![]() |
|
Log-Analyse und Auswertung: Win 8.1: langsames InternetWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Win 8.1: langsames Internet Hallo, habe seit kurzem das Problem das mein Internet sehr langsam ist, komischerweise habe ich grade eine Datei mit 200 kb/s runtergeladen aber Seiten oder sonst was lädt der nur sehr langsam oder überhaupt nicht. Hier die logs: Malwarebytes Anti-Malware Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 23.04.2014 Suchlauf-Zeit: 15:46:48 Logdatei: Malware Anti.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.03.04.09 Rootkit Datenbank: v2014.02.20.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Raphael Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 286073 Verstrichene Zeit: 34 Min, 10 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 2 PUP.Optional.InstallCore.A, HKU\S-1-5-21-1373000766-1126567924-601248936-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [88c14cb3552594a28fe9a9eb7f83fb05], PUP.Optional.InstallCore.A, HKU\S-1-5-21-1373000766-1126567924-601248936-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [2e1bdb24235704325579adfd1fe4bc44], Registrierungswerte: 1 PUP.Optional.InstallCore.A, HKU\S-1-5-21-1373000766-1126567924-601248936-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0X2O1C0R2R1R, In Quarantäne, [2e1bdb24235704325579adfd1fe4bc44] Registrierungsdaten: 0 (No malicious items detected) Ordner: 2 PUP.Optional.RegCleanerPro.A, C:\Users\Raphael\AppData\Roaming\Systweak\RegClean Pro, In Quarantäne, [7fca37c8acce0b2bd139ccbb649e54ac], PUP.Optional.RegCleanerPro.A, C:\Users\Raphael\AppData\Roaming\Systweak\RegClean Pro\Version 6.1, In Quarantäne, [7fca37c8acce0b2bd139ccbb649e54ac], Dateien: 2 PUP.Optional.RegCleanerPro, C:\Users\Raphael\AppData\Local\Temp\is1070216317\4567992_stp\rcpsetup_adppi_adppi.exe, In Quarantäne, [7ecb3ec16218c076a33a3c1029d8f10f], PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [ef5ace31c0baf1457a9c107eb052aa56], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 16:14 on 23/04/2014 (Raphael) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2014 Ran by Raphael at 2014-04-23 16:15:53 Running from C:\Users\Raphael\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Kaspersky Internet Security (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Disabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.1.0.4880 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Help Manager (x32 Version: 4.0.244 - Adobe Systems Incorporated) Hidden Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated) Adobe Premiere Pro CS6 (HKLM-x32\...\{7176B973-6011-43C1-AEBC-2D73FE7C6982}) (Version: 6.0 - Adobe Systems Incorporated) Apowersoft Gratis - Audiorekorder V2.1.2 (HKLM-x32\...\{E35F91E4-C68C-43E8-BE90-35CDEE4E5730}_is1) (Version: 2.1.2 - Apowersoft) Apple Application Support (HKLM-x32\...\{21FC2093-6E43-460B-B9B0-5F5AA35BBB0F}) (Version: 3.0 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}) (Version: 7.1.0.32 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Autodesk Backburner 2014 (HKLM-x32\...\{3D347E6D-5A03-4342-B5BA-6A771885F379}) (Version: 14.0.0.0 - Autodesk, Inc.) Autodesk Composite 2014 (HKLM\...\Autodesk Composite 2014) (Version: 9.0.0.0 - Autodesk) Autodesk Composite 2014 (Version: 9.0.0.0 - Autodesk) Hidden Autodesk DirectConnect 2014 64-bit (HKLM\...\Autodesk DirectConnect 2014 64-bit) (Version: 8.0.56.1 - Autodesk) Autodesk DirectConnect 2014 64-bit (Version: 8.0.56.1 - Autodesk) Hidden Autodesk MatchMover 2014 (HKLM\...\{B151ECD3-2DBE-45E9-816E-F8AA6238F6A8}) (Version: 14.00.0000 - Autodesk) Autodesk Maya 2014 (HKLM\...\Autodesk Maya 2014) (Version: 16.0.0.0 - Autodesk) Autodesk Maya 2014 (Version: 16.0.0.0 - Autodesk) Hidden Banished (HKLM-x32\...\QmFuaXNoZWQ=_is1) (Version: 1 - ) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.2.0.0 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.2 - EA Digital Illusions CE AB) bl (x32 Version: 1.0.0 - Your Company Name) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive) Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{F68634D8-574F-42B2-B6D0-9B447EA9581E}) (Version: - Microsoft) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) Euro Truck Simulator 2 (HKLM-x32\...\Steam App 227300) (Version: - SCS Software) Explorer Suite IV (HKLM\...\Explorer Suite_is1) (Version: - ) FUSSBALL MANAGER 13 (HKLM-x32\...\{80AF0300-866F-400F-A350-D53E3C3E34E0}) (Version: 1.0.4.0 - Electronic Arts) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Ghost Recon Online (EU) (HKCU\...\d8be6c3f847d7d92) (Version: 1.35.3440.2 - Ubisoft) HAWKEN (HKLM-x32\...\Steam App 271290) (Version: - Adhesive Games) HP Officejet 6600 - Grundlegende Software für das Gerät (HKLM\...\{F58934BD-F483-43EB-B307-CFFD88B18455}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation) iTunes (HKLM\...\{96B53CA8-5ABB-49D8-96F1-F6C0D73A76C6}) (Version: 11.1.4.62 - Apple Inc.) Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) Hidden M.U.D. TV (HKLM-x32\...\{E71AC707-179D-458D-A1E8-F52977CAEAB4}) (Version: 1.0.0.0 - Realmforge Studios GmbH) Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) mental ray renderer for Autodesk Maya 2014 (HKLM\...\{4F5AD3FF-38C6-43FB-BB6F-8EF830DEDF16}) (Version: 13.0.0.0 - mental ray) Microsoft Access MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft DCF MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Excel MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Groove MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft InfoPath MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Lync MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office 32-bit Components 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM UX MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft OneNote MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Outlook MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft PowerPoint MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Publisher MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Word MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Music Manager (HKCU\...\MusicManager) (Version: - Google, Inc.) NVIDIA 3D Vision Controller-Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.82 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.82 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8 - NVIDIA Corporation) NVIDIA Grafiktreiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.82 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.142.992 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Photoshop Plug-ins 64 bit (HKLM-x32\...