Razormouth | 25.11.2014 13:48 | Hallo Schrauber,
einen Punkt hatte ich vergessen: aufgetreten ist das am 13.11. erstmals. Und ich habe daraufhin gleich versucht, das mit malwarebytes Antimalware zu scannen, aber der hat nichts gemeldet - das fehlte in meiner Auflistung.
habe die Dateien angehängt, aber den Inhalt auch hier zum schnellscannen:
Inhalt der Frst.txt:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-11-2014
Ran by dirk (administrator) on WS-BUERO on 25-11-2014 13:36:52
Running from C:\Users\dirk\Desktop
Loaded Profiles: UpdatusUser & dirk (Available profiles: WS-EMPFANG & UpdatusUser & dirk & Dennis & Bine & Administrator & DefaultAppPool)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(BUFFALO INC.) C:\Program Files\BUFFALO\NASNAVI\nassvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
() C:\Program Files\WISO\Steuersoftware 2013\mshaktuell.exe
(Buffalo Inc.) C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe
(BUFFALO INC.) C:\Program Files\BUFFALO\NASNAVI\nassche.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\setup_wm.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avscan.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_223.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_223.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [FreePDF Assistant] => C:\Program Files\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [amd_dc_opt] => C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2007-07-23] (AMD)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-11-19] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [EPSON Stylus DX4200 Series] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE [98304 2005-03-08] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-09-12] (Adobe Systems Incorporated)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [124208 2014-10-22] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-20\...\Run: [Windows Update Service] => C:\ProgramData\Windows Update Service0\mwvaztybt.exe [0 ] ()
HKU\S-1-5-21-2250351183-3509862589-1668780546-1006\...\Run: [Windows Update Service] => C:\ProgramData\Windows Update Service0\mwvaztybt.exe [0 ] ()
HKU\S-1-5-21-2250351183-3509862589-1668780546-1006\...\Policies\Explorer: [DisallowRun] 1
HKU\S-1-5-21-2250351183-3509862589-1668780546-1006\...\MountPoints2: {a4d9e17c-43b9-11e3-93a2-002264bf1a2b} - K:\AutoRun.exe TMM70
HKU\S-1-5-21-2250351183-3509862589-1668780546-1006\...\MountPoints2: {b7f20f1b-3d32-11e3-b2ed-002264bf1a2b} - K:\AutoRun.exe TMM70
HKU\S-1-5-21-2250351183-3509862589-1668780546-1006\...\MountPoints2: {ec6e6c15-4e95-11e3-ae49-002264bf1a2b} - G:\LaunchU3.exe -a
IFEO\rstrui.exe: [Debugger] dtdasnd_.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
ShortcutTarget: WISO Mein Steuer-Sparbuch heute.lnk -> C:\Program Files\WISO\Steuersoftware 2013\mshaktuell.exe ()
Startup: C:\Users\dirk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BUFFALO NAS Navigator2.lnk
ShortcutTarget: BUFFALO NAS Navigator2.lnk -> C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe (Buffalo Inc.)
Startup: C:\Users\dirk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NAS Scheduler.lnk
ShortcutTarget: NAS Scheduler.lnk -> C:\Program Files\BUFFALO\NASNAVI\nassche.exe (BUFFALO INC.)
BootExecute: autocheck autochk * bootdelete
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2250351183-3509862589-1668780546-1006\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
HKU\S-1-5-21-2250351183-3509862589-1668780546-1006\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKLM -> DefaultScope value is missing.
