Alpinist | 29.01.2015 18:43 | Hallo,
vielen Dank!
Hier FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-01-2015 01
Ran by Vista32 (administrator) on VISTA32-PC on 29-01-2015 18:40:42
Running from C:\Users\Vista32\Desktop
Loaded Profiles: Vista32 (Available profiles: Vista32)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcsrvx.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
(Binary Fortress Software) C:\Program Files\DisplayFusion\DisplayFusionService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgemcx.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Binary Fortress Software) C:\Program Files\DisplayFusion\DisplayFusion.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
(Binary Fortress Software) C:\Program Files\DisplayFusion\DisplayFusionHookAppWIN6032.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Nullsoft, Inc.) C:\Program Files\Winamp\winamp.exe
(ICQ) C:\Users\Vista32\AppData\Roaming\ICQM\icq.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcfgex.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [122880 2009-03-05] (Alps Electric Co., Ltd.)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3674576 2015-01-06] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-107438096-1250777658-1232194404-1000\...\Run: [icq] => C:\Users\Vista32\AppData\Roaming\ICQM\icq.exe [35239432 2014-10-11] (ICQ)
HKU\S-1-5-21-107438096-1250777658-1232194404-1000\...\Run: [EPSON Stylus SX400 Series] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEGE.EXE [188928 2007-12-17] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-107438096-1250777658-1232194404-1000\...\Run: [DisplayFusion] => C:\Program Files\DisplayFusion\DisplayFusion.exe [8854880 2014-09-09] (Binary Fortress Software)
HKU\S-1-5-21-107438096-1250777658-1232194404-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-107438096-1250777658-1232194404-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-107438096-1250777658-1232194404-1000\...\Run: [Google Update] => C:\Users\Vista32\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2015-01-29] (Google Inc.)
Startup: C:\Users\Vista32\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-107438096-1250777658-1232194404-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.facebook.com/?ref=logo
HKU\S-1-5-21-107438096-1250777658-1232194404-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Vista32\AppData\Roaming\Mozilla\Firefox\Profiles\862hrnw9.default
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKU\S-1-5-21-107438096-1250777658-1232194404-1000: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-107438096-1250777658-1232194404-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Vista32\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-107438096-1250777658-1232194404-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Vista32\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF user.js: detected! => C:\Users\Vista32\AppData\Roaming\Mozilla\Firefox\Profiles\862hrnw9.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\wtu-secure-search.xml
FF Extension: DownloadHelper - C:\Users\Vista32\AppData\Roaming\Mozilla\Firefox\Profiles\862hrnw9.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-10-08]
FF Extension: ProxTube - C:\Users\Vista32\AppData\Roaming\Mozilla\Firefox\Profiles\862hrnw9.default\Extensions\ich@maltegoetz.de.xpi [2014-10-08]
FF Extension: Adblock Plus - C:\Users\Vista32\AppData\Roaming\Mozilla\Firefox\Profiles\862hrnw9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-09-22]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-02-10]
Chrome:
=======
CHR StartupUrls: Default -> "https://www.google.de/&noj=1"
CHR Profile: C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-15]
CHR Extension: (Google Docs) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-15]
CHR Extension: (Google Drive) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-15]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-15]
CHR Extension: (YouTube) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-15]
CHR Extension: (Adblock Plus) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-10-15]
CHR Extension: (Google-Suche) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-22]
CHR Extension: (Google Tabellen) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-22]
CHR Extension: (AdBlock) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-10-15]
CHR Extension: (Google Mail-Checker) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-10-15]
CHR Extension: (Google Wallet) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-22]
CHR Extension: (Google Mail) - C:\Users\Vista32\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-22]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3440080 2015-01-06] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [309232 2015-01-06] (AVG Technologies CZ, s.r.o.)
