2013-06-15 14:38 - 2013-06-15 14:38 - 00000000 ____D C:\FRST
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\FRST64.exe
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\FRST64.exe
2013-06-15 14:31 - 2013-06-15 14:31 - 00760723 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\MiniToolBox.exe
2013-06-15 12:21 - 2013-06-15 12:21 - 10285040 ____A (Malwarebytes Corporation                                    ) C:\Users\S. Voß HUK\Downloads\mbam-setup-1.75.0.1300.exe
2013-06-15 12:21 - 2013-06-15 12:21 - 00001113 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-14 18:35 - 2012-09-25 19:12 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\TeamViewer
2013-06-14 18:34 - 2013-06-14 18:35 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Desktop\TeamViewer_Setup_de.exe
2013-06-14 18:34 - 2013-06-14 18:34 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Downloads\TeamViewer_Setup_de.exe
2013-06-14 18:05 - 2013-06-14 18:05 - 00377856 ____A C:\Users\S. Voß HUK\Downloads\gmer_2.1.19163.exe
2013-06-14 18:04 - 2009-07-14 07:13 - 01769366 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-14 18:04 - 2007-10-10 19:26 - 00757356 ____A C:\Windows\System32\perfh007.dat
2013-06-14 18:04 - 2007-10-10 19:26 - 00172606 ____A C:\Windows\System32\perfc007.dat
2013-06-14 17:55 - 2013-06-14 17:55 - 00101782 ____A C:\Users\S. Voß HUK\Downloads\Extras.Txt
2013-06-14 17:54 - 2013-06-14 17:54 - 00112916 ____A C:\Users\S. Voß HUK\Downloads\OTL.Txt
2013-06-14 17:47 - 2013-06-14 17:47 - 00602112 ____A (OldTimer Tools) C:\Users\S. Voß HUK\Downloads\OTL.exe
2013-06-14 17:38 - 2012-11-13 18:34 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Steganos
2013-06-14 17:37 - 2011-09-22 07:53 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-06-14 17:37 - 2010-08-15 13:55 - 00000000 ____D C:\ProgramData\Cisco
2013-06-14 17:11 - 2013-05-09 10:25 - 00000000 ____D C:\ProgramData\Norton
2013-06-14 16:56 - 2013-05-04 20:10 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-14 16:56 - 2013-05-04 20:10 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-14 16:52 - 2010-08-15 13:55 - 01746324 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2013-06-14 15:38 - 2013-06-14 15:35 - 182243952 ____A C:\Users\S. Voß HUK\Downloads\smoney (1).exe
2013-06-12 04:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-12 03:23 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther
2013-06-12 03:05 - 2009-07-14 04:34 - 00000499 ____A C:\Windows\win.ini
2013-06-12 03:01 - 2010-09-04 17:46 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-09 12:16 - 2012-09-01 13:24 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Boomzap
2013-06-09 12:16 - 2010-08-15 11:37 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Local\VirtualStore
2013-06-08 16:08 - 2013-06-25 17:25 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-25 17:25 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-25 17:25 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-25 17:25 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-25 17:25 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-25 17:25 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-25 17:25 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-25 17:25 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-25 17:25 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-25 17:25 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-25 17:25 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-25 17:25 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-05 23:40 - 2013-05-09 13:43 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Local\CrashDumps
2013-06-02 14:32 - 2012-09-09 14:38 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\ERS Game Studios
2013-05-26 16:07 - 2013-05-09 12:49 - 00000000 ____D C:\Program Files (x86)\Grim Tales - Die Steinkoenigin Sammleredition
2013-05-26 15:26 - 2012-08-26 14:21 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Elephant Games
2013-05-26 15:26 - 2012-08-26 14:21 - 00000000 ____D C:\ProgramData\Elephant Games
2013-05-26 09:02 - 2012-09-30 14:19 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\AlawarEntertainment

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-25 17:50

==================== End Of Log ============================
         
--- --- ---

Alt 25.06.2013, 20:22   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Das is normal mit FRST


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST Log. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 26.06.2013, 18:40   #11
Bambaataa22
 
Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Hi, hier die Logs:

SecurityCheck sagt aber nur "Unsupported Operating System"

Das ursprüngliche Problem mit StarMoney ist aber nicht beseitigt.
Der Kontakt zum SMoney-Service schlägt weiterhin fehl...:-(

Hast du noch einen anderen Tip, z.B. komplettes Zurücksetzen des WIndows Netzwerk-Stacks oder so?

