|
Plagegeister aller Art und deren Bekämpfung: BCD-Fehler und fehlendes wow64cpu.dllWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
25.12.2013, 13:51 | #1 |
| BCD-Fehler und fehlendes wow64cpu.dll Servus, Ich habe folgendes Problem: Ich besitze einen Dell Inspiron 15 Laptop mit Windows 8. Gestern habe ich bei Facebook gesurft und plötzlich ging der PC aus. Als ich ihn wieder einschalten wollte, kam ein blauer Bildschirm mit Recovery - your PC Needs to be repaired File BCD Errorcode 0x0000034. Weiter ging's nicht mehr. Hab dann mal über das Setup, in welches ich mit der Escapetaste reingekommen bin das prüfen lassen und da kam dann am Ende, dass Hard-Drive 0 Short test unsucessfully war. Ich habe dann den Recoverystick eines anderen Dellpcs mit Win8 genommen und wollte das wieder herstellen(für diesen hatte ich keine Recovery). Lief auch ganz gut, aber bei ca. 21% hat das Programm aufgehört und plötzlich das Windows gestartet. Desktop alles da, nur kann ich kein Programm starten, weil wow64cpu.dll fehlt und ich das installieren solle. Kann ich aber nicht. Und dann hab ich ein bisschen gesurft und gelesen, dass das Problem mit einem Virus zusammenhängen kann... Könnt ihr mir da irgendwie helfen? |
25.12.2013, 14:14 | #2 |
/// the machine /// TB-Ausbilder | BCD-Fehler und fehlendes wow64cpu.dll hi,
__________________kanste in die Recovery und von dort sfc /scannow starten?
__________________ |
25.12.2013, 14:36 | #3 |
| BCD-Fehler und fehlendes wow64cpu.dll Meinst du wenn ich jetzt das Windows hochgefahren habe?
__________________In die Recovery aufm Stick? Im Prinzip kann ich gar nichts öffnen, auch bei der Systemwiederherstellung tut sich gar nix. Browser kann ich auch keine öffnen... |
26.12.2013, 14:21 | #4 |
/// the machine /// TB-Ausbilder | BCD-Fehler und fehlendes wow64cpu.dll hi, Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8) Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.12.2013, 18:07 | #5 |
| BCD-Fehler und fehlendes wow64cpu.dll Also, ich bin in das Menü reingekommen, in dem ich reparieren anwählen kann. (Was mir spanisch vorkam ist, dass da was von Windows 7 oben steht (siehe Foto im Anhang). Als ich auf Reparieren gegangen bin kam das auf Bild 2. Ich habe dann das Windows im abgesicherten Modus gestartet und über die Eingabeaufforderung als Admin den FRST-Scan gemacht. Der ließ sich starten, auch wenn der PC wieder wegen dem wow64cpu.dll gemotzt hat. Dabei kam folgendes raus: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-12-2013 Ran by Carolina (administrator) on CAROLINA on 26-12-2013 17:53:08 Running from E:\ Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Safe Mode (with Networking) ==================== Processes (Whitelisted) ================= (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [DellWPF] - [x] HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6842000 2012-09-25] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1230992 2012-09-28] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2918200 2012-09-21] (Synaptics Incorporated) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\quickset.exe [5757328 2012-10-19] (Dell Inc.) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4123 2012-05-30] () HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM\...\Run: [ActivControl] - C:\Program Files\Activ Software\ActivDriver\ActivControl2x64.exe [1238312 2010-06-10] (Promethean Technologies Group Ltd) HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE [2779024 2011-03-14] (CANON INC.) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642728 2012-10-25] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [CLMLServer_For_P2G8] - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-04] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [143888 2012-06-01] (CyberLink Corp.) HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\mcafee.com\agent\mcagent.exe [537512 2013-09-24] (McAfee, Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1612920 2011-08-04] (CANON INC.) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [mcpltui_exe] - C:\Program Files\mcafee.com\agent\mcagent.exe [537512 2013-09-24] (McAfee, Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoControlPanel] 0 MountPoints2: {0ed07f4e-68e2-11e2-be65-806e6f6e6963} - "D:\SETUP.EXE" AppInit_DLLs-x32: [ ] () Startup: C:\Users\Carolina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Carolina\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {E9019C22-93E4-4C0D-B77C-3DEFD9E83856} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDCJS SearchScopes: HKLM-x32 - {E9019C22-93E4-4C0D-B77C-3DEFD9E83856} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDCJS SearchScopes: HKCU - DefaultScope {E9019C22-93E4-4C0D-B77C-3DEFD9E83856} URL = SearchScopes: HKCU - {E9019C22-93E4-4C0D-B77C-3DEFD9E83856} URL = BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll () BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll () BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll () Toolbar: HKCU - WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll () Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll () Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.) FireFox: ======== FF ProfilePath: C:\Users\Carolina\AppData\Roaming\Mozilla\Firefox\Profiles\rfnhoztn.default FF Homepage: hxxp://www.google.com FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\Carolina\AppData\Roaming\Mozilla\Firefox\Profiles\rfnhoztn.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: Adblock Plus - C:\Users\Carolina\AppData\Roaming\Mozilla\Firefox\Profiles\rfnhoztn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK ==================== Services (Whitelisted) ================= S2 0041591386328475mcinstcleanup; C:\windows\TEMP\004159~1.EXE [834664 2013-07-30] (McAfee, Inc.) S2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [138192 2011-02-07] () S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) S2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178048 2013-11-28] (McAfee, Inc.) S3 McAWFwk; C:\Program Files\mcafee\msc\McAWFwk.exe [332080 2012-01-26] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S2 McNaiAnn; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.) S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S2 McProxy; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1025232 2013-11-26] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-11-04] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-11-04] (McAfee, Inc.) S2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-25] () S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201360 2012-09-01] (Realtek Semiconductor) S2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [1914728 2012-11-26] (SoftThinks SAS) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R3 ActivHidSerMini; C:\Windows\System32\drivers\activhidsermini.sys [86104 2010-05-26] (Promethean Technologies Ltd) R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [35496 2012-07-09] (Advanced Micro Devices, Inc.) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [121728 2012-08-27] (Motorola Solutions, Inc.) S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [857472 2012-08-29] (Motorola Solutions, Inc.) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-11-04] (McAfee, Inc.) S1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) S3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2012-08-05] (OSR Open Systems Resources, Inc.) S3 ElmoSESAME; C:\Windows\System32\drivers\ElmoSESAME.sys [28264 2012-01-20] (ELMO COMPANY, LIMITED) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) S2 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179792 2013-11-04] (McAfee, Inc.) S2 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311120 2013-11-04] (McAfee, Inc.) S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69344 2013-11-04] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519576 2013-11-04] (McAfee, Inc.) R2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [782360 2013-11-04] (McAfee, Inc.) S3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [411944 2013-11-26] (McAfee, Inc.) S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96112 2013-11-26] (McAfee, Inc.) R2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343696 2013-11-04] (McAfee, Inc.) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-10-08] (Intel Corporation) R3 prmvmouse; C:\Windows\System32\drivers\activmouse.sys [8152 2010-05-26] (Promethean Technologies Ltd) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-09-21] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-09-21] (Synaptics Incorporated) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-26 17:32 - 2013-12-26 17:32 - 00000000 ____D C:\FRST 2013-12-25 16:34 - 2013-12-25 16:34 - 00371240 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-25 13:33 - 2013-12-25 13:33 - 00000023 _____ C:\Users\Carolina\AppData\Roaming\mbam.context.scan 2013-12-23 15:49 - 2013-12-23 15:49 - 01909242 _____ C:\Users\Carolina\Desktop\Konflikt_Seminar.zip 2013-12-23 15:48 - 2012-05-10 14:57 - 00000000 ____D C:\Users\Carolina\Desktop\Konflikt_Seminar 2013-12-20 17:47 - 2013-12-20 17:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-18 23:30 - 2013-12-18 23:30 - 00864256 _____ C:\Users\Carolina\Desktop\Ampelabfrage_Geometrie_ zentr.Streckung_Seitz.ppt 2013-12-15 12:38 - 2013-12-15 12:39 - 00000000 ____D C:\Users\Carolina\Desktop\Friseur 2013-12-12 23:09 - 2013-10-25 07:19 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 23:09 - 2013-10-25 07:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 23:09 - 2013-10-25 07:19 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-12-12 23:09 - 2013-10-25 07:19 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-12 23:09 - 2013-10-25 07:18 - 19271168 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 23:09 - 2013-10-25 07:18 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-12 23:09 - 2013-10-25 07:17 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 23:09 - 2013-10-25 07:17 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 23:09 - 2013-10-25 07:17 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 23:09 - 2013-10-25 07:17 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-12 23:09 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-12 23:09 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-12 23:09 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-12 23:09 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-12 23:09 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-12 23:09 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-12 23:09 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-12 23:09 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-12 23:08 - 2013-11-07 00:18 - 04036608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 23:08 - 2013-10-19 06:45 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-12 23:08 - 2013-10-19 05:04 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-12 23:08 - 2013-10-08 23:27 - 03279872 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-12-12 23:08 - 2013-10-08 23:27 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-12-12 23:08 - 2013-09-28 04:35 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-12 23:08 - 2013-08-30 06:18 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll 2013-12-12 23:07 - 2013-11-23 07:43 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-12 23:07 - 2013-11-23 06:05 - 00368640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-12 23:07 - 2013-11-01 06:38 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-12 23:07 - 2013-11-01 04:49 - 00273408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-12 23:07 - 2013-10-10 10:32 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-12 23:07 - 2013-10-10 10:30 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrobj.dll 2013-12-12 23:07 - 2013-10-10 10:30 - 00156160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-12 23:07 - 2013-10-10 10:24 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 23:07 - 2013-10-10 10:23 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-12 23:07 - 2013-10-10 10:22 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll 2013-12-12 23:07 - 2013-10-10 10:22 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 23:07 - 2013-10-09 02:33 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-12-12 23:07 - 2013-10-08 23:30 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2013-12-12 23:07 - 2013-10-08 23:30 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2013-12-12 23:07 - 2013-10-08 23:30 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2013-12-12 23:07 - 2013-10-08 23:30 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2013-12-12 23:07 - 2013-10-08 23:28 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-12-12 23:07 - 2013-10-08 23:27 - 01622016 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-12-12 23:07 - 2013-10-08 23:27 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2013-12-12 23:07 - 2013-10-08 23:27 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2013-12-12 23:07 - 2013-10-08 23:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-12-12 23:07 - 2013-10-08 23:27 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-12-12 23:07 - 2013-10-05 07:10 - 00285016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys 2013-12-12 23:07 - 2013-10-03 23:09 - 00385528 _____ C:\Windows\system32\ApnDatabase.xml 2013-12-12 23:07 - 2013-10-02 03:50 - 00447320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS 2013-12-12 23:07 - 2013-09-28 06:48 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2013-12-12 23:07 - 2013-09-28 04:58 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2013-12-12 23:07 - 2013-09-19 08:32 - 01455448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-12-12 23:07 - 2013-08-30 06:19 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll 2013-12-12 23:07 - 2013-08-30 00:48 - 00488960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll 2013-12-12 23:07 - 2013-08-30 00:47 - 00302080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll 2013-12-06 13:40 - 2013-12-13 07:58 - 00000000 ____D C:\Users\Carolina\Desktop\Reisekostenabrechnung 2013-12-03 07:48 - 2013-12-10 10:27 - 00000000 ____D C:\Users\Carolina\Desktop\Ehlers Stunde 2013-12-01 14:09 - 2013-12-01 14:17 - 53313165 _____ C:\Users\Carolina\Desktop\Fragebögen + Ausbildungskontaktgespräch.zip 2013-12-01 14:08 - 2013-12-01 14:16 - 00000000 ____D C:\Users\Carolina\Desktop\Fragebögen + Ausbildungskontaktgespräch 2013-12-01 12:24 - 2013-12-01 12:26 - 00000000 ____D C:\Users\Carolina\Desktop\Fotos für Präsentation 2013-12-01 11:47 - 2013-12-01 11:47 - 00000000 ____D C:\Users\Carolina\Desktop\akg 2013-11-30 18:31 - 2013-11-30 18:34 - 00000000 ____D C:\Users\Carolina\Desktop\Fotoshooting 2013-11-28 08:23 - 2013-11-28 08:23 - 00041472 _____ C:\Users\Carolina\Desktop\GS 10 C Noten WL.xls 2013-11-27 22:35 - 2013-11-27 22:50 - 01254400 _____ C:\Users\Carolina\Desktop\Punkte Geometrie 1 SA.xls 2013-11-26 22:07 - 2013-11-26 22:07 - 00411944 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfencbdc.sys 2013-11-26 22:07 - 2013-11-26 22:07 - 00096112 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfencrk.sys 2013-11-26 22:07 - 2013-11-26 22:07 - 00010856 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfeclnrk.sys ==================== One Month Modified Files and Folders ======= 2013-12-26 17:45 - 2013-03-27 02:41 - 01347242 _____ C:\Windows\WindowsUpdate.log 2013-12-26 17:43 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-26 17:38 - 2012-07-26 11:27 - 00754172 _____ C:\Windows\system32\perfh007.dat 2013-12-26 17:38 - 2012-07-26 11:27 - 00156362 _____ C:\Windows\system32\perfc007.dat 2013-12-26 17:38 - 2012-07-26 08:28 - 01748838 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-26 17:32 - 2013-12-26 17:32 - 00000000 ____D C:\FRST 2013-12-26 17:26 - 2012-07-26 08:21 - 00023129 _____ C:\Windows\setupact.log 2013-12-26 17:25 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\sru 2013-12-25 16:34 - 2013-12-25 16:34 - 00371240 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-25 16:23 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-12-25 16:22 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\SecureBootUpdates 2013-12-25 16:20 - 2013-08-15 19:12 - 00000000 ____D C:\Windows\system32\MRT 2013-12-25 16:19 - 2013-05-23 17:40 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-25 16:19 - 2013-03-29 12:27 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-25 16:18 - 2012-07-26 06:38 - 00000000 ____D C:\Windows\system32\oobe 2013-12-25 13:33 - 2013-12-25 13:33 - 00000023 _____ C:\Users\Carolina\AppData\Roaming\mbam.context.scan 2013-12-25 13:16 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-12-24 13:25 - 2013-01-28 01:31 - 00232502 _____ C:\Windows\PFRO.log 2013-12-24 12:20 - 2013-01-28 02:04 - 00000000 ____D C:\Program Files (x86)\Dell Backup and Recovery 2013-12-24 12:17 - 2013-04-03 17:17 - 00000000 ____D C:\Users\Carolina\AppData\Roaming\Dropbox 2013-12-24 12:16 - 2013-04-03 17:21 - 00000000 ___RD C:\Users\Carolina\Dropbox 2013-12-23 15:49 - 2013-12-23 15:49 - 01909242 _____ C:\Users\Carolina\Desktop\Konflikt_Seminar.zip 2013-12-23 15:49 - 2013-04-05 09:16 - 01388544 ___SH C:\Users\Carolina\Desktop\Thumbs.db 2013-12-21 11:58 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\ELAM 2013-12-21 09:44 - 2013-05-23 16:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-20 17:47 - 2013-12-20 17:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-19 18:05 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\NDF 2013-12-19 16:34 - 2013-05-22 06:40 - 00000000 ____D C:\Program Files\My Dell 2013-12-19 16:34 - 2013-01-28 01:56 - 00000000 ____D C:\ProgramData\PCDr 2013-12-18 23:30 - 2013-12-18 23:30 - 00864256 _____ C:\Users\Carolina\Desktop\Ampelabfrage_Geometrie_ zentr.Streckung_Seitz.ppt 2013-12-18 18:21 - 2013-09-10 16:23 - 00000000 ____D C:\Users\Carolina\AppData\Roaming\TeamViewer 2013-12-18 08:23 - 2013-11-19 22:23 - 00000000 ____D C:\Users\Carolina\Desktop\Hausarbeit 2013-12-15 12:39 - 2013-12-15 12:38 - 00000000 ____D C:\Users\Carolina\Desktop\Friseur 2013-12-13 07:58 - 2013-12-06 13:40 - 00000000 ____D C:\Users\Carolina\Desktop\Reisekostenabrechnung 2013-12-13 07:58 - 2013-01-28 01:33 - 00000000 ____D C:\Program Files (x86)\Intel 2013-12-13 07:03 - 2013-01-28 02:01 - 00000000 ____D C:\Program