AVG meldet: Trojaner Generic33.BQLJ Hallo,
meine Antivirensoftware AVG Free 2013 meldet folgenden Befund:
Trojaner: Generic33.BQLJ,
c:\$Recycle.Bin\S-1-5-21-2285999782-1160698361-228544789-1001\$5d81d647b15eb0267c1bc99fc033b5fb\o
"Infiziert";"10.07.2013, 08:59:39";"Datei oder Verzeichnis";"C:\Windows\explorer.exe"
Einen Scan mit FRST habe ich bereits durchgeführt. Hier das passende Log-File:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-07-2013 01
Ran by Kathrinchen (administrator) on 10-07-2013 10:12:00
Running from C:\Users\Kathrinchen\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(SafeNet Inc.) C:\Windows\system32\hasplms.exe
(PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(X-Rite Inc.) C:\Program Files (x86)\X-Rite\Devices\Services\xrdd.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
() C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe
() C:\Program Files (x86)\X-Rite\i1Profiler\i1ProfilerTray.exe
(Dropbox, Inc.) C:\Users\Kathrinchen\AppData\Roaming\Dropbox\bin\Dropbox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Opera Software) C:\Program Files (x86)\Opera\Opera.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(TeamViewer GmbH) c:\program files (x86)\teamviewer\version8\TeamViewer_Desktop.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AdobeAAMUpdater-1.0] - "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [446392 2012-05-31] (Adobe Systems Incorporated)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$5d81d647b15eb0267c1bc99fc033b5fb\o. ATTENTION! ====> ZeroAccess
HKCU\...\Run: [AdobeBridge] - [x]
HKCU\...\Run: [DAEMON Tools Lite] - "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3673728 2012-11-06] (DT Soft Ltd)
HKCU\...\Run: [AirVideoServer] - C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe [4935112 2012-07-20] ()
HKCR\...409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-2285999782-1160698361-228544789-1001\$5d81d647b15eb0267c1bc99fc033b5fb\o. ATTENTION! ====> ZeroAccess?
MountPoints2: E - E:\start.exe
MountPoints2: {c31a0184-4af9-11e2-8ca3-00241dd62195} - E:\start.exe
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] - "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BCSSync] - "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVG_UI] - "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY [4408368 2013-04-29] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [642808 2012-12-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-05-31] (Geek Software GmbH)
HKU\Default\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
Startup: C:\ProgramData\Start Menu\Programs\Startup\i1Profiler Tray.lnk
ShortcutTarget: i1Profiler Tray.lnk -> C:\Program Files (x86)\X-Rite\i1Profiler\i1ProfilerTray.exe ()
Startup: C:\ProgramData\Start Menu\Programs\Startup\XRGamma.lnk
ShortcutTarget: XRGamma.lnk -> C:\Program Files (x86)\X-Rite\i1Profiler\XRGamma.exe (LOGO Kommunikations- und Drucktechnik GmbH & Co. KG)
Startup: C:\Users\Kathrinchen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Kathrinchen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 195.50.140.182 195.50.140.114
==================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4937264 2013-05-14] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-04-18] (AVG Technologies CZ, s.r.o.)
R2 hasplms; C:\Windows\system32\hasplms.exe [3750400 2009-12-16] (SafeNet Inc.)
R2 xrdd.exe; C:\Program Files (x86)\X-Rite\Devices\Services\xrdd.exe [203640 2012-08-14] (X-Rite Inc.)
==================== Drivers (Whitelisted) ====================
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-03-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206136 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311096 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-21] (AVG Technologies CZ, s.r.o.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-21] (DT Soft Ltd)
R2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [142120 2007-04-27] (SafeNet, Inc.)
R3 ttBudget2_NTAMD64; C:\Windows\System32\drivers\ttBudget2_amd64.sys [645152 2009-01-16] (TechnoTrend GmbH)
R2 WinI2C-DDC; C:\Windows\system32\drivers\DDCDrv.sys [20832 2013-01-15] (Nicomsoft Ltd.)
R2 WinI2C-DDC; C:\Windows\system32\drivers\DDCDrv.sys [20832 2013-01-15] (Nicomsoft Ltd.)