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKU\S-1-5-21-2250351183-3509862589-1668780546-1006 -> No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.188.1
FireFox:
========
FF ProfilePath: C:\Users\dirk\AppData\Roaming\Mozilla\Firefox\Profiles\vnvpiaqb.default-1416553315137
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1214154.dll (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2250351183-3509862589-1668780546-1006: sony.com/MediaGoDetector -> C:\Program Files\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
Chrome:
=======
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2014-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2014-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [993584 2014-11-19] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [164656 2014-10-22] (Avira Operations GmbH & Co. KG)
S4 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [387616 2009-08-10] ()
R2 NasPmService; C:\Program Files\BUFFALO\NASNAVI\nassvc.exe [245760 2013-09-13] (BUFFALO INC.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
S4 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [178720 2009-08-10] ()
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-28] (Avira Operations GmbH & Co. KG)
S3 BazisVirtualCDBus; C:\Windows\System32\DRIVERS\BazisVirtualCDBus.sys [115808 2011-06-19] (SysProgs.org)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [30976 2014-06-14] ()
R3 SRS_PremiumSound_Service; C:\Windows\System32\drivers\srs_PremiumSound_i386.sys [246000 2009-11-10] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-29] (Avira GmbH)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2010-12-23] (Samsung Electronics) [File not signed]
S3 XDva401; \??\C:\Windows\system32\XDva401.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-25 13:36 - 2014-11-25 13:37 - 00010471 _____ () C:\Users\dirk\Desktop\FRST.txt
2014-11-25 13:36 - 2014-11-25 13:36 - 00000000 ____D () C:\FRST
2014-11-25 13:35 - 2014-11-25 13:35 - 01110016 _____ (Farbar) C:\Users\dirk\Desktop\FRST.exe
2014-11-25 07:49 - 2014-11-25 07:49 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-11-21 07:22 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-21 07:22 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-14 07:18 - 2014-11-14 07:18 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-11-14 07:18 - 2014-11-14 07:18 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-11-13 12:40 - 2014-11-13 12:40 - 00001180 _____ () C:\Windows\PFRO.log
2014-11-13 12:15 - 2014-11-13 12:15 - 00000000 ____D () C:\Windows\system32\Adobe
2014-11-13 12:14 - 2014-11-13 12:14 - 05008056 _____ (Adobe Systems Inc.) C:\Users\dirk\Downloads\Shockwave_Installer_Slim.exe
2014-11-13 12:13 - 2014-11-25 13:33 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-11-13 12:13 - 2014-11-14 07:08 - 00000000 ____D () C:\Users\dirk\AppData\Local\Mozilla
2014-11-13 12:13 - 2014-11-13 12:13 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-13 12:13 - 2014-11-13 12:13 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-11-13 12:05 - 2014-11-13 12:06 - 36294704 _____ () C:\Users\dirk\Downloads\Firefox Setup 33.1.exe
2014-11-13 11:55 - 2014-11-13 11:56 - 00000000 ____D () C:\Program Files\Recuva
2014-11-13 11:55 - 2014-11-13 11:55 - 03161056 _____ (Piriform Ltd) C:\Users\dirk\Downloads\rcsetup151_slim.exe
2014-11-13 11:55 - 2014-11-13 11:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2014-11-13 10:57 - 2014-11-25 07:10 - 00010416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-13 10:57 - 2014-11-25 07:10 - 00010416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-13 10:57 - 2014-11-13 10:57 - 00000552 _____ () C:\Windows\system32\spsys.log
2014-11-13 10:55 - 2014-11-13 10:55 - 00414896 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-13 10:31 - 2014-11-13 10:31 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-13 10:31 - 2014-11-13 10:31 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-13 10:31 - 2014-11-13 10:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-13 10:31 - 2014-11-13 10:31 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-11-13 10:31 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-13 10:31 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-13 10:31 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-13 10:29 - 2014-11-13 10:29 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\dirk\Downloads\mbamsetup_20730.exe