Files\Common Files\mcafee 2013-12-10 22:19 - 2013-05-23 17:40 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-10 18:44 - 2013-04-07 19:34 - 00000000 ____D C:\Users\Carolina\Desktop\Wochenberichte 2013-12-10 13:15 - 2013-09-29 21:16 - 00000000 ____D C:\Users\Carolina\Desktop\Unterrichte Christopher_Pierre_Franzi 2013-12-10 13:15 - 2013-06-22 15:37 - 00000000 ____D C:\Users\Carolina\Desktop\PDFs 2013-12-10 13:14 - 2013-05-31 17:24 - 00000000 ____D C:\Users\Carolina\Desktop\Portfolio 2013-12-10 13:13 - 2013-11-10 17:13 - 00000000 ____D C:\Users\Carolina\Desktop\Lehrprobe 2013-12-10 12:32 - 2013-05-31 17:26 - 00000000 ____D C:\Users\Carolina\Desktop\Wichtiges Referendariat 2013-12-10 10:27 - 2013-12-03 07:48 - 00000000 ____D C:\Users\Carolina\Desktop\Ehlers Stunde 2013-12-06 20:20 - 2013-04-03 18:18 - 00000000 ____D C:\Users\Carolina\AppData\Local\Adobe 2013-12-06 12:14 - 2012-07-26 09:12 - 00000000 ___HD C:\Windows\ELAMBKUP 2013-12-06 12:13 - 2013-01-28 02:01 - 00000000 ____D C:\Program Files (x86)\McAfee 2013-12-04 01:53 - 2013-11-15 06:58 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-04 01:53 - 2013-11-15 06:58 - 00078304 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-03 08:17 - 2013-06-22 16:19 - 00000000 ____D C:\Users\Carolina\Desktop\Protokolle 2013-12-02 21:07 - 2013-04-06 12:36 - 00000000 ____D C:\ProgramData\CanonIJPLM 2013-12-01 18:12 - 2013-10-03 20:48 - 00000000 ____D C:\Users\Carolina\Desktop\Unterricht 2 Halbjahr 2013-12-01 14:17 - 2013-12-01 14:09 - 53313165 _____ C:\Users\Carolina\Desktop\Fragebögen + Ausbildungskontaktgespräch.zip 2013-12-01 14:16 - 2013-12-01 14:08 - 00000000 ____D C:\Users\Carolina\Desktop\Fragebögen + Ausbildungskontaktgespräch 2013-12-01 12:26 - 2013-12-01 12:24 - 00000000 ____D C:\Users\Carolina\Desktop\Fotos für Präsentation 2013-12-01 11:47 - 2013-12-01 11:47 - 00000000 ____D C:\Users\Carolina\Desktop\akg 2013-11-30 18:34 - 2013-11-30 18:31 - 00000000 ____D C:\Users\Carolina\Desktop\Fotoshooting 2013-11-28 08:23 - 2013-11-28 08:23 - 00041472 _____ C:\Users\Carolina\Desktop\GS 10 C Noten WL.xls 2013-11-27 22:50 - 2013-11-27 22:35 - 01254400 _____ C:\Users\Carolina\Desktop\Punkte Geometrie 1 SA.xls 2013-11-26 22:07 - 2013-11-26 22:07 - 00411944 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfencbdc.sys 2013-11-26 22:07 - 2013-11-26 22:07 - 00096112 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfencrk.sys 2013-11-26 22:07 - 2013-11-26 22:07 - 00010856 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfeclnrk.sys Some content of TEMP: ==================== C:\Users\Carolina\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Carolina\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Carolina\AppData\Local\Temp\TouchURL.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-19 08:35 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-12-2013 Ran by Carolina at 2013-12-26 17:35:55 Running from E:\ Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} ==================== Installed Programs ====================== ActivDriver x64 v5.5 (Version: 5.5.37.4) ActivInspire Help (DEU) v1 (x32 Version: 1.4.0) ActivInspire HWR Resources (INT) v1 (x32 Version: 1.3.0) ActivInspire v1 (x32 Version: 1.4.23015) Activstudio Dokumente (DEU) v3.7.1 (x32 Version: 3.7.1) Activstudio Hilfe (DEU) v3.6.1 (x32 Version: 3.6.1) Activstudio Professional Edition v3.7 (x32 Version: 3.7.19) Activstudio Ressourcen (DEU) v3.5.1 (x32 Version: 3.5.1) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) Adobe Shockwave Player (x32 Version: 10.2.0.023) Amazon Browser App (x32 Version: 1.0.0.0) AMD Accelerated Video Transcoding (Version: 12.5.100.21025) AMD APP SDK Runtime (Version: 10.0.1016.4) AMD Catalyst Install Manager (Version: 8.0.891.0) Apple Application Support (x32 Version: 2.3.4) Apple Software Update (x32 Version: 2.1.3.127) Bandizip (HKCU Version: 3.08) Canon Easy-PhotoPrint EX (x32) Canon IJ Network Scanner Selector EX (x32) Canon IJ Network Tool (x32 Version: 3.1.1) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32) Canon iP3500 series Canon MG5200 series MP Drivers Canon MG5300 series Benutzerregistrierung (x32) Canon MG5300 series MP Drivers Canon MG5300 series On-screen Manual (x32) Canon MP Navigator EX 5.0 (x32) Canon My Printer (x32) Canon Solution Menu EX (x32) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2012.1025.346.4844) Catalyst Control Center InstallProxy (x32 Version: 2012.1025.346.4844) Catalyst Control Center Localization All (x32 Version: 2012.1025.346.4844) Catalyst Control Center Profiles Mobile (x32 Version: 2012.1025.346.4844) CCC Help Chinese Standard (x32 Version: 2012.1025.0345.4844) CCC Help Chinese Traditional (x32 Version: 2012.1025.0345.4844) CCC Help Danish (x32 Version: 2012.1025.0345.4844) CCC Help Dutch (x32 Version: 2012.1025.0345.4844) CCC Help English (x32 Version: 2012.1025.0345.4844) CCC Help Finnish (x32 Version: 2012.1025.0345.4844) CCC Help French (x32 Version: 2012.1025.0345.4844) CCC Help German (x32 Version: 2012.1025.0345.4844) CCC Help Italian (x32 Version: 2012.1025.0345.4844) CCC Help Japanese (x32 Version: 2012.1025.0345.4844) CCC Help Korean (x32 Version: 2012.1025.0345.4844) CCC Help Norwegian (x32 Version: 2012.1025.0345.4844) CCC Help Portuguese (x32 Version: 2012.1025.0345.4844) CCC Help Russian (x32 Version: 2012.1025.0345.4844) CCC Help Spanish (x32 Version: 2012.1025.0345.4844) CCC Help Swedish (x32 Version: 2012.1025.0345.4844) ccc-utility64 (Version: 2012.1025.346.4844) CyberLink LabelPrint 2.5 (x32 Version: 2.5.5415a) CyberLink Media Suite 10 (x32 Version: 10.0.1.1913) CyberLink Media Suite Essentials (x32 Version: 10.0) CyberLink Power2Go 8 (x32 Version: 8.0.0.1904) CyberLink PowerDirector 10 (x32 Version: 10.0.1.1904) CyberLink PowerDVD 10 (x32 Version: 10.0.4318.52) D3DX10 (x32 Version: 15.4.2368.0902) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Dell Backup and Recovery - Support Software (x32 Version: 1.0.0.5) Dell Backup and Recovery (x32 Version: 1.0.0.5) Dell Touchpad (Version: 16.2.12.17) Dropbox (HKCU Version: 2.0.22) ELMO Drivers (x32 Version: 1.00.0000) Fotogalerie (x32 Version: 16.4.3505.0912) Free YouTube to MP3 Converter version 3.12.2.430 (x32 Version: 3.12.2.430) GeoGebra 4.2 (x32 Version: 4.2.28.0) GeoGebra 4.4 (x32 Version: 4.3.31.0) HotPotatoes v 6.3.0.5 (x32) Image Mate (Version: 3.07.0798) Intel(R) Control Center (x32 Version: 1.2.1.1008) Intel(R) Management Engine Components (x32 Version: 8.1.0.1252) Intel(R) PRO/Wireless Driver (Version: 16.01.5000.0577) Intel(R) Processor Graphics (x32 Version: 9.17.10.2867) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 15.5.4.0423) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 2.6.1209.0268) Intel(R) Rapid Storage Technology (x32 Version: 11.5.0.1207) Intel® PROSet/Wireless Software (x32 Version: 16.1.5) Intel® Trusted Connect Service Client (Version: 1.24.388.1) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) MatheGrafix 9 (Version 9.50) (x32) McAfee SecurityCenter (x32 Version: 12.8.903) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office (x32 Version: 14.0.6120.5004) Microsoft Office 2010 Service Pack 1 (SP1) (x32) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Movie Maker (x32 Version: 16.4.3505.0912) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0) Mozilla Maintenance Service (x32 Version: 26.0) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT110 (x32 Version: 16.4.1108.0727) MSVCRT110_amd64 (Version: 16.4.1109.0912) My Dell (Version: 3.5.6422.14) PDFCreator (x32 Version: 1.7.0) Photo Gallery (x32 Version: 16.4.3505.0912) PowerXpressHybrid (x32 Version: 1.00.0000) PX Profile Update (x32 Version: 1.00.1.) Quickset64 (Version: 10.15.012) QuickTime (x32 Version: 7.74.80.86) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6741) Realtek USB 2.0 Card Reader (x32 Version: 6.1.8400.39030) Shared C Run-time for x64 (Version: 10.0.0) TeamViewer 8 (x32 Version: 8.0.22298) Überwachungstool für die Intel® Turbo-Boost-Technik 2.6 (Version: 2.6.2.0) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553065) (x32) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2566458) (x32) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32) Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition (x32) Windows Live Communications Platform (x32 Version: 16.4.3505.0912) Windows Live Essentials (x32 Version: 16.4.3505.0912) Windows Live Installer (x32 Version: 16.4.3505.0912) Windows Live Photo Common (x32 Version: 16.4.3505.0912) Windows Live PIMT Platform (x32 Version: 16.4.3505.0912) Windows Live SOXE (x32 Version: 16.4.3505.0912) Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912) Windows Live UX Platform (x32 Version: 16.4.3505.0912) Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912) WOT für Internet Explorer (Version: 12.8.2.0) ==================== Restore Points ========================= 28-11-2013 07:05:21 Geplanter Prüfpunkt 10-12-2013 14:43:28 Geplanter Prüfpunkt 19-12-2013 15:37:55 Geplanter Prüfpunkt 25-12-2013 15:16:13 Windows Update ==================== Hosts content: ========================== 2012-07-26 06:26 - 2012-07-26 06:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0B4BC264-7E47-41F8-A67E-74A5EB674BC5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {6A8064E6-9CA4-480D-A84E-9077DD926215} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\System32\NotificationUI.exe [2013-08-16] (Microsoft Corporation) Task: {827D89F5-A426-42B2-89C6-477D6A38CC1A} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect <==== ATTENTION Task: {90DDC8C9-5FEE-47CF-A5AA-021D941E954A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated) Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {B608A739-FDB0-49D4-933B-E77FCCEEAE02} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2013-12-07] (PC-Doctor, Inc.) Task: {B7EDEF70-9C37-41AE-ABD6-1CB0D72ED575} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2013-09-06] (PC-Doctor, Inc.) Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {C8188876-12D5-42D6-A4ED-DDE32BC11BB3} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-03-27 11:42 - 2013-03-27 11:42 - 00066048 _____ () C:\ProgramData\ACTIV Software\ActivApplications\ActivFocusHook.dll 2013-01-28 09:44 - 2012-10-16 11:38 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2010-06-10 14:59 - 2010-06-10 14:59 - 00083224 _____ () C:\Program Files\Activ Software\ActivDriver\prmnstx64.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/25/2013 04:21:43 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Single Image 2010 - Update "Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition" konnte nicht installiert werden. Fehlercode 1603. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (12/25/2013 04:21:43 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Single Image 2010 -- Fehler 1719.Auf den Windows Installer-Dienst konnte nicht zugegriffen werden. Dies kann auftreten, wenn der Windows Installer nicht richtig installiert wurde. Wenden Sie sich an den Support, um weitere Unterstützung zu erhalten. Error: (12/25/2013 04:19:07 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Single Image 2010 - Update "Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition" konnte nicht installiert werden. Fehlercode 1603. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (12/25/2013 04:19:07 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Single Image 2010 -- Fehler 1719.Auf den Windows Installer-Dienst konnte nicht zugegriffen werden. Dies kann auftreten, wenn der Windows Installer nicht richtig installiert wurde. Wenden Sie sich an den Support, um weitere Unterstützung zu erhalten. Error: (12/25/2013 04:19:05 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Single Image 2010 - Update "Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition" konnte nicht installiert werden. Fehlercode 1603. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (12/25/2013 04:19:05 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Single Image 2010 -- Fehler 1719.Auf den Windows Installer-Dienst konnte nicht zugegriffen werden. Dies kann auftreten, wenn der Windows Installer nicht richtig installiert wurde. Wenden Sie sich an den Support, um weitere Unterstützung zu erhalten. Error: (12/25/2013 04:16:59 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Proof (English) 2010 - Update "Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition" konnte nicht installiert werden. Fehlercode 1603. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (12/25/2013 04:16:59 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT) Description: Product: Microsoft Office Proof (English) 2010 -- Error 1719. The Windows Installer Service could not be accessed. This can occur if the Windows Installer is not correctly installed. Contact your support personnel for assistance. Error: (12/25/2013 01:15:54 PM) (Source: Microsoft-Windows-EapHost) (User: NT-AUTORITÄT) Description: Überspringen: Eap method DLL path name Fehler bei der Überprüfung. Fehler: Type-ID=43, Autor-ID=9, Lieferant-ID=0, Lieferant-Typ=0 Error: (12/25/2013 01:15:54 PM) (Source: Microsoft-Windows-EapHost) (User: NT-AUTORITÄT) Description: Überspringen: Eap method DLL path name Fehler bei der Überprüfung. Fehler: Type-ID=25, Autor-ID=9, Lieferant-ID=0, Lieferant-Typ=0 System errors: ============= Error: (12/26/2013 05:33:48 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) Management and Security Application User Notification Service" ist vom Dienst "Intel(R) Management and Security Application Local Management Service" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1053 Error: (12/26/2013 05:33:48 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) Management and Security Application Local Management Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/26/2013 05:33:48 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Intel(R) Management and Security Application Local Management Service erreicht. Error: (12/26/2013 05:33:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SoftThinks Agent Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/26/2013 05:33:38 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SoftThinks Agent Service erreicht. Error: (12/26/2013 05:33:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) Management and Security Application Local Management Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/26/2013 05:33:38 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Intel(R) Management and Security Application Local Management Service erreicht. Error: (12/26/2013 05:33:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) Rapid Storage-Technologie" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/26/2013 05:33:38 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Intel(R) Rapid Storage-Technologie erreicht. Error: (12/26/2013 05:33:10 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Bluetooth OBEX Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Microsoft Office Sessions: ========================= Error: (12/25/2013 04:21:43 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Microsoft Office Single Image 2010Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition1603(NULL)(NULL)(NULL) Error: (12/25/2013 04:21:43 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Single Image 2010 -- Fehler 1719.Auf den Windows Installer-Dienst konnte nicht zugegriffen werden. Dies kann auftreten, wenn der Windows Installer nicht richtig installiert wurde. Wenden Sie sich an den Support, um weitere Unterstützung zu erhalten.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (12/25/2013 04:19:07 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Microsoft Office Single Image 2010Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition1603(NULL)(NULL)(NULL) Error: (12/25/2013 04:19:07 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Single Image 2010 -- Fehler 1719.Auf den Windows Installer-Dienst konnte nicht zugegriffen werden. Dies kann auftreten, wenn der Windows Installer nicht richtig installiert wurde. Wenden Sie sich an den Support, um weitere Unterstützung zu erhalten.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (12/25/2013 04:19:05 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Microsoft Office Single Image 2010Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition1603(NULL)(NULL)(NULL) Error: (12/25/2013 04:19:05 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Produkt: Microsoft Office Single Image 2010 -- Fehler 1719.Auf den Windows Installer-Dienst konnte nicht zugegriffen werden. Dies kann auftreten, wenn der Windows Installer nicht richtig installiert wurde. Wenden Sie sich an den Support, um weitere Unterstützung zu erhalten.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (12/25/2013 04:16:59 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Microsoft Office Proof (English) 2010Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition1603(NULL)(NULL)(NULL) Error: (12/25/2013 04:16:59 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT) Description: Product: Microsoft Office Proof (English) 2010 -- Error 1719. The Windows Installer Service could not be accessed. This can occur if the Windows Installer is not correctly installed. Contact your support personnel for assistance.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (12/25/2013 01:15:54 PM) (Source: Microsoft-Windows-EapHost)(User: NT-AUTORITÄT) Description: Eap method DLL path name43900 Error: (12/25/2013 01:15:54 PM) (Source: Microsoft-Windows-EapHost)(User: NT-AUTORITÄT) Description: Eap method DLL path name25900 ==================== Memory info =========================== Percentage of memory in use: 18% Total physical RAM: 8061.27 MB Available physical RAM: 6579.48 MB Total Pagefile: 9277.27 MB Available Pagefile: 7792.39 MB Total Virtual: 8192 MB Available Virtual: 8191.75 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:917.1 GB) (Free:814.02 GB) NTFS Drive e: () (Removable) (Total:1.87 GB) (Free:1.87 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 7FD47089) Partition: GPT Partition Type ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=2 GB) - (Type=06) ==================== End Of Log ============================ |
27.12.2013, 16:37 | #6 |
/// the machine /// TB-Ausbilder | BCD-Fehler und fehlendes wow64cpu.dll Öffne bitte FRST, kopiere das folgende in die Search Box wow64cpu.dll und klicke auf Search, poste bitte das Logfile.