\{5E386C5B-CDE7-435A-B5C9-EC73A1B0553A}) (Version: 8.50 - ) NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation) NVIDIA ShadowPlay 10.10.5 (Version: 10.10.5 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3182 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 331.82 (Version: 331.82 - NVIDIA Corporation) Hidden NVIDIA Update 10.10.5 (Version: 10.10.5 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 10.10.5 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.12 - NVIDIA Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.3.10.4710 - Electronic Arts, Inc.) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden ph (x32 Version: 1.0.0 - Your Company Name) Hidden PlanetSide 2 (HKCU\...\SOE-PlanetSide 2) (Version: 1.0.3.183 - Sony Online Entertainment) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) QuickTime Alternative 1.81 (HKLM-x32\...\QuicktimeAlt_is1) (Version: 1.81 - ) Rainmeter (HKLM-x32\...\Rainmeter) (Version: 3.1 beta r2187 - ) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden SHIELD Streaming (Version: 1.6.75 - NVIDIA Corporation) Hidden SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 2.0.0.0 - Electronic Arts) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) State of Decay Version 1.0 (HKLM-x32\...\State of Decay_is1) (Version: 1.0 - Undead Labs) Stonehearth (HKLM-x32\...\{E651F539-2C1E-41BF-BD4C-4B531D72FEF4}) (Version: 0.1.0.52 - Radiant Entertainment) Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve) Update for Microsoft Excel 2013 (KB2752087) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{A2275591-C3AA-4A6C-A696-F958B6C65B3E}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2752087) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{A2275591-C3AA-4A6C-A696-F958B6C65B3E}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2752087) 64-Bit Edition (HKLM\...\{90150000-0018-0407-1000-0000000FF1CE}_Office15.PROPLUS_{A2275591-C3AA-4A6C-A696-F958B6C65B3E}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2752087) 64-Bit Edition (HKLM\...\{90150000-001B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{A2275591-C3AA-4A6C-A696-F958B6C65B3E}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2752087) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{A2275591-C3AA-4A6C-A696-F958B6C65B3E}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2817678) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{237834D6-FA98-44E1-8739-ABD56DDADC59}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2863908) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{259F7CA1-7A87-4E60-85A9-0A55E60FF254}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2863908) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{259F7CA1-7A87-4E60-85A9-0A55E60FF254}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2863908) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{8D84B988-2A7A-4DB6-A7A5-08DA7B3DE9EE}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760344) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EF77B4A6-DFEC-4010-A87D-9B6BF87FABEC}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760544) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{62857CDD-2985-4939-91BA-19ED0B0031A5}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2768012) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{0814662C-FD28-4DE0-ACE5-EE50D1D6C8FB}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817636) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D97AACA3-9AEA-43FF-8CBA-93BED0443FC2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817636) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{D97AACA3-9AEA-43FF-8CBA-93BED0443FC2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817636) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D97AACA3-9AEA-43FF-8CBA-93BED0443FC2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2825631) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{A54917FC-2C84-40F2-9525-7549BE08DE40}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2825631) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{A54917FC-2C84-40F2-9525-7549BE08DE40}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2825631) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{A54917FC-2C84-40F2-9525-7549BE08DE40}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827272) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{50F6EF67-B93C-4B7A-A2EB-E179E3436C69}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827272) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{50F6EF67-B93C-4B7A-A2EB-E179E3436C69}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827272) 64-Bit Edition (HKLM\...\{90150000-0090-0407-1000-0000000FF1CE}_Office15.PROPLUS_{50F6EF67-B93C-4B7A-A2EB-E179E3436C69}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863825) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{327EABFD-EDD3-44E7-AB47-7592DF33B719}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863843) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{290D80DE-03AB-47EC-9402-108AF4CE4F66}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863844) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{50F31E04-D56A-4159-BF36-CF3CE27DB30C}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863860) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6D170CB5-8D22-4D1B-A811-B899FE588946}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863860) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6D170CB5-8D22-4D1B-A811-B899FE588946}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2863864) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{AFB7E303-C8CA-4A08-AD3F-44A562B3C809}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2863864) 64-Bit Edition (HKLM\...\{90150000-00BA-0407-1000-0000000FF1CE}_Office15.PROPLUS_{AFB7E303-C8CA-4A08-AD3F-44A562B3C809}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2863864) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{AFB7E303-C8CA-4A08-AD3F-44A562B3C809}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2863864) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{AFB7E303-C8CA-4A08-AD3F-44A562B3C809}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2817628) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{9367C385-2EF9-4BE3-8351-7D2AB0798A57}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2817628) 64-Bit Edition (HKLM\...\{90150000-00A1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{9367C385-2EF9-4BE3-8351-7D2AB0798A57}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2817628) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{9367C385-2EF9-4BE3-8351-7D2AB0798A57}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2863911) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{DF3798F3-F45C-44DA-83B7-229A9EBC9654}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2863911) 64-Bit Edition (HKLM\...