2014-11-13 10:15 - 2014-11-13 10:17 - 00000230 _____ () C:\Users\dirk\Desktop\FFXprofiles.txt
2014-11-13 09:15 - 2014-11-13 09:15 - 00000000 __SHD () C:\Users\dirk\AppData\Local\EmieBrowserModeList
2014-11-13 09:12 - 2014-11-13 09:12 - 00007266 _____ () C:\Users\dirk\Documents\cc_20141113_091232.reg
2014-11-13 08:43 - 2014-11-25 13:28 - 00000840 _____ () C:\Windows\setupact.log
2014-11-13 08:43 - 2014-11-13 08:43 - 00000000 _____ () C:\Windows\setuperr.log
2014-11-13 08:39 - 2014-11-13 08:39 - 00028328 _____ () C:\Users\dirk\Documents\cc_20141113_083910.reg
2014-11-13 08:20 - 2014-11-13 08:20 - 00000020 ___SH () C:\Users\DefaultAppPool\ntuser.ini
2014-11-13 08:20 - 2014-11-13 08:20 - 00000000 _SHDL () C:\Users\DefaultAppPool\Startmenü
2014-11-13 08:20 - 2014-11-13 08:20 - 00000000 _SHDL () C:\Users\DefaultAppPool\Netzwerkumgebung
2014-11-13 08:20 - 2014-11-13 08:20 - 00000000 _SHDL () C:\Users\DefaultAppPool\Druckumgebung
2014-11-13 08:20 - 2014-11-13 08:20 - 00000000 _SHDL () C:\Users\DefaultAppPool\Documents\Eigene Musik
2014-11-13 08:20 - 2014-11-13 08:20 - 00000000 _SHDL () C:\Users\DefaultAppPool\Documents\Eigene Bilder
2014-11-13 08:20 - 2014-11-13 08:20 - 00000000 _SHDL () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-13 08:20 - 2014-11-13 08:20 - 00000000 _SHDL () C:\Users\DefaultAppPool\AppData\Local\Verlauf
2014-11-13 08:20 - 2014-11-13 08:20 - 00000000 ____D () C:\Users\DefaultAppPool
2014-11-13 08:20 - 2011-10-11 02:11 - 00000000 ____D () C:\Users\DefaultAppPool\Documents\Visual Studio 2005
2014-11-13 08:20 - 2011-09-09 11:39 - 00000000 ____D () C:\Users\DefaultAppPool\AppData\Local\Microsoft Help
2014-11-13 08:20 - 2009-07-14 05:42 - 00000000 ___RD () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-13 08:20 - 2009-07-14 05:37 - 00000000 ___RD () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-12 10:09 - 2014-11-12 10:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2014-11-12 10:06 - 2014-11-12 10:07 - 02705808 _____ () C:\Users\dirk\Downloads\mp3tagv265asetup.exe
2014-11-12 07:37 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-12 07:37 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-12 07:37 - 2014-10-03 02:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-12 07:37 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-12 07:37 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-12 07:37 - 2014-10-03 02:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-12 07:37 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-12 07:37 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-12 07:37 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-12 07:37 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-12 07:36 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-12 07:36 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-12 07:36 - 2014-11-06 04:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-12 07:36 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-12 07:36 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-12 07:36 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-12 07:36 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-12 07:36 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-12 07:36 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-12 07:36 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-12 07:36 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-12 07:36 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-12 07:36 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-12 07:36 - 2014-11-06 03:59 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-12 07:36 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-12 07:36 - 2014-11-06 03:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-12 07:36 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-12 07:36 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-12 07:36 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-12 07:36 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-12 07:36 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-12 07:36 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-12 07:36 - 2014-11-06 03:22 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-12 07:36 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-12 07:36 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-12 07:36 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-12 07:36 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-12 07:36 