Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: LOG Auswertung, Keine Office Updates, Fragmente BKA Trojaner

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 26.12.2013, 13:26   #1
candelaver
 
LOG Auswertung, Keine Office Updates, Fragmente BKA Trojaner - Standard

LOG Auswertung, Keine Office Updates, Fragmente BKA Trojaner



Hi Leute,

ich kann aktuelle Office2013 Updates nicht installieren, ich habe ein wenig vorarbeit geleistet
und gemäß der Anleitungen des TB Forums, mit folgenden Programmen, erste LOGs erstellt.

Ich habe z.B. mit JRT Fragmente gefunden, die laut Forum auf BKA Trojaner deuten.
Allerdings hat Eset keine Warnmeldung ausgegeben.

Zitat:
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Failed to delete: [Folder] "C:\Program Files (x86)\myfree codec"
Des Weiteren, lassen sich aktuell keine Office 2013 Updates installieren, daher mein Verdacht auf Befall und Scanbedarf, um schwachstellen zu erkennen etc.

bevor ich weiter spekuliere, poste ich die bereits erstellen LOGs zur Ansicht und Auswertung.
Danke euch im Voraus für euer Hilfe und weiterhin frohes Fest.

JRT LOG
Zitat:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 8 Pro x64
Ran by ***** on 24.12.2013 at 3:18:25,67
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL



~~~ Registry Keys

Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\AppID\secman.dll
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4250488A-CB24-0893-C066-B1AEA57BCFF2}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Failed to delete: [Folder] "C:\Program Files (x86)\myfree codec"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24.12.2013 at 3:30:18,57
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

GMER LOG

GMER Logfile:
Code:
ATTFilter
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-12-25 06:05:59
Windows 6.2.9200  x64 \Device\Harddisk0\DR0 -> \Device\0000003d SAMSUNG_HM641JI rev.2AJ10001 596,17GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\******\AppData\Local\Temp\fgloquog.sys


---- User code sections - GMER 2.1 ----

.text   C:\Windows\system32\vmms.exe[1632] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306                000007ffc56e177a 4 bytes [6E, C5, FF, 07]
.text   C:\Windows\system32\vmms.exe[1632] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314                000007ffc56e1782 4 bytes [6E, C5, FF, 07]
.text   C:\Windows\Explorer.EXE[2568] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690                               000007ffb85e1532 4 bytes [5E, B8, FF, 07]
.text   C:\Windows\Explorer.EXE[2568] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698                               000007ffb85e153a 4 bytes [5E, B8, FF, 07]
.text   C:\Windows\Explorer.EXE[2568] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246                             000007ffb85e165a 4 bytes [5E, B8, FF, 07]
.text   C:\Program Files\ESET\ESET Smart Security\egui.exe[3220] C:\Windows\SYSTEM32\msimg32.dll!GradientFill + 690    000007ffb85e1532 4 bytes [5E, B8, FF, 07]
.text   C:\Program Files\ESET\ESET Smart Security\egui.exe[3220] C:\Windows\SYSTEM32\msimg32.dll!GradientFill + 698    000007ffb85e153a 4 bytes [5E, B8, FF, 07]
.text   C:\Program Files\ESET\ESET Smart Security\egui.exe[3220] C:\Windows\SYSTEM32\msimg32.dll!TransparentBlt + 246  000007ffb85e165a 4 bytes [5E, B8, FF, 07]

---- Threads - GMER 2.1 ----

Thread  System [4:768]                                                                                                 fffffa8005915630
Thread  C:\Windows\system32\csrss.exe [536:560]                                                                        fffff960007945e8

---- Registry - GMER 2.1 ----

Reg     HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\RNG@RNGAuxiliarySeed                              -1259165456
Reg     HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd508976                                    
Reg     HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd508976@c4731e05de87                       0x78 0x0E 0x41 0x6F ...
Reg     HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0009dd508976@0808c29c97e5                       0xA7 0xD9 0x72 0x31 ...

