|
Log-Analyse und Auswertung: Windos XP Professionell SP3 läuft nicht flüssig und hängt sich mehrmals aufWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
27.08.2014, 19:39 | #1 |
| Windos XP Professionell SP3 läuft nicht flüssig und hängt sich mehrmals auf Hallo ich melde mich hier weil ein Freund mir diese seite empfohlen hat. es geht darum das mein system nicht mehr flüssig läuft und ich einfach keine ahnung habe wieso und hoffe das mir hier geholfen werden kann sympthome sind z.b meine taskleiste verschwindet nicht mehr automatisch, mauszeiger macht sich selten von alleine auf dem weg, spiele alle system vorrausetztungen vorhanden laufen nur mit ruckeln, FF braucht ziemlich lange zum öffnen es kommt mir so vor als wäre die cpu auslastung fast komplett aufgebraucht, dabei habe ich eigentlich nur den wmp laufen. Rechner daten sind: CPU: 3,20GHz RAM: 2,62GB bin einfach langsam planlos was ich da noch machen soll. Geändert von #Neolec# (27.08.2014 um 19:46 Uhr) |
27.08.2014, 19:51 | #2 |
/// the machine /// TB-Ausbilder | Windos XP Professionell SP3 läuft nicht flüssig und hängt sich mehrmals auf hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
27.08.2014, 20:06 | #3 |
| Windos XP Professionell SP3 läuft nicht flüssig und hängt sich mehrmals auf FRST.txt
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:26-08-2014 Ran by Administrator (administrator) on WINDOWSPC on 27-08-2014 19:52:37 Running from C:\Dokumente und Einstellungen\Administrator\Eigene Dateien\Downloads Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVM Berlin) C:\Programme\avmwlanstick\WLanNetService.exe (Oracle Corporation) C:\Programme\Java\jre7\bin\jqs.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (Microsoft Corporation) C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe () C:\Programme\1&1 Surf-Stick\AssistantServices.exe (Realtek Semiconductor Corp.) C:\WINDOWS\SOUNDMAN.EXE (AVM Berlin) C:\Programme\avmwlanstick\WLanGUI.exe (NVIDIA Corporation) C:\Programme\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe (Oracle Corporation) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\dlprotect.exe () C:\Programme\1&1 Surf-Stick\UIExec.exe (Akamai Technologies, Inc.) C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Akamai\netsession_win.exe (Sony) C:\Programme\Sony\Sony PC Companion\PCCompanion.exe (Akamai Technologies, Inc.) C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Akamai\netsession_win.exe (Microsoft Corporation) C:\Programme\Windows Media Player\wmpnscfg.exe () C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe (Oracle Corporation) C:\Programme\Gemeinsame Dateien\Java\Java Update\jucheck.exe (Microsoft Corporation) C:\Programme\Windows Media Player\wmplayer.exe (Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Programme\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\WINDOWS\system32\dllhost.exe (Mozilla Corporation) C:\Programme\Mozilla Firefox\firefox.exe (TeamSpeak Systems GmbH) C:\Programme\TeamSpeak 3 Client\ts3client_win32.exe (Microsoft Corporation) C:\WINDOWS\system32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [67072 2004-11-11] (Realtek Semiconductor Corp.) HKLM\...\Run: [AVMWlanClient] => C:\Programme