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-12 07:36 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-12 07:36 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-12 07:36 - 2014-11-05 18:50 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-12 07:36 - 2014-11-05 18:50 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-12 07:36 - 2014-11-05 18:47 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-12 07:36 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-12 07:36 - 2014-10-14 02:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-12 07:36 - 2014-10-14 02:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-12 07:36 - 2014-10-14 02:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-12 07:36 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-12 07:36 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-12 07:36 - 2014-10-10 01:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-12 07:36 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-12 07:36 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-12 07:36 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-12 07:36 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-12 07:36 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-12 07:36 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-25 13:34 - 2013-10-14 16:53 - 00000000 ____D () C:\Users\dirk\AppData\Local\CrashDumps
2014-11-25 13:34 - 2011-09-08 13:38 - 01431779 _____ () C:\Windows\WindowsUpdate.log
2014-11-25 13:28 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-25 07:23 - 2013-09-29 20:01 - 00000000 ____D () C:\Users\dirk\AppData\Roaming\UseNeXT
2014-11-21 08:20 - 2011-09-08 13:58 - 00000000 ____D () C:\TMP
2014-11-21 07:38 - 2013-09-29 20:01 - 00001807 _____ () C:\Users\dirk\Desktop\UseNeXT by Tangysoft.lnk
2014-11-21 07:38 - 2013-09-29 20:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UseNeXT
2014-11-21 07:38 - 2013-09-29 20:01 - 00000000 ____D () C:\Program Files\UseNeXT
2014-11-18 07:24 - 2014-03-24 15:15 - 00000000 ____D () C:\Users\dirk\Documents\Mein Steuer-Sparbuch Heute
2014-11-16 11:42 - 2013-10-22 16:14 - 00012862 _____ () C:\Windows\EPISMG00.SWB
2014-11-14 07:43 - 2013-10-17 06:31 - 00000000 ____D () C:\Users\dirk\AppData\Roaming\Mp3tag
2014-11-14 07:18 - 2013-09-29 21:12 - 00000000 ____D () C:\Users\dirk\AppData\Local\Adobe
2014-11-14 06:53 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-13 17:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-11-13 13:17 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-11-13 11:28 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-13 11:18 - 2011-09-08 13:52 - 01757540 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-13 08:55 - 2013-10-07 07:23 - 00000000 ____D () C:\Program Files\VideoLAN
2014-11-13 08:42 - 2011-09-08 14:34 - 00000000 ____D () C:\Windows\Panther
2014-11-13 07:23 - 2014-05-07 06:49 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-13 07:23 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-11-12 21:45 - 2011-09-08 14:10 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-12 21:42 - 2013-09-22 20:49 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-12 21:40 - 2011-09-27 07:56 - 100445232 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-12 10:09 - 2013-09-29 19:41 - 00000000 ____D () C:\Program Files\Mp3tag
2014-11-10 07:48 - 2014-09-17 06:21 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-11-10 07:48 - 2014-08-14 20:06 - 00000000 ____D () C:\ProgramData\Package Cache
2014-11-10 07:48 - 2013-09-29 18:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-11-10 07:48 - 2013-09-29 18:45 - 00000000 ____D () C:\Program Files\Avira
Some content of TEMP:
====================
C:\Users\Administrator.WS-BUERO\AppData\Local\Temp\avgnt.exe
C:\Users\Bine\AppData\Local\Temp\avgnt.exe
C:\Users\Dennis\AppData\Local\Temp\avgnt.exe
C:\Users\dirk\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-15 00:39
==================== End Of Log ============================ --- --- ---
--- --- ---
Und hier die Addition.txt:FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-11-2014
Ran by dirk at 2014-11-25 13:38:35
Running from C:\Users\dirk\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
32 Bit HP BiDi Channel Components Installer (Version: 1.1.0.2 - Hewlett-Packard) Hidden
7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.223 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.4.154 - Adobe Systems, Inc.)
