winlocked | 23.06.2014 21:10 | Sorry, hatte wohl zwei Mal das gleich rein kopiert :-(
Jetzt das Addition.txt log Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:22-06-2014
Ran by Joerg at 2014-06-23 16:02:19
Running from C:\Users\Joerg\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
ABBYY FineReader for ScanSnap (TM) 4.1 (HKLM\...\{FB400000-0002-0000-0000-074957833700}) (Version: 8.02.380.7259 - ABBYY)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 13.0.0.111 - Adobe Systems Incorporated)
Adobe AIR (Version: 13.0.0.111 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 13 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Amazon MP3-Downloader 1.0.17 (HKLM\...\Amazon MP3-Downloader) (Version: 1.0.17 - Amazon Services LLC)
AMD APP SDK Runtime (Version: 10.0.938.2 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{33FFD86B-569C-9E8D-6659-A1F84D07CAD0}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft MediaImpression 2 (HKLM\...\{81FC0476-9507-4CD3-95A7-2BE60E256D1D}) (Version: 2.0.27.846 - ArcSoft)
AuthenTec TrueSuite (HKLM\...\{E6C44758-FF49-47D1-8182-65E3818ACE23}) (Version: 2.0.0.57 - AuthenTec, Inc.)
Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.4.672 - Avira)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CardMinder (HKLM\...\{D4F2AFD3-0167-4464-B92F-78AB6DA8A0AA}) (Version: V4.1L10 - PFU)
CardMinder V4.1 (Version: 4.1.10.1 - PFU) Hidden
Catalyst Control Center - Branding (Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (Version: 2009.0312.2223.38381 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (Version: 2009.0312.2223.38381 - ATI) Hidden
Catalyst Control Center Graphics Full New (Version: 2009.0312.2223.38381 - ATI) Hidden
Catalyst Control Center Graphics Light (Version: 2009.0312.2223.38381 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (Version: 2009.0312.2223.38381 - ATI) Hidden
Catalyst Control Center Localization All (Version: 2009.0312.2223.38381 - ATI) Hidden
CCC Help Chinese Standard (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Chinese Traditional (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Czech (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Danish (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Dutch (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help English (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Finnish (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help French (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help German (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Greek (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Hungarian (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Italian (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Japanese (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Korean (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Norwegian (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Polish (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Portuguese (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Russian (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Spanish (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Swedish (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Thai (Version: 2009.0312.2222.38381 - ATI) Hidden
CCC Help Turkish (Version: 2009.0312.2222.38381 - ATI) Hidden
ccc-core-static (Version: 2009.0312.2223.38381 - Ihr Firmenname) Hidden
ccc-utility (Version: 2009.0312.2223.38381 - ATI) Hidden
DataSync Outlook (HKLM\...\InstallShield_{1C9171AC-5519-4DF4-B44D-B28F678DEB4C}) (Version: 7.00.2906 - O3SIS IT AG)
DataSync Outlook (Version: 7.00.2906 - O3SIS IT AG) Hidden
devolo dLAN Cockpit (HKLM\...\dlancockpit) (Version: 3.0.0.0 - devolo AG)
DHTML Editing Component (HKLM\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation)
dLAN Cockpit (HKLM\...\Cockpit.92121A72F826FA9D0BD3A830E7F04987B31AFB22.1) (Version: 3 (23.12.2010) - devolo AG)
dLAN Cockpit (Version: 3.23.12 - devolo AG) Hidden
Google Chrome (HKLM\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Earth Plug-in (HKLM\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
High-Definition Video Playback (Version: 7.3.10900.8.0 - Nero AG) Hidden
HP Product Detection (HKLM\...\{4F38594F-2C4A-4C42-B2C4-505E225F6F80}) (Version: 11.14.0004 - HP)
HP Product Detection (HKLM\...\{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}) (Version: 10.7.9.0 - Hewlett-Packard Company)
HP Quick Launch Buttons (HKLM\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.14.1 - Hewlett-Packard Company)
iCloud (HKLM\...\{79BD66B2-4DAE-4C3B-B08E-DC72E507C163}) (Version: 2.1.3.25 - Apple Inc.)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.30 - Irfan Skiljan)
iTunes (HKLM\...\{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}) (Version: 11.1.5.5 - Apple Inc.)