U3 aswMBR; C:\Users\KATHRI~1\AppData\Local\Temp\aswMBR.sys [57048 2013-07-10] ()
S1 Aspi32; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-10 10:11 - 2013-07-10 10:11 - 01776221 ____A (Farbar) C:\Users\Kathrinchen\Desktop\FRST64.exe
2013-07-10 10:11 - 2013-07-10 10:11 - 00000000 ____D C:\FRST
2013-07-10 09:32 - 2013-07-10 09:33 - 04745728 ____A (AVAST Software) C:\Users\Kathrinchen\Desktop\aswMBR.exe
2013-07-10 08:49 - 2013-07-10 08:49 - 00000000 ____A C:\Users\Kathrinchen\Desktop\Neues Textdokument.txt
2013-07-10 07:49 - 2013-07-10 07:58 - 00028137 ____A C:\Windows\System32\avgrep.txt
2013-07-10 07:34 - 2013-07-10 07:34 - 01238414 ____A C:\Users\Kathrinchen\Desktop\Facebook Insights Data Export - Liebe zum Bild - 2013-07-09.xls
2013-07-09 14:53 - 2013-07-09 15:04 - 10589428 ____A C:\Users\Kathrinchen\Desktop\_MG_5867.psd
2013-07-09 08:02 - 2013-07-09 08:02 - 00000138 ____A C:\Users\Kathrinchen\Desktop\To-Do.txt
2013-06-23 01:11 - 2013-06-23 01:10 - 17031680 ____A C:\Users\Kathrinchen\Desktop\Praktikum_Präsentation .ppt
2013-06-20 18:46 - 2013-07-09 17:29 - 00000000 ____D C:\Users\Kathrinchen\Desktop\Praktikum
2013-06-20 13:57 - 2013-06-20 13:57 - 00083501 ____A C:\Users\Kathrinchen\Downloads\eltric-weihnachtskatalog-2012.htm
==================== One Month Modified Files and Folders =======
2013-07-10 10:11 - 2013-07-10 10:11 - 01776221 ____A (Farbar) C:\Users\Kathrinchen\Desktop\FRST64.exe
2013-07-10 10:11 - 2013-07-10 10:11 - 00000000 ____D C:\FRST
2013-07-10 09:33 - 2013-07-10 09:32 - 04745728 ____A (AVAST Software) C:\Users\Kathrinchen\Desktop\aswMBR.exe
2013-07-10 09:28 - 2012-12-30 00:23 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-10 09:04 - 2009-07-14 06:45 - 00031680 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-10 09:04 - 2009-07-14 06:45 - 00031680 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-10 09:03 - 2011-04-12 09:43 - 00657438 ____A C:\Windows\System32\perfh007.dat
2013-07-10 09:03 - 2011-04-12 09:43 - 00130810 ____A C:\Windows\System32\perfc007.dat
2013-07-10 09:03 - 2009-07-14 07:13 - 01507106 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-10 09:02 - 2012-12-20 22:11 - 01333121 ____A C:\Windows\WindowsUpdate.log
2013-07-10 08:59 - 2013-05-21 17:53 - 00002016 ____A C:\Windows\setupact.log
2013-07-10 08:59 - 2013-03-12 21:43 - 00000000 ___HD C:\jexepackres
2013-07-10 08:59 - 2013-01-23 16:19 - 00000000 ____D C:\Users\Kathrinchen\AppData\Roaming\Dropbox
2013-07-10 08:59 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-10 08:49 - 2013-07-10 08:49 - 00000000 ____A C:\Users\Kathrinchen\Desktop\Neues Textdokument.txt
2013-07-10 08:39 - 2012-12-21 17:17 - 00000000 ____D C:\ProgramData\MFAData
2013-07-10 08:04 - 2013-01-15 02:53 - 00000000 ____D C:\Users\Kathrinchen\Documents\Outlook-Dateien
2013-07-10 07:58 - 2013-07-10 07:49 - 00028137 ____A C:\Windows\System32\avgrep.txt
2013-07-10 07:34 - 2013-07-10 07:34 - 01238414 ____A C:\Users\Kathrinchen\Desktop\Facebook Insights Data Export - Liebe zum Bild - 2013-07-09.xls
2013-07-09 17:38 - 2013-01-10 11:15 - 00000000 ____D C:\Users\Kathrinchen\Documents\Bewerbungen
2013-07-09 17:29 - 2013-06-20 18:46 - 00000000 ____D C:\Users\Kathrinchen\Desktop\Praktikum
2013-07-09 16:50 - 2013-01-16 17:20 - 00001456 ____A C:\Users\Kathrinchen\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2013-07-09 15:04 - 2013-07-09 14:53 - 10589428 ____A C:\Users\Kathrinchen\Desktop\_MG_5867.psd
2013-07-09 08:02 - 2013-07-09 08:02 - 00000138 ____A C:\Users\Kathrinchen\Desktop\To-Do.txt
2013-07-09 07:52 - 2012-12-20 22:12 - 00000000 ____D C:\Program Files (x86)\Opera
2013-06-23 01:10 - 2013-06-23 01:11 - 17031680 ____A C:\Users\Kathrinchen\Desktop\Praktikum_Präsentation .ppt
2013-06-22 00:15 - 2013-05-01 23:31 - 00000000 ____D C:\Users\Kathrinchen\Desktop\Hochzeit