__________________ --> BCD-Fehler und fehlendes wow64cpu.dll |
27.12.2013, 16:52 | #7 |
| BCD-Fehler und fehlendes wow64cpu.dllCode:
ATTFilter Farbar Recovery Scan Tool (x64) Version: 25-12-2013 Ran by Carolina at 2013-12-27 16:42:12 Running from E:\ Boot Mode: Safe Mode (with Networking) ================== Search: "wow64cpu.dll" =================== C:\Windows\WinSxS\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.2.9200.16384_none_c0ef6f6e611367c0\wow64cpu.dll [2012-07-26 03:30] - [2012-07-26 04:08] - 0012800 ____A (Microsoft Corporation) 1E2E99B4FA9A5F0D9934F8B99B528A62 ====== End Of Search ====== |
28.12.2013, 12:49 | #8 |
/// the machine /// TB-Ausbilder | BCD-Fehler und fehlendes wow64cpu.dll Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Move: C:\Windows\WinSxS\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.2.9200.16384_none_c0ef6f6e611367c0\wow64cpu.dll C:\Windows\System32\wow64cpu.dll Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.12.2013, 20:42 | #9 |
| BCD-Fehler und fehlendes wow64cpu.dllCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-12-2013 01 Ran by Carolina at 2013-12-28 20:40:27 Run:1 Running from E:\ Boot Mode: Normal ============================================== Content of fixlist: ***************** Move: C:\Windows\WinSxS\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.2.9200.16384_none_c0ef6f6e611367c0\wow64cpu.dll C:\Windows\System32\wow64cpu.dll ***************** Could not find C:\Windows\System32\wow64cpu.dll. Could not replace C:\Windows\System32\wow64cpu.dll. ==== End of Fixlog ==== |
29.12.2013, 12:42 | #10 |
/// the machine /// TB-Ausbilder | BCD-Fehler und fehlendes wow64cpu.dll Scheisse bin ich doof Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Replace: C:\Windows\WinSxS\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.2.9200.16384_none_c0ef6f6e611367c0\wow64cpu.dll C:\Windows\System32\wow64cpu.dll Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.12.2013, 13:37 | #11 |
| BCD-Fehler und fehlendes wow64cpu.dllCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-12-2013 Ran by Carolina at 2013-12-29 13:35:57 Run:2 Running from E:\ Boot Mode: Normal ============================================== Content of fixlist: ***************** Replace: C:\Windows\WinSxS\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.2.9200.16384_none_c0ef6f6e611367c0\wow64cpu.dll C:\Windows\System32\wow64cpu.dll ***************** Could not find C:\Windows\System32\wow64cpu.dll. C:\Windows\WinSxS\amd64_microsoft-windows-wow64_31bf3856ad364e35_6.2.9200.16384_none_c0ef6f6e611367c0\wow64cpu.dll copied successfully to C:\Windows\System32\wow64cpu.dll ==== End of Fixlog ==== |
30.12.2013, 10:48 | #12 |
/// the machine /// TB-Ausbilder | BCD-Fehler und fehlendes wow64cpu.dll Sag ja, never trust a schraubi wenn er erst eine Kanne Kaffee hat
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.12.2013, 10:19 | #13 |
| BCD-Fehler und fehlendes wow64cpu.dll Also augenscheinlich laufen jetzt die Programme. Gestern ist mir aber nun folgendes noch passiert. Der Laptop ging plötzlich aus. Ich hab ihn dreimal versucht zu starten. Bei den ersten beiden Malen hat er sich aufgehängt, beim dritten Mal ging es. Kann ich da iwie herausfinden, woran das lag? |
01.01.2014, 12:44 | #14 |
/// the machine /// TB-Ausbilder | BCD-Fehler und fehlendes wow64cpu.dll Öffne mal FRST, setz nen Haken bei additional und scanne, poste beide Logfiles.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.01.2014, 14:32 | #15 |
| BCD-Fehler und fehlendes wow64cpu.dll Habe den Scan jetzt gemacht. Was war/ist eigentlich jetzt das Problem gewesen? War das ein Trojaner, oder ein anderer Fehler? Ich habe vor Weihnachten auch noch Dell geschrieben, weil ich auf das Teil ja noch Garantie habe und falls da an der Hardware etwas defekt ist. Jetzt haben die mir heute geschrieben, dass es das beste wäre, wenn man die Festplatte austauschen würde. Ist das wirklich notwendig, oder haben die keinen Bock oder Zeit das Problem zu lösen und die Festplatte zu tauschen wäre günstiger? Wie siehst du das? Hier die Scans: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-01-2014 01 Ran by Carolina (administrator) on CAROLINA on 02-01-2014 14:27:36 Running from E:\ Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (McAfee, Inc.) C:\Program Files\mcafee\msm\McSmtFwk.exe (AMD) C:\Windows\System32\atieclxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4396.1016_x64__8wekyb3d8bbwe\LiveComm.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Promethean Technologies Group Ltd) C:\Program Files\Activ Software\ActivDriver\ActivControl2x64.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (Dropbox, Inc.) C:\Users\Carolina\AppData\Roaming\Dropbox\bin\Dropbox.exe () C:\Program Files\Activ Software\ActivDriver\ActivMgr.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\DBRUpd.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Microsoft Corporation) C:\Windows\System32\mspaint.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McUICnt.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE (Microsoft Corporation) C:\Windows\System32\msiexec.exe (McAfee, Inc.) C:\Program Files\mcafee\virusscan\McVsShld.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\Core\mchost.exe (Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [DellWPF] - [x] HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6842000 2012-09-25] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1230992 2012-09-28] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2918200 2012-09-21] (Synaptics Incorporated) HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\quickset.exe [5757328 2012-10-19] (Dell Inc.) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4123 2012-05-30] () HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM\...\Run: [ActivControl] - C:\Program Files\Activ Software\ActivDriver\ActivControl2x64.exe [1238312 2010-06-10] (Promethean Technologies Group Ltd) HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE [2779024 2011-03-14] (CANON INC.) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642728 2012-10-25] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [CLMLServer_For_P2G8] - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-04] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [143888 2012-06-01] (CyberLink Corp.) HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\mcafee.com\agent\mcagent.exe [537512 2013-09-24] (McAfee, Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1612920 2011-08-04] (CANON INC.) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [mcpltui_exe] - C:\Program Files\mcafee.com\agent\mcagent.exe [537512 2013-09-24] (McAfee, Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoControlPanel] 0 MountPoints2: {0ed07f4e-68e2-11e2-be65-806e6f6e6963} - "D:\SETUP.EXE" AppInit_DLLs-x32: [ ] () Startup: C:\Users\Carolina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Carolina\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {E9019C22-93E4-4C0D-B77C-3DEFD9E83856} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDCJS SearchScopes: HKLM-x32 - {E9019C22-93E4-4C0D-B77C-3DEFD9E83856} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MDDCJS SearchScopes: HKCU - DefaultScope {E9019C22-93E4-4C0D-B77C-3DEFD9E83856} URL = SearchScopes: HKCU - {E9019C22-93E4-4C0D-B77C-3DEFD9E83856} URL = BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll () BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll () BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll () Toolbar: HKCU - WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll () Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll () Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Carolina\AppData\Roaming\Mozilla\Firefox\Profiles\rfnhoztn.default FF Homepage: hxxp://www.google.com FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\Carolina\AppData\Roaming\Mozilla\Firefox\Profiles\rfnhoztn.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: Adblock Plus - C:\Users\Carolina\AppData\Roaming\Mozilla\Firefox\Profiles\rfnhoztn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK ==================== Services (Whitelisted) ================= R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [138192 2011-02-07] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178048 2013-11-28] (McAfee, Inc.) S3 McAWFwk; C:\Program Files\mcafee\msc\McAWFwk.exe [332080 2012-01-26] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.) S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1025232 2013-11-26] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-11-04] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-11-04] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-25] () R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201360 2012-09-01] (Realtek Semiconductor) R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [1914728 2012-11-26] (SoftThinks SAS) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R3 ActivHidSerMini; C:\Windows\System32\drivers\activhidsermini.sys [86104 2010-05-26] (Promethean Technologies Ltd) R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [35496 2012-07-09] (Advanced Micro Devices, Inc.) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [121728 2012-08-27] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [857472 2012-08-29] (Motorola Solutions, Inc.) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-11-04] (McAfee, Inc.) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) S3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2012-08-05] (OSR Open Systems Resources, Inc.) S3 ElmoSESAME; C:\Windows\System32\drivers\ElmoSESAME.sys [28264 2012-01-20] (ELMO COMPANY, LIMITED) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) R2 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179792 2013-11-04] (McAfee, Inc.) R2 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311120 2013-11-04] (McAfee, Inc.) S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69344 2013-11-04] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519576 2013-11-04] (McAfee, Inc.) R2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [782360 2013-11-04] (McAfee, Inc.) R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [411944 2013-11-26] (McAfee, Inc.) S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96112 2013-11-26] (McAfee, Inc.) R2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343696 2013-11-04] (McAfee, Inc.) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-10-08] (Intel Corporation) R3 prmvmouse; C:\Windows\System32\drivers\activmouse.sys [8152 2010-05-26] (Promethean Technologies Ltd) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-09-21] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-09-21] (Synaptics Incorporated) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-29 13:35 - 2012-07-26 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-12-26 17:32 - 2014-01-02 14:26 - 00000000 ____D C:\FRST 2013-12-25 16:34 - 2013-12-25 16:34 - 00371240 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-25 13:33 - 2013-12-25 13:33 - 00000023 _____ C:\Users\Carolina\AppData\Roaming\mbam.context.scan 2013-12-23 15:49 - 2013-12-23 15:49 - 01909242 _____ C:\Users\Carolina\Desktop\Konflikt_Seminar.zip 2013-12-23 15:48 - 2012-05-10 14:57 - 00000000 ____D C:\Users\Carolina\Desktop\Konflikt_Seminar 2013-12-20 17:47 - 2013-12-20 17:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-18 23:30 - 2013-12-18 23:30 - 00864256 _____ C:\Users\Carolina\Desktop\Ampelabfrage_Geometrie_ zentr.Streckung_Seitz.ppt 2013-12-15 12:38 - 2013-12-15 12:39 - 00000000 ____D C:\Users\Carolina\Desktop\Friseur 2013-12-12 23:09 - 2013-10-25 07:19 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 23:09 - 2013-10-25 07:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 23:09 - 2013-10-25 07:19 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-12-12 23:09 - 2013-10-25 07:19 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-12 23:09 - 2013-10-25 07:18 - 19271168 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 23:09 - 2013-10-25 07:18 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-12 23:09 - 2013-10-25 07:17 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 23:09 - 2013-10-25 07:17 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 23:09 - 2013-10-25 07:17 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 23:09 - 2013-10-25 07:17 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-12 23:09 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-12 23:09 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-12 23:09 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-12 23:09 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-12 23:09 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-12 23:09 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-12 23:09 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-12 23:09 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-12 23:08 - 2013-11-07 00:18 - 04036608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 23:08 - 2013-10-19 06:45 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-12 23:08 - 2013-10-19 05:04 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-12 23:08 - 2013-10-08 23:27 - 03279872 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-12-12 23:08 - 2013-10-08 23:27 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-12-12 23:08 - 2013-09-28 04:35 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-12 23:08 - 2013-08-30 06:18 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll 2013-12-12 23:07 - 2013-11-23 07:43 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-12 23:07 - 2013-11-23 06:05 - 00368640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-12 23:07 - 2013-11-01 06:38 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-12 23:07 - 2013-11-01 04:49 - 00273408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-12 23:07 - 2013-10-10 10:32 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-12 23:07 - 2013-10-10 10:30 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrobj.dll 2013-12-12 23:07 - 2013-10-10 10:30 - 00156160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-12 23:07 - 2013-10-10 10:24 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 23:07 - 2013-10-10 10:23 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-12 23:07 - 2013-10-10 10:22 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll 2013-12-12 23:07 - 2013-10-10 10:22 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 23:07 - 2013-10-09 02:33 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-12-12 23:07 - 2013-10-08 23:30 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2013-12-12 23:07 - 2013-10-08 23:30 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2013-12-12 23:07 - 2013-10-08 23:30 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2013-12-12 23:07 - 2013-10-08 23:30 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2013-12-12 23:07 - 2013-10-08 23:28 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-12-12 23:07 - 2013-10-08 23:27 - 01622016 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-12-12 23:07 - 2013-10-08 23:27 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2013-12-12 23:07 - 2013-10-08 23:27 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2013-12-12 23:07 - 2013-10-08 23:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-12-12 23:07 - 2013-10-08 23:27 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-12-12 23:07 - 2013-10-05 07:10 - 00285016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys 2013-12-12 23:07 - 2013-10-03 23:09 - 00385528 _____ C:\Windows\system32\ApnDatabase.xml 2013-12-12 23:07 - 2013-10-02 03:50 - 00447320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS 2013-12-12 23:07 - 2013-09-28 06:48 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2013-12-12 23:07 - 2013-09-28 04:58 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2013-12-12 23:07 - 2013-09-19 08:32 - 01455448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-12-12 23:07 - 2013-08-30 06:19 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll 2013-12-12 23:07 - 2013-08-30 00:48 - 00488960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll 2013-12-12 23:07 - 2013-08-30 00:47 - 00302080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll 2013-12-06 13:40 - 2013-12-13 07:58 - 00000000 ____D C:\Users\Carolina\Desktop\Reisekostenabrechnung 2013-12-03 07:48 - 2013-12-10 10:27 - 00000000 ____D C:\Users\Carolina\Desktop\Ehlers Stunde ==================== One Month Modified Files and Folders ======= 2014-01-02 14:26 - 2013-12-26 17:32 - 00000000 ____D C:\FRST 2014-01-02 14:25 - 2013-03-27 02:41 - 02038481 _____ C:\Windows\WindowsUpdate.log 2014-01-02 14:19 - 2013-05-23 17:40 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-02 14:00 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\sru 2014-01-02 13:43 - 2013-10-03 20:48 - 00000000 ____D C:\Users\Carolina\Desktop\Unterricht 2 Halbjahr 2014-01-01 15:05 - 2013-04-03 17:17 - 00000000 ____D C:\Users\Carolina\AppData\Roaming\Dropbox 2013-12-31 17:20 - 2013-01-28 02:04 - 00000000 ____D C:\Program Files (x86)\Dell Backup and Recovery 2013-12-31 17:16 - 2013-04-03 17:21 - 00000000 ___RD C:\Users\Carolina\Dropbox 2013-12-30 19:13 - 2012-07-26 11:27 - 00754172 _____ C:\Windows\system32\perfh007.dat 2013-12-30 19:13 - 2012-07-26 11:27 - 00156362 _____ C:\Windows\system32\perfc007.dat 2013-12-30 19:13 - 2012-07-26 08:28 - 01748838 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-30 18:44 - 2013-01-28 02:01 - 00000000 ____D C:\Program Files (x86)\McAfee 2013-12-30 18:44 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-30 18:43 - 2013-01-28 01:31 - 00232866 _____ C:\Windows\PFRO.log 2013-12-29 20:50 - 2013-03-27 03:15 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-29 20:11 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\ELAM 2013-12-27 16:53 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-12-26 17:26 - 2012-07-26 08:21 - 00023129 _____ C:\Windows\setupact.log 2013-12-25 16:34 - 2013-12-25 16:34 - 00371240 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-25 16:22 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\SecureBootUpdates 2013-12-25 16:20 - 2013-08-15 19:12 - 00000000 ____D C:\Windows\system32\MRT 2013-12-25 16:19 - 2013-03-29 12:27 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-25 16:18 - 2012-07-26 06:38 - 00000000 ____D C:\Windows\system32\oobe 2013-12-25 13:33 - 2013-12-25 13:33 - 00000023 _____ C:\Users\Carolina\AppData\Roaming\mbam.context.scan 2013-12-25 13:16 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-12-23 15:49 - 2013-12-23 15:49 - 01909242 _____ C:\Users\Carolina\Desktop\Konflikt_Seminar.zip 2013-12-23 15:49 - 2013-04-05 09:16 - 01388544 ___SH C:\Users\Carolina\Desktop\Thumbs.db 2013-12-21 09:44 - 2013-05-23 16:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-20 17:47 - 2013-12-20 17:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-19 18:05 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\NDF 2013-12-19 16:34 - 2013-05-22 06:40 - 00000000 ____D C:\Program Files\My Dell 2013-12-19 16:34 - 2013-01-28 01:56 - 00000000 ____D C:\ProgramData\PCDr 2013-12-18 23:30 - 2013-12-18 23:30 - 00864256 _____ C:\Users\Carolina\Desktop\Ampelabfrage_Geometrie_ zentr.Streckung_Seitz.ppt 2013-12-18 18:21 - 2013-09-10 16:23 - 00000000 ____D C:\Users\Carolina\AppData\Roaming\TeamViewer 2013-12-18 08:23 - 2013-11-19 22:23 - 00000000 ____D C:\Users\Carolina\Desktop\Hausarbeit 2013-12-15 12:39 - 2013-12-15 12:38 - 00000000 ____D C:\Users\Carolina\Desktop\Friseur 2013-12-13 07:58 - 2013-12-06 13:40 - 00000000 ____D C:\Users\Carolina\Desktop\Reisekostenabrechnung 2013-12-13 07:58 - 2013-01-28 01:33 - 00000000 ____D C:\Program Files (x86)\Intel 2013-12-13 07:03 - 2013-01-28 02:01 - 00000000 ____D C:\Program Files\Common Files\mcafee 2013-12-10 22:19 - 2013-05-23 17:40 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-10 18:44 - 2013-04-07 19:34 - 00000000 ____D C:\Users\Carolina\Desktop\Wochenberichte 2013-12-10 13:15 - 2013-09-29 21:16 - 00000000 ____D C:\Users\Carolina\Desktop\Unterrichte Christopher_Pierre_Franzi 2013-12-10 13:15 - 2013-06-22 15:37 - 00000000 ____D C:\Users\Carolina\Desktop\PDFs 2013-12-10 13:14 - 2013-05-31 17:24 - 00000000 ____D C:\Users\Carolina\Desktop\Portfolio 2013-12-10 13:13 - 2013-11-10 17:13 - 00000000 ____D C:\Users\Carolina\Desktop\Lehrprobe 2013-12-10 12:32 - 2013-05-31 17:26 - 00000000 ____D C:\Users\Carolina\Desktop\Wichtiges Referendariat 2013-12-10 10:27 - 2013-12-03 07:48 - 00000000 ____D C:\Users\Carolina\Desktop\Ehlers Stunde 2013-12-06 20:20 - 2013-04-03 18:18 - 00000000 ____D C:\Users\Carolina\AppData\Local\Adobe 2013-12-06 12:14 - 2012-07-26 09:12 - 00000000 ___HD C:\Windows\ELAMBKUP 2013-12-04 01:53 - 2013-11-15 06:58 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-04 01:53 - 2013-11-15 06:58 - 00078304 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-03 08:17 - 2013-06-22 16:19 - 00000000 ____D C:\Users\Carolina\Desktop\Protokolle Some content of TEMP: ==================== C:\Users\Carolina\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Carolina\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Carolina\AppData\Local\Temp\TouchURL.