R2 DisplayFusionService; C:\Program Files\DisplayFusion\DisplayFusionService.exe [5278064 2014-09-09] (Binary Fortress Software)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208152 2014-12-08] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [154904 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [192792 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [230680 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [200984 2014-10-10] (AVG Technologies CZ, s.r.o.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-01-29] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-29 18:40 - 2015-01-29 18:41 - 00015014 _____ () C:\Users\Vista32\Desktop\FRST.txt
2015-01-29 18:40 - 2015-01-29 18:40 - 00000000 ____D () C:\FRST
2015-01-29 18:39 - 2015-01-29 18:39 - 01121792 _____ (Farbar) C:\Users\Vista32\Desktop\FRST.exe
2015-01-29 17:48 - 2015-01-29 17:53 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-107438096-1250777658-1232194404-1000UA.job
2015-01-29 17:48 - 2015-01-29 17:53 - 00001076 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-107438096-1250777658-1232194404-1000Core.job
2015-01-29 17:26 - 2015-01-29 17:29 - 06000640 _____ () C:\Program Files\GUTFC97.tmp
2015-01-29 17:26 - 2015-01-29 17:29 - 00000000 ____D () C:\Program Files\GUMFC96.tmp
2015-01-29 17:26 - 2015-01-29 17:26 - 00880784 _____ (Google Inc.) C:\Users\Vista32\Desktop\ChromeSetup.exe
2015-01-29 16:21 - 2015-01-29 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-01-29 16:02 - 2015-01-29 17:55 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-29 16:00 - 2015-01-29 16:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-29 15:59 - 2015-01-29 15:59 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-29 15:59 - 2015-01-29 15:59 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-01-29 15:59 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-29 15:59 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-29 15:59 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-28 12:03 - 2015-01-28 12:04 - 00000000 ____D () C:\Program Files\Free Codec Pack
2015-01-28 12:03 - 2015-01-28 12:03 - 00000000 ____D () C:\Users\Vista32\AppData\Roaming\RHEng
2015-01-25 03:06 - 2015-01-25 03:06 - 00000000 ____D () C:\Users\Vista32\Desktop\irgendwelche memos
2015-01-22 22:34 - 2015-01-22 22:36 - 28566404 _____ () C:\Users\Vista32\Desktop\videodb_2862_75544_5444321_16x9_hp.flv
2015-01-20 16:51 - 2015-01-28 01:01 - 00000000 ___RD () C:\Users\Vista32\Desktop\Neu
2015-01-16 03:00 - 2014-12-06 04:14 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-15 14:18 - 2014-12-19 01:25 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-15 13:55 - 2014-12-06 04:14 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-15 13:55 - 2014-12-06 04:14 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-15 13:55 - 2014-12-06 04:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-10 01:11 - 2015-01-10 01:11 - 00000000 ____D () C:\Users\Vista32\AppData\Roaming\Tracker Software
2015-01-08 00:55 - 2015-01-08 00:55 - 68942938 _____ () C:\Users\Vista32\Desktop\2CELLOS_-_Wake_Me_Up_-_Avicii_OFFICIAL_VIDEO.mp4
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-29 18:09 - 2014-11-03 20:20 - 00000000 ____D () C:\Users\Vista32\AppData\Local\CrashDumps
2015-01-29 17:59 - 2008-01-21 02:35 - 02012907 _____ () C:\Windows\WindowsUpdate.log
2015-01-29 17:55 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-29 17:55 - 2006-11-02 13:47 - 00005328 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-29 17:55 - 2006-11-02 13:47 - 00005328 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-29 17:54 - 2014-09-22 18:06 - 00000012 _____ () C:\Windows\bthservsdp.dat
2015-01-29 17:54 - 2006-11-02 14:01 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-29 17:48 - 2014-09-22 21:42 - 00000000 ____D () C:\Users\Vista32\AppData\Local\Google
2015-01-29 17:21 - 2014-10-14 20:19 - 00006768 _____ () C:\Windows\PFRO.log
2015-01-29 17:03 - 2014-10-06 01:49 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-29 16:20 - 2014-10-14 20:14 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-28 18:40 - 2014-09-22 17:48 - 00000000 ___RD () C:\Users\Vista32\Desktop\Ablage
2015-01-28 12:06 - 2014-09-22 23:56 - 00000000 ____D () C:\Users\Vista32\AppData\Roaming\DVDVideoSoft
2015-01-28 12:05 - 2014-09-22 23:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2015-01-28 12:05 - 2014-09-22 23:57 - 00000000 ____D () C:\Program Files\DVDVideoSoft