Avira (HKLM\...\{9480d4af-12b9-4e56-8034-4031ef6ab39d}) (Version: 1.1.25.25607 - Avira Operations GmbH & Co. KG)
Avira (Version: 1.1.25.25607 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.342 - Avira)
Avira SearchFree Toolbar (HKLM\...\{41564952-412D-5637-00A7-A758B70C0A03}) (Version: 12.10.3.4489 - APN, LLC)
BUFFALO NAS Navigator2 (HKLM\...\UN060501) (Version: - )
calibre (HKLM\...\{4ED40090-5A38-415F-B222-26DD6D3C1AEF}) (Version: 2.2.0 - Kovid Goyal)
CCleaner (HKLM\...\CCleaner) (Version: 4.06 - Piriform)
ChannelEditor (HKLM\...\{2CB14BDA-5241-4F45-98C5-23520E366B89}) (Version: 1.0.0 - inverto.tv)
Common Desktop Agent (Version: 1.52.0 - OEM) Hidden
Die Siedler IV (HKLM\...\S4Uninst) (Version: - )
Dual-Core Optimizer (HKLM\...\{FF3D660E-E5CC-47FD-8050-1B4DE3BA81A9}) (Version: 1.1.3.0161 - AMD)
EPSON Scan (HKLM\...\EPSON Scanner) (Version: - )
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version: - )
EZ-RC (HKLM\...\EZ-RC) (Version: 1.0.0.222 - Universal Electronics)
FreePDF (Remove only) (HKLM\...\FreePDF_XP) (Version: - )
GolfStar (HKLM\...\GolfStar) (Version: 13.2.8 - Com2uS Corporation)
GPL Ghostscript (HKLM\...\GPL Ghostscript 9.04) (Version: 9.04 - Artifex Software Inc.)
GPL Ghostscript 8.62 (HKLM\...\GPL Ghostscript 8.62) (Version: - )
GPL Ghostscript Fonts (HKLM\...\GPL Ghostscript Fonts) (Version: - )
Java 7 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.450 - Oracle)
Langenscheidt Vokabeltrainer 6.0 Italienisch (HKLM\...\{EED46B38-D85F-4EE3-B5C3-F47F5AB630BE}) (Version: 6.0.1 - Langenscheidt)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Media Go (HKLM\...\{8D92969D-A6A3-44C8-9D63-D377E94F44B5}) (Version: 2.6.205 - Sony)
Media Go Video Playback Engine 2.0.117.09030 (HKLM\...\{49D9CE9D-C8B7-B941-90E1-608044A0FC8D}) (Version: 2.0.117.09030 - Sony)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISER) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft SQL Server 2008 Native Client (HKLM\...\{D9D937B0-E842-4130-9588-B948E876904A}) (Version: 10.0.1600.22 - Microsoft Corporation)
Microsoft SQL Server Native Client (HKLM\...\{F46E21DF-5BE1-48E2-8390-5EEA8B25E36A}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 33.1.1 (x86 de) (HKLM\...\Mozilla Firefox 33.1.1 (x86 de)) (Version: 33.1.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 33.1 - Mozilla)
Mp3tag v2.65a (HKLM\...\Mp3tag) (Version: v2.65a - Florian Heidenreich)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Notepad++ (HKLM\...\Notepad++) (Version: 6.5.1 - Notepad++ Team)
NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.11.9739 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.58.36 - NVIDIA Corporation)
NVIDIA ForceWare Network Access Manager (HKLM\...\InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}) (Version: 1.00.7316 - NVIDIA Corporation)
NVIDIA Grafiktreiber 307.83 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 307.83 - NVIDIA Corporation)
NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
NWZ-E580 WALKMAN Guide (HKLM\...\{1D6FB94F-E8B4-4CBF-B0FD-D566506CBEF6}) (Version: 2.2.0.05230 - Sony Corporation)
OmniPage SE 2.0 (HKLM\...\{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}) (Version: 2.00.0004 - ScanSoft, Inc.)
pcvisit EasySupport 10.0 (HKLM\...\pcvisit EasySupport 10.0) (Version: 10.0.13.7341 - pcvisit Software AG)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.2 - Frank Heindörfer, Philip Chinery)
pdfforge Toolbar v6.2 (HKLM\...\{2511D82C-2688-41C2-ABF8-AF237795989B}) (Version: 6.2 - Spigot, Inc.) <==== ATTENTION
PlayStation(R)Store (HKLM\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.18.0.15698 - Sony Computer Entertainment Inc.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - )
SAP Business One 8.8 - BTHF (Version: 88 - SAP) Hidden
SAP Business One 8.8 - Electronic File Manager Format Definition (Version: 88 - SAP) Hidden
SAP Business One 8.8 - Elster (Version: 88 - SAP) Hidden
SAP Business One 8.8 - Fixed Assets (Version: 88 - SAP) Hidden
SAP Business One 8.8 - Payment Engine (Version: 88 - SAP) Hidden
SRS Premium Sound for HP Thin Speakers (HKLM\...\{0EEDADC6-5614-4823-8CFD-B448F1601E83}) (Version: 1.12.2600 - SRS Labs, Inc.)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TELL ME MORE (HKLM\...\TMM70) (Version: - )
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISER_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISER_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISER_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISER_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
UseNeXT by Tangysoft (HKLM\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.)