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-29 20:48 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-01-2014 01 Ran by Carolina at 2014-01-02 14:28:52 Running from E:\ Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} ==================== Installed Programs ====================== ActivDriver x64 v5.5 (Version: 5.5.37.4 - Promethean) ActivInspire Help (DEU) v1 (x32 Version: 1.4.0 - Promethean) ActivInspire HWR Resources (INT) v1 (x32 Version: 1.3.0 - Promethean) ActivInspire v1 (x32 Version: 1.4.23015 - Promethean) Activstudio Dokumente (DEU) v3.7.1 (x32 Version: 3.7.1 - Promethean Ltd.) Activstudio Hilfe (DEU) v3.6.1 (x32 Version: 3.6.1 - Promethean Ltd.) Activstudio Professional Edition v3.7 (x32 Version: 3.7.19 - Promethean Ltd.) Activstudio Ressourcen (DEU) v3.5.1 (x32 Version: 3.5.1 - Promethean Ltd.) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05 - Adobe Systems Incorporated) Adobe Shockwave Player (x32 Version: 10.2.0.023 - Adobe Systems, Inc.) Amazon Browser App (x32 Version: 1.0.0.0 - Amazon) AMD Accelerated Video Transcoding (Version: 12.5.100.21025 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.1016.4 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (Version: 8.0.891.0 - Advanced Micro Devices, Inc.) Apple Application Support (x32 Version: 2.3.4 - Apple Inc.) Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.) Bandizip (HKCU Version: 3.08 - Bandisoft.com) Canon Easy-PhotoPrint EX (x32 Version: - ) Canon IJ Network Scanner Selector EX (x32 Version: - ) Canon IJ Network Tool (x32 Version: 3.1.1 - Canon Inc.) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32 Version: - ) Canon iP3500 series (Version: - ) Canon MG5200 series MP Drivers (Version: - ) Canon MG5300 series Benutzerregistrierung (x32 Version: - ) Canon MG5300 series MP Drivers (Version: - Canon Inc.) Canon MG5300 series On-screen Manual (x32 Version: - ) Canon MP Navigator EX 5.0 (x32 Version: - ) Canon My Printer (x32 Version: - ) Canon Solution Menu EX (x32 Version: - ) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center (x32 Version: 2012.1025.346.4844 - Ihr Firmenname) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.1025.346.4844 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.1025.346.4844 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Profiles Mobile (x32 Version: 2012.1025.346.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.1025.0345.4844 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.1025.346.4844 - Advanced Micro Devices, Inc.) Hidden CyberLink LabelPrint 2.5 (x32 Version: 2.5.5415a - CyberLink Corp.) Hidden CyberLink Media Suite 10 (x32 Version: 10.0.1.1913 - CyberLink Corp.) Hidden CyberLink Media Suite Essentials (x32 Version: 10.0 - CyberLink Corp.) CyberLink Power2Go 8 (x32 Version: 8.0.0.1904 - CyberLink Corp.) Hidden CyberLink PowerDirector 10 (x32 Version: 10.0.1.1904 - CyberLink Corp.) Hidden CyberLink PowerDVD 10 (x32 Version: 10.0.4318.52 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32 Version: - Microsoft) Dell Backup and Recovery - Support Software (x32 Version: 1.0.0.5 - Dell Inc.) Dell Backup and Recovery (x32 Version: 1.0.0.5 - Dell Inc.) Dell Touchpad (Version: 16.2.12.17 - Synaptics Incorporated) Dropbox (HKCU Version: 2.0.22 - Dropbox, Inc.) ELMO Drivers (x32 Version: 1.00.0000 - ELMO) Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Free YouTube to MP3 Converter version 3.12.2.430 (x32 Version: 3.12.2.430 - DVDVideoSoft Ltd.) GeoGebra 4.2 (x32 Version: 4.2.28.0 - International GeoGebra Institute) GeoGebra 4.4 (x32 Version: 4.3.31.0 - International GeoGebra Institute) HotPotatoes v 6.3.0.5 (x32 Version: - HalfBaked) Image Mate (Version: 3.07.0798 - ELMO) Intel(R) Control Center (x32 Version: 1.2.1.1008 - Intel Corporation) Intel(R) Management Engine Components (x32 Version: 8.1.0.1252 - Intel Corporation) Intel(R) PRO/Wireless Driver (Version: 16.01.5000.0577 - Intel Corporation) Hidden Intel(R) Processor Graphics (x32 Version: 9.17.10.2867 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 15.5.4.0423 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 2.6.1209.0268 - Motorola Solutions, Inc.) Intel(R) Rapid Storage Technology (x32 Version: 11.5.0.1207 - Intel Corporation) Intel® PROSet/Wireless Software (x32 Version: 16.1.5 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden Java 7 Update 25 (x32 Version: 7.0.250 - Oracle) Java Auto Updater (x32 Version: 2.1.9.5 - Sun Microsystems, Inc.) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) MatheGrafix 9 (Version 9.50) (x32 Version: - ) McAfee SecurityCenter (x32 Version: 12.8.903 - McAfee, Inc.) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office (x32 Version: 14.0.6120.5004 - Microsoft Corporation) Microsoft Office 2010 Service Pack 1 (SP1) (x32 Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden My Dell (Version: 3.4.6422.14 - PC-Doctor, Inc.) PDFCreator (x32 Version: 1.7.0 - pdfforge) Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden PowerXpressHybrid (x32 Version: 1.00.0000 - Ihr Firmenname) Hidden PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden Quickset64 (Version: 10.15.012 - Dell Inc.) QuickTime (x32 Version: 7.74.80.86 - Apple Inc.) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6741 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (x32 Version: 6.1.8400.39030 - Realtek Semiconductor Corp.) Shared C Run-time for x64 (Version: 10.0.0 - McAfee) TeamViewer 8 (x32 Version: 8.0.22298 - TeamViewer) Überwachungstool für die Intel® Turbo-Boost-Technik 2.6 (Version: 2.6.2.0 - Intel) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2553065) (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2566458) (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (x32 Version: - Microsoft) Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden WOT für Internet Explorer (Version: 12.8.2.0 - WOT Services Oy) ==================== Restore Points ========================= 10-12-2013 14:43:28 Geplanter Prüfpunkt 19-12-2013 15:37:55 Geplanter Prüfpunkt 25-12-2013 15:16:13 Windows Update 29-12-2013 19:48:53 Windows Update ==================== Hosts content: ========================== 2012-07-26 06:26 - 2012-07-26 06:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0B4BC264-7E47-41F8-A67E-74A5EB674BC5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {6A8064E6-9CA4-480D-A84E-9077DD926215} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\System32\NotificationUI.exe [2013-08-16] (Microsoft Corporation) Task: {827D89F5-A426-42B2-89C6-477D6A38CC1A} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect <==== ATTENTION Task: {90DDC8C9-5FEE-47CF-A5AA-021D941E954A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated) Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {B608A739-FDB0-49D4-933B-E77FCCEEAE02} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2013-12-07] (PC-Doctor, Inc.) Task: {B7EDEF70-9C37-41AE-ABD6-1CB0D72ED575} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2013-09-06] (PC-Doctor, Inc.) Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {C8188876-12D5-42D6-A4ED-DDE32BC11BB3} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2013-03-27 11:42 - 2013-03-27 11:42 - 00066048 _____ () C:\ProgramData\ACTIV Software\ActivApplications\ActivFocusHook.dll 2013-01-28 09:40 - 2012-11-01 23:43 - 00175008 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4396.1016_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll 2013-01-28 09:44 - 2012-10-16 11:38 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2010-06-10 14:59 - 2010-06-10 14:59 - 00083224 _____ () C:\Program Files\Activ Software\ActivDriver\prmnstx64.dll 2013-08-16 20:55 - 2013-08-16 20:55 - 00017920 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\PSIClient\d4b49cde56288aa4c132208d7aba2a82\PSIClient.ni.dll 2013-01-28 01:51 - 2012-06-25 19:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Carolina\AppData\Roaming\Dropbox\bin\libcef.dll 2010-06-10 14:59 - 2010-06-10 14:59 - 00340248 _____ () C:\Program Files\Activ Software\ActivDriver\QtXml4.dll 2010-06-10 14:59 - 2010-06-10 14:59 - 07993624 _____ () C:\Program Files\Activ Software\ActivDriver\QtGui4.dll 2010-06-10 14:59 - 2010-06-10 14:59 - 00934688 _____ () C:\Program Files\Activ Software\ActivDriver\QtNetwork4.dll 2010-06-10 14:59 - 2010-06-10 14:59 - 02151704 _____ () C:\Program Files\Activ Software\ActivDriver\QtCore4.dll 2010-06-10 14:59 - 2010-06-10 14:59 - 00227624 _____ () C:\Windows\libactivboardex.dll 2013-01-28 01:57 - 2012-06-08 04:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2012-06-08 11:34 - 2012-06-08 11:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll 2013-12-20 17:47 - 2013-12-20 17:47 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf 2011-02-18 10:04 - 2011-02-18 10:04 - 00196448 _____ () C:\Program Files (x86)\Microsoft Office\Office14\IEAWSDC.DLL ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/02/2014 02:06:00 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80070005 Error: (12/31/2013 05:20:48 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: TOASTER.EXE, Version: 1.0.0.44, Zeitstempel: 0x50b3754f Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x049ead5f ID des fehlerhaften Prozesses: 0x1a60 Startzeit der fehlerhaften Anwendung: 0xTOASTER.EXE0 Pfad der fehlerhaften Anwendung: TOASTER.EXE1 Pfad des fehlerhaften Moduls: TOASTER.EXE2 Berichtskennung: TOASTER.EXE3 Vollständiger Name des fehlerhaften Pakets: TOASTER.