![]() |
Programmstart langsam Hallo, mein Rechner läuft langsamer als vorher. Auch das starten der Programme nimmt sehr viel Zeit in Anspruch wie kann ich das ändern. Hier mal die Hijack This Log. Ich kann mir daraus nix nehmen. Ich bitte um Hilfe. |
Hi, Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. Ich kann auf Arbeit keine Anhänge öffnen, danke. ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
Hallo schrauber, danke für deinen Hinweis werde ich berücksichtigen. Hier den Inhalt der Frst.txt FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-03-2014 --- --- --- Und hier den Inhalt der Datei Addition.txt Additional scan result of Farbar Recovery Scan Tool (x86) Version: 05-03-2014 Ran by xsterni at 2014-03-05 15:58:20 Running from C:\Users\xsterni\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== A Gnome's Home: Der Kristall des Lebens (HKLM\...\BFG-A Gnome's Home - Der Kristall des Lebens) (Version: - ) Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.5.146 - Adobe Systems, Inc.) Advertising Center (Version: 0.0.0.2 - Nero AG) Hidden Amazon MP3-Downloader 1.0.18 (HKCU\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC) Apple Application Support (HKLM\...\{A922C4B7-50E0-4787-A94C-59DBF3C65DBE}) (Version: 3.0 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{10E3A6DD-84D8-4D8A-BB11-5E5314BCA7FD}) (Version: 7.1.0.32 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Arizona Rose and the Pirates' Riddles (HKLM\...\BFG-Arizona Rose and the Pirates' Riddles) (Version: - ) Ashampoo MP3 Cover Finder v.1.0.7 (HKLM\...\{5A842CF6-7E61-52D7-C64C-2F20E9D408F1}_is1) (Version: 1.0.7 - Ashampoo GmbH & Co. KG) AudibleManager (HKLM\...\AudibleManager) (Version: 2010929776.48.56.23530730 - Audible, Inc.) Auslogics DiskDefrag (HKLM\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 4.5.0.0 - Auslogics Labs Pty Ltd) Battle.net (HKLM\...\Battle.net) (Version: - Blizzard Entertainment) Big Fish: Game Manager (HKLM\...\BFGC) (Version: 3.2.0.6 - ) Bing Maps 3D (HKLM\...\{2D87E961-577B-492B-AD54-1368680FB9A7}) (Version: 4.0.903.16005 - Microsoft Corporation) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Canon Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - ) Canon Easy-WebPrint EX (HKLM\...\Easy-WebPrint EX) (Version: 1.3.5.0 - Canon Inc.) Canon IJ Network Scanner Selector EX (HKLM\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - ) Canon IJ Network Tool (HKLM\...\Canon_IJ_Network_UTILITY) (Version: - ) Canon MG5300 series Benutzerregistrierung (HKLM\...\Canon MG5300 series Benutzerregistrierung) (Version: - ) Canon MG5300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series) (Version: - Canon Inc.) Canon MG5300 series On-screen Manual (HKLM\...\Canon MG5300 series On-screen Manual) (Version: - ) Canon MP Navigator EX 5.0 (HKLM\...\MP Navigator EX 5.0) (Version: - ) Canon My Printer (HKLM\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.) Canon Solution Menu EX (HKLM\...\CanonSolutionMenuEX) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4478 - CDBurnerXP) Cooking Dash (HKLM\...\BFG-Cooking Dash) (Version: - ) Curse Client (HKCU\...\101a9f93b8f0bb6f) (Version: 5.1.1.792 - Curse) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.47.1.0333 - Disc Soft Ltd) Dark Parables: Der Fluch des Froschkönigs (HKLM\...\BFG-Dark Parables - Der Fluch des Froschkoenigs) (Version: - ) Dark Parables: Der Orden der Rotkäppchen Sammleredition (HKLM\...\BFG-Dark Parables - Der Orden der Rotkaeppchen Sammleredition) (Version: - ) Dark Parables: Der Schmerz der Schneekönigin (HKLM\...\BFG-Dark Parables - Der Schmerz der Schneekoenigin) (Version: - ) Definition Update for Microsoft Office 2013 (KB2760587) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{CD3C2621-B611-4A30-BB37-81CA880AB895}) (Version: - Microsoft) Defraggler (HKLM\...\Defraggler) (Version: 2.16 - Piriform) Der Schnee (HKLM\...\BFG-Der Schnee) (Version: - ) Die Legende von Atlantis: Exodus (HKLM\...\BFG-Die Legende von Atlantis - Exodus) (Version: - ) Diner Dash: Flo Through Time (HKLM\...\BFG-Diner Dash - Flo Through Time) (Version: - ) DVDFab 9.1.1.5 (07/12/2013) (HKLM\...