2013-06-22 00:15 - 2013-02-28 22:24 - 00000000 ____D C:\Users\Kathrinchen\Desktop\Bildideen
2013-06-21 17:28 - 2013-04-17 22:50 - 00000000 ____D C:\ProgramData\hps
2013-06-20 13:57 - 2013-06-20 13:57 - 00083501 ____A C:\Users\Kathrinchen\Downloads\eltric-weihnachtskatalog-2012.htm
2013-06-19 16:28 - 2012-12-30 00:23 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-19 16:28 - 2012-12-30 00:23 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-2285999782-1160698361-228544789-1001\$5d81d647b15eb0267c1bc99fc033b5fb
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
C:\Program Files\Windows Defender\mpsvc.dll => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
LastRegBack: 2013-07-09 09:40
==================== End Of Log ============================ --- --- ---
Die Additions.txt beinhaltet folgendes:
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-07-2013 01
Ran by Kathrinchen at 2013-07-10 10:12:23
Running from C:\Users\Kathrinchen\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
2013 (Version: 2013.0.3349)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
AC3Filter 1.63b (x32 Version: 1.63b)
Adobe AIR (x32 Version: 3.1.0.4880)
Adobe Captivate 6 (64 Bit) (x32 Version: 6.0)
Adobe Captivate Quiz Results Analyzer (x32 Version: 6.0)
Adobe Creative Suite 6 Master Collection (x32 Version: 6)
Adobe eLearning Assets All 1.0 (x32 Version: 1.0)
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
Adobe Help Manager (x32 Version: 4.0.244)
Adobe Photoshop Lightroom 4.4 64-bit (Version: 4.4.1)
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03)
Adobe Widget Browser (x32 Version: 2.0 Build 348)
Adobe Widget Browser (x32 Version: 2.0.348)
Air Video Server 2.4.6-beta3 (x32 Version: 2.4.6-beta3)
AMD Accelerated Video Transcoding (Version: 12.5.100.21219)
AMD APP SDK Runtime (Version: 10.0.1084.4)
AMD Catalyst Install Manager (Version: 8.0.903.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Media Foundation Decoders (Version: 1.0.71219.1540)
Anki (x32)
Apple Application Support (x32 Version: 2.3)
Apple Software Update (x32 Version: 2.1.3.127)
AVG 2013 (Version: 13.0.3204)
AVG 2013 (Version: 13.0.3349)
Avid License Control (x32 Version: 3.0.0)
Avid Media Composer (Version: 6.5.0)
Biet-O-Matic v2.14.12 (x32 Version: 2.14.12)
bl (x32 Version: 1.0.0)
Bonjour (Version: 2.0.2.0)
Bonjour-Druckdienste (Version: 2.0.2.0)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center (x32 Version: 2012.1219.1521.27485)
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485)
Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485)
Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485)
CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485)
CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485)
CCC Help Czech (x32 Version: 2012.1219.1520.27485)
CCC Help Danish (x32 Version: 2012.1219.1520.27485)
CCC Help Dutch (x32 Version: 2012.1219.1520.27485)
CCC Help English (x32 Version: 2012.1219.1520.27485)
CCC Help Finnish (x32 Version: 2012.1219.1520.27485)
CCC Help French (x32 Version: 2012.1219.1520.27485)
CCC Help German (x32 Version: 2012.1219.1520.27485)
CCC Help Greek (x32 Version: 2012.1219.1520.27485)
CCC Help Hungarian (x32 Version: 2012.1219.1520.27485)
CCC Help Italian (x32 Version: 2012.1219.1520.27485)
CCC Help Japanese (x32 Version: 2012.1219.1520.27485)
CCC Help Korean (x32 Version: 2012.1219.1520.27485)
CCC Help Norwegian (x32 Version: 2012.1219.1520.27485)
CCC Help Polish (x32 Version: 2012.1219.1520.27485)
CCC Help Portuguese (x32 Version: 2012.1219.1520.27485)
CCC Help Russian (x32 Version: 2012.1219.1520.27485)
CCC Help Spanish (x32 Version: 2012.1219.1520.27485)
CCC Help Swedish (x32 Version: 2012.1219.1520.27485)
CCC Help Thai (x32 Version: 2012.1219.1520.27485)
CCC Help Turkish (x32 Version: 2012.1219.1520.27485)