Hast du irgendeinen Schädling entdeckt während deiner Analyse?

Ich bedanke mich aber schonmal recht herzlich für deine tolle Hilfe!

MfG Bam

Code:
ATTFilter
ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# version=8
# IEXPLORE.EXE=10.00.9200.16521 (win8_gdr_soc_ie.130216-2100)
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=08e12cc0f9f2014796437d38ecce5639
# engine=14155
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-25 09:15:23
# local_time=2013-06-25 11:15:23 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 0 123824773 0 0
# scanned=274649
# found=0
# cleaned=0
# scan_time=6537
         

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013 (ATTENTION: FRST version is 13 days old)
Ran by S. Voß HUK (administrator) on 26-06-2013 19:05:34
Running from C:\Users\S. Voß HUK\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe
(DATA BECKER GmbH & Co KG) C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
() C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe
(AGFEO      ) C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe
(AGFEO      ) C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tkmedia.exe
() C:\OEM\USBDECTION\USBS3S4Detection.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
() C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Microsoft) C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUI.exe
(TeamViewer GmbH) C:\Users\SDBC1~1.VOH\AppData\Local\Temp\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Users\SDBC1~1.VOH\AppData\Local\Temp\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Users\SDBC1~1.VOH\AppData\Local\Temp\TeamViewer\Version8\tv_x64.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(TeamViewer GmbH) c:\users\sdbc1~1.voh\appdata\local\temp\teamviewer\version8\TeamViewer_Desktop.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe                                                                                                                                                                                                              [349552 2010-02-01] (Egis Technology Inc.)
HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1609296 2010-06-26] (Logitech, Inc.)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [8306208 2009-10-20] (Realtek Semiconductor)
HKLM\...\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [CanonMyPrinter] K:\BJMyPrt.exe /logon [x]
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKCU\...\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup [578560 2013-02-06] (Samsung Electronics)
HKCU\...\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload [1509232 2013-02-13] (Samsung)
HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17877168 2012-11-09] (Skype Technologies S.A.)
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-03-20] (Google Inc.)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [337264 2010-02-01] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d                                                                                                                                                                                                                    [201512 2009-12-25] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"                                                                                                                                                                                                                        [401192 2009-12-25] (Egis Technology Inc.)
HKLM-x32\...\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [563744 2010-03-26] ()
HKLM-x32\...\Run: [MDS_Menu] "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6" [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2010-04-27] (Renesas Electronics Corporation)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] ()
Startup: C:\Users\S. Voß HUK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * K:\PROGRA~1\PARAGO~1\FESTPL~1\bluescrn\bluescrn.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_x3950&r=173608102207pe458v135w4651v85o
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Password Depot 5 - {9F79B165-70F7-4C46-B1A5-8828E2FF21F9} - C:\Program Files (x86)\AceBIT\Password Depot 5\pdIEAddOn.dll (AceBIT)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM {28B66320-9687-4B13-8757-36F901887AB5} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/canvasx64.cab
DPF: HKLM {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/jordan64.cab
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: msdaipp - No CLSID Value - 
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: msdaipp - No CLSID Value - 
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

Chrome: 
=======
CHR HomePage: hxxp://www.google.com
CHR DefaultSearchURL: (Google) - {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR Extension: (YouTube) - C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0
CHR Extension: (Google Search) - C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0
CHR Extension: (Gmail) - C:\Users\S. Voß HUK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0

==================== Services (Whitelisted) =================

R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [514128 2012-03-19] (REINER SCT)
R2 DBService; C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe [187456 2009-01-08] (DATA BECKER GmbH & Co KG)
R2 MSSQL$SQLHUK; C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
S4 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-02-01] (Egis Technology Inc.)
R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [244904 2010-02-03] ()
R2 StarMoney 8.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
R2 tksock; C:\Program Files (x86)\AGFEO\Tk-Suite\tkserver\tksock.exe [2104320 2010-04-20] (AGFEO      )
R2 USBS3S4Detection; C:\OEM\USBDECTION\USBS3S4Detection.exe [76320 2009-12-09] ()