---- EOF - GMER 2.1 ----
         
--- --- ---



OTL LOG / Extras
OTL EXTRAS Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 25.12.2013 07:11:45 - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\******\Desktop\Security
64bit- Professional  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16750)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,73 Gb Total Physical Memory | 2,09 Gb Available Physical Memory | 55,92% Memory free
7,48 Gb Paging File | 5,54 Gb Available in Paging File | 74,12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 595,83 Gb Total Space | 113,22 Gb Free Space | 19,00% Space Free | Partition Type: NTFS
 
Computer Name: ******_ACER | User Name: ****** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B69B967-C913-414E-B469-33049E99F988}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{14B17654-E4E2-4B41-B6E6-7E7C47C0776E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{14BD8869-80F8-4499-BD47-883BAD23B1A1}" = lport=rpc | protocol=6 | dir=in | app=c:\program files\sisoftware\sisoftware sandra lite 2013.sp3a\wnt500x64\rpcsandrasrv.exe | 
"{15BA6126-0D61-4182-B4D6-96560D04A911}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{1E890845-6C0C-4BC7-A87F-2E6094B27DAD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{1F545C4E-9839-4657-ADCE-0D43D5C3931E}" = lport=19376 | protocol=6 | dir=in | app=c:\program files (x86)\devolo\dlan\devolonetsvc.exe | 
"{307C4718-79EB-4E52-B133-9DE6C093F2E4}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{38480A0D-F94B-4F86-91D9-A6352285D817}" = rport=139 | protocol=6 | dir=out | app=system | 
"{52832964-7C80-421E-9833-B98CEA06FBB4}" = lport=137 | protocol=17 | dir=in | app=system | 
"{57728488-CD29-44C9-AA0D-AB5EECE19A27}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{5CBDF52A-34AF-4477-9D92-4B2A377B9235}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{6B8181F7-E084-4EC6-A3D9-DADF297365CF}" = lport=445 | protocol=6 | dir=in | app=system | 
"{728238FC-6E9C-4670-B884-3AF6F15F8CD2}" = lport=rpc | protocol=6 | dir=in | app=c:\program files\sisoftware\sisoftware sandra lite 2013.sp3a\rpcagentsrv.exe | 
"{83DECDA6-FC75-4CEE-A26A-3CF0C68B5FE2}" = rport=138 | protocol=17 | dir=out | app=system | 
"{8C70855B-BE23-471A-A29E-238C15B8047C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{93F7BFCF-C323-4661-9CFC-D442C50B2F19}" = rport=445 | protocol=6 | dir=out | app=system | 
"{96A39704-93BF-4A91-BE23-B150FFAF9E0C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe | 
"{B1565166-5D71-4CA7-8453-C2120990D2DB}" = lport=139 | protocol=6 | dir=in | app=system | 
"{B3746986-0AD1-4690-9A7F-8F0F09ADB8A9}" = lport=19375 | protocol=17 | dir=in | app=c:\program files (x86)\devolo\dlan\devolonetsvc.exe | 
"{B9CAD40E-1340-48B6-B192-0F7E76445CDF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{D9AD2A58-05B7-4F14-8139-63C7C6B934C7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{E2D27982-A5FF-4621-85EA-F043A7DE355D}" = rport=137 | protocol=17 | dir=out | app=system | 
"{EE4FACB7-9388-4637-9C29-3AC970B8CA1F}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{F2A875D3-9247-46FE-9F2D-86FF68F55C71}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{F9506146-8E1A-4E2B-98BB-44C9A7812D75}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{FD03D522-2B7F-4379-B24C-801A234CD2CB}" = lport=138 | protocol=17 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0601D271-78F0-4448-87AD-AD6D4D581403}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | 
"{10965F33-0971-4392-993B-DEE87B239EF7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{13B7241B-B33D-4AB0-8330-6191FA195868}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | 
"{152E7F15-9E30-42DB-8511-F18E341CA888}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{157CF050-1110-4464-9289-0F0CBA357D31}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | 
"{24F558E9-181D-49CA-BD8E-28F8BE02C288}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | 
"{2E739CFA-567B-45A4-BC0D-ED05A412D6AE}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | 
"{2EA361C3-3110-4461-A05F-023B472A4997}" = protocol=6 | dir=out | app=system | 
"{2FEB5C43-A599-485E-BD6A-3A566D72A48E}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | 
"{32EA2758-57A7-43B8-953E-CEECE5606297}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{3A5985E1-266F-4755-8146-763D819F1DE7}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | 
"{3AAE50F7-CE99-4A5C-8CE0-3DE2F0188DF5}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{3F071E39-42EF-4A6A-87FC-86D31332AB14}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{4373FE82-3A09-4438-84B5-4EA800468FDD}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | 
"{442EEC3D-9440-469F-ABCF-50941EEC48A8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{460DB205-5E17-4F6F-93D7-5D51D4A100F5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{5346D377-BE1C-4B00-9711-1EC670FCF297}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{534FE60A-13ED-4007-AFF4-CDAE1A070511}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 
"{5B9410FA-E736-4B63-BC77-B46119F6DECA}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | 
"{5BC18219-8E39-4475-BBB3-33B4113737DA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{5CC54D11-7872-4A72-8E49-1BEAD23E02C4}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | 
"{5D7AD459-64BF-4098-863D-B0A169077949}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | 
"{636AC02E-83FE-4384-8A44-5547159CF136}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{64D3FC3C-9AD7-4855-9CB5-5AC31E26FF62}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{67905AD2-1E22-4AE4-AA69-B4F1667527B1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{732B4717-8AC2-493E-B1AD-FE2BF2D6E9C0}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) | 