\DVDFab 9_is1) (Version: - Fengtao Software Inc.) eReg (Version: 1.20.138.34 - Logitech, Inc.) Hidden EssentialPIM Pro (HKLM\...\EssentialPIM Pro) (Version: 5.57 - Astonsoft Ltd) Fishdom 3 (HKLM\...\BFG-Fishdom 3) (Version: - ) Foxtab (HKLM\...\foxtab) (Version: - FoxTab) <==== ATTENTION Gardenscapes: Mansion Makeover™ (HKLM\...\BFG-Gardenscapes - Mansion Makeover) (Version: - ) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Google Chrome (HKLM\...\Google Chrome) (Version: 33.0.1750.146 - Google Inc.) Google Update Helper (Version: 1.3.22.5 - Google Inc.) Hidden HD Tune 2.55 (HKLM\...\HD Tune_is1) (Version: - EFD Software) Hearthstone (HKLM\...\Hearthstone) (Version: - Blizzard Entertainment) Hot Dish (HKLM\...\BFG-Hot Dish) (Version: - ) Hotel Dash: Suite Success (HKLM\...\BFG-Hotel Dash - Suite Success) (Version: - ) iCloud (HKLM\...\{20C6FF70-690B-4DF7-8F5D-269DD3A7FD23}) (Version: 3.0.2.163 - Apple Inc.) Island Tribe 4 (HKLM\...\BFG-Island Tribe 4) (Version: - ) iTunes (HKLM\...\{616445AF-BBCF-41C1-A4D6-8CFF171C182D}) (Version: 11.1.4.62 - Apple Inc.) Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java SE Development Kit 7 Update 25 (HKLM\...\{32A3A4F4-B792-11D6-A78A-00B0D0170250}) (Version: 1.7.0.250 - Oracle) JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) Jewel Charm (HKLM\...\BFG-Jewel Charm) (Version: - ) Jewel Legends: Atlantis (HKLM\...\BFG-Jewel Legends - Atlantis) (Version: - ) Jewel Legends: Tree of Life (HKLM\...\BFG-Jewel Legends - Tree of Life) (Version: - ) Kaspersky Internet Security (HKLM\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Internet Security (Version: 14.0.0.4651 - Kaspersky Lab) Hidden Kingdom Tales (HKLM\...\BFG-Kingdom Tales) (Version: - ) K-Lite Codec Pack 5.2.0 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 5.2.0 - ) Logitech Harmony Remote Software 7 (HKLM\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech) Logitech Harmony Remote Software 7 (Version: 7.7.0.0 - Logitech) Hidden Logitech SetPoint 6.61 (HKLM\...\sp6) (Version: 6.61.15 - Logitech) Lost in Night (HKLM\...\BFG-Lost in Night) (Version: - ) Luxor HD (HKLM\...\BFG-Luxor HD) (Version: - ) Mahjongg Dimensions Deluxe (HKLM\...\BFG-Mahjongg Dimensions Deluxe) (Version: - ) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Mein CEWE FOTOBUCH (HKLM\...\Mein CEWE FOTOBUCH) (Version: 5.1.2 - CEWE COLOR AG u Co. OHG) Mein Königreich für die Prinzessin (HKLM\...\BFG-Mein Koenigreich fuer die Prinzessin) (Version: - ) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Access MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft DCF MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Excel MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Groove MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft InfoPath MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Lync MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Office OSM UX MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft OneNote MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Outlook MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft PowerPoint MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Publisher MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Word MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden MOBackup - Datensicherung für Outlook (Vollversion) (HKLM\...\MOBackup-DatensicherungfürOutlook) (Version: 7.0 - Heiko Schröder) MobMap 5.40 (HKLM\...\MobMap_is1) (Version: - Slarti on EU-Blackhand) Mozilla Firefox 27.0.1 (x86 de) (HKLM\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) My Kingdom for the Princess III (HKLM\...\BFG-My Kingdom for the Princess III) (Version: - ) MyFreeCodec (HKCU\...\MyFreeCodec) (Version: - ) Mystika: Zwischen Licht und Schatten (HKLM\...\BFG-Mystika - Zwischen Licht und Schatten) (Version: - ) Need4 Video Converter 9 (HKLM\...\Need4 Video Converter 9) (Version: 9 - Need4Video) Nero BurnLite 10 (HKLM\...\{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}) (Version: 10.0.10600 - Nero AG) Nero BurnLite 10 (HKLM\...