2015-01-28 12:04 - 2014-09-22 23:57 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2015-01-28 11:27 - 2008-01-21 08:16 - 01565124 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-27 15:05 - 2014-09-22 10:26 - 00000000 ____D () C:\Users\Vista32\AppData\Roaming\vlc
2015-01-27 11:35 - 2014-02-10 17:47 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-26 17:54 - 2014-10-06 14:52 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-01-25 03:21 - 2014-10-26 15:11 - 00000000 ____D () C:\Users\Vista32\AppData\Local\DisplayFusion
2015-01-25 03:16 - 2014-11-28 03:41 - 00000000 ___RD () C:\Users\Vista32\Desktop\mugg
2015-01-25 03:10 - 2014-09-22 17:48 - 00000000 ____D () C:\Users\Vista32\Desktop\Bahnbilder
2015-01-24 16:17 - 2014-10-06 01:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-01-22 23:32 - 2014-10-01 12:34 - 00021504 _____ () C:\Users\Vista32\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-20 16:53 - 2014-11-05 13:13 - 00001424 _____ () C:\Users\Vista32\Desktop\Studienarbeit - Verknüpfung.lnk
2015-01-15 16:17 - 2014-09-30 01:46 - 00000000 ____D () C:\Users\Vista32\AppData\Local\Microsoft Help
2015-01-15 14:18 - 2014-02-10 15:01 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-15 13:56 - 2006-11-02 11:24 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-01-12 01:44 - 2014-02-10 11:35 - 00000000 ____D () C:\Users\Vista32\AppData\Local\VirtualStore
2014-12-31 12:13 - 2014-02-10 14:46 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-12-31 03:51 - 2014-10-08 03:38 - 00000000 ____D () C:\Users\Vista32\dwhelper
==================== Files in the root of some directories =======
2015-01-29 17:26 - 2015-01-29 17:29 - 6000640 _____ () C:\Program Files\GUTFC97.tmp
2014-02-10 11:35 - 2014-09-20 09:35 - 0001356 _____ () C:\Users\Vista32\AppData\Local\d3d9caps.dat
2014-10-01 12:34 - 2015-01-22 23:32 - 0021504 _____ () C:\Users\Vista32\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some content of TEMP:
====================
C:\Users\Vista32\AppData\Local\Temp\FreeYouTubeToMP3Converter.exe
C:\Users\Vista32\AppData\Local\Temp\tmd_34013127.exe
C:\Users\Vista32\AppData\Local\Temp\tmd_34016753.exe
C:\Users\Vista32\AppData\Local\Temp\tmd_34019347.exe
C:\Users\Vista32\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\Vista32\AppData\Local\Temp\_is1B3E.exe
C:\Users\Vista32\AppData\Local\Temp\_is76C5.exe
C:\Users\Vista32\AppData\Local\Temp\_is9E81.exe
C:\Users\Vista32\AppData\Local\Temp\_isFBEB.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-29 18:04
==================== End Of Log ============================ --- --- ---
--- --- --- Und hier Addition:
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 28-01-2015 01
Ran by Vista32 at 2015-01-29 18:41:38
Running from C:\Users\Vista32\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
ABBYY FineReader 6.0 Sprint (HKLM\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House)
Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Alps Pointing-device for VAIO (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: - )
ATI Catalyst Install Manager (HKLM\...\{1F07C5EC-A79E-9A66-7BE8-352E18A21CC9}) (Version: 3.0.732.0 - ATI Technologies, Inc.)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5646 - AVG Technologies)
AVG 2015 (Version: 15.0.4273 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.5646 - AVG Technologies) Hidden
Camera RAW Plug-In for EPSON Creativity Suite (HKLM\...\{42EDF895-158C-484E-A7F2-42B90759F281}) (Version: 2.3.0.0 - SEIKO EPSON CORPORATION)
ccc-core-static (Version: 2009.0804.2223.38385 - Ihr Firmenname) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform)
DisplayFusion 6.1.2 (HKLM\...\B076073A-5527-4f4f-B46B-B10692277DA2_is1) (Version: 6.1.2.0 - Binary Fortress Software)
EPSON Attach To Email (HKLM\...\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON)
EPSON Attach To Email (Version: 1.01.0000 - SEIKO EPSON) Hidden
EPSON Easy Photo Print (HKLM\...\{8A8F8391-4C2C-4BE1-A984-CD4A5A546467}) (Version: 1.5.1.0 - SEIKO EPSON CORPORATION)
EPSON File Manager (HKLM\...\{46CBBDF8-55B5-40DB-B459-7B848394309C}) (Version: 1.3.1.0 - )
EPSON Scan (HKLM\...\EPSON Scanner) (Version: - )
EPSON Scan Assistant (HKLM\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - )
EPSON Stylus SX200_SX400_TX200_TX400 Handbuch (HKLM\...\EPSON Stylus SX200_SX400_TX200_TX400 Benutzerhandbuch) (Version: - )
EPSON Stylus SX400 Series Printer Uninstall (HKLM\...\EPSON Stylus SX400 Series) (Version: - SEIKO EPSON Corporation)
Free YouTube to MP3 Converter version 3.12.53.113 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.53.113 - DVDVideoSoft Ltd.)