\{90150000-001A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{DAEE93F9-D258-45E4-AFD3-12AC5ED04693}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2837627) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{FE06DACB-AE2C-4DB7-B95D-97A320E59F45}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2837627) 64-Bit Edition (HKLM\...\{90150000-0018-0407-1000-0000000FF1CE}_Office15.PROPLUS_{FE06DACB-AE2C-4DB7-B95D-97A320E59F45}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2863909) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{F9FAC8C0-20D9-4DC7-9A56-13B02BD4B724}) (Version: - Microsoft) VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN) Warface Launcher (Beta) (HKLM-x32\...\{28D1723C-31C4-4A83-9799-DFFB3739026D}) (Version: 1.0.0 - Crytek GmbH) WinRAR 5.00 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) XMedia Recode Version 3.1.8.2 (HKLM-x32\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.8.2 - XMedia Recode) Zoo Tycoon 2 (HKLM-x32\...\Zoo Tycoon 2) (Version: 1.0 - Microsoft) ==================== Restore Points ========================= 07-04-2014 16:31:59 Windows Update 10-04-2014 17:23:56 Windows Update 18-04-2014 09:45:54 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3ADDA047-CA6D-472B-8997-123BF637354A} - System32\Tasks\Microsoft Office 15 Sync Maintenance for BERNZEN-Raphael Bernzen => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2014-01-23] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {816B6FCF-D9C8-40C3-AA3E-DDE3F114289D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {85142E75-B444-452A-BC63-E5F02D0A16ED} - System32\Tasks\AdobeAAMUpdater-1.0-Bernzen-Raphael => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-03] (Adobe Systems Incorporated) Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {94786DF6-3811-40C2-A029-8A32BA87909B} - System32\Tasks\FoxTab => C:\Users\Raphael\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {AA79C3BD-6D57-4CF9-81E0-AC037AFF1D12} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1373000766-1126567924-601248936-1001UA => C:\Users\Raphael\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-12] (Google Inc.) Task: {B47CB2DF-B8F4-4F93-BD61-750305B10018} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {BA0F74F9-0755-4D53-A51C-F9210B1AEB1C} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D6B2E614-855D-483D-8797-DA5CD9D64D09} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-11] (Adobe Systems Incorporated) Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {E9B90C1B-424A-4CBD-BEF7-89F6DCF0CDCF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1373000766-1126567924-601248936-1001Core => C:\Users\Raphael\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-12] (Google Inc.) Task: {F20B964E-B36E-4EE1-86A1-761108082A12} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-04-09] (Microsoft Corporation) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\FoxTab.job => C:\Users\Raphael\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1373000766-1126567924-601248936-1001Core.job => C:\Users\Raphael\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1373000766-1126567924-601248936-1001UA.job => C:\Users\Raphael\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-11-01 14:39 - 2013-11-11 17:02 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-11-01 16:38 - 2014-03-07 19:24 - 00076888 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2013-11-10 18:51 - 2013-11-10 18:51 - 00036536 _____ () E:\Programme\Rainmeter\Rainmeter.exe 2013-11-10 18:51 - 2013-11-10 18:51 - 00804536 _____ () E:\Programme\Rainmeter\Rainmeter.dll 2013-11-10 18:49 - 2013-11-10 18:49 - 00058880 _____ () E:\Programme\Rainmeter\Plugins\WebParser.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-03-29 12:34 - 2014-03-29 12:34 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Raphael\Cookies:eMYIoD28EmH7nihZTe1tHyRSz AlternateDataStreams: C:\Users\Raphael\Cookies:Et7hKUTDiSiA5NQ0nOpzmV0KF AlternateDataStreams: C:\Users\Raphael\Lokale Einstellungen:0mkGklRemZbIEcaiHFHV AlternateDataStreams: C:\Users\Raphael\SkyDrive:ms-properties AlternateDataStreams: C:\Users\Raphael\SkyDrive (2).old:ms-properties AlternateDataStreams: C:\Users\Raphael\SkyDrive (3).old:ms-properties AlternateDataStreams: C:\Users\Raphael\SkyDrive.old:ms-properties AlternateDataStreams: C:\Users\Raphael\AppData\Local:0mkGklRemZbIEcaiHFHV AlternateDataStreams: C:\Users\Raphael\AppData\Local\Anwendungsdaten:0mkGklRemZbIEcaiHFHV ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/23/2014 02:38:30 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (04/23/2014 02:34:26 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (04/23/2014 02:01:39 PM) (Source: Office 2013 Licensing Service) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (04/22/2014 07:48:07 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (04/22/2014 07:44:04 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (04/22/2014 04:32:41 PM) (Source: Application Error) (User: ) Description: Aus einem der folgenden Gründe kann nicht auf die Datei "" zugegriffen werden: Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger mit der gespeicherten Datei bzw. den auf dem Computer installierten Speichertreibern, oder der Datenträger fehlt. Das Programm FUSSBALL MANAGER 13 wurde wegen dieses Fehlers geschlossen. Programm: FUSSBALL MANAGER 13 Datei: Der Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet. Benutzeraktion 1. Öffnen Sie die Datei erneut. Diese Situation ist eventuell ein temporäres Problem, das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird. 2. Wenn Sie weiterhin nicht auf die Datei zugreifen können und - diese sich im Netzwerk befindet, dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem besteht und dass eine Verbindung mit dem Server hergestellt werden kann. - diese sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet, überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist. 3. Überprüfen und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE. 4. Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin besteht. 5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt. Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware, um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt. Zusätzliche Daten Fehlerwert: 00000000 Datenträgertyp: 0 Error: (04/22/2014 04:32:41 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Manager13.exe, Version: 1.0.4.0, Zeitstempel: 0x026d3040 Name des fehlerhaften Moduls: Manager13.exe, Version: 1.0.4.0, Zeitstempel: 0x026d3040 Ausnahmecode: 0xc000001d Fehleroffset: 0x014f5fb0 ID des fehlerhaften Prozesses: 0x13f4 Startzeit der fehlerhaften Anwendung: 0xManager13.exe0 Pfad der fehlerhaften Anwendung: Manager13.exe1 Pfad des fehlerhaften Moduls: Manager13.exe2 Berichtskennung: Manager13.exe3 Vollständiger Name des fehlerhaften Pakets: Manager13.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Manager13.exe5 Error: (04/22/2014 11:46:01 AM) (Source: Application Error) (User: ) Description: Aus einem der folgenden Gründe kann nicht auf die Datei "" zugegriffen werden: Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger mit der gespeicherten Datei bzw. den auf dem Computer installierten Speichertreibern, oder der Datenträger fehlt. Das Programm FUSSBALL MANAGER 13 wurde wegen dieses Fehlers geschlossen. Programm: FUSSBALL MANAGER 13 Datei: Der Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet. Benutzeraktion 1. Öffnen Sie die Datei erneut. Diese Situation ist eventuell ein temporäres Problem, das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird. 2. Wenn Sie weiterhin nicht auf die Datei zugreifen können und - diese sich im Netzwerk befindet, dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem besteht und dass eine Verbindung mit dem Server hergestellt werden kann. - diese sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet, überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist. 3. Überprüfen und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE. 4. Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin besteht. 5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt. Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware, um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt. Zusätzliche Daten Fehlerwert: 00000000 Datenträgertyp: 0 Error: (04/22/2014 11:46:01 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Manager13.exe, Version: 1.0.4.0, Zeitstempel: 0x026d3040 Name des fehlerhaften Moduls: Manager13.exe, Version: 1.0.4.0, Zeitstempel: 0x026d3040 Ausnahmecode: 0xc000001d Fehleroffset: 0x014f5fb0 ID des fehlerhaften Prozesses: 0x9f4 Startzeit der fehlerhaften Anwendung: 0xManager13.exe0 Pfad der fehlerhaften Anwendung: Manager13.exe1 Pfad des fehlerhaften Moduls: Manager13.exe2 Berichtskennung: Manager13.exe3 Vollständiger Name des fehlerhaften Pakets: Manager13.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Manager13.exe5 Error: (04/22/2014 10:40:43 AM) (Source: Office 2013 Licensing Service) (User: ) Description: Subscription licensing service failed: -1073418154 System errors: ============= Error: (04/23/2014 02:28:03 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Apple Mobile Device" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/23/2014 02:27:59 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definitionsupdate für Windows Defender – KB2267602 (Definition 1.173.413.0) Error: (04/23/2014 02:02:58 PM) (Source: Service Control Manager) (User: ) Description: Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. Error: (04/23/2014 02:01:44 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/23/2014 02:00:56 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Apple Mobile Device" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/23/2014 01:57:21 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Apple Mobile Device" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/23/2014 01:57:07 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/23/2014 00:55:23 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Superfetch" wurde mit folgendem Fehler beendet: %%1062 Error: (04/22/2014 10:53:30 PM) (Source: disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (04/22/2014 07:31:30 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Superfetch" wurde mit folgendem Fehler beendet: %%1062 Microsoft Office Sessions: ========================= Error: (04/23/2014 02:38:30 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"e:\programme\Autodesk\composite2014\python\lib\distutils\command\wininst-8_d.exe Error: (04/23/2014 02:34:26 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"e:\programme\Autodesk\composite2014\python\lib\distutils\command\wininst-8_d.exe Error: (04/23/2014 02:01:39 PM) (Source: Office 2013 Licensing Service)(User: ) Description: Subscription licensing service failed: -1073418154 Error: (04/22/2014 07:48:07 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"e:\programme\Autodesk\composite2014\python\lib\distutils\command\wininst-8_d.exe Error: (04/22/2014 07:44:04 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"e:\programme\Autodesk\composite2014\python\lib\distutils\command\wininst-8_d.exe Error: (04/22/2014 04:32:41 PM) (Source: Application Error)(User: ) Description: FUSSBALL MANAGER 13000000000 Error: (04/22/2014 04:32:41 PM) (Source: Application Error)(User: ) Description: Manager13.exe1.0.4.0026d3040Manager13.exe1.0.4.0026d3040c000001d014f5fb013f401cf5e37a8f8bcd6C:\Program Files (x86)\Origin Games\FIFA Manager 13\Manager13.exeC:\Program Files (x86)\Origin Games\FIFA Manager 13\Manager13.exef547ff91-ca2a-11e3-829a-14dae9390ddc Error: (04/22/2014 11:46:01 AM) (Source: Application Error)(User: ) Description: FUSSBALL MANAGER 13000000000 Error: (04/22/2014 11:46:01 AM) (Source: Application Error)(User: ) Description: Manager13.exe1.0.4.0026d3040Manager13.exe1.0.4.0026d3040c000001d014f5fb09f401cf5e0fa4977d5bC:\Program Files (x86)\Origin Games\FIFA Manager 13\Manager13.exeC:\Program Files (x86)\Origin Games\FIFA Manager 13\Manager13.exee940d88c-ca02-11e3-8299-14dae9390ddc Error: (04/22/2014 10:40:43 AM) (Source: Office 2013 Licensing Service)(User: ) Description: Subscription licensing service failed: -1073418154 ==================== Memory info =========================== Percentage of memory in use: 21% Total physical RAM: 8173.24 MB Available physical RAM: 6450.5 MB Total Pagefile: 9453.24 MB Available Pagefile: 7402.61 MB Total Virtual: 131072 MB Available Virtual: 131071.79 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:478.5 GB) (Free:256.21 GB) NTFS Drive d: (HITACHI) (Fixed) (Total:931.51 GB) (Free:130.86 GB) NTFS Drive e: (Bernzen) (Fixed) (Total:452.91 GB) (Free:175.86 GB) NTFS Drive f: (LS2013) (CDROM) (Total:1.36 GB) (Free:0 GB) CDFS Drive h: () (Removable) (Total:29.31 GB) (Free:24.06 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 3D4849AF) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=479 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=453 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 932 GB) (Disk ID: 6278319A) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 29 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014 Ran by Raphael (administrator) on BERNZEN on 23-04-2014 16:15:23 Running from C:\Users\Raphael\Desktop Windows 8.1 Pro (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\WINDOWS\system32\dashost.