\{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}) (Version: 10.0.10500.5.100 - Nero AG) Nero Control Center 10 (Version: 10.0.13100.3.1 - Nero AG) Hidden Nero ControlCenter (Version: 9.0.0.1 - Nero AG) Hidden Nero ControlCenter 10 Help (CHM) (Version: 1.0.10700 - Nero AG) Hidden Nero Core Components 10 (Version: 2.0.15100.0.1 - Nero AG) Hidden Nero Installer (Version: 4.4.9.0 - Nero AG) Hidden Nero MediaHome 4 (Version: 4.5.9.2 - Nero AG) Hidden Nero MediaHome 4 Essentials (HKLM\...\{5dcd8c1d-8689-4a0b-bb18-cb9cfee6fb21}) (Version: - Nero AG) Nero MediaHome 4 Help (Version: 4.5.5.0 - Nero AG) Hidden Nero Online Upgrade (Version: 1.3.0.0 - Nero AG) Hidden Nero Update (Version: 11.0.13300.42.0 - Nero AG) Hidden Northern Tale (HKLM\...\BFG-Northern Tale) (Version: - ) NVIDIA 3D Vision Controller-Treiber 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 334.89 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 334.89 - NVIDIA Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.57.35 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 334.89 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.3489 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 334.89 (Version: 334.89 - NVIDIA Corporation) Hidden NVIDIA Update 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 10.11.15 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.19 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.19 - NVIDIA Corporation) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.213.0 - Tracker Software Products Ltd) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) Pizza Chef (HKLM\...\BFG-Pizza Chef) (Version: - ) QuickTime (HKLM\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Ravensburger Puzzle Selection (HKLM\...\BFG-Ravensburger Puzzle Selection) (Version: - ) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.) Remote Control USB Driver (HKLM\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - ) Robinson Crusoe and the Cursed Pirates (HKLM\...\BFG-Robinson Crusoe and the Cursed Pirates) (Version: - ) Rossmann Fotowelt Software 4.12.1 (HKLM\...\Rossmann Fotowelt Software) (Version: 4.12.1 - ORWO Net) Rush for Gold: Alaska (HKLM\...\BFG-Rush for Gold - Alaska) (Version: - ) Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.0.13064_2 - Samsung Electronics Co., Ltd.) Samsung Kies (Version: 2.6.0.13064_2 - Samsung Electronics Co., Ltd.) Hidden Samsung Kies3 (HKLM\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.13114.22 - Samsung Electronics Co., Ltd.) Samsung Kies3 (Version: 3.2.13114.22 - Samsung Electronics Co., Ltd.) Hidden Samsung Story Album Viewer (HKLM\...\InstallShield_{698BBAD8-B116-495D-B879-0F07A533E57F}) (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.) Samsung Story Album Viewer (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.29.0 - SAMSUNG Electronics Co., Ltd.) SHIELD Streaming (Version: 1.6.85 - NVIDIA Corporation) Hidden Shockwave (HKLM\...\Shockwave) (Version: - ) Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) ss helper 1.74 (HKLM\...\SP_360582d7) (Version: - ) <==== ATTENTION swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.13.1 - TeamSpeak Systems GmbH) TeamViewer 9 (HKLM\...\TeamViewer 9) (Version: 9.0.24951 - TeamViewer) Tukui Client (HKLM\...\{510CF4AB-E9C8-4F48-BB02-CDC11B880D68}) (Version: 2.2.7 - Tukui) Tukui Client (HKLM\...\{EF0FAA54-5532-4B90-99C4-B4A97D600A94}) (Version: 2.4.3 - Tukui) Update for Microsoft Access 2013 (KB2768008) 32-Bit Edition (HKLM\...\{90150000-0015-0407-0000-0000000FF1CE}_Office15.PROPLUS_{02DD2FBD-76D9-4B8B-AAE6-657542F4F6E6}) (Version: - Microsoft) Update for Microsoft Access 2013 (KB2827233) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{FB31ABE4-BB41-4E9A-A252-1A4BC9DC8C43}) (Version: - Microsoft) Update for Microsoft InfoPath 2013 (KB2837648) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{F15AA550-A0B9-44AD-9067-2294CCA51F1C}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2817678) 32-Bit Edition (HKLM\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{7FBE2D23-9F3C-4983-B927-2A4BF600B7A7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2726954) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{4F307363-49DA-4AE7-9D9D-DAA1FF59274F}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2726996) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{6E6B2968-B9D7-40C9-9FC2-8E729DDBB39C}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2726996) 32-Bit Edition (HKLM\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{49893259-C896-4972-9B6C-6B75790945F1}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2738038) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{AFDC9BDD-5608-4A21-8066-13E2ACE1EDB4}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760224) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{4F8AD68D-9F41-446E-AA81-C43BF88671BF}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760242) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{BCD0EA38-A8FB-4F3D-B04E-DFFB38BC7849}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760267) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{9E03AB38-EF60-4DE6-92FB-656E23403BFA}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760539) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{E58009CD-D950-4CAE-89B4-E97C3B78319B}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760553) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{03FC8649-9511-4FB1-BE34-67A442505DCF}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760610) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{B299B17D-874D-43DD-84AA-414BD9C70021}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760610) 32-Bit Edition (HKLM\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{65D789FD-9118-45AF-8DE4-F49F358A8525}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2767845) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7E8D777B-BD75-480D-AC03-AF9C3D83CDBF}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2768016) 32-Bit Edition (HKLM\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{B9DB28D9-15D0-4DDE-A123-C9B82AC9A579}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817314) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{B9A3A7A7-8B5B-4D07-9816-80EE2EA5B9B7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817316) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{670559E6-5725-4B84-A16C-0859771F25DE}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817316) 32-Bit Edition (HKLM\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{5EFADE14-CE0B-43BF-ADD2-850FCB79485F}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817316) 32-Bit Edition (HKLM\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{8E942418-D7DE-48A4-8210-AD994006EFAA}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817490) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{188DFB16-BA3F-4AD3-9432-45C8FA64EC8B}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817626) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{BC369230-B0E0-4BB0-82D6-E93196060BFA}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2826004) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{FD782270-0456-4B87-AC5E-C6EE2D063C48}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827225) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{C5CF8938-646A-41A5-A4E6-6EEE4205CBA4}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827227) 32-Bit Edition (HKLM\...\{90150000-001F-0407-0000-0000000FF1CE}_Office15.PROPLUS_{08F8B8BC-97B5-4110-8FC1-A840DEAD0DF9}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827227) 32-Bit Edition (HKLM\...\{90150000-001F-0409-0000-0000000FF1CE}_Office15.PROPLUS_{F75F8521-118D-4DE2-927F-073BE7B6DC7F}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827227) 32-Bit Edition (HKLM\...\{90150000-001F-040C-0000-0000000FF1CE}_Office15.PROPLUS_{E11A0DDD-9F6D-49C6-8F02-850D44DD7639}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827227) 32-Bit Edition (HKLM\...\{90150000-001F-0410-0000-0000000FF1CE}_Office15.PROPLUS_{A1416C8A-2BA0-43D0-BCD5-C6C29D029327}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827230) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{954A0EA5-CCCB-4B4E-8664-40E2CC8BBCBB}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827239) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{4B1A48FA-CAE2-49BB-A912-6F96AE7875D9}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2837626) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{079FC22A-639F-4690-8512-F54DCD8493C7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2837637) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{13A97DC6-1E49-40B1-94E6-EB4CC3087607}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2837638) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{C89EE024-ECC9-43EB-9D6A-52AB9B73ED63}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2837655) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{2982593C-B10B-4757-A58A-7926ED063448}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2837655) 32-Bit Edition (HKLM\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{EBEB9885-E941-44AB-960A-FE4970ACB1F1}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2850066) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{0AA960ED-0F9A-42EC-B9F4-52A104EB954D}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2850063) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{FA115DB4-AD0A-4C2B-8713-DB15275B7426}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2850063) 32-Bit Edition (HKLM\...\{90150000-00A1-0407-0000-0000000FF1CE}_Office15.PROPLUS_{7E7400E8-36C5-4FA3-A75E-9F3BFE44EA7D}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2850061) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{3EF35AB5-21A1-4858-97BB-E4CF1ECF3736}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2850061) 32-Bit Edition (HKLM\...\{90150000-001A-0407-0000-0000000FF1CE}_Office15.PROPLUS_{43E84964-1A37-4115-AD8D-ED2E2F0A7674}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2767850) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{94A5E2C5-5F2C-4238-8387-F16873B7927C}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2767850) 32-Bit Edition (HKLM\...\{90150000-0018-0407-0000-0000000FF1CE}_Office15.PROPLUS_{A45FD7A9-2E67-41AA-8473-1463D10AAF55}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2837635) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{696ACAB0-DCE3-4050-849A-629CE94A9E3A}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2837635) 32-Bit Edition (HKLM\...\{90150000-0019-0407-0000-0000000FF1CE}_Office15.PROPLUS_{67F8928F-664E-47A9-B283-3121D5F904CC}) (Version: - Microsoft) Update for Microsoft SkyDrive Pro (KB2817495) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{00ADF78E-D103-44D9-93FC-4E0B4255DF61}) (Version: - Microsoft) Update for Microsoft SkyDrive Pro (KB2837652) 32-Bit Edition (HKLM\...\{90150000-00BA-0407-0000-0000000FF1CE}_Office15.PROPLUS_{A499C133-698D-430B-970B-E5E2ABB28930}) (Version: - Microsoft) Update for Microsoft Visio 2013 (KB2817306) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{166909FC-6736-4EE5-9491-1BF9A4EE84E7}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2768338) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{9CEFDC22-A298-451A-905E-28E42B90A563}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2837647) 32-Bit Edition (HKLM\...\{90150000-001A-0407-0000-0000000FF1CE}_Office15.PROPLUS_{E666A48D-62E6-4B76-AE27-128DD5C42684}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2837647) 32-Bit Edition (HKLM\...\{90150000-001B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{E666A48D-62E6-4B76-AE27-128DD5C42684}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2837647) 32-Bit Edition (HKLM\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{E666A48D-62E6-4B76-AE27-128DD5C42684}) (Version: - Microsoft) Ver 1.2.0 (HKLM\...\USB Audio_is1) (Version: - Oscar) Video DVD Maker v3.30.0.75 (HKLM\...\{1A3E23D7-7A1E-43EC-B35D-EB2A31BED943}) (Version: - ) Virtual CD v10 (HKLM\...\{10C51313-A308-4B40-90E3-B368D5882660}) (Version: 10.10.14 - H+H Software GmbH) Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Wacky Races (HKLM\...\{6C132D40-361B-11D4-81D4-00E029561B9E}) (Version: - ) WinRAR 4.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) Wochenplan-Trainingssoftware 2 (HKLM\...\Wochenplan-Trainingssoftware 2) (Version: - ) World Mosaics 4 (HKLM\...\BFG-World Mosaics 4) (Version: - ) World Mosaics 5 (HKLM\...\BFG-World Mosaics 5) (Version: - ) World Mosaics 6 (HKLM\...\BFG-World Mosaics 6) (Version: - ) World Riddles: Animals (HKLM\...\BFG-World Riddles - Animals) (Version: - ) World Riddles: Secrets of the Ages (HKLM\...\BFG-World Riddles - Secrets of the Ages) (Version: - ) World Riddles: Seven Wonders (HKLM\...\BFG-World Riddles - Seven Wonders) (Version: - ) ==================== Restore Points ========================= 25-02-2014 10:31:33 Windows Update 26-02-2014 10:33:37 Windows Update 04-03-2014 23:20:42 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {22384D3D-87B0-4A96-9CEE-4E5090F3BC2A} - System32\Tasks\FoxTab => C:\Users\xsterni\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {3EA3DDD0-7C14-4586-BCD9-2D07973C7B58} - System32\Tasks\Microsoft Office 15 Sync Maintenance for xsterni-PC-xsterni xsterni-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2013-11-08] (Microsoft Corporation) Task: {4891860E-EF95-471A-BA6D-FCB9F02A02E3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {57840658-C34E-4AB5-A958-7DA10E2347A8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {5DF4D3E7-6210-4A17-A8C4-E6D350BBA944} - System32\Tasks\Apple Diagnostics => C:\Program Files\Common Files\Apple\Internet Services\EReporter.exe [2013-09-14] (Apple Inc.) Task: {677411F7-8D59-45F6-A973-9B00C596CD6B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-21] (Adobe Systems Incorporated) Task: {98CA58AC-4696-4AE2-89C0-795B56CB3C8C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd) Task: {99B3CAEB-FD5D-4E97-8F90-8FCF35106316} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-28] (Google Inc.) Task: {AC1B06BB-7255-4DE4-B83A-3098C0CC4155} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation) Task: {AC6FE01E-3935-4CB7-B316-775F04E478BE} - System32\Tasks\Speedfan => C:\Program Files (x86)\SpeedFan\speedfan.exe [2013-03-15] (Almico Software (www.almico.com)) Task: {AD443545-93D6-4C8D-A91E-F2D3382AC151} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {E6C5A58A-B063-4FDA-9E0A-39648F0E0286} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {FBE0439A-D93F-4521-A0D1-B20413B6DE28} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-28] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FoxTab.job => C:\Users\xsterni\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-07 18:48 - 2014-02-08 18:11 - 00107808 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 13:16 - 2014-01-20 13:16 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll 2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll 2013-11-16 00:43 - 2013-07-24 09:24 - 00137728 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll 2013-12-28 23:33 - 2008-08-18 16:08 - 00050688 _____ () C:\Program Files\Virtual CD v10\System\ogg.dll 2013-12-28 23:33 - 2008-08-18 16:11 - 01237504 _____ () C:\Program Files\Virtual CD v10\System\vorbis.dll 2014-03-05 04:27 - 2014-03-05 04:27 - 26118656 _____ () C:\Program Files\Battle.net\Battle.net.4269\libcef.dll 2014-03-05 04:27 - 2014-03-05 04:27 - 00739840 _____ () C:\Program Files\Battle.net\Battle.net.4269\libglesv2.dll 2014-03-05 04:27 - 2014-03-05 04:27 - 00130048 _____ () C:\Program Files\Battle.net\Battle.net.4269\libegl.dll 2014-02-15 00:14 - 2014-02-15 00:14 - 03578992 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-07-19 11:56 - 2013-07-19 11:56 - 01027240 _____ () C:\Program Files\Microsoft Office\Office15\ADDINS\UmOutlookAddin.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:000D6A25 AlternateDataStreams: C:\ProgramData\TEMP:008586AE AlternateDataStreams: C:\ProgramData\TEMP:0406003C AlternateDataStreams: C:\ProgramData\TEMP:0ADCCF52 AlternateDataStreams: C:\ProgramData\TEMP:0BF4DA47 AlternateDataStreams: C:\ProgramData\TEMP:0C65EA0E AlternateDataStreams: C:\ProgramData\TEMP:165AF2C6 AlternateDataStreams: C:\ProgramData\TEMP:1ECED34B AlternateDataStreams: C:\ProgramData\TEMP:22741C1F AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F AlternateDataStreams: C:\ProgramData\TEMP:33384BC0 AlternateDataStreams: C:\ProgramData\TEMP:38FF076E AlternateDataStreams: C:\ProgramData\TEMP:43F5FA9D AlternateDataStreams: C:\ProgramData\TEMP:45912F61 AlternateDataStreams: C:\ProgramData\TEMP:46CBC45C AlternateDataStreams: C:\ProgramData\TEMP:4C49306C AlternateDataStreams: C:\ProgramData\TEMP:57173DB4 AlternateDataStreams: C:\ProgramData\TEMP:5B4686D7 AlternateDataStreams: C:\ProgramData\TEMP:6378B6B8 AlternateDataStreams: C:\ProgramData\TEMP:69FD6BF0 AlternateDataStreams: C:\ProgramData\TEMP:7A2101AB AlternateDataStreams: C:\ProgramData\TEMP:7A632F57 AlternateDataStreams: C:\ProgramData\TEMP:7BB584AA AlternateDataStreams: C:\ProgramData\TEMP:84FA02E7 AlternateDataStreams: C:\ProgramData\TEMP:8AC20936 AlternateDataStreams: C:\ProgramData\TEMP:97CA3B9E AlternateDataStreams: C:\ProgramData\TEMP:A4241298 AlternateDataStreams: C:\ProgramData\TEMP:A7964713 AlternateDataStreams: C:\ProgramData\TEMP:B88DC997 AlternateDataStreams: C:\ProgramData\TEMP:D2397415 AlternateDataStreams: C:\ProgramData\TEMP:D254266B AlternateDataStreams: C:\ProgramData\TEMP:D5CCCBAA AlternateDataStreams: C:\ProgramData\TEMP:D6A4A911 AlternateDataStreams: C:\ProgramData\TEMP:D6D084A5 AlternateDataStreams: C:\ProgramData\TEMP:D987CB43 AlternateDataStreams: C:\ProgramData\TEMP:E153075C AlternateDataStreams: C:\ProgramData\TEMP:E54FC174 AlternateDataStreams: C:\ProgramData\TEMP:E5BA9ADD AlternateDataStreams: C:\ProgramData\TEMP:EA701346 AlternateDataStreams: C:\ProgramData\TEMP:EB333CFC AlternateDataStreams: C:\ProgramData\TEMP:EB86F355 AlternateDataStreams: C:\ProgramData\TEMP:EDE28CFC AlternateDataStreams: C:\ProgramData\TEMP:F4362715 ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: com.apple.dav.bookmarks.daemon => C:\Program Files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: MobMapUpdater => "C:\Program Files\MobMapUpdater\MobMapUpdater.exe" --silent ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (03/05/2014 03:52:24 PM) (Source: Application Hang) (User: ) Description: Programm FRST.exe, Version 3.3.10.2 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1a98 Startzeit: 01cf388205b21d45 Endzeit: 0 Anwendungspfad: C:\Users\xsterni\Downloads\FRST.exe Berichts-ID: 7a8458c6-a475-11e3-a766-90e6ba5a66c0 Error: (03/05/2014 03:38:27 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/05/2014 11:35:49 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/05/2014 07:46:55 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (User: ) Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (03/05/2014 06:45:46 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/05/2014 04:38:46 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/05/2014 04:37:58 AM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (03/05/2014 04:37:58 AM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (03/05/2014 04:29:20 AM) (Source: Office 2013 Licensing Service) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (03/05/2014 04:20:48 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (03/05/2014 03:40:23 PM) (Source: bowser) (User: ) Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "EASYBOX" zum Namen "XSTERNI-PC" auf Transport "NetBT_Tcpip_{DCA1A7C3-6864-4737-858B". Das Datagramm steht in den Daten. Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist. Error: (03/05/2014 03:38:34 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (03/05/2014 11:36:04 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (03/05/2014 11:35:59 AM) (Source: bowser) (User: ) Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "EASYBOX" zum Namen "XSTERNI-PC" auf Transport "NetBT_Tcpip_{DCA1A7C3-6864-4737-858B". Das Datagramm steht in den Daten. Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist. Error: (03/05/2014 06:46:24 AM) (Source: bowser) (User: ) Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "EASYBOX" zum Namen "XSTERNI-PC" auf Transport "NetBT_Tcpip_{DCA1A7C3-6864-4737-858B". Das Datagramm steht in den Daten. Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist. Error: (03/05/2014 06:45:58 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (03/05/2014 04:38:34 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (03/05/2014 04:38:06 AM) (Source: bowser) (User: ) Description: Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom Remotecomputer "EASYBOX" zum Namen "XSTERNI-PC" auf Transport "NetBT_Tcpip_{DCA1A7C3-6864-4737-858B". Das Datagramm steht in den Daten. Es werden keine weiteren Ereignisse erzeugt, solange die Rücksetzfrequenz nicht abgelaufen ist. Error: (03/05/2014 04:21:17 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (03/05/2014 04:20:11 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Virtual CD v10 Management Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Microsoft Office Sessions: ========================= Error: (03/05/2014 03:52:24 PM) (Source: Application Hang)(User: ) Description: FRST.exe3.3.10.21a9801cf388205b21d450C:\Users\xsterni\Downloads\FRST.exe7a8458c6-a475-11e3-a766-90e6ba5a66c0 Error: (03/05/2014 03:38:27 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/05/2014 11:35:49 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/05/2014 07:46:55 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe)(User: ) Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (03/05/2014 06:45:46 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/05/2014 04:38:46 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/05/2014 04:37:58 AM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (03/05/2014 04:37:58 AM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (03/05/2014 04:29:20 AM) (Source: Office 2013 Licensing Service)(User: ) Description: Subscription licensing service failed: -1073418154 Error: (03/05/2014 04:20:48 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2014-02-28 00:36:42.897 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-28 00:36:42.895 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-28 00:36:42.886 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-28 00:36:42.851 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-28 00:36:42.849 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-28 00:36:42.847 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-28 00:36:42.837 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-28 00:36:42.834 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-28 00:36:42.831 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-28 00:36:42.795 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 55% Total physical RAM: 3327.11 MB Available physical RAM: 1486.34 MB Total Pagefile: 12541.4 MB Available Pagefile: 10385.07 MB Total Virtual: 2047.88 MB Available Virtual: 1920.46 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.76 GB) (Free:66.43 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:232.88 GB) (Free:30.48 GB) NTFS Drive e: () (Fixed) (Total:152.66 GB) (Free:35.76 GB) NTFS Drive f: (Wochenplan2) (CDROM) (Total:0.18 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 233 GB) (Disk ID: 16841683) Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 153 GB) (Disk ID: 27B527B4) Partition 1: (Not Active) - (Size=153 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 1C041C03) Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Danke in vorraus. |
hi, ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Scan mit Combofix
|
Hallo jetzt die Datei. Code: ComboFix 14-03-05.01 - xsterni 06.03.2014 15:10:58.1.4 - x86 |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Hallo, Malwarebytes Anti-Malware Code: Malwarebytes Anti-Malware (Test) 1.75.0.1300 Code: # AdwCleaner v3.020 - Bericht erstellt am 07/03/2014 um 16:50:25 Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ein frisches FRST log FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-03-2014 |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
Code: ESETSmartInstaller@High as downloader log: Code: Results of screen317's Security Check version 0.99.80 FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-03-2014 01 Danke Dir schon mal. Noch als Frage wie kann ich mein System noch erfolgreich vor so einem Angriff schützen, reicht Kaspersky oder doch lieber was einzelnes? Gruß Raasuul |
Ich empfehle immer Emsisoft. Rest kommt jetzt :) Fertig :) Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :) Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 01:24 Uhr. |
Copyright ©2000-2025, Trojaner-Board