"{74852A99-838E-4BE6-B1DB-E44982396206}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | 
"{762E30EA-7708-4F6C-8560-94896CF1C1DC}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{82E18FDA-F1A1-4895-B1AC-A3F51CB75165}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | 
"{83648A94-0824-43AD-B71F-697489195076}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | 
"{841C183E-6439-41CD-84EA-BEF664880D67}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{94A06A99-AD78-4101-9D06-944D6F144A8F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{9723267B-7D6F-4835-AC9B-7883BB9F83E4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{985DB806-8466-4B2B-9860-D016E62F541E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{9C351D59-2255-4E25-B94E-E0C3262B55FA}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe | 
"{9D899732-E8BC-4D17-BF81-7029767DF063}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | 
"{9F47414C-4B2B-4D9B-AE39-7B3D5158F57D}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{A0A6DA1F-2591-42C6-B9BA-A0F55DAFB289}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | 
"{A2AC84D0-D763-491D-B705-2FA5D70A0AA8}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | 
"{A4358C1A-55A8-48C7-BAFE-EA52CC902BDB}" = protocol=1 | dir=in | name=sisoftware deployment agent service (icmp-in) | 
"{B3879CCA-6868-4F9F-8CA9-C974A8741F1C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{B62C0529-D1F0-4402-9BD7-8646CB1166D6}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | 
"{BD7A9018-0BA4-4955-993B-2C0C275C63B5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{BEF3B58E-AB82-4B86-B0CC-B3958338D885}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | 
"{C0555A5E-21C4-4141-8AE7-B1CF201C8DC5}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{CB702152-C96F-4E5F-BF0F-FE9A9425551E}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{CB72C95B-609A-4E80-BD80-AF14E9A741D8}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{D7ADFB07-7F09-4C0D-B0A6-2FD30CE35691}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{D90CA66F-2999-4BD7-B883-41D5C244AA2E}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | 
"{DC1C21C6-F61D-430E-AFDA-BA8BC6EFA8FB}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe | 
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{EA9FB5D5-E0C6-40AE-A1E7-EE665D524D7F}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{ECA7F3B4-8B42-4506-9922-E7E28A69773B}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{ECE396C7-24DC-4120-AB9E-98AB4EE7BC94}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | 
"{F19C3A81-38DD-4541-8640-CC51D1CA44E5}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | 
"{F66CF718-58E3-4D71-8CEA-CD7B89A76B23}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{FB01C266-5629-4637-AD2E-82A355DC2E6D}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | 
"{FB7B3401-F630-4F72-8075-E1FB443C1BD2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"TCP Query User{0AD70F9D-1955-4ECE-858D-08F39BDB4050}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | 
"TCP Query User{F1F25BF9-AEBA-4C5C-851B-295291B10214}C:\program files\jdownloader 2\jdownloader 2.exe" = protocol=6 | dir=in | app=c:\program files\jdownloader 2\jdownloader 2.exe | 
"UDP Query User{1D1CD301-0DBB-4E58-8966-B24FC9C0FF21}C:\program files\jdownloader 2\jdownloader 2.exe" = protocol=17 | dir=in | app=c:\program files\jdownloader 2\jdownloader 2.exe | 
"UDP Query User{43E20FB4-332B-4A6D-9324-27FD777CC2D8}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417021FF}" = Java 7 Update 21 (64-bit)
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = MPC-HC 1.6.6.6957 (3975d54) (64-bit)
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{427174C0-096E-40D9-9684-9C109BEE2CBF}" = iTunes
"{53A97E00-7252-4ED0-A1EB-9F9712FC0AC9}" = HP webOS SDK
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90150000-0015-0407-1000-0000000FF1CE}" = Microsoft Access MUI (German) 2013
"{90150000-0016-0407-1000-0000000FF1CE}" = Microsoft Excel MUI (German) 2013
"{90150000-0018-0407-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (German) 2013
"{90150000-0019-0407-1000-0000000FF1CE}" = Microsoft Publisher MUI (German) 2013
"{90150000-001A-0407-1000-0000000FF1CE}" = Microsoft Outlook MUI (German) 2013
"{90150000-001B-0407-1000-0000000FF1CE}" = Microsoft Word MUI (German) 2013
"{90150000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Korrekturhilfen 2013 - Deutsch
"{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English
"{90150000-001F-040C-1000-0000000FF1CE}" = Outils de vérification linguistique 2013 de Microsoft Office*- Français
"{90150000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - Italiano
"{90150000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2013
"{90150000-0044-0407-1000-0000000FF1CE}" = Microsoft InfoPath MUI (German) 2013
"{90150000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2013
"{90150000-0090-0407-1000-0000000FF1CE}" = Microsoft DCF MUI (German) 2013
"{90150000-00A1-0407-1000-0000000FF1CE}" = Microsoft OneNote MUI (German) 2013
"{90150000-00BA-0407-1000-0000000FF1CE}" = Microsoft Groove MUI (German) 2013
"{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013
"{90150000-00C1-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2013
"{90150000-00E1-0407-1000-0000000FF1CE}" = Microsoft Office OSM MUI (German) 2013
"{90150000-00E2-0407-1000-0000000FF1CE}" = Microsoft Office OSM UX MUI (German) 2013
"{90150000-012B-0407-1000-0000000FF1CE}" = Microsoft Lync MUI (German) 2013