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\WINDOWS\SysWOW64\PnkBstrA.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\skydrive.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe () E:\Programme\Rainmeter\Rainmeter.exe (Apple Inc.) E:\Programme\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\WINDOWS\system32\taskmgr.exe (Microsoft Corporation) C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17031_none_fa50b3979b1bcb4a\TiWorker.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-03] (Adobe Systems Incorporated) HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\nvspcap64.dll [1096480 2013-11-29] (NVIDIA Corporation) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2273056 2013-11-29] (NVIDIA Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Realtime Audio Engine] => "mmrtkrnl.exe" /i HKLM-x32\...\Run: [iTunesHelper] => E:\Programme\iTunes\iTunesHelper.exe [152392 2014-02-06] (Apple Inc.) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1373000766-1126567924-601248936-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1373000766-1126567924-601248936-1001\...\Run: [HP Officejet 6600 (NET)] => C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-1373000766-1126567924-601248936-1001\...\Run: [Google Update] => C:\Users\Raphael\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-02-12] (Google Inc.) HKU\S-1-5-21-1373000766-1126567924-601248936-1001\...\MountPoints2: {72d3b8b9-cec3-11e2-be6b-14dae9390ddc} - "G:\setup.exe" HKU\S-1-5-21-1373000766-1126567924-601248936-1001\...\MountPoints2: {760a63e4-ca03-11e2-be66-806e6f6e6963} - "F:\cdstart.exe" Startup: C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk ShortcutTarget: Rainmeter.lnk -> E:\Programme\Rainmeter\Rainmeter.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x54D79DCAEA5ECF01 BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\jemj500s.default FF Homepage: hxxp://de.msn.com/ FF NetworkProxy: "backup.ftp", "" FF NetworkProxy: "backup.ftp_port", 0 FF NetworkProxy: "backup.socks", "" FF NetworkProxy: "backup.socks_port", 0 FF NetworkProxy: "backup.ssl", "" FF NetworkProxy: "backup.ssl_port", 0 FF NetworkProxy: "ftp", "189.254.5.82" FF NetworkProxy: "ftp_port", 8080 FF NetworkProxy: "http", "189.254.5.82" FF NetworkProxy: "http_port", 8080 FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "189.254.5.82" FF NetworkProxy: "socks_port", 8080 FF NetworkProxy: "ssl", "189.254.5.82" FF NetworkProxy: "ssl_port", 8080 FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.0 - E:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 - E:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - E:\Programme\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll No File FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Raphael\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Raphael\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: YouTube ALL HTML5 - C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\jemj500s.default\Extensions\jid1-qj0w91o64N7Eeg@jetpack.xpi [2013-11-09] FF Extension: Download YouTube Videos as MP4 - C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\jemj500s.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2013-11-05] FF Extension: Adblock Plus - C:\Users\Raphael\AppData\Roaming\Mozilla\Firefox\Profiles\jemj500s.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-11-05] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2013-11-02] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2013-11-02] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2013-11-02] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2013-11-02] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2013-11-02] ==================== Services (Whitelisted) ================= S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1370912 2013-11-29] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15128352 2013-11-29] (NVIDIA Corporation) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2014-03-07] () R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-11-17] (DT Soft Ltd) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-08-23] (Microsoft Corporation) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-11-06] (Kaspersky Lab ZAO) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29792 2013-11-06] (Kaspersky Lab) U5 klflt; C:\Windows\System32\Drivers\klflt.sys [115296 2014-03-20] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625760 2014-03-20] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2014-02-17] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [65120 2014-03-20] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178272 2013-12-18] (Kaspersky Lab ZAO) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2013-10-30] (NVIDIA Corporation) R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-10] (Corel Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation) S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2013-08-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-23 16:15 - 2014-04-23 16:15 - 00018301 _____ () C:\Users\Raphael\Desktop\FRST.txt 2014-04-23 16:15 - 2014-04-23 16:15 - 00000000 ____D () C:\FRST 2014-04-23 16:14 - 2014-04-23 16:14 - 00000476 _____ () C:\Users\Raphael\Desktop\defogger_disable.log 2014-04-23 16:14 - 2014-04-23 16:14 - 00000000 _____ () C:\Users\Raphael\defogger_reenable 2014-04-23 16:10 - 2014-04-23 16:06 - 02061312 ____N (Farbar) C:\Users\Raphael\Desktop\FRST64.exe 2014-04-23 16:10 - 2014-04-23 16:06 - 00380416 ____N () C:\Users\Raphael\Desktop\Gmer-19357.exe 2014-04-23 16:10 - 2014-04-23 16:06 - 00050477 ____N () C:\Users\Raphael\Desktop\Defogger.exe 2014-04-23 16:09 - 2014-04-23 15:29 - 100242441 ____N (Realtek Semiconductor Corp.) C:\Users\Raphael\Desktop\32bit_Win7_Win8_Win81_R273.exe 2014-04-23 15:56 - 2014-04-23 15:56 - 00002203 _____ () C:\Users\Raphael\Desktop\ Malwarebytes Anti-Malware .txt 2014-04-23 15:11 - 2014-04-23 15:55 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-04-23 15:11 - 2014-04-23 15:11 - 00000750 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-23 15:11 - 2014-04-23 15:11 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-23 15:11 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-04-23 15:11 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2014-04-23 15:11 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-04-23 