==================== Drivers (Whitelisted) ====================

R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [116096 2011-08-07] (AVM Berlin)
R3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2011-03-29] (REINER SCT)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
S3 GigasetGenericUSB_x64; C:\Windows\System32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2009-02-20] (Siemens Home and Office Communication Devices GmbH & Co. KG)
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [37456 2011-03-03] (Paragon Software Group)
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [203104 2012-09-20] (DEVGURU Co., LTD.(www.devguru.co.kr))
R1 UimBus; C:\Windows\System32\DRIVERS\uimx64.sys [53840 2011-03-03] (Windows (R) 2000 DDK provider)
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [528464 2011-03-03] (Paragon)
S3 BioNT_BS; \??\K:\Program Files (x86)\Paragon Software\Festplatten Manager 2011 Kompakt\bluescrn\BioNT_bs.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 cpuz132; \??\C:\Users\SDBC1~1.VOH\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [x]
U3 DfSdkS; 
S3 EraserUtilDrv11220; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys [x]
S3 vpnva; system32\DRIVERS\vpnva64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-26 19:02 - 2013-06-26 19:07 - 00890988 ____A C:\Users\S. Voß HUK\Desktop\SecurityCheck.exe
2013-06-26 19:02 - 2013-06-26 19:02 - 00890988 ____A C:\Users\S. Voß HUK\Downloads\SecurityCheck.exe
2013-06-25 21:24 - 2013-06-25 21:24 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-25 20:49 - 2013-06-25 20:49 - 01931854 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\FRST64 (1).exe
2013-06-25 20:49 - 2013-06-25 20:49 - 01931854 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\FRST64 (1).exe
2013-06-25 20:47 - 2013-06-25 20:48 - 00000000 ____D C:\Users\S. Voß HUK\Desktop\tools
2013-06-25 20:43 - 2013-06-25 20:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-25 20:43 - 2013-06-25 20:43 - 00000000 ____D C:\JRT
2013-06-25 20:41 - 2013-06-25 20:41 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\S. Voß HUK\Downloads\JRT.exe
2013-06-25 20:28 - 2013-06-25 20:28 - 00002142 ____A C:\AdwCleaner[S1].txt
2013-06-25 20:27 - 2013-06-25 20:27 - 00002080 ____A C:\AdwCleaner[R1].txt
2013-06-25 20:25 - 2013-06-25 20:25 - 00648201 ____A C:\Users\S. Voß HUK\Downloads\AdwCleaner.exe
2013-06-25 17:31 - 2013-06-25 20:34 - 00000262 ____A C:\Windows\wininit.ini
2013-06-25 17:25 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-25 17:25 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-25 17:25 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-25 17:25 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-25 17:25 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-25 17:25 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-25 17:25 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-25 17:25 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-25 17:25 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-25 17:25 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-25 17:25 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-25 17:25 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-25 17:24 - 2013-06-25 17:24 - 00028371 ____A C:\ComboFix.txt
2013-06-25 17:19 - 2013-06-25 17:19 - 1191829032 ____A C:\Windows\MEMORY.DMP
2013-06-25 17:19 - 2013-06-25 17:19 - 00455784 ____A C:\Windows\Minidump\062513-18688-01.dmp
2013-06-15 17:55 - 2013-06-25 17:24 - 00000000 ____D C:\Qoobox
2013-06-15 17:55 - 2013-06-25 17:23 - 00000000 ____D C:\Windows\erdnt
2013-06-15 17:55 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe
2013-06-15 17:55 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe
2013-06-15 17:55 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-06-15 17:55 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-06-15 17:55 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-06-15 17:55 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe
2013-06-15 17:55 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe
2013-06-15 17:55 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe
2013-06-15 17:54 - 2013-06-15 17:55 - 05080151 ____A (Swearware) C:\Users\S. Voß HUK\Downloads\ComboFix.exe
2013-06-15 14:38 - 2013-06-15 14:38 - 00000000 ____D C:\FRST
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\FRST64.exe
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\FRST64.exe
2013-06-15 14:31 - 2013-06-15 14:31 - 00760723 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\MiniToolBox.exe
2013-06-15 12:21 - 2013-06-15 12:21 - 10285040 ____A (Malwarebytes Corporation                                    ) C:\Users\S. Voß HUK\Downloads\mbam-setup-1.75.0.1300.exe
2013-06-15 12:21 - 2013-06-15 12:21 - 00001113 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-15 12:21 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-06-14 18:35 - 2013-06-14 18:34 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Desktop\TeamViewer_Setup_de.exe
2013-06-14 18:34 - 2013-06-14 18:34 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Downloads\TeamViewer_Setup_de.exe
2013-06-14 18:05 - 2013-06-14 18:05 - 00377856 ____A C:\Users\S. Voß HUK\Downloads\gmer_2.1.19163.exe
2013-06-14 17:55 - 2013-06-14 17:55 - 00101782 ____A C:\Users\S. Voß HUK\Downloads\Extras.Txt
2013-06-14 17:54 - 2013-06-14 17:54 - 00112916 ____A C:\Users\S. Voß HUK\Downloads\OTL.Txt
2013-06-14 17:47 - 2013-06-14 17:47 - 00602112 ____A (OldTimer Tools) C:\Users\S. Voß HUK\Downloads\OTL.exe
2013-06-14 15:35 - 2013-06-14 15:38 - 182243952 ____A C:\Users\S. Voß HUK\Downloads\smoney (1).exe
2013-06-12 03:01 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 03:01 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-12 03:01 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 03:01 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 03:01 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 03:01 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-12 03:01 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-12 03:01 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-12 00:40 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 00:40 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 00:40 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 00:40 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 00:40 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 00:40 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 00:40 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 00:40 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 00:40 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 00:40 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 00:40 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 00:40 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 00:40 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 00:40 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 00:40 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-12 00:40 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-12 00:40 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-12 00:40 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-12 00:40 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll

==================== One Month Modified Files and Folders =======

2013-06-26 19:07 - 2013-06-26 19:02 - 00890988 ____A C:\Users\S. Voß HUK\Desktop\SecurityCheck.exe
2013-06-26 19:02 - 2013-06-26 19:02 - 00890988 ____A C:\Users\S. Voß HUK\Downloads\SecurityCheck.exe
2013-06-26 18:29 - 2013-05-04 20:10 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-26 18:24 - 2010-08-15 14:25 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-26 17:24 - 2013-05-09 10:17 - 01699817 ____A C:\Windows\WindowsUpdate.log
2013-06-25 21:24 - 2013-06-25 21:24 - 00000000 ____D C:\Program Files (x86)\ESET
2013-06-25 20:49 - 2013-06-25 20:49 - 01931854 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\FRST64 (1).exe
2013-06-25 20:49 - 2013-06-25 20:49 - 01931854 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\FRST64 (1).exe
2013-06-25 20:48 - 2013-06-25 20:47 - 00000000 ____D C:\Users\S. Voß HUK\Desktop\tools
2013-06-25 20:43 - 2013-06-25 20:43 - 00000000 ____D C:\Windows\ERUNT
2013-06-25 20:43 - 2013-06-25 20:43 - 00000000 ____D C:\JRT
2013-06-25 20:43 - 2012-12-28 12:40 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Skype
2013-06-25 20:41 - 2013-06-25 20:41 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\S. Voß HUK\Downloads\JRT.exe
2013-06-25 20:37 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-25 20:37 - 2009-07-14 06:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-25 20:34 - 2013-06-25 17:31 - 00000262 ____A C:\Windows\wininit.ini
2013-06-25 20:34 - 2010-08-15 14:25 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-25 20:30 - 2013-05-23 19:17 - 00002332 ____A C:\Windows\setupact.log
2013-06-25 20:30 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-25 20:28 - 2013-06-25 20:28 - 00002142 ____A C:\AdwCleaner[S1].txt
2013-06-25 20:27 - 2013-06-25 20:27 - 00002080 ____A C:\AdwCleaner[R1].txt
2013-06-25 20:25 - 2013-06-25 20:25 - 00648201 ____A C:\Users\S. Voß HUK\Downloads\AdwCleaner.exe
2013-06-25 17:24 - 2013-06-25 17:24 - 00028371 ____A C:\ComboFix.txt
2013-06-25 17:24 - 2013-06-15 17:55 - 00000000 ____D C:\Qoobox
2013-06-25 17:24 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default
2013-06-25 17:23 - 2013-06-15 17:55 - 00000000 ____D C:\Windows\erdnt
2013-06-25 17:21 - 2012-07-10 15:31 - 00000000 ____D C:\Program Files (x86)\StarMoney 8.0 S-Edition
2013-06-25 17:20 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini
2013-06-25 17:19 - 2013-06-25 17:19 - 1191829032 ____A C:\Windows\MEMORY.DMP
2013-06-25 17:19 - 2013-06-25 17:19 - 00455784 ____A C:\Windows\Minidump\062513-18688-01.dmp
2013-06-25 17:19 - 2013-05-23 19:17 - 00445650 ____A C:\Windows\PFRO.log
2013-06-25 17:19 - 2010-11-22 18:57 - 00000000 ____D C:\Windows\Minidump
2013-06-15 17:55 - 2013-06-15 17:54 - 05080151 ____A (Swearware) C:\Users\S. Voß HUK\Downloads\ComboFix.exe
2013-06-15 14:38 - 2013-06-15 14:38 - 00000000 ____D C:\FRST
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\FRST64.exe
2013-06-15 14:37 - 2013-06-15 14:37 - 01920398 ____A (Farbar) C:\Users\S. Voß HUK\Desktop\FRST64.exe
2013-06-15 14:31 - 2013-06-15 14:31 - 00760723 ____A (Farbar) C:\Users\S. Voß HUK\Downloads\MiniToolBox.exe
2013-06-15 12:21 - 2013-06-15 12:21 - 10285040 ____A (Malwarebytes Corporation                                    ) C:\Users\S. Voß HUK\Downloads\mbam-setup-1.75.0.1300.exe