WISO Steuer-Sparbuch 2012 (HKLM\...\{0CC1DAFB-40C8-4903-953D-471E541477C7}) (Version: 19.00.7303 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2013 (HKLM\...\{D6CC2FAF-F827-4091-96A1-D32CC9B69C79}) (Version: 20.00.8137 - Buhl Data Service GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
04-11-2014 09:11:06 Geplanter Prüfpunkt
12-11-2014 13:50:48 Geplanter Prüfpunkt
12-11-2014 20:39:15 Windows Update
21-11-2014 07:44:27 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {404D42BB-B616-4FA2-BC1E-A82B3B3F8136} - System32\Tasks\Windows Update Check - 0x1FE004EA => C:\ProgramData\Windows
Task: {654AECBF-CB16-4A99-AA13-69F9FB3E43E0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-09-19] (Piriform Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Loaded Modules (whitelisted) =============
2011-09-09 08:39 - 2001-10-28 16:42 - 00116224 _____ () C:\Windows\System32\pdfcmnnt.dll
2011-09-08 16:11 - 2008-02-25 21:23 - 00116224 _____ () C:\Windows\System32\redmonnt.dll
2012-01-02 13:46 - 2011-06-16 04:11 - 00024064 _____ () C:\Windows\System32\ssn2mlm.dll
2012-06-18 16:24 - 2012-06-18 16:24 - 00260096 _____ () C:\Program Files\Notepad++\NppShell_05.dll
2014-07-07 20:00 - 2014-03-13 21:32 - 01398064 _____ () C:\Program Files\WISO\Steuersoftware 2013\mshaktuell.exe
2014-07-07 19:59 - 2014-03-13 21:34 - 08952624 _____ () C:\Program Files\WISO\Steuersoftware 2013\wgui13.dll
2014-07-07 19:59 - 2014-03-13 21:32 - 00028672 _____ () C:\Program Files\WISO\Steuersoftware 2013\rsdcom48.dll
2014-07-07 19:59 - 2014-03-13 21:32 - 00309040 _____ () C:\Program Files\WISO\Steuersoftware 2013\rscorewinapi48.dll
2014-07-07 19:59 - 2014-03-13 21:32 - 00321328 _____ () C:\Program Files\WISO\Steuersoftware 2013\rsguiwinapi48.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 03506992 _____ () C:\Program Files\WISO\Steuersoftware 2013\wcore13.dll
2014-07-07 19:59 - 2014-03-13 21:32 - 00136496 _____ () C:\Program Files\WISO\Steuersoftware 2013\rsodbc48.dll
2014-07-07 19:59 - 2014-03-14 09:55 - 02194736 _____ () C:\Program Files\WISO\Steuersoftware 2013\wfvie13.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 01611056 _____ () C:\Program Files\WISO\Steuersoftware 2013\wsteu13.dll
2014-07-07 19:59 - 2014-03-13 21:32 - 01739568 _____ () C:\Program Files\WISO\Steuersoftware 2013\wreli13.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 04273456 _____ () C:\Program Files\WISO\Steuersoftware 2013\wauff13.dll
2013-01-17 13:30 - 2014-01-14 09:50 - 01043456 _____ () C:\Program Files\WISO\Steuersoftware 2013\clucene-core.dll
2013-01-17 13:30 - 2014-01-14 09:50 - 00094720 _____ () C:\Program Files\WISO\Steuersoftware 2013\clucene-shared.dll
2013-01-17 13:30 - 2014-01-14 09:50 - 00250368 _____ () C:\Program Files\WISO\Steuersoftware 2013\clucene-contribs-lib.dll
2014-07-07 19:59 - 2014-03-13 21:32 - 01505584 _____ () C:\Program Files\WISO\Steuersoftware 2013\wmain13.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 04972336 _____ () C:\Program Files\WISO\Steuersoftware 2013\wbae113.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 01373488 _____ () C:\Program Files\WISO\Steuersoftware 2013\wbae213.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 01748784 _____ () C:\Program Files\WISO\Steuersoftware 2013\wbae313.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 01582896 _____ () C:\Program Files\WISO\Steuersoftware 2013\wbae413.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 01147184 _____ () C:\Program Files\WISO\Steuersoftware 2013\whau113.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 01230640 _____ () C:\Program Files\WISO\Steuersoftware 2013\whau213.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 01307952 _____ () C:\Program Files\WISO\Steuersoftware 2013\wwerb13.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 06789936 _____ () C:\Program Files\WISO\Steuersoftware 2013\wkont13.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 01253888 _____ () C:\Program Files\WISO\Steuersoftware 2013\wimp13.dll