"{91150000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2013
"{BA9A297F-0198-4EE8-90CB-F5036C180E1D}" = Novacomd
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2396}_is1" = SiSoftware Sandra Lite 2013.SP3a
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{E507B0D7-A623-4F66-BB61-B31D7609B7B9}" = Nitro Pro 8
"{F5A3E880-A737-48F2-A124-6F5D4CEA6AB4}" = ESET Smart Security
"0630-0716-3135-7887" = JDownloader 2
"332CCC08910F1AE2E4D90D25DEDE87E3EF797832" = Windows Driver Package - Palm (WinUSB) Palm Devices  (10/09/2009 1.0.1)
"CCleaner" = CCleaner
"Ext2Ifs_for_NT6" = Ext2 IFS 1.11a for Windows Vista/2008
"Office15.PROPLUSR" = Microsoft Office Professional Plus 2013
"Sandboxie" = Sandboxie 4.06 (64-bit)
"Totalcmd64" = Total Commander 64-bit (Remove or Repair)
"Unlocker" = Unlocker 1.9.2
"VLC media player" = VLC media player 2.0.6
"WinRAR archiver" = WinRAR 4.20 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{065F384A-5C64-4532-814A-A24BA5374503}" = WinDFT
"{0D2FC29F-980A-4BAB-BC60-1463408F521E}" = USB Playback Console
"{0F1861E5-113D-46F9-B559-81587DF15C6D}" = SatChannelListEditor
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 45
"{450CFD4D-7E60-3839-D0FA-56DB08675447}" = dLAN Cockpit
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8C6E319B-4F27-4A50-B43E-79525B8AB295}" = Web Tools
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI - Deutsch
"{CCF298AF-9CE1-4B26-B251-486E98A34789}" = Windows 7 USB/DVD Download Tool
"{D4328CA9-E332-456F-B68D-3D3DE90E50B5}" = calibre
"{D9C4202E-6D51-4B06-A8F1-22316E654BCA}" = Universal Adb Driver
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"AAF Recovery tool AT700_is1" = AAF_Recovery_tool installer V4.6
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AIDA64 Engineer_is1" = AIDA64 Engineer v4.00
"Artisteer 3" = Artisteer 3
"Belarc Advisor" = Belarc Advisor 8.4
"dlancockpit" = devolo dLAN Cockpit
"DokanLibrary" = Dokan Library 0.6.0
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink DE_is1" = DVD Shrink 3.2 deutsch (DeCSS-frei)
"ESET Online Scanner" = ESET Online Scanner v3
"FlashFXP 4" = FlashFXP 4
"Hard Disk Low Level Format Tool_is1" = Hard Disk Low Level Format Tool 4.25
"ICE ECC" = ICE ECC v2.7
"InfraRecorder" = InfraRecorder
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{8C6E319B-4F27-4A50-B43E-79525B8AB295}" = Web Tools
"KindleDRMRemoval" = Kindle DRM Removal
"LinuxLive USB Creator" = LinuxLive USB Creator
"Mirillis Splash PRO" = Splash PRO
"Mirillis Splash PRO EX" = Splash PRO EX
"Mozilla Thunderbird 16.0.1 (x86 de)" = Mozilla Thunderbird 16.0.1 (x86 de)
"NAVIGON Fresh" = NAVIGON Fresh 3.4.1
"Notepad++" = Notepad++
"Secure Eraser_is1" = Secure Eraser
"Start8" = Start8
"TeamViewer 8" = TeamViewer 8
"UFB Code SetupV2.6" = UFB Code Setup
"WinPcapInst" = WinPcap 4.1.2
"Wireshark" = Wireshark 1.8.3 (64-bit)
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3754388793-1346805017-1485128776-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 24.07.2013 11:00:18 | Computer Name = ******_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 26.07.2013 15:55:20 | Computer Name = ******_Acer | Source = Application Hang | ID = 1002
Description = Programm SplashPro.exe, Version 1.13.1.0 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 10cc    Startzeit:
 01ce8a39a7da5b66    Endzeit: 1296    Anwendungspfad: C:\Program Files (x86)\Mirillis\Splash
 PRO\SplashPro.exe    Berichts-ID: 260d03c8-f62d-11e2-bf56-b870f4dd05aa    Vollständiger
 Name des fehlerhaften Pakets:     Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:   
 
Error - 26.07.2013 16:05:47 | Computer Name = ******_Acer | Source = Application Hang | ID = 1002
Description = Programm SplashPro.exe, Version 1.13.1.0 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 1300    Startzeit:
 01ce8a3af6b21b61    Endzeit: 109    Anwendungspfad: C:\Program Files (x86)\Mirillis\Splash
 PRO\SplashPro.exe    Berichts-ID: a6a3606f-f62e-11e2-bf56-b870f4dd05aa    Vollständiger
 Name des fehlerhaften Pakets:     Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:   
 
Error - 27.07.2013 13:31:55 | Computer Name = ******_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 29.07.2013 23:03:25 | Computer Name = ******_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 31.07.2013 13:52:15 | Computer Name = ******_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 31.07.2013 13:55:51 | Computer Name = ******_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 31.07.2013 14:06:11 | Computer Name = ******_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 31.07.2013 14:08:23 | Computer Name = ******_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 02.08.2013 03:23:27 | Computer Name = ******_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
[ System Events ]
Error - 21.07.2013 05:25:03 | Computer Name = ******_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2817469)
 64-Bit-Edition
 
Error - 21.07.2013 05:25:20 | Computer Name = ******_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2767865)
 64-Bit-Edition
 
Error - 21.07.2013 08:24:47 | Computer Name = ******_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft Office 2013 (KB2726996) 
64-Bit-Edition
 
Error - 21.07.2013 08:24:47 | Computer Name = ******_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2817469)
 64-Bit-Edition
 
Error - 21.07.2013 08:24:47 | Computer Name = ******_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2767865)
 64-Bit-Edition
 
Error - 22.07.2013 10:29:50 | Computer Name = ******_Acer | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?21.?07.?2013 um 20:55:10 unerwartet heruntergefahren.