2013-06-15 12:21 - 2013-06-15 12:21 - 00001113 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-15 12:21 - 2013-06-15 12:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-14 18:35 - 2012-09-25 19:12 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\TeamViewer
2013-06-14 18:34 - 2013-06-14 18:35 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Desktop\TeamViewer_Setup_de.exe
2013-06-14 18:34 - 2013-06-14 18:34 - 05141464 ____A (TeamViewer GmbH) C:\Users\S. Voß HUK\Downloads\TeamViewer_Setup_de.exe
2013-06-14 18:05 - 2013-06-14 18:05 - 00377856 ____A C:\Users\S. Voß HUK\Downloads\gmer_2.1.19163.exe
2013-06-14 18:04 - 2009-07-14 07:13 - 01769366 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-14 18:04 - 2007-10-10 19:26 - 00757356 ____A C:\Windows\System32\perfh007.dat
2013-06-14 18:04 - 2007-10-10 19:26 - 00172606 ____A C:\Windows\System32\perfc007.dat
2013-06-14 17:55 - 2013-06-14 17:55 - 00101782 ____A C:\Users\S. Voß HUK\Downloads\Extras.Txt
2013-06-14 17:54 - 2013-06-14 17:54 - 00112916 ____A C:\Users\S. Voß HUK\Downloads\OTL.Txt
2013-06-14 17:47 - 2013-06-14 17:47 - 00602112 ____A (OldTimer Tools) C:\Users\S. Voß HUK\Downloads\OTL.exe
2013-06-14 17:38 - 2012-11-13 18:34 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Steganos
2013-06-14 17:37 - 2011-09-22 07:53 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-06-14 17:37 - 2010-08-15 13:55 - 00000000 ____D C:\ProgramData\Cisco
2013-06-14 17:11 - 2013-05-09 10:25 - 00000000 ____D C:\ProgramData\Norton
2013-06-14 16:56 - 2013-05-04 20:10 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-14 16:56 - 2013-05-04 20:10 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-14 16:52 - 2010-08-15 13:55 - 01746324 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2013-06-14 15:38 - 2013-06-14 15:35 - 182243952 ____A C:\Users\S. Voß HUK\Downloads\smoney (1).exe
2013-06-12 04:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-12 03:23 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther
2013-06-12 03:05 - 2009-07-14 04:34 - 00000499 ____A C:\Windows\win.ini
2013-06-12 03:01 - 2010-09-04 17:46 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-09 12:16 - 2012-09-01 13:24 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\Boomzap
2013-06-09 12:16 - 2010-08-15 11:37 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Local\VirtualStore
2013-06-08 16:08 - 2013-06-25 17:25 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-25 17:25 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-25 17:25 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-25 17:25 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-25 17:25 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-25 17:25 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-25 17:25 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-25 17:25 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-25 17:25 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-25 17:25 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-25 17:25 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-25 17:25 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-05 23:40 - 2013-05-09 13:43 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Local\CrashDumps
2013-06-02 14:32 - 2012-09-09 14:38 - 00000000 ____D C:\Users\S. Voß HUK\AppData\Roaming\ERS Game Studios