Google Chrome (HKLM\...\Google Chrome) (Version: 40.0.2214.93 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
ICQ 8.2 (build 7138) (HKU\S-1-5-21-107438096-1250777658-1232194404-1000\...\ICQ) (Version: 8.2.7138.0 - ICQ)
InfraRecorder (HKLM\...\InfraRecorder) (Version: - Christian Kindahl)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
LibreOffice 4.2.5.2 (HKLM\...\{93AD8CBD-C32E-4318-90BB-A294BE2D712C}) (Version: 4.2.5.2 - The Document Foundation)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
MM Eisenbahn-Bildschirmschoner V3 (HKLM\...\MM Eisenbahn-Bildschirmschoner V3) (Version: - )
Mozilla Firefox 35.0.1 (x86 de) (HKLM\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 32.0.2 - Mozilla)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.211.0 - Tracker Software Products Ltd)
Railroad Tycoon II - Platinum (HKLM\...\{C7E9FB5B-626B-49D9-A99C-7BFA63C222D3}) (Version: - )
Skins (Version: 2009.0804.2223.38385 - ATI) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
VAIO Power Management (HKLM\...\{802889F8-6AF5-45A5-9764-CA5B999E50FC}) (Version: 2.5.0.06250 - Sony Corporation)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Winamp (HKLM\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
WinRAR 4.11 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-107438096-1250777658-1232194404-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Vista32\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-107438096-1250777658-1232194404-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Vista32\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-107438096-1250777658-1232194404-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Vista32\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-107438096-1250777658-1232194404-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Vista32\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-107438096-1250777658-1232194404-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Vista32\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-107438096-1250777658-1232194404-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Vista32\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-107438096-1250777658-1232194404-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Vista32\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-107438096-1250777658-1232194404-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Vista32\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-107438096-1250777658-1232194404-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Vista32\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.)
==================== Restore Points =========================
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {1FEAD6CD-325F-457B-BAB5-FE1D8798982F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-107438096-1250777658-1232194404-1000UA => C:\Users\Vista32\AppData\Local\Google\Update\GoogleUpdate.exe [2015-01-29] (Google Inc.)
Task: {4481F645-63AD-4429-A53C-9D7FB167720F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-107438096-1250777658-1232194404-1000Core => C:\Users\Vista32\AppData\Local\Google\Update\GoogleUpdate.exe [2015-01-29] (Google Inc.)
Task: {69BC0011-E2DA-4ACF-B1DC-860FCF206B01} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-09-22] (Google Inc.)
Task: {7E22C6AF-9828-40FE-A8CB-D217A31D1A88} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-09-22] (Google Inc.)
Task: {9ACB125D-13D4-422E-B295-3C9ECEA26F4D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd)
Task: {9C740240-FAB5-4234-81A8-D3933027744B} - System32\Tasks\AVG_SYS_TASK_1114av => C:\ProgramData\Avg_Update_1114av\AVG-Secure-Search-Update_1114av.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-107438096-1250777658-1232194404-1000Core.job => C:\Users\Vista32\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-107438096-1250777658-1232194404-1000UA.job => C:\Users\Vista32\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-09-20 09:27 - 2012-02-17 19:55 - 00166912 _____ () C:\Program Files\WinRAR\rarext.dll
2014-10-11 15:29 - 2014-10-11 15:29 - 00334856 _____ () C:\Users\Vista32\AppData\Roaming\ICQM\ICQ\dll\mramenu.dll
2014-10-06 14:52 - 2015-01-26 17:54 - 03925104 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2008-08-26 10:41 - 2008-08-26 10:41 - 00016384 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
2014-09-20 09:41 - 2014-09-20 09:41 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2015-01-29 18:20 - 2015-01-29 18:20 - 00014336 _____ () C:\Users\Vista32\AppData\Local\Temp\WDEC255.tmp\ml_online.lng
2015-01-29 18:20 - 2015-01-29 18:20 - 00036352 _____ () C:\Users\Vista32\AppData\Local\Temp\WDEC255.tmp\ombrowser.lng
2013-12-13 03:47 - 2013-12-13 03:47 - 00333824 _____ () C:\Program Files\Winamp\Plugins\freeform\wacs\freetype\freetype.wac
2014-10-11 15:29 - 2014-10-11 15:29 - 00859144 _____ () C:\Users\Vista32\AppData\Roaming\ICQM\ICQ\dll\YLUSBTEL.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: MozillaMaintenance => 3
========================= Accounts: ==========================
Administrator (S-1-5-21-107438096-1250777658-1232194404-500 - Administrator - Disabled)
Gast (S-1-5-21-107438096-1250777658-1232194404-501 - Limited - Disabled)
Vista32 (S-1-5-21-107438096-1250777658-1232194404-1000 - Administrator - Enabled) => C:\Users\Vista32
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Tun-Miniportadapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Basissystemgerät
Description: Basissystemgerät
Class Guid:
Manufacturer:
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (01/29/2015 06:09:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung chrome.exe, Version 40.0.2214.93, Zeitstempel 0x54c46198, fehlerhaftes Modul chrome.dll, Version 40.0.2214.93, Zeitstempel 0x54c45d6b, Ausnahmecode 0xc0000005, Fehleroffset 0x0000f16d,
Prozess-ID 0xe2c, Anwendungsstartzeit chrome.exe0.