 
Error - 22.07.2013 10:31:00 | Computer Name = ******_Acer | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde mit
 folgendem Fehler beendet:   %%1008
 
Error - 22.07.2013 10:41:16 | Computer Name = ******_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft Office 2013 (KB2726996) 
64-Bit-Edition
 
Error - 22.07.2013 10:41:16 | Computer Name = ******_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2817469)
 64-Bit-Edition
 
Error - 22.07.2013 10:41:16 | Computer Name = ******_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2767865)
 64-Bit-Edition
 
 
< End of report >
         
--- --- ---


OTL EXTRAS
OTL EXTRAS Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 25.12.2013 07:11:45 - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\*****\Desktop\Security
64bit- Professional  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16750)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,73 Gb Total Physical Memory | 2,09 Gb Available Physical Memory | 55,92% Memory free
7,48 Gb Paging File | 5,54 Gb Available in Paging File | 74,12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 595,83 Gb Total Space | 113,22 Gb Free Space | 19,00% Space Free | Partition Type: NTFS
 
Computer Name: *****_ACER | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B69B967-C913-414E-B469-33049E99F988}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{14B17654-E4E2-4B41-B6E6-7E7C47C0776E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{14BD8869-80F8-4499-BD47-883BAD23B1A1}" = lport=rpc | protocol=6 | dir=in | app=c:\program files\sisoftware\sisoftware sandra lite 2013.sp3a\wnt500x64\rpcsandrasrv.exe | 
"{15BA6126-0D61-4182-B4D6-96560D04A911}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{1E890845-6C0C-4BC7-A87F-2E6094B27DAD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{1F545C4E-9839-4657-ADCE-0D43D5C3931E}" = lport=19376 | protocol=6 | dir=in | app=c:\program files (x86)\devolo\dlan\devolonetsvc.exe | 
"{307C4718-79EB-4E52-B133-9DE6C093F2E4}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{38480A0D-F94B-4F86-91D9-A6352285D817}" = rport=139 | protocol=6 | dir=out | app=system | 
"{52832964-7C80-421E-9833-B98CEA06FBB4}" = lport=137 | protocol=17 | dir=in | app=system | 
"{57728488-CD29-44C9-AA0D-AB5EECE19A27}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{5CBDF52A-34AF-4477-9D92-4B2A377B9235}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{6B8181F7-E084-4EC6-A3D9-DADF297365CF}" = lport=445 | protocol=6 | dir=in | app=system | 
"{728238FC-6E9C-4670-B884-3AF6F15F8CD2}" = lport=rpc | protocol=6 | dir=in | app=c:\program files\sisoftware\sisoftware sandra lite 2013.sp3a\rpcagentsrv.exe | 
"{83DECDA6-FC75-4CEE-A26A-3CF0C68B5FE2}" = rport=138 | protocol=17 | dir=out | app=system | 
"{8C70855B-BE23-471A-A29E-238C15B8047C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{93F7BFCF-C323-4661-9CFC-D442C50B2F19}" = rport=445 | protocol=6 | dir=out | app=system | 
"{96A39704-93BF-4A91-BE23-B150FFAF9E0C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe | 
"{B1565166-5D71-4CA7-8453-C2120990D2DB}" = lport=139 | protocol=6 | dir=in | app=system | 
"{B3746986-0AD1-4690-9A7F-8F0F09ADB8A9}" = lport=19375 | protocol=17 | dir=in | app=c:\program files (x86)\devolo\dlan\devolonetsvc.exe | 
"{B9CAD40E-1340-48B6-B192-0F7E76445CDF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{D9AD2A58-05B7-4F14-8139-63C7C6B934C7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{E2D27982-A5FF-4621-85EA-F043A7DE355D}" = rport=137 | protocol=17 | dir=out | app=system | 
"{EE4FACB7-9388-4637-9C29-3AC970B8CA1F}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{F2A875D3-9247-46FE-9F2D-86FF68F55C71}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{F9506146-8E1A-4E2B-98BB-44C9A7812D75}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{FD03D522-2B7F-4379-B24C-801A234CD2CB}" = lport=138 | protocol=17 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0601D271-78F0-4448-87AD-AD6D4D581403}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | 
"{10965F33-0971-4392-993B-DEE87B239EF7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{13B7241B-B33D-4AB0-8330-6191FA195868}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | 
"{152E7F15-9E30-42DB-8511-F18E341CA888}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{157CF050-1110-4464-9289-0F0CBA357D31}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | 
"{24F558E9-181D-49CA-BD8E-28F8BE02C288}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | 
"{2E739CFA-567B-45A4-BC0D-ED05A412D6AE}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | 
"{2EA361C3-3110-4461-A05F-023B472A4997}" = protocol=6 | dir=out | app=system | 
"{2FEB5C43-A599-485E-BD6A-3A566D72A48E}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | 
"{32EA2758-57A7-43B8-953E-CEECE5606297}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{3A5985E1-266F-4755-8146-763D819F1DE7}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | 
"{3AAE50F7-CE99-4A5C-8CE0-3DE2F0188DF5}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{3F071E39-42EF-4A6A-87FC-86D31332AB14}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{4373FE82-3A09-4438-84B5-4EA800468FDD}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | 
"{442EEC3D-9440-469F-ABCF-50941EEC48A8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{460DB205-5E17-4F6F-93D7-5D51D4A100F5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{5346D377-BE1C-4B00-9711-1EC670FCF297}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{534FE60A-13ED-4007-AFF4-CDAE1A070511}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 
"{5B9410FA-E736-4B63-BC77-B46119F6DECA}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | 
"{5BC18219-8E39-4475-BBB3-33B4113737DA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{5CC54D11-7872-4A72-8E49-1BEAD23E02C4}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | 