ccc-utility64 (Version: 2012.1219.1521.27485)
Celtx (2.9) (x32 Version: 2.9 (de))
Core Temp 1.0 RC4 (Version: 1.0)
DAEMON Tools Lite (x32 Version: 4.46.1.0327)
Dropbox (HKCU Version: 2.0.22)
DVBViewer Pro (x32 Version: 5.0)
FileZilla Client 3.6.0.2 (x32 Version: 3.6.0.2)
Firebird SQL Server - MAGIX Edition (x32 Version: 2.1.31.0)
i1Profiler (x32)
IrfanView (remove only) (x32 Version: 4.35)
Java 7 Update 17 (64-bit) (Version: 7.0.170)
Java 7 Update 17 (x32 Version: 7.0.170)
Java Auto Updater (x32 Version: 2.1.9.0)
Java(TM) SE Runtime Environment 6 Update 6 (Version: 1.6.0.60)
JDownloader 2 (x32 Version: 2)
License Support (Version: 1.1.0.0929)
License Support (x32 Version: 1.1.0.0929)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6)
MAGIX Video deluxe 2013 Plus (Version: 12.0.0.32)
MAGIX Video deluxe 2013 Plus (Video Plugins) (Version: 1.0.0.0)
MAGIX Video deluxe 2013 Plus (Video Plugins) (x32 Version: 1.0.0.0)
MAGIX Video deluxe 2013 Plus (x32 Version: 12.0.0.32)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.4763.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
Notepad++ (x32 Version: 6.3.2)
Opera 12.16 (x32 Version: 12.16.1860)
PDF Settings CS6 (x32 Version: 11.0)
PDF24 Creator 5.5.1 (x32)
ph (x32 Version: 1.0.0)
Pixum Fotobuch (x32 Version: 5.0.1)
PlayReady PC Runtime amd64 (Version: 1.3.0)
QuickTime (x32 Version: 7.73.80.64)
Sentinel Protection Installer 7.4.0 (x32 Version: 7.4.0)
TeamViewer 8 (x32 Version: 8.0.17396)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Visual C++ 64-bit Redistributables (Version: 1.1.0.0929)
Visual C++ 64-bit Redistributables (x32 Version: 1.1.0.0929)
Visual C++ Redistributables (x32 Version: 1.1.0.0929)
Visual Studio 2008 x64 Redistributables (x32 Version: 10.0.0.2)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
VLC media player 2.0.5 (Version: 2.0.5)
WinRAR 4.11 (64-Bit) (Version: 4.11.0)
WOW Slider (x32)
XAMPP 1.8.1 (x32)
X-Rite Device Services Manager (x32 Version: 2.2.61)
==================== Restore Points =========================
06-06-2013 11:32:34 Removed SSDlife Pro
20-06-2013 07:21:52 Geplanter Prüfpunkt
09-07-2013 07:47:27 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2009-07-14 04:34 - 2013-03-11 17:24 - 00001012 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
==================== Scheduled Tasks (whitelisted) =============
Task: {5439E7DD-AE63-433F-8412-D4ECFDA0C571} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2013-01-23] ()
Task: {64C4392A-A911-4438-8F01-F557CC5C9655} - System32\Tasks\XRDeviceServicesSoftwareUpdate => C:\PROGRA~2\X-Rite\Devices\Services\XRDSOF~1.EXE [2012-08-14] (X-Rite Inc.)
Task: {AAEEF308-EB46-4751-80C3-D78F7E050DA8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-19] (Adobe Systems Incorporated)
Task: {B822C49A-4A5F-4BB1-8FD8-88528BEBBEC8} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-21] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/10/2013 09:37:52 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: aswMBR.exe, Version: 0.9.9.1771, Zeitstempel: 0x5147644e
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002e3be
ID des fehlerhaften Prozesses: 0xab4
Startzeit der fehlerhaften Anwendung: 0xaswMBR.exe0
Pfad der fehlerhaften Anwendung: aswMBR.exe1
Pfad des fehlerhaften Moduls: aswMBR.exe2
Berichtskennung: aswMBR.exe3
Error: (07/10/2013 09:01:03 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/10/2013 08:58:11 AM) (Source: Bonjour Service) (User: )
Description: 516: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde vom Remotehost geschlossen.)
Error: (07/10/2013 08:15:52 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/10/2013 08:04:52 AM) (Source: Outlook) (User: )
Description: Fehler beim Bestimmen, ob sich der Speicher im Durchforstungsbereich befindet (Fehler=0x8007043c).