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: TOASTER.EXE5 Error: (12/31/2013 05:20:47 PM) (Source: .NET Runtime) (User: ) Description: Anwendung: TOASTER.EXE Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.NullReferenceException Stapel: bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.DispatcherOperation.InvokeImpl() bei System.Windows.Threading.DispatcherOperation.InvokeInSecurityContext(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Windows.Threading.DispatcherOperation.Invoke() bei System.Windows.Threading.Dispatcher.ProcessQueue() bei System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) bei MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) bei System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame) bei System.Windows.Threading.Dispatcher.Run() bei System.Windows.Application.RunDispatcher(System.Object) bei System.Windows.Application.RunInternal(System.Windows.Window) bei System.Windows.Application.Run(System.Windows.Window) bei Toaster.App.Main() Error: (12/31/2013 05:20:46 PM) (Source: TOASTER.EXE) (User: ) Description: An Unhandled Exception occured. Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt. bei Toaster.Helper.GetDelayBeforeReminders(ObservableCollection`1 notificationHelpers) bei Toaster.ToasterTimerManager.SetNextNotification() bei Toaster.ToasterTimerManager.UpdateAllTimers() bei Toaster.ToasterTimerManager.InitTimers() bei Toaster.ToasterTimerManager.GetInstance() bei Toaster.MainWindowViewModel..ctor() bei Toaster.App.OnStartup(StartupEventArgs e) bei System.Windows.Application.<.ctor>b__1(Object unused) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback, Object args, Int32 numArgs) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(Object source, Delegate method, Object args, Int32 numArgs, Delegate catchHandler) Error: (12/31/2013 00:57:31 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80070005 Error: (12/30/2013 00:26:41 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: CNSEUPDT.EXE, Version: 1.3.5.0, Zeitstempel: 0x4e3a32f0 Name des fehlerhaften Moduls: CNMDWLD.DLL, Version: 1.0.0.0, Zeitstempel: 0x4cad61a4 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000024c0 ID des fehlerhaften Prozesses: 0xddc Startzeit der fehlerhaften Anwendung: 0xCNSEUPDT.EXE0 Pfad der fehlerhaften Anwendung: CNSEUPDT.EXE1 Pfad des fehlerhaften Moduls: CNSEUPDT.EXE2 Berichtskennung: CNSEUPDT.EXE3 Vollständiger Name des fehlerhaften Pakets: CNSEUPDT.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: CNSEUPDT.EXE5 Error: (12/30/2013 00:25:21 PM) (Source: ESENT) (User: ) Description: taskhostex (5532) Versuch, Datei "C:\Users\Carolina\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat" für den Lesezugriff zu öffnen, ist mit Systemfehler 32 (0x00000020): "Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird. " fehlgeschlagen. Fehler -1032 (0xfffffbf8) beim Öffnen von Dateien. Error: (12/30/2013 01:30:41 AM) (Source: ATIeRecord) (User: ) Description: ATI EEU Client event error Error: (12/30/2013 01:30:34 AM) (Source: Microsoft-Windows-Immersive-Shell) (User: CAROLINA) Description: Bei der Aktivierung der App „Microsoft.BingWeather_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (12/30/2013 01:30:33 AM) (Source: Application Hang) (User: ) Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 13e4 Startzeit: 01cf04f64eb3bee8 Endzeit: 4294967295 Anwendungspfad: C:\Windows\system32\wwahost.exe Berichts-ID: 9745ef5a-70e9-11e3-bea6-6036dda75de5 Vollständiger Name des fehlerhaften Pakets: Microsoft.BingWeather_1.5.1.245_x64__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App System errors: ============= Error: (12/31/2013 05:16:13 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SftService erreicht. Error: (12/31/2013 00:06:57 PM) (Source: DCOM) (User: CAROLINA) Description: {209500FC-6B45-4693-8871-6296C4843751} Error: (12/31/2013 00:00:17 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SftService erreicht. Error: (12/30/2013 06:44:22 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "McAfee Inc. mfeapfk" wurde aufgrund folgenden Fehlers nicht gestartet: %%1243 Error: (12/30/2013 06:44:07 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 30.12.2013 um 15:17:12 unerwartet heruntergefahren. Error: (12/30/2013 06:42:01 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: {211EBA3A-EA5A-496B-A021-5C6BEB365E4C} Error: (12/30/2013 03:24:39 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: {211EBA3A-EA5A-496B-A021-5C6BEB365E4C} Error: (12/30/2013 03:23:34 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: {211EBA3A-EA5A-496B-A021-5C6BEB365E4C} Error: (12/29/2013 08:49:25 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80246007 fehlgeschlagen: Update für Microsoft Office 2010 (KB2850079) 32-Bit-Edition Error: (12/29/2013 01:35:26 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: 1053Bluetooth Device MonitorNicht verfügbar{DABF28BE-F6B4-4E40-8F40-C4FB26F3116C} Microsoft Office Sessions: ========================= Error: (01/02/2014 02:06:00 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 80070005 Error: (12/31/2013 05:20:48 PM) (Source: Application Error)(User: ) Description: TOASTER.EXE1.0.0.4450b3754funknown0.0.0.000000000c0000005049ead5f1a6001cf064441297714C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXEunknown819efdc9-7237-11e3-bea7-6036dda75de5 Error: (12/31/2013 05:20:47 PM) (Source: .NET Runtime)(User: ) Description: Anwendung: TOASTER.EXE Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.NullReferenceException Stapel: bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.DispatcherOperation.InvokeImpl() bei System.Windows.Threading.DispatcherOperation.InvokeInSecurityContext(System.Object) bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Windows.Threading.DispatcherOperation.Invoke() bei System.Windows.Threading.Dispatcher.ProcessQueue() bei System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) bei MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) bei System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame) bei System.Windows.Threading.Dispatcher.Run() bei System.Windows.Application.RunDispatcher(System.Object) bei System.Windows.Application.RunInternal(System.Windows.Window) bei System.Windows.Application.Run(System.Windows.Window) bei Toaster.App.Main() Error: (12/31/2013 05:20:46 PM) (Source: TOASTER.EXE)(User: ) Description: An Unhandled Exception occured. Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt. bei Toaster.Helper.GetDelayBeforeReminders(ObservableCollection`1 notificationHelpers) bei Toaster.ToasterTimerManager.SetNextNotification() bei Toaster.ToasterTimerManager.UpdateAllTimers() bei Toaster.ToasterTimerManager.InitTimers() bei Toaster.ToasterTimerManager.GetInstance() bei Toaster.MainWindowViewModel..ctor() bei Toaster.App.OnStartup(StartupEventArgs e) bei System.Windows.Application.<.ctor>b__1(Object unused) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback, Object args, Int32 numArgs) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(Object source, Delegate method, Object args, Int32 numArgs, Delegate catchHandler) Error: (12/31/2013 00:57:31 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 80070005 Error: (12/30/2013 00:26:41 PM) (Source: Application Error)(User: ) Description: CNSEUPDT.EXE1.3.5.04e3a32f0CNMDWLD.DLL1.0.0.04cad61a4c0000005000024c0ddc01cf0551e6ccd292C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXEC:\Program Files (x86)\Canon\Solution Menu EX\CNMDWLD.DLL40cd1bfc-7145-11e3-bea6-6036dda75de5 Error: (12/30/2013 00:25:21 PM) (Source: ESENT)(User: ) Description: taskhostex5532C:\Users\Carolina\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat-1032 (0xfffffbf8)32 (0x00000020)Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird. Error: (12/30/2013 01:30:41 AM) (Source: ATIeRecord)(User: ) Description: Error: (12/30/2013 01:30:34 AM) (Source: Microsoft-Windows-Immersive-Shell)(User: CAROLINA) Description: Microsoft.BingWeather_8wekyb3d8bbwe!App-2144927142 Error: (12/30/2013 01:30:33 AM) (Source: Application Hang)(User: ) Description: wwahost.exe6.2.9200.1642013e401cf04f64eb3bee84294967295C:\Windows\system32\wwahost.exe9745ef5a-70e9-11e3-bea6-6036dda75de5Microsoft.BingWeather_1.5.1.245_x64__8wekyb3d8bbweApp ==================== Memory info =========================== Percentage of memory in use: 47% Total physical RAM: 8061.27 MB Available physical RAM: 4264.88 MB Total Pagefile: 9277.27 MB Available Pagefile: 4311.32 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:917.1 GB) (Free:812.99 GB) NTFS Drive e: () (Removable) (Total:1.87 GB) (Free:1.6 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 7FD47089) Partition: GPT Partition Type ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=2 GB) - (Type=06) ==================== End Of Log ============================ |
Themen zu BCD-Fehler und fehlendes wow64cpu.dll |
andere, anderen, bildschirm, blauer, blauer bildschirm, desktop, escape, file, folge, folgendes, herstellen, hängen, installieren, laptop, plötzlich, problem, programm, prüfen, recovery, servus, setup, starten, test, virus, wieder herstellen, windows |