"{5D7AD459-64BF-4098-863D-B0A169077949}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | 
"{636AC02E-83FE-4384-8A44-5547159CF136}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{64D3FC3C-9AD7-4855-9CB5-5AC31E26FF62}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{67905AD2-1E22-4AE4-AA69-B4F1667527B1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{732B4717-8AC2-493E-B1AD-FE2BF2D6E9C0}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) | 
"{74852A99-838E-4BE6-B1DB-E44982396206}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | 
"{762E30EA-7708-4F6C-8560-94896CF1C1DC}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{82E18FDA-F1A1-4895-B1AC-A3F51CB75165}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | 
"{83648A94-0824-43AD-B71F-697489195076}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | 
"{841C183E-6439-41CD-84EA-BEF664880D67}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{94A06A99-AD78-4101-9D06-944D6F144A8F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{9723267B-7D6F-4835-AC9B-7883BB9F83E4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{985DB806-8466-4B2B-9860-D016E62F541E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{9C351D59-2255-4E25-B94E-E0C3262B55FA}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe | 
"{9D899732-E8BC-4D17-BF81-7029767DF063}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | 
"{9F47414C-4B2B-4D9B-AE39-7B3D5158F57D}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{A0A6DA1F-2591-42C6-B9BA-A0F55DAFB289}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | 
"{A2AC84D0-D763-491D-B705-2FA5D70A0AA8}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | 
"{A4358C1A-55A8-48C7-BAFE-EA52CC902BDB}" = protocol=1 | dir=in | name=sisoftware deployment agent service (icmp-in) | 
"{B3879CCA-6868-4F9F-8CA9-C974A8741F1C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{B62C0529-D1F0-4402-9BD7-8646CB1166D6}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | 
"{BD7A9018-0BA4-4955-993B-2C0C275C63B5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{BEF3B58E-AB82-4B86-B0CC-B3958338D885}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | 
"{C0555A5E-21C4-4141-8AE7-B1CF201C8DC5}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{CB702152-C96F-4E5F-BF0F-FE9A9425551E}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{CB72C95B-609A-4E80-BD80-AF14E9A741D8}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{D7ADFB07-7F09-4C0D-B0A6-2FD30CE35691}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{D90CA66F-2999-4BD7-B883-41D5C244AA2E}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | 
"{DC1C21C6-F61D-430E-AFDA-BA8BC6EFA8FB}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe | 
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{EA9FB5D5-E0C6-40AE-A1E7-EE665D524D7F}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{ECA7F3B4-8B42-4506-9922-E7E28A69773B}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{ECE396C7-24DC-4120-AB9E-98AB4EE7BC94}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | 
"{F19C3A81-38DD-4541-8640-CC51D1CA44E5}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | 
"{F66CF718-58E3-4D71-8CEA-CD7B89A76B23}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{FB01C266-5629-4637-AD2E-82A355DC2E6D}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | 
"{FB7B3401-F630-4F72-8075-E1FB443C1BD2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"TCP Query User{0AD70F9D-1955-4ECE-858D-08F39BDB4050}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | 
"TCP Query User{F1F25BF9-AEBA-4C5C-851B-295291B10214}C:\program files\jdownloader 2\jdownloader 2.exe" = protocol=6 | dir=in | app=c:\program files\jdownloader 2\jdownloader 2.exe | 
"UDP Query User{1D1CD301-0DBB-4E58-8966-B24FC9C0FF21}C:\program files\jdownloader 2\jdownloader 2.exe" = protocol=17 | dir=in | app=c:\program files\jdownloader 2\jdownloader 2.exe | 
"UDP Query User{43E20FB4-332B-4A6D-9324-27FD777CC2D8}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417021FF}" = Java 7 Update 21 (64-bit)
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = MPC-HC 1.6.6.6957 (3975d54) (64-bit)
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{427174C0-096E-40D9-9684-9C109BEE2CBF}" = iTunes
"{53A97E00-7252-4ED0-A1EB-9F9712FC0AC9}" = HP webOS SDK
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90150000-0015-0407-1000-0000000FF1CE}" = Microsoft Access MUI (German) 2013
"{90150000-0016-0407-1000-0000000FF1CE}" = Microsoft Excel MUI (German) 2013
"{90150000-0018-0407-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (German) 2013
"{90150000-0019-0407-1000-0000000FF1CE}" = Microsoft Publisher MUI (German) 2013
"{90150000-001A-0407-1000-0000000FF1CE}" = Microsoft Outlook MUI (German) 2013
"{90150000-001B-0407-1000-0000000FF1CE}" = Microsoft Word MUI (German) 2013
"{90150000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Korrekturhilfen 2013 - Deutsch
"{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English
"{90150000-001F-040C-1000-0000000FF1CE}" = Outils de vérification linguistique 2013 de Microsoft Office*- Français
"{90150000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - Italiano
"{90150000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2013
"{90150000-0044-0407-1000-0000000FF1CE}" = Microsoft InfoPath MUI (German) 2013
"{90150000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2013
"{90150000-0090-0407-1000-0000000FF1CE}" = Microsoft DCF MUI (German) 2013
"{90150000-00A1-0407-1000-0000000FF1CE}" = Microsoft OneNote MUI (German) 2013
"{90150000-00BA-0407-1000-0000000FF1CE}" = Microsoft Groove MUI (German) 2013
"{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013
"{90150000-00C1-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2013
"{90150000-00E1-0407-1000-0000000FF1CE}" = Microsoft Office OSM MUI (German) 2013