2014-07-07 19:59 - 2014-03-13 21:33 - 01317168 _____ () C:\Program Files\WISO\Steuersoftware 2013\wfabu13.dll
2014-11-25 07:49 - 2014-11-25 07:49 - 03649648 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2014-11-14 07:18 - 2014-11-14 07:18 - 16840880 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: ForceWare Intelligent Application Manager (IAM) => 2
MSCONFIG\Services: nSvcIp => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^EZ-RC System Tray.lnk => C:\Windows\pss\EZ-RC System Tray.lnk.CommonStartup
MSCONFIG\startupreg: ApnTBMon => "C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
MSCONFIG\startupreg: CDAServer => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
MSCONFIG\startupreg: OpwareSE2 => "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
========================= Accounts: ==========================
Administrator (S-1-5-21-2250351183-3509862589-1668780546-500 - Administrator - Enabled) => C:\Users\Administrator.WS-BUERO
Bine (S-1-5-21-2250351183-3509862589-1668780546-1008 - Limited - Enabled) => C:\Users\Bine
Dennis (S-1-5-21-2250351183-3509862589-1668780546-1007 - Limited - Enabled) => C:\Users\Dennis
dirk (S-1-5-21-2250351183-3509862589-1668780546-1006 - Administrator - Enabled) => C:\Users\dirk
Gast (S-1-5-21-2250351183-3509862589-1668780546-501 - Limited - Disabled)
UpdatusUser (S-1-5-21-2250351183-3509862589-1668780546-1005 - Limited - Enabled) => C:\Users\UpdatusUser
WS-EMPFANG (S-1-5-21-2250351183-3509862589-1668780546-1000 - Administrator - Disabled) => C:\Users\WS-EMPFANG
==================== Faulty Device Manager Devices =============
Name: Standardtastatur (PS/2)
Description: Standardtastatur (PS/2)
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardtastaturen)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/25/2014 01:34:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_15_0_0_223.exe, Version: 15.0.0.223, Zeitstempel: 0x544ece05
Name des fehlerhaften Moduls: FlashPlayerPlugin_15_0_0_223.exe, Version: 15.0.0.223, Zeitstempel: 0x544ece05
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002de86
ID des fehlerhaften Prozesses: 0x1354
Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_15_0_0_223.exe0
Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_15_0_0_223.exe1
Pfad des fehlerhaften Moduls: FlashPlayerPlugin_15_0_0_223.exe2
Berichtskennung: FlashPlayerPlugin_15_0_0_223.exe3
Error: (11/25/2014 07:53:04 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
Error: (11/21/2014 08:40:19 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 33.1.0.5423 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 146c
Startzeit: 01d0055d1d6593b0
Endzeit: 27
Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe
Berichts-ID: 9f937401-7151-11e4-a3c8-002264bf1a2b
Error: (11/21/2014 08:05:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rundll32.exe_inetcpl.cpl, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc637
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002d6f3
ID des fehlerhaften Prozesses: 0x1684
Startzeit der fehlerhaften Anwendung: 0xrundll32.exe_inetcpl.cpl0
Pfad der fehlerhaften Anwendung: rundll32.exe_inetcpl.cpl1
Pfad des fehlerhaften Moduls: rundll32.exe_inetcpl.cpl2
Berichtskennung: rundll32.exe_inetcpl.cpl3