Error: (01/29/2015 05:56:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung chrome.exe, Version 40.0.2214.93, Zeitstempel 0x54c46198, fehlerhaftes Modul chrome.dll, Version 40.0.2214.93, Zeitstempel 0x54c45d6b, Ausnahmecode 0xc0000005, Fehleroffset 0x0000f16d,
Prozess-ID 0xf40, Anwendungsstartzeit chrome.exe0.
Error: (01/29/2015 05:56:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/29/2015 05:44:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung chrome.exe, Version 40.0.2214.93, Zeitstempel 0x54c46198, fehlerhaftes Modul chrome.dll, Version 40.0.2214.93, Zeitstempel 0x54c45d6b, Ausnahmecode 0xc0000005, Fehleroffset 0x0000f16d,
Prozess-ID 0x1350, Anwendungsstartzeit chrome.exe0.
Error: (01/29/2015 05:41:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung chrome.exe, Version 40.0.2214.93, Zeitstempel 0x54c46198, fehlerhaftes Modul chrome.dll, Version 40.0.2214.93, Zeitstempel 0x54c45d6b, Ausnahmecode 0xc0000005, Fehleroffset 0x0000f16d,
Prozess-ID 0x604, Anwendungsstartzeit chrome.exe0.
Error: (01/29/2015 05:39:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung chrome.exe, Version 40.0.2214.93, Zeitstempel 0x54c46198, fehlerhaftes Modul chrome.dll, Version 40.0.2214.93, Zeitstempel 0x54c45d6b, Ausnahmecode 0xc0000005, Fehleroffset 0x0000f16d,
Prozess-ID 0x3cc, Anwendungsstartzeit chrome.exe0.
Error: (01/29/2015 05:39:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung chrome.exe, Version 40.0.2214.93, Zeitstempel 0x54c46198, fehlerhaftes Modul chrome.dll, Version 40.0.2214.93, Zeitstempel 0x54c45d6b, Ausnahmecode 0xc0000005, Fehleroffset 0x0000f16d,
Prozess-ID 0x107c, Anwendungsstartzeit chrome.exe0.
Error: (01/29/2015 05:33:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung chrome.exe, Version 40.0.2214.93, Zeitstempel 0x54c46198, fehlerhaftes Modul chrome.dll, Version 40.0.2214.93, Zeitstempel 0x54c45d6b, Ausnahmecode 0xc0000005, Fehleroffset 0x0000f16d,
Prozess-ID 0xc10, Anwendungsstartzeit chrome.exe0.
Error: (01/29/2015 05:32:54 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/29/2015 05:28:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung chrome.exe, Version 40.0.2214.93, Zeitstempel 0x54c46198, fehlerhaftes Modul chrome.dll, Version 40.0.2214.93, Zeitstempel 0x54c45d6b, Ausnahmecode 0xc0000005, Fehleroffset 0x0000f16d,
Prozess-ID 0x10f8, Anwendungsstartzeit chrome.exe0.
System errors:
=============
Error: (01/29/2015 05:55:17 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (01/29/2015 05:55:16 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (01/29/2015 05:31:23 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (01/29/2015 05:31:22 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (01/29/2015 05:21:42 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (01/29/2015 05:21:40 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (01/29/2015 05:09:17 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Service Mgr PositiveFinds
Error: (01/29/2015 05:07:10 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (01/29/2015 05:07:09 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (01/29/2015 02:21:42 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Service Mgr PositiveFinds
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2015-01-29 18:41:31.675
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-29 18:41:31.531
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-29 18:41:31.386
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-29 18:41:31.241
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-29 18:41:30.942
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-29 18:41:30.788
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-29 18:41:30.633
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-29 18:41:30.481
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-29 18:41:05.118
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-29 18:41:04.975
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
Percentage of memory in use: 60%
Total physical RAM: 3038.11 MB
Available physical RAM: 1189.33 MB
Total Pagefile: 6282.49 MB
Available Pagefile: 4064.94 MB
Total Virtual: 2047.88 MB
Available Virtual: 1888.06 MB
==================== Drives ================================
Drive c: (Volume) (Fixed) (Total:465.76 GB) (Free:215.84 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C41723F9)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)
==================== End Of Log ============================ --- --- ---
Grüsse Philipp |