"{90150000-00E2-0407-1000-0000000FF1CE}" = Microsoft Office OSM UX MUI (German) 2013
"{90150000-012B-0407-1000-0000000FF1CE}" = Microsoft Lync MUI (German) 2013
"{91150000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2013
"{BA9A297F-0198-4EE8-90CB-F5036C180E1D}" = Novacomd
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2396}_is1" = SiSoftware Sandra Lite 2013.SP3a
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{E507B0D7-A623-4F66-BB61-B31D7609B7B9}" = Nitro Pro 8
"{F5A3E880-A737-48F2-A124-6F5D4CEA6AB4}" = ESET Smart Security
"0630-0716-3135-7887" = JDownloader 2
"332CCC08910F1AE2E4D90D25DEDE87E3EF797832" = Windows Driver Package - Palm (WinUSB) Palm Devices  (10/09/2009 1.0.1)
"CCleaner" = CCleaner
"Ext2Ifs_for_NT6" = Ext2 IFS 1.11a for Windows Vista/2008
"Office15.PROPLUSR" = Microsoft Office Professional Plus 2013
"Sandboxie" = Sandboxie 4.06 (64-bit)
"Totalcmd64" = Total Commander 64-bit (Remove or Repair)
"Unlocker" = Unlocker 1.9.2
"VLC media player" = VLC media player 2.0.6
"WinRAR archiver" = WinRAR 4.20 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{065F384A-5C64-4532-814A-A24BA5374503}" = WinDFT
"{0D2FC29F-980A-4BAB-BC60-1463408F521E}" = USB Playback Console
"{0F1861E5-113D-46F9-B559-81587DF15C6D}" = SatChannelListEditor
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 45
"{450CFD4D-7E60-3839-D0FA-56DB08675447}" = dLAN Cockpit
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8C6E319B-4F27-4A50-B43E-79525B8AB295}" = Web Tools
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI - Deutsch
"{CCF298AF-9CE1-4B26-B251-486E98A34789}" = Windows 7 USB/DVD Download Tool
"{D4328CA9-E332-456F-B68D-3D3DE90E50B5}" = calibre
"{D9C4202E-6D51-4B06-A8F1-22316E654BCA}" = Universal Adb Driver
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"AAF Recovery tool AT700_is1" = AAF_Recovery_tool installer V4.6
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AIDA64 Engineer_is1" = AIDA64 Engineer v4.00
"Artisteer 3" = Artisteer 3
"Belarc Advisor" = Belarc Advisor 8.4
"dlancockpit" = devolo dLAN Cockpit
"DokanLibrary" = Dokan Library 0.6.0
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink DE_is1" = DVD Shrink 3.2 deutsch (DeCSS-frei)
"ESET Online Scanner" = ESET Online Scanner v3
"FlashFXP 4" = FlashFXP 4
"Hard Disk Low Level Format Tool_is1" = Hard Disk Low Level Format Tool 4.25
"ICE ECC" = ICE ECC v2.7
"InfraRecorder" = InfraRecorder
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{8C6E319B-4F27-4A50-B43E-79525B8AB295}" = Web Tools
"KindleDRMRemoval" = Kindle DRM Removal
"LinuxLive USB Creator" = LinuxLive USB Creator
"Mirillis Splash PRO" = Splash PRO
"Mirillis Splash PRO EX" = Splash PRO EX
"Mozilla Thunderbird 16.0.1 (x86 de)" = Mozilla Thunderbird 16.0.1 (x86 de)
"NAVIGON Fresh" = NAVIGON Fresh 3.4.1
"Notepad++" = Notepad++
"Secure Eraser_is1" = Secure Eraser
"Start8" = Start8
"TeamViewer 8" = TeamViewer 8
"UFB Code SetupV2.6" = UFB Code Setup
"WinPcapInst" = WinPcap 4.1.2
"Wireshark" = Wireshark 1.8.3 (64-bit)
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3754388793-1346805017-1485128776-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 24.07.2013 11:00:18 | Computer Name = *****_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 26.07.2013 15:55:20 | Computer Name = *****_Acer | Source = Application Hang | ID = 1002
Description = Programm SplashPro.exe, Version 1.13.1.0 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 10cc    Startzeit:
 01ce8a39a7da5b66    Endzeit: 1296    Anwendungspfad: C:\Program Files (x86)\Mirillis\Splash
 PRO\SplashPro.exe    Berichts-ID: 260d03c8-f62d-11e2-bf56-b870f4dd05aa    Vollständiger
 Name des fehlerhaften Pakets:     Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:   
 
Error - 26.07.2013 16:05:47 | Computer Name = *****_Acer | Source = Application Hang | ID = 1002
Description = Programm SplashPro.exe, Version 1.13.1.0 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 1300    Startzeit:
 01ce8a3af6b21b61    Endzeit: 109    Anwendungspfad: C:\Program Files (x86)\Mirillis\Splash
 PRO\SplashPro.exe    Berichts-ID: a6a3606f-f62e-11e2-bf56-b870f4dd05aa    Vollständiger
 Name des fehlerhaften Pakets:     Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist:   
 
Error - 27.07.2013 13:31:55 | Computer Name = *****_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 29.07.2013 23:03:25 | Computer Name = *****_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 31.07.2013 13:52:15 | Computer Name = *****_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 31.07.2013 13:55:51 | Computer Name = *****_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 31.07.2013 14:06:11 | Computer Name = *****_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 31.07.2013 14:08:23 | Computer Name = *****_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
Error - 02.08.2013 03:23:27 | Computer Name = *****_Acer | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "c:\program files
 (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
 
[ System Events ]
Error - 21.07.2013 05:25:03 | Computer Name = *****_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2817469)
 64-Bit-Edition
 
Error - 21.07.2013 05:25:20 | Computer Name = *****_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2767865)
 64-Bit-Edition
 
Error - 21.07.2013 08:24:47 | Computer Name = *****_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft Office 2013 (KB2726996) 
64-Bit-Edition
 
Error - 21.07.2013 08:24:47 | Computer Name = *****_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2817469)
 64-Bit-Edition
 
Error - 21.07.2013 08:24:47 | Computer Name = *****_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2767865)
 64-Bit-Edition
 
Error - 22.07.2013 10:29:50 | Computer Name = *****_Acer | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?21.?07.?2013 um 20:55:10 unerwartet heruntergefahren.