15:09 - 2014-04-23 15:10 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Raphael\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-23 14:27 - 2014-01-19 09:38 - 00270496 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2014-04-23 14:19 - 2014-04-23 14:19 - 00002346 _____ () C:\Users\Raphael\Desktop\Sicherer Zahlungsverkehr.lnk 2014-04-23 14:17 - 2014-04-23 14:17 - 00001140 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-04-22 10:40 - 2014-04-22 10:40 - 00000276 _____ () C:\Users\Raphael\Downloads\SLAMFM_MEDIAPLAYER.asx 2014-04-21 21:19 - 2014-04-21 21:21 - 00000132 _____ () C:\Users\Raphael\AppData\Roaming\Adobe CS6-Targa-Format - Voreinstellungen 2014-04-20 19:33 - 2014-04-20 19:33 - 00000000 ____D () C:\Users\Raphael\Desktop\FENDT_MIX_FIN 2014-04-20 19:33 - 2014-04-20 19:32 - 03441973 ____N () C:\Users\Raphael\Desktop\FENDT_MIX_FIN.zip 2014-04-18 17:21 - 2014-04-18 17:21 - 00000000 ____D () C:\Users\Public\Documents\Explorer Suite Signatures 2014-04-16 18:21 - 2014-04-16 18:21 - 00000000 ____D () C:\Users\Raphael\Downloads\Club_of_fans_Dance 2014-04-15 22:13 - 2014-04-15 23:19 - 723977226 _____ () C:\Users\Raphael\Downloads\Club_of_fans_Dance.rar 2014-04-13 12:36 - 2014-04-13 20:18 - 00000000 ____D () C:\Users\Raphael\Downloads\Kontor - Top of The Clubs 2014.2 2014-04-12 14:31 - 2014-04-12 14:31 - 00000470 _____ () C:\Users\Raphael\Downloads\001. TB.asx 2014-04-09 20:44 - 2014-03-06 11:19 - 01287576 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2014-04-09 20:44 - 2014-03-06 11:02 - 01109424 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2014-04-09 20:44 - 2014-03-06 08:17 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2014-04-09 20:44 - 2014-03-06 08:10 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2014-04-09 20:43 - 2014-03-10 12:35 - 02008408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2014-04-09 20:43 - 2014-03-10 12:35 - 00377176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2014-04-09 20:33 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-04-09 20:33 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-04-09 18:29 - 2014-04-09 18:29 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2014-04-09 18:29 - 2014-04-09 18:29 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2014-04-08 21:53 - 2014-04-11 19:47 - 00000000 ____D () C:\Users\Raphael\Desktop\Familienfest 2014 2014-03-30 21:47 - 2014-03-30 21:49 - 00000000 ____D () C:\Users\Raphael\AppData\Roaming\MudTV 2014-03-30 14:42 - 2014-04-06 19:40 - 00000000 ____D () C:\Users\Raphael\AppData\Local\Game Dev Tycoon - Steam 2014-03-29 12:34 - 2014-03-29 12:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-26 17:32 - 2014-03-26 17:32 - 00000085 _____ () C:\Users\Raphael\Downloads\stream.wax 2014-03-24 23:09 - 2014-03-24 23:09 - 00000000 ____D () C:\Users\Raphael\.MCTranscodingSDK 2014-03-24 23:08 - 2014-03-24 23:13 - 00000000 ____D () C:\Users\Public\Documents\Lightworks 2014-03-24 23:08 - 2014-03-24 23:08 - 00000000 ____D () C:\ProgramData\Geevs 2014-03-24 20:33 - 2014-03-24 20:33 - 00000000 ____D () C:\Users\Raphael\AppData\Roaming\XMedia Recode 2014-03-24 19:09 - 2014-03-24 19:09 - 00000000 ____D () C:\Users\Raphael\AppData\Roaming\MPEG Streamclip 2014-03-24 19:08 - 2014-03-24 19:08 - 00000000 ____D () C:\Program Files (x86)\Media Player Classic 2014-03-24 19:08 - 2007-04-27 10:42 - 00065536 _____ (Apple Inc.) C:\WINDOWS\SysWOW64\QuickTimeVR.qtx 2014-03-24 19:08 - 2007-04-27 10:42 - 00049152 _____ (Apple Inc.) C:\WINDOWS\SysWOW64\QuickTime.qts 2014-03-24 19:08 - 2004-01-12 01:00 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr71.dll 2014-03-24 19:08 - 2003-03-19 06:14 - 00499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp71.dll ==================== One Month Modified Files and Folders ======= 2014-04-23 16:15 - 2014-04-23 16:15 - 00018301 _____ () C:\Users\Raphael\Desktop\FRST.txt 2014-04-23 16:15 - 2014-04-23 16:15 - 00000000 ____D () C:\FRST 2014-04-23 16:14 - 2014-04-23 16:14 - 00000476 _____ () C:\Users\Raphael\Desktop\defogger_disable.log 2014-04-23 16:14 - 2014-04-23 16:14 - 00000000 _____ () C:\Users\Raphael\defogger_reenable 2014-04-23 16:14 - 2013-11-01 13:59 - 01422970 _____ () C:\WINDOWS\WindowsUpdate.log 2014-04-23 16:14 - 2013-11-01 13:57 - 00000000 ____D () C:\Users\Raphael 2014-04-23 16:06 - 2014-04-23 16:10 - 02061312 ____N (Farbar) C:\Users\Raphael\Desktop\FRST64.exe 2014-04-23 16:06 - 2014-04-23 16:10 - 00380416 ____N () C:\Users\Raphael\Desktop\Gmer-19357.exe 2014-04-23 16:06 - 2014-04-23 16:10 - 00050477 ____N () C:\Users\Raphael\Desktop\Defogger.exe 2014-04-23 16:01 - 2013-11-05 17:20 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-04-23 16:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-04-23 15:57 - 2014-02-12 22:46 - 00001144 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1373000766-1126567924-601248936-1001UA.job 2014-04-23 15:56 - 2014-04-23 15:56 - 00002203 _____ () C:\Users\Raphael\Desktop\ Malwarebytes Anti-Malware .txt 2014-04-23 15:55 - 2014-04-23 15:11 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-04-23 15:54 - 2013-11-01 14:06 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1373000766-1126567924-601248936-1001 2014-04-23 15:53 - 2013-11-01 14:02 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-04-23 15:53 - 2013-08-23 01:24 - 00764340 _____ () C:\WINDOWS\system32\perfh007.dat 2014-04-23 15:53 - 2013-08-23 01:24 - 00159160 _____ () C:\WINDOWS\system32\perfc007.dat 2014-04-23 15:50 - 2014-03-17 22:03 - 00005124 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for BERNZEN-Raphael Bernzen 2014-04-23 15:50 - 2014-02-02 23:02 - 00000000 __RDO () C:\Users\Raphael\SkyDrive 2014-04-23 15:49 - 2013-11-02 12:59 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-04-23 15:49 - 2013-11-01 14:39 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-23 15:49 - 2013-11-01 13:53 - 00158630 _____ () C:\WINDOWS\PFRO.log 2014-04-23 15:49 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\schemas 2014-04-23 15:49 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-04-23 15:48 - 2013-08-22 15:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI 2014-04-23 15:47 - 2013-11-01 16:47 - 00000312 _____ () C:\WINDOWS\Tasks\FoxTab.job 2014-04-23 15:46 - 2013-11-01 16:47 - 00000000 ____D () C:\Users\Raphael\AppData\Roaming\Systweak 2014-04-23 15:29 - 2014-04-23 16:09 - 100242441 ____N (Realtek Semiconductor Corp.) C:\Users\Raphael\Desktop\32bit_Win7_Win8_Win81_R273.exe 2014-04-23 15:11 - 2014-04-23 15:11 - 00000750 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-23 15:11 - 2014-04-23 15:11 