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-25 17:50

==================== End Of Log ============================
         
--- --- ---

Alt 26.06.2013, 19:40   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Ja wir haben einiges entfernt. Bitte mal Starmoney komplett deinstallieren, rebooten und neu installieren.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 06.07.2013, 16:39   #13
Bambaataa22
 
Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Sorry, dass ich mich so lange nicht gemeldet habe...
Hab meinem Kollegen gesagt, dass er SMoney neu installieren soll, hab aber noch keine Rückmeldung bekommen ob das Problem gelöst ist.

Ich bedanke mich aber schonmal recht herzlich für deine kompetente Hilfe!

LG Bam

Alt 06.07.2013, 17:41   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Netzwerkprobleme - Schädling eingefangen? - Standard

Netzwerkprobleme - Schädling eingefangen?



Gern Geschehen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Netzwerkprobleme - Schädling eingefangen?
adobe, adobe reader xi, becker, bho, curse, ebay, error, excel, failed, festplatte, firefox, flash player, format, home, iexplore.exe, install.exe, internet, logfile, ntdll.dll, pirates, plug-in, pmmupdate.exe, realtek, registry, rundll, schädling, secrets, security, senden, software, starmoney, svchost.exe, temp, usb, windows




Ähnliche Themen: Netzwerkprobleme - Schädling eingefangen?


  1. Schädling aus Email eingefangen
    Plagegeister aller Art und deren Bekämpfung - 13.10.2015 (9)
  2. Netzwerkprobleme
    Alles rund um Windows - 18.08.2015 (7)
  3. Netzwerkprobleme/auslastung
    Plagegeister aller Art und deren Bekämpfung - 10.06.2015 (15)
  4. TR/Mediyes.J.1 und Netzwerkprobleme
    Log-Analyse und Auswertung - 26.08.2014 (7)
  5. GVU Virus befällt PC, Browser öffnet, dennoch Blackscreen beim Booten und Netzwerkprobleme
    Plagegeister aller Art und deren Bekämpfung - 26.09.2013 (21)
  6. GVU Virus befällt PC, Browser öffnet, dennoch Blackscreen beim Booten und Netzwerkprobleme
    Mülltonne - 21.09.2013 (2)
  7. Netzwerkprobleme wg. IP-Adresse durch Gema-Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 19.10.2012 (28)
  8. Dateivolumenüberprüfung, Netzwerkprobleme + Schneckentempo hoch 10! - Virus eingefangen?
    Plagegeister aller Art und deren Bekämpfung - 01.03.2012 (1)
  9. Netzwerkprobleme nach Entfernen Zbot
    Log-Analyse und Auswertung - 17.07.2010 (3)
  10. hartnäckiger Schädling
    Plagegeister aller Art und deren Bekämpfung - 22.06.2009 (1)
  11. Spam-Schädling
    Plagegeister aller Art und deren Bekämpfung - 13.01.2009 (1)
  12. evt. Schädling
    Mülltonne - 28.10.2007 (1)
  13. Schädling eingefangen?
    Log-Analyse und Auswertung - 24.09.2007 (3)
  14. Schädling eingefangen? Bitte um Hilfe...
    Log-Analyse und Auswertung - 01.08.2007 (2)
  15. Schädling eingefangen !!Hilfe !!!
    Plagegeister aller Art und deren Bekämpfung - 24.04.2006 (6)
  16. Schädling oder nicht Schädling ?!?
    Plagegeister aller Art und deren Bekämpfung - 07.05.2004 (0)
  17. Netzwerkprobleme mit Win ME und XP
    Netzwerk und Hardware - 22.02.2004 (11)

Zum Thema Netzwerkprobleme - Schädling eingefangen? - Moin, mein Arbeitskollege hat Probleme mit seinem Rechner. Und zwar kann Starmoney keinen Konatkt zum Starmoney-Service aufnehmen. Dann scheitert z.B. die Lizenz-Überprüfung. "Normales" Banking, z.B. Kontenabruf und Überweisungen funktionieren, Internet - Netzwerkprobleme - Schädling eingefangen?...
Archiv
Du betrachtest: Netzwerkprobleme - Schädling eingefangen? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.