 
Error - 22.07.2013 10:31:00 | Computer Name = *****_Acer | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde mit
 folgendem Fehler beendet:   %%1008
 
Error - 22.07.2013 10:41:16 | Computer Name = *****_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft Office 2013 (KB2726996) 
64-Bit-Edition
 
Error - 22.07.2013 10:41:16 | Computer Name = *****_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2817469)
 64-Bit-Edition
 
Error - 22.07.2013 10:41:16 | Computer Name = *****_Acer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070663 fehlgeschlagen: Update für Microsoft SkyDrive Pro (KB2767865)
 64-Bit-Edition
 
 
< End of report >
         
--- --- ---






MBAR Rootkit LOG
Zitat:
Malwarebytes Anti-Rootkit BETA 1.07.0.1008
www.malwarebytes.org

Database version: v2013.12.24.03

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16750
****** :: ******_ACER [administrator]

24.12.2013 11:04:21
mbar-log-2013-12-24 (11-04-21).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 269322
Time elapsed: 1 hour(s), 47 minute(s), 35 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

 

Themen zu LOG Auswertung, Keine Office Updates, Fragmente BKA Trojaner
7-zip, adobe reader xi, desktop, error, excel, fehler, firefox, flash player, format, google, homepage, iexplore.exe, install.exe, internet, internet explorer, logfile, mozilla, registry, richtlinie, rundll, security, software, svchost.exe, system, tcp, total commander, trojaner, updates, usb, version., windows




Ähnliche Themen: LOG Auswertung, Keine Office Updates, Fragmente BKA Trojaner


  1. Win XP: Nach bereinigung mit MBAM lassen sich keine Office-Dateien öffnen
    Plagegeister aller Art und deren Bekämpfung - 29.06.2015 (4)
  2. Nach Adware Cleaner Meldung: "Keine Internetverbindung". Keine Updates, kein Skype u.ä. mehr möglich!
    Antiviren-, Firewall- und andere Schutzprogramme - 08.01.2015 (15)
  3. Windows 8.1 macht nach Vierenbefall/Trojaner keine Updates mehr
    Log-Analyse und Auswertung - 06.08.2014 (11)
  4. Keine Installationen/Updates möglich
    Alles rund um Windows - 30.06.2014 (5)
  5. Keine Downloads Internet möglich, Office 2013 funktioniert nicht
    Plagegeister aller Art und deren Bekämpfung - 03.06.2014 (41)
  6. Windows 7 Starter startet nach Updates nicht mehr (Microsoft Office Updates)
    Log-Analyse und Auswertung - 31.03.2014 (15)
  7. Trojaner der den Zugang zur Windows-Homepage blockiert und keine Updates zulässt
    Log-Analyse und Auswertung - 21.01.2014 (19)
  8. Win 7 64 bit- Kaspersky IS 2013-keine Updates-keine Aktivierung nach Neuinstallation-Fehler 2 Arbeitsstationsdienst
    Log-Analyse und Auswertung - 27.09.2013 (34)
  9. Updates für Mac Office 2004, 2008 und 2011
    Nachrichten - 15.06.2011 (0)
  10. MS-Patchday: Updates für Office und Forefront
    Nachrichten - 05.11.2010 (0)
  11. alte office (2003) dateien mit explorer oder win comander in office 2010 öffnen
    Alles rund um Windows - 06.08.2010 (10)
  12. Keine Updates mehr
    Plagegeister aller Art und deren Bekämpfung - 10.05.2009 (14)
  13. Hilfe! Keine Updates funktionieren! Trojaner?
    Log-Analyse und Auswertung - 18.04.2009 (0)
  14. Keine .exe, Keine Updates, Keine https
    Log-Analyse und Auswertung - 09.09.2008 (16)
  15. Fehlermeldung beim Öffnen von worddokume in office xp und office 2003
    Alles rund um Windows - 24.08.2006 (7)
  16. Fragmente
    Plagegeister aller Art und deren Bekämpfung - 28.06.2006 (3)

Zum Thema LOG Auswertung, Keine Office Updates, Fragmente BKA Trojaner - Hi Leute, ich kann aktuelle Office2013 Updates nicht installieren, ich habe ein wenig vorarbeit geleistet und gemäß der Anleitungen des TB Forums, mit folgenden Programmen, erste LOGs erstellt. Ich habe - LOG Auswertung, Keine Office Updates, Fragmente BKA Trojaner...
Archiv
Du betrachtest: LOG Auswertung, Keine Office Updates, Fragmente BKA Trojaner auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.