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-23 15:10 - 2014-04-23 15:09 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Raphael\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-23 14:27 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-04-23 14:23 - 2013-06-01 22:05 - 00000000 ____D () C:\Users\Raphael\Documents\Any Video Converter 2014-04-23 14:19 - 2014-04-23 14:19 - 00002346 _____ () C:\Users\Raphael\Desktop\Sicherer Zahlungsverkehr.lnk 2014-04-23 14:17 - 2014-04-23 14:17 - 00001140 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-04-23 14:11 - 2013-12-07 00:31 - 00007599 _____ () C:\Users\Raphael\AppData\Local\Resmon.ResmonCfg 2014-04-23 13:55 - 2013-11-02 13:05 - 00000000 ____D () C:\Users\Raphael\AppData\Local\Adobe 2014-04-22 16:31 - 2013-11-01 15:49 - 00000000 ____D () C:\ProgramData\Origin 2014-04-22 16:27 - 2013-11-01 15:48 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-04-22 11:45 - 2014-01-30 15:32 - 00000000 ____D () C:\Users\Raphael\Desktop\Silberhochzeit 2014-04-22 10:40 - 2014-04-22 10:40 - 00000276 _____ () C:\Users\Raphael\Downloads\SLAMFM_MEDIAPLAYER.asx 2014-04-21 21:21 - 2014-04-21 21:19 - 00000132 _____ () C:\Users\Raphael\AppData\Roaming\Adobe CS6-Targa-Format - Voreinstellungen 2014-04-21 20:57 - 2014-02-12 22:46 - 00001092 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1373000766-1126567924-601248936-1001Core.job 2014-04-21 13:17 - 2013-05-31 17:12 - 00000000 ____D () C:\Users\Raphael\AppData\Local\Packages 2014-04-20 19:33 - 2014-04-20 19:33 - 00000000 ____D () C:\Users\Raphael\Desktop\FENDT_MIX_FIN 2014-04-20 19:32 - 2014-04-20 19:33 - 03441973 ____N () C:\Users\Raphael\Desktop\FENDT_MIX_FIN.zip 2014-04-18 23:54 - 2013-05-31 18:14 - 00000000 ____D () C:\Users\Raphael\Desktop\Spiele 2014-04-18 17:21 - 2014-04-18 17:21 - 00000000 ____D () C:\Users\Public\Documents\Explorer Suite Signatures 2014-04-18 16:49 - 2013-11-01 16:37 - 00182245 _____ () C:\WINDOWS\DirectX.log 2014-04-18 14:45 - 2013-08-22 16:46 - 00058679 _____ () C:\WINDOWS\setupact.log 2014-04-17 21:01 - 2013-11-01 16:38 - 00214392 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe 2014-04-16 21:30 - 2013-11-01 16:01 - 00000000 ____D () C:\Program Files (x86)\Origin Games 2014-04-16 18:21 - 2014-04-16 18:21 - 00000000 ____D () C:\Users\Raphael\Downloads\Club_of_fans_Dance 2014-04-15 23:19 - 2014-04-15 22:13 - 723977226 _____ () C:\Users\Raphael\Downloads\Club_of_fans_Dance.rar 2014-04-14 19:55 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-04-13 20:18 - 2014-04-13 12:36 - 00000000 ____D () C:\Users\Raphael\Downloads\Kontor - Top of The Clubs 2014.2 2014-04-13 12:45 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\tracing 2014-04-13 12:15 - 2013-11-18 21:03 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-12 19:47 - 2013-11-06 17:15 - 00000132 _____ () C:\Users\Raphael\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen 2014-04-12 14:31 - 2014-04-12 14:31 - 00000470 _____ () C:\Users\Raphael\Downloads\001. TB.asx 2014-04-11 19:47 - 2014-04-08 21:53 - 00000000 ____D () C:\Users\Raphael\Desktop\Familienfest 2014 2014-04-10 17:38 - 2013-08-22 16:44 - 06888896 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-04-09 22:33 - 2013-11-16 11:57 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-04-09 22:32 - 2013-11-16 11:56 - 90655440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-04-09 18:29 - 2014-04-09 18:29 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2014-04-09 18:29 - 2014-04-09 18:29 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2014-04-08 21:50 - 2013-11-01 16:44 - 00000000 ____D () C:\Users\Raphael\AppData\Roaming\vlc 2014-04-08 19:46 - 2013-11-01 16:38 - 00214392 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.ex0 2014-04-07 18:45 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\System 2014-04-07 18:45 - 2013-08-22 15:25 - 00000167 _____ () C:\WINDOWS\win.ini 2014-04-07 18:41 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-04-06 19:40 - 2014-03-30 14:42 - 00000000 ____D () C:\Users\Raphael\AppData\Local\Game Dev Tycoon - Steam 2014-04-03 09:51 - 2014-04-23 15:11 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-23 15:11 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-23 15:11 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-04-01 13:39 - 2013-11-12 16:19 - 00000000 ____D () C:\Users\Raphael\AppData\Roaming\.minecraft 2014-04-01 13:15 - 2013-05-31 18:14 - 00000000 ____D () C:\Users\Raphael\Desktop\Programme 2014-04-01 13:09 - 2013-11-05 17:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-31 23:23 - 2013-08-22 17:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-03-31 23:23 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-31 03:16 - 2014-04-09 20:33 - 23134208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-03-31 01:57 - 2014-04-09 20:33 - 17073152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-03-30 21:49 - 2014-03-30 21:47 - 00000000 ____D () C:\Users\Raphael\AppData\Roaming\MudTV 2014-03-29 12:34 - 2014-03-29 12:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-28 20:09 - 2014-03-16 15:24 - 00000000 ____D () C:\Users\Raphael\AppData\Local\wf-launcher 2014-03-28 19:06 - 2014-03-16 15:24 - 00000000 ____D () C:\ProgramData\GFACE 2014-03-27 21:52 - 2014-02-12 22:46 - 00004094 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1373000766-1126567924-601248936-1001UA 2014-03-27 21:52 - 2014-02-12 22:46 - 00003714 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1373000766-1126567924-601248936-1001Core 2014-03-26 17:32 - 2014-03-26 17:32 - 00000085 _____ () C:\Users\Raphael\Downloads\stream.wax 2014-03-25 15:34 - 2013-11-07 13:52 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-03-24 23:13 - 2014-03-24 23:08 - 00000000 ____D () C:\Users\Public\Documents\Lightworks 2014-03-24 23:09 - 2014-03-24 23:09 - 00000000 ____D () C:\Users\Raphael\.MCTranscodingSDK 2014-03-24 23:08 - 2014-03-24 23:08 - 00000000 ____D () C:\ProgramData\Geevs 2014-03-24 22:07 - 2014-02-10 18:38 - 00291760 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.xtr 2014-03-24 20:59 - 2014-03-04 21:33 - 00000000 ____D () C:\Users\Raphael\AppData\Local\Deployment 2014-03-24 20:58 - 2014-03-04 21:33 - 00000000 ____D () C:\Users\Raphael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2014-03-24 20:35 - 2013-11-01 14:26 - 00000000 ____D () C:\Program Files (x86)\Google 2014-03-24 20:34 - 2013-11-01 14:25 - 00000000 ____D () C:\Users\Raphael\AppData\Local\Google 2014-03-24 20:33 - 2014-03-24 20:33 - 00000000 ____D () C:\Users\Raphael\AppData\Roaming\XMedia Recode 2014-03-24 19:09 - 2014-03-24 19:09 - 00000000 ____D () C:\Users\Raphael\AppData\Roaming\MPEG Streamclip 2014-03-24 19:09 - 2013-11-01 14:00 - 00000000 ____D () C:\Users\Raphael\AppData\Local\VirtualStore 2014-03-24 19:08 - 2014-03-24 19:08 - 00000000 ____D () C:\Program Files (x86)\Media Player Classic 2014-03-24 19:08 - 2014-02-21 16:58 - 00000000 ____D () C:\ProgramData\Apple Computer Files to move or delete: ==================== C:\Users\Raphael\setup.exe Some content of TEMP: ==================== C:\Users\Raphael\AppData\Local\Temp\68561uninstall.exe C:\Users\Raphael\AppData\Local\Temp\AcDeltree.exe C:\Users\Raphael\AppData\Local\Temp\BackupSetup.exe C:\Users\Raphael\AppData\Local\Temp\fileutil.dll C:\Users\Raphael\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Raphael\AppData\Local\Temp\iupdate.exe C:\Users\Raphael\AppData\Local\Temp\jpathwatch-nativelib-v-0-94-jpathwatch-native.dll C:\Users\Raphael\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\Raphael\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Raphael\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Raphael\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Raphael\AppData\Local\Temp\nvStInst.exe C:\Users\Raphael\AppData\Local\Temp\readSTILog.dll C:\Users\Raphael\AppData\Local\Temp\sonarinst.exe C:\Users\Raphael\AppData\Local\Temp\Sqlite3.dll C:\Users\Raphael\AppData\Local\Temp\vcredist_x64.exe C:\Users\Raphael\AppData\Local\Temp\vlc-2.1.2-win64.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-22 19:43 ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-04-23 16:59:21 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 SAMSUNG_HD103SJ rev.1AJ10001 931,51GB Running: Gmer-19357.exe; Driver: C:\Users\Raphael\AppData\Local\Temp\pwddqpog.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff960001b2e00 15 bytes [00, FA, 0E, 02, C0, 9C, 70, ...] .text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 16 fffff960001b2e10 11 bytes [00, 00, FC, FF, 80, FA, C0, ...] ---- User code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe8d98169a 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe8d9816a2 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe8d98181a 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe8d981832 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\system32\nvvsvc.exe[84] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe8d98169a 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\system32\nvvsvc.exe[84] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe8d9816a2 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\system32\nvvsvc.exe[84] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe8d98181a 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\system32\nvvsvc.exe[84] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe8d981832 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\System32\spoolsv.exe[1488] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe8d98169a 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\System32\spoolsv.exe[1488] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe8d9816a2 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\System32\spoolsv.exe[1488] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe8d98181a 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\System32\spoolsv.exe[1488] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe8d981832 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\Explorer.EXE[2040] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe8d98169a 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\Explorer.EXE[2040] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe8d9816a2 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\Explorer.EXE[2040] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe8d98181a 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\Explorer.EXE[2040] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe8d981832 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\system32\svchost.exe[2076] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe8d98169a 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\system32\svchost.exe[2076] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe8d9816a2 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\system32\svchost.exe[2076] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe8d98181a 4 bytes [98, 8D, FE, 7F] .text C:\WINDOWS\system32\svchost.exe[2076] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe8d981832 4 bytes [98, 8D, FE, 7F] .text C:\Program Files\Windows Defender\MsMpEng.exe[2100] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ffe8d98169a 4 bytes [98, 8D, FE, 7F] .text C:\Program Files\Windows Defender\MsMpEng.exe[2100] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ffe8d9816a2 4 bytes [98, 8D, FE, 7F] .text C:\Program Files\Windows Defender\MsMpEng.exe[2100] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ffe8d98181a 4 bytes [98, 8D, FE, 7F] .text C:\Program Files\Windows Defender\MsMpEng.exe[2100] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ffe8d981832 4 bytes [98, 8D, FE, 7F] ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [668:676] fffff96000a994d0 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\RNG@RNGAuxiliarySeed 1934680429 Reg HKLM\SYSTEM\CurrentControlSet\Services\rdyboost\Parameters@LastBootPlanUserTime ?Mi?, ?Apr ?23 ?14, 03:50:18??????Y???????Y???????????????Y???? Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 3755 Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 1040 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\iexplore@Count 2261 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\RegistrarData@LastRenewCollectionsInterest 0x47 0x4D 0x6B 0xF9 ... Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting@LastRateLimitedDumpGenerationTime 0x3B 0x33 0x27 0xB8 ... Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug@StoreLocation C:\Users\Raphael\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_Data Reconnect_a8a3982ade222dd172c23395ecbe1ca4e1cf2a_00000000_cab_0ea39806 Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles@CheckingForSolutionDialog 0x80 0x08 0x08 0x00 ... Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles@CloseDialog 0x80 0x08 0x08 0x00 ... ---- EOF - GMER 2.1 ---- |
Themen zu Win 8.1: langsames Internet |
avp, c:\windows\system32\roboot64.exe, computer, ebanking, excel, fehler, festplatte, flash player, google, homepage, iexplore, kaspersky, langsam, officejet, onedrive, outlook 2013, problem, pup.optional.installcore.a, pup.optional.pcperformer.a, pup.optional.regcleanerpro, pup.optional.regcleanerpro.a, registry, scan, server, software, svchost.exe, vcredist, windows, windows xp |