Error: (11/21/2014 08:00:12 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 33.1.0.5423 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 22c
Startzeit: 01d00557923ecfe0
Endzeit: 65
Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe
Berichts-ID: 06b9a381-714c-11e4-a335-002264bf1a2b
Error: (11/21/2014 07:26:26 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 33.1.0.5423 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 118c
Startzeit: 01d00552c9afd000
Endzeit: 16
Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe
Berichts-ID: 4fa5e3b1-7147-11e4-a335-002264bf1a2b
Error: (11/21/2014 07:15:02 AM) (Source: Software Protection Platform Service) (EventID: 1012) (User: )
Description: Fehler beim Erwerb des Produktzertifikats. hr=0xC004C003
SKU-ID=770bc271-8dc1-467d-b574-73cbacbeccd1
Error: (11/21/2014 07:15:02 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Lizenzerwerb-Fehlerdetails.
hr=0xC004C003
Error: (11/16/2014 00:42:42 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
Error: (11/14/2014 11:15:25 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_15_0_0_223.exe, Version: 15.0.0.223, Zeitstempel: 0x544ece05
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x061ce000
ID des fehlerhaften Prozesses: 0x1374
Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_15_0_0_223.exe0
Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_15_0_0_223.exe1
Pfad des fehlerhaften Moduls: FlashPlayerPlugin_15_0_0_223.exe2
Berichtskennung: FlashPlayerPlugin_15_0_0_223.exe3
System errors:
=============
Error: (11/13/2014 01:21:41 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error: (11/13/2014 00:51:34 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error: (11/13/2014 11:32:33 AM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error: (11/13/2014 11:30:02 AM) (Source: Schannel) (EventID: 4119) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung empfangen: 20.
Error: (11/13/2014 08:28:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Net.Tcp-Portfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/13/2014 08:28:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Net.Tcp-Listeneradapter" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/13/2014 08:28:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Net.Pipe-Listeneradapter" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/13/2014 08:28:03 AM) (Source: WAS) (EventID: 5175) (User: )
Description: Der Listeneradapter für Protokoll "net.tcp" hat unerwartet die Verbindung getrennt.
Error: (11/13/2014 08:28:03 AM) (Source: WAS) (EventID: 5175) (User: )
Description: Der Listeneradapter für Protokoll "net.pipe" hat unerwartet die Verbindung getrennt.
Error: (11/04/2014 07:15:23 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Programmkompatibilitäts-Assistent-Dienst" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler:
%%1056
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: AMD Athlon(tm) Dual Core Processor 5400B
Percentage of memory in use: 44%
Total physical RAM: 3454.49 MB
Available physical RAM: 1932.05 MB
Total Pagefile: 10361.77 MB
Available Pagefile: 8102.88 MB
Total Virtual: 2047.88 MB
Available Virtual: 1819.98 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:148.95 GB) (Free:108.76 GB) NTFS
Drive d: (SYSDATA) (Fixed) (Total:362.89 GB) (Free:347 GB) NTFS
Drive e: (DATA) (Fixed) (Total:1500 GB) (Free:1161.5 GB) NTFS
Drive m: () (Network) (Total:917.07 GB) (Free:26.91 GB)
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 2DAF2DAF)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
==================== End Of Log ============================ --- --- --- |