Error: (07/10/2013 08:04:52 AM) (Source: Outlook) (User: )
Description: Fehler beim Abrufen des Durchforstungsbereichs-Managers. Fehler=0x8007043c.
Error: (07/10/2013 08:04:52 AM) (Source: Outlook) (User: )
Description: Fehler beim Bestimmen, ob sich der Speicher im Durchforstungsbereich befindet (Fehler=0x8007043c).
Error: (07/10/2013 08:04:52 AM) (Source: Outlook) (User: )
Description: Fehler beim Abrufen des Durchforstungsbereichs-Managers. Fehler=0x8007043c.
Error: (07/10/2013 07:48:49 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/10/2013 07:44:45 AM) (Source: Bonjour Service) (User: )
Description: 280: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde vom Remotehost geschlossen.)
System errors:
=============
Error: (07/10/2013 08:59:39 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2147024891
Error: (07/10/2013 08:59:39 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet:
%%-2147024891
Error: (07/10/2013 08:59:31 AM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (07/10/2013 08:59:29 AM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
Aspi32
Error: (07/10/2013 08:59:23 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet:
%%-2147024891
Error: (07/10/2013 08:58:20 AM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (07/10/2013 08:14:27 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2147024891
Error: (07/10/2013 08:14:27 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet:
%%-2147024891
Error: (07/10/2013 08:14:19 AM) (Source: Service Control Manager) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (07/10/2013 08:14:17 AM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
Aspi32
Microsoft Office Sessions:
=========================
Error: (07/10/2013 09:37:52 AM) (Source: Application Error)(User: )
Description: aswMBR.exe0.9.9.17715147644entdll.dll6.1.7601.177254ec49b8fc00000050002e3beab401ce7d3fc4ffbd26C:\Users\Kathrinchen\Desktop\aswMBR.exeC:\Windows\SysWOW64\ntdll.dlla05a2d15-e933-11e2-a2c1-
00241dd62195
Error: (07/10/2013 09:01:03 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/10/2013 08:58:11 AM) (Source: Bonjour Service)(User: )
Description: 516: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde vom Remotehost geschlossen.)
Error: (07/10/2013 08:15:52 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/10/2013 08:04:52 AM) (Source: Outlook)(User: )
Description: 0x8007043c
Error: (07/10/2013 08:04:52 AM) (Source: Outlook)(User: )
Description: 0x8007043c
Error: (07/10/2013 08:04:52 AM) (Source: Outlook)(User: )
Description: 0x8007043c
Error: (07/10/2013 08:04:52 AM) (Source: Outlook)(User: )
Description: 0x8007043c
Error: (07/10/2013 07:48:49 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/10/2013 07:44:45 AM) (Source: Bonjour Service)(User: )
Description: 280: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde vom Remotehost geschlossen.)
CodeIntegrity Errors:
===================================
Date: 2012-12-25 13:44:18.046
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden
wurde.
Date: 2012-12-25 12:45:06.426
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden
wurde.
Date: 2012-12-25 12:36:12.915
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden
wurde.
Date: 2012-12-22 17:43:07.338
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden
wurde.
Date: 2012-12-22 16:53:15.671
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden
wurde.
Date: 2012-12-22 11:19:02.654
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden
wurde.
Date: 2012-12-22 11:00:36.181
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden
wurde.
Date: 2012-12-22 10:42:19.238
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden
wurde.
Date: 2012-12-22 10:04:01.832
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden
wurde.
Date: 2012-12-22 09:57:16.620
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden
wurde.
==================== Memory info ===========================
Percentage of memory in use: 36%
Total physical RAM: 8190.49 MB
Available physical RAM: 5227.86 MB
Total Pagefile: 16379.16 MB
Available Pagefile: 13353.7 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:111.69 GB) (Free:42.27 GB) NTFS (Disk=1 Partition=2)
Drive d: (DATA) (Fixed) (Total:1862.89 GB) (Free:1510.53 GB) NTFS (Disk=0 Partition=2)
Drive e: (Video-Training) (CDROM) (Total:4.01 GB) (Free:0 GB) CDFS
Drive h: (EOS_DIGITAL) (Removable) (Total:14.89 GB) (Free:13.03 GB) FAT32 (Disk=3 Partition=1)
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000)
Partition: GPT Partition Type
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 801538C3)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS)
========================================================
Disk: 3 (Size: 15 GB) (Disk ID: 00000000)
Partition 1: (Active) - (Size=15 GB) - (Type=0C)
==================== End Of Log ============================ --- --- ---
Viele Grüße und Danke schonmal
Kathrin |