Java 7 Update 60 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217060FF}) (Version: 7.0.600 - Oracle)
Java Auto Updater (Version: 2.1.60.19 - Oracle, Inc.) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20125.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft_VC100_CRT_SP1_x86 (Version: 10.0.40219.1 - Nokia) Hidden
MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 10 Movie ThemePack Basic (Version: 10.6.10000.1.0 - Nero AG) Hidden
Nero Audio Pack 1 (Version: 2.0.13100.0.10 - Nero AG) Hidden
Nero Core Components 10 (Version: 2.0.20100.9.13 - Nero AG) Hidden
Nero Kwik Media (HKLM\...\{1F7D9F37-C39C-486C-BDF8-8F440FFB3352}) (Version: 1.6.16800.75.100 - Nero AG)
Nero Kwik Media (HKLM\...\{D9B5AE52-FEF9-4E5C-A63E-06A6638B2935}) (Version: 10.6.12300 - Nero AG)
Nero Update (Version: 11.0.10022.15.0 - Nero AG) Hidden
NeroKwikMedia Help (CHM) (Version: 10.6.10700 - Nero AG) Hidden
Nokia Connectivity Cable Driver (HKLM\...\{4AA68A73-DB9C-439D-9481-981C82BD008B}) (Version: 7.1.69.0 - Nokia)
Nokia Suite (Version: 3.3.89.0 - Nokia) Hidden
Norton Security Scan (HKLM\...\NSS) (Version: 4.1.0.28 - Symantec Corporation)
PC Connectivity Solution (HKLM\...\{A2AA4204-C05A-4013-888A-AD153139297F}) (Version: 11.5.29.0 - Nokia)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.2 - Frank Heindörfer, Philip Chinery)
Polar Daemon (HKLM\...\{2BA9320D-E061-4C71-ACCB-AC0E9D4FC82B}) (Version: 2.2.20000 - Polar Electro Oy)
Polar WebSync (HKLM\...\{41D4A454-9DF4-4299-8C30-1BBA753E83E1}) (Version: 2.6.00001 - Polar Electro Oy)
QuickTime (HKLM\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
RealDownloader (Version: 17.0.9 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM\...\RealPlayer 17.0) (Version: 17.0.9 - RealNetworks)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Safari (HKLM\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
ScanSnap (Version: 5.1.11.1 - PFU Limited) Hidden
ScanSnap Manager (HKLM\...\{DBCDB997-EEEB-4BE9-BAFF-26B4094DBDE6}) (Version: V5.1L11 - PFU)
ScanSnap Organizer (HKLM\...\{E58F3B88-3B3E-4F85-9323-04789D979C15}) (Version: V4.1L11 - PFU)
ScanSnap Organizer (Version: 4.1.11.18 - PFU LIMITED) Hidden
Skins (Version: 2009.0312.2223.38381 - ATI) Hidden
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.4.11328 - Skype Technologies S.A.)
Skype™ 6.1 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.1.129 - Skype Technologies S.A.)
Turbo Lister 2 (HKLM\...\{8927E07C-97F7-4A54-88FB-D976F50DD46E}) (Version: 2.00.0000 - eBay Inc.)
Update für Microsoft Outlook Social Connector (KB2289116) (HKLM\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{10B1662A-566C-43C2-8469-5A470E0C7D7B}) (Version: - Microsoft)
Update für Microsoft Outlook Social Connector (KB2289116) (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{75F91382-920C-4AE1-B9E6-FFFCEDA797E8}) (Version: - Microsoft)
UpdateService (Version: 1.0.0 - RealNetworks, Inc.) Hidden
VLC media player 1.1.11 (HKLM\...\VLC media player) (Version: 1.1.11 - VideoLAN)
VMware View Client (HKLM\...\{A3ED7FC4-865D-403B-905C-C55EF79A4936}) (Version: 5.1.0.704644 - VMware, Inc.)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) (HKLM\...\504244733D18C8F63FF584AEB290E3904E791693) (Version: 08/22/2008 7.0.0.0 - Nokia)
WinRAR 4.01 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)
WISO Steuer-Sparbuch 2012 (HKLM\...\{0CC1DAFB-40C8-4903-953D-471E541477C7}) (Version: 19.00.7303 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2013 (HKLM\...\{D6CC2FAF-F827-4091-96A1-D32CC9B69C79}) (Version: 20.00.8137 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2014 (HKLM\...\{5021FE2F-5F56-4B8B-9235-B5159FC34508}) (Version: 21.00.8480 - Buhl Data Service GmbH)
XING Connector 1.2 (HKLM\...\XING Connector) (Version: 1.2 - XING AG)
==================== Restore Points =========================
22-06-2014 17:28:50 ComboFix created restore point
==================== Hosts content: ==========================
2009-07-14 04:04 - 2014-06-22 19:41 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {339EB264-FED1-4DA5-BEB6-F7273F3E09D9} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1486621387-3127899674-3502170536-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {4F197CC5-1AA8-4B2A-9ED8-6A99FE915AF7} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1486621387-3127899674-3502170536-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {A6050E2A-8712-4721-9ED2-BFCCF04C9B38} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1486621387-3127899674-3502170536-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {A8286858-4A95-4B21-8680-C5B928D43589} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1486621387-3127899674-3502170536-1000 => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe [2014-04-06] (RealNetworks, Inc.)
Task: {B3F6E18F-36FC-422D-B7EB-4C0C31F2A962} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1486621387-3127899674-3502170536-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {C5307688-D689-4564-8C15-3E8F5AFE96E8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-11-06] (Google Inc.)
Task: {E28B9C57-76B3-48BE-AD2B-2060696C2910} - System32\Tasks\Norton Security Scan for Joerg => C:\Program Files\Norton Security Scan\Engine\4.1.0.28\Nss.exe [2014-01-27] (Symantec Corporation)
Task: {E6F543FC-1DB1-474B-8B95-5C5B73673BFE} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1486621387-3127899674-3502170536-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {EDF06597-C596-4CDC-B806-94E74D261BBC} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1486621387-3127899674-3502170536-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {F4398352-ED10-4F5E-9685-A84B3BCE0C71} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-16] (Adobe Systems Incorporated)
Task: {F9DE8CF0-BBB7-4288-A013-1D634B991E2B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-11-06] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Joerg.job => C:\PROGRA~1\NORTON~2\Engine\410~1.28\Nss.exe
==================== Loaded Modules (whitelisted) =============
2011-08-31 21:36 - 2001-10-28 17:42 - 00116224 _____ () C:\Windows\System32\pdfcmnnt.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2012-08-17 14:43 - 2012-08-17 14:43 - 00413184 _____ () C:\Program Files\Polar\Daemon\polard.exe
2012-08-17 14:42 - 2012-08-17 14:42 - 03477504 _____ () C:\Program Files\Polar\Daemon\libpolar.dll
2014-04-06 23:00 - 2014-04-06 23:00 - 00039568 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-05-01 15:03 - 2014-05-01 15:03 - 00859224 _____ () c:\program files\real\realplayer\RPDS\Plugins\cldplin.dll
2014-04-07 03:06 - 2014-04-07 03:06 - 00023552 _____ () C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe
2010-01-30 02:41 - 2010-01-30 02:41 - 04254560 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-01-30 02:41 - 2010-01-30 02:41 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-09-14 01:51 - 2013-09-14 01:51 - 00087952 _____ () C:\Program Files\Common Files\Apple\Internet Services\zlib1.dll
2013-09-14 01:50 - 2013-09-14 01:50 - 01242952 _____ () C:\Program Files\Common Files\Apple\Internet Services\libxml2.dll
2012-05-13 12:15 - 2008-11-12 15:32 - 00014848 _____ () C:\Program Files\PFU\ScanSnap\CardMinder\CardPath.dll
2012-05-13 12:16 - 2008-09-10 13:04 - 00069632 _____ () C:\Program Files\PFU\ScanSnap\CardMinder\0407\CardConfig0407.dll
2012-05-13 12:09 - 2009-11-23 09:34 - 00344064 _____ () C:\Program Files\PFU\ScanSnap\Driver\PfuSsConfig.dll
2012-05-13 12:09 - 2009-10-15 09:02 - 00233472 _____ () C:\Program Files\PFU\ScanSnap\Driver\PfuSsExtention.dll
2012-05-13 12:09 - 2003-03-26 18:46 - 00135168 _____ () C:\Program Files\PFU\ScanSnap\Driver\PfuSsImgIO.dll
2012-05-13 12:09 - 2007-06-26 20:27 - 00167936 _____ () C:\Program Files\PFU\ScanSnap\Driver\SSsltsa.dll
2013-12-31 19:34 - 2014-02-11 13:07 - 01429808 _____ () C:\Program Files\WISO\Steuersoftware 2014\mshaktuell.exe
2013-12-31 19:30 - 2014-02-12 16:13 - 09658160 _____ () C:\Program Files\WISO\Steuersoftware 2014\wgui14.dll
2013-12-31 19:31 - 2014-02-11 20:14 - 00035120 _____ () C:\Program Files\WISO\Steuersoftware 2014\rsdcom48.dll
2013-12-31 19:31 - 2014-02-11 13:00 - 00309040 _____ () C:\Program Files\WISO\Steuersoftware 2014\rscorewinapi48.dll
2013-12-31 19:31 - 2014-02-11 13:07 - 00321840 _____ () C:\Program Files\WISO\Steuersoftware 2014\rsguiwinapi48.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 03781936 _____ () C:\Program Files\WISO\Steuersoftware 2014\wcore14.dll
2013-12-31 19:31 - 2014-02-11 13:07 - 00136496 _____ () C:\Program Files\WISO\Steuersoftware 2014\rsodbc48.dll
2013-12-31 19:30 - 2014-02-11 20:14 - 02672432 _____ () C:\Program Files\WISO\Steuersoftware 2014\wfvie14.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 01968944 _____ () C:\Program Files\WISO\Steuersoftware 2014\wsteu14.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 01911088 _____ () C:\Program Files\WISO\Steuersoftware 2014\wreli14.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 04279088 _____ () C:\Program Files\WISO\Steuersoftware 2014\wauff14.dll
2013-12-31 19:31 - 2014-02-11 12:53 - 01043456 _____ () C:\Program Files\WISO\Steuersoftware 2014\clucene-core.dll
2013-12-31 19:31 - 2014-02-11 12:53 - 00094720 _____ () C:\Program Files\WISO\Steuersoftware 2014\clucene-shared.dll
2013-12-31 19:31 - 2014-02-11 12:53 - 00250368 _____ () C:\Program Files\WISO\Steuersoftware 2014\clucene-contribs-lib.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 01507120 _____ () C:\Program Files\WISO\Steuersoftware 2014\wmain14.dll
2013-12-31 19:30 - 2014-02-12 13:23 - 05095216 _____ () C:\Program Files\WISO\Steuersoftware 2014\wbae114.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 01687344 _____ () C:\Program Files\WISO\Steuersoftware 2014\wbae214.dll
2013-12-31 19:30 - 2014-02-12 13:23 - 01796400 _____ () C:\Program Files\WISO\Steuersoftware 2014\wbae314.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 01627952 _____ () C:\Program Files\WISO\Steuersoftware 2014\wbae414.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 01115440 _____ () C:\Program Files\WISO\Steuersoftware 2014\whau114.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 01318704 _____ () C:\Program Files\WISO\Steuersoftware 2014\whau214.dll
2013-12-31 19:31 - 2014-02-11 13:07 - 01245488 _____ () C:\Program Files\WISO\Steuersoftware 2014\wwerb14.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 07324976 _____ () C:\Program Files\WISO\Steuersoftware 2014\wkont14.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 01276720 _____ () C:\Program Files\WISO\Steuersoftware 2014\wimp14.dll
2013-12-31 19:30 - 2014-02-11 13:07 - 01330480 _____ () C:\Program Files\WISO\Steuersoftware 2014\wfabu14.dll
2012-11-14 10:03 - 2012-11-14 10:03 - 00014848 _____ () C:\Windows\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll
2014-05-01 15:03 - 2014-05-01 15:03 - 00572504 _____ () c:\program files\real\realplayer\RPDS\Lib\r1api.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
MSCONFIG\startupfolder: C:^Users^Joerg^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^runctf.lnk => C:\Windows\pss\runctf.lnk.Startup
MSCONFIG\startupreg: ctfmon.exe => C:\PROGRA~2\rundll32.exe FG00
MSCONFIG\startupreg: QlbCtrl.exe => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
==================== Faulty Device Manager Devices =============
Name: PCI Simple Communications Controller
Description: PCI Simple Communications Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Mass Storage Controller
Description: Mass Storage Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/23/2014 09:03:55 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (06/23/2014 09:03:55 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (06/23/2014 09:00:12 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.4148"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.4148" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (06/22/2014 07:39:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: catchme.3XE, version: 0.0.0.0, time stamp: 0x49d34e5b
Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp: 0x4ec49caf
Exception code: 0xc0000005
Fault offset: 0x00055e40
Faulting process id: 0xa30
Faulting application start time: 0xcatchme.3XE0
Faulting application path: catchme.3XE1
Faulting module path: catchme.3XE2
Report Id: catchme.3XE3
Error: (06/22/2014 05:48:56 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (06/22/2014 05:48:55 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (06/22/2014 05:44:43 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.4148"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.4148" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (06/22/2014 05:17:33 PM) (Source: Microsoft Office 14) (EventID: 2001) (User: )
Description: Microsoft Outlook: Rejected Safe Mode action : Outlook konnte zuletzt nicht korrekt gestartet werden. Das Starten von Outlook im abgesicherten Modus hilft Ihnen, ein Startproblem zu korrigieren oder zu isolieren, sodass Sie das Programm erfolgreich starten können. Einige Funktionen können in diesem Modus deaktiviert sein.
Möchten Sie Outlook im abgesicherten Modus starten?.
Rejected Safe Mode action : Microsoft Outlook.
Error: (06/09/2014 06:59:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Reader.exe, version: 2.3.0.3130, time stamp: 0x532107b6
Faulting module name: Reader.exe, version: 2.3.0.3130, time stamp: 0x532107b6
Exception code: 0xc0000005
Fault offset: 0x0038dbd4
Faulting process id: 0x19d8
Faulting application start time: 0xReader.exe0
Faulting application path: Reader.exe1
Faulting module path: Reader.exe2
Report Id: Reader.exe3
Error: (06/09/2014 06:28:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Reader.exe, version: 2.3.0.3130, time stamp: 0x532107b6
Faulting module name: Reader.exe, version: 2.3.0.3130, time stamp: 0x532107b6
Exception code: 0xc0000005
Fault offset: 0x0038dbd4
Faulting process id: 0x1f58
Faulting application start time: 0xReader.exe0
Faulting application path: Reader.exe1
Faulting module path: Reader.exe2
Report Id: Reader.exe3
System errors:
=============
Error: (06/23/2014 03:56:41 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk6\DR30.
Error: (06/23/2014 03:56:40 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk6\DR30.
Error: (06/23/2014 03:56:40 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk6\DR30.
Error: (06/23/2014 03:56:39 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk6\DR30.
Error: (06/23/2014 07:56:18 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for DeleteFlag with the following error:
%%5
Error: (06/22/2014 07:43:00 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 19:41:25 on 22.06.2014 was unexpected.
Error: (06/22/2014 07:35:56 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
Error: (06/22/2014 07:31:45 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk7\DR7.
Error: (06/22/2014 07:31:43 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk7\DR7.
Error: (06/22/2014 07:31:22 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
Microsoft Office Sessions:
=========================
Error: (06/23/2014 09:03:55 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Bin64\Setup.exe
Error: (06/23/2014 09:03:55 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Bin64\InstallManagerApp.exe
Error: (06/23/2014 09:00:12 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.4148"C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator64.exe
Error: (06/22/2014 07:39:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: catchme.3XE0.0.0.049d34e5bntdll.dll6.1.7600.169154ec49cafc000000500055e40a3001cf8e40e817c2f6C:\ComboFix\catchme.3XEC:\Windows\SYSTEM32\ntdll.dll26f9c0ba-fa34-11e3-a86f-001a6b179060
Error: (06/22/2014 05:48:56 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Bin64\Setup.exe
Error: (06/22/2014 05:48:55 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Bin64\InstallManagerApp.exe
Error: (06/22/2014 05:44:43 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.4148"C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator64.exe
Error: (06/22/2014 05:17:33 PM) (Source: Microsoft Office 14) (EventID: 2001) (User: )
Description: Microsoft OutlookOutlook konnte zuletzt nicht korrekt gestartet werden. Das Starten von Outlook im abgesicherten Modus hilft Ihnen, ein Startproblem zu korrigieren oder zu isolieren, sodass Sie das Programm erfolgreich starten können. Einige Funktionen können in diesem Modus deaktiviert sein.
Möchten Sie Outlook im abgesicherten Modus starten?
Error: (06/09/2014 06:59:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Reader.exe2.3.0.3130532107b6Reader.exe2.3.0.3130532107b6c00000050038dbd419d801cf83fff7434890C:\Program Files\Sony\ReaderDesktop\Reader.exeC:\Program Files\Sony\ReaderDesktop\Reader.exe65966afe-eff7-11e3-b0eb-001a6b179060
Error: (06/09/2014 06:28:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Reader.exe2.3.0.3130532107b6Reader.exe2.3.0.3130532107b6c00000050038dbd41f5801cf83fe9e495d20C:\Program Files\Sony\ReaderDesktop\Reader.exeC:\Program Files\Sony\ReaderDesktop\Reader.exe0b2381cb-eff3-11e3-b0eb-001a6b179060
==================== Memory info ===========================
Percentage of memory in use: 47%
Total physical RAM: 2047.43 MB
Available physical RAM: 1078.61 MB
Total Pagefile: 4094.86 MB
Available Pagefile: 2688.29 MB
Total Virtual: 2047.88 MB
Available Virtual: 1915.35 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:74.52 GB) (Free:10.23 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (KRD10) (CDROM) (Total:0.38 GB) (Free:0 GB) CDFS
Drive e: (USB DISK) (Removable) (Total:3.72 GB) (Free:0.09 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 75 GB) (Disk ID: BC4FB76E)
Partition 1: (Active) - (Size=75 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 4 GB) (Disk ID: C3072E18)
Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)
==================== End Of Log ============================ langsam bekomme ich Übung ;-)
Viele Grüße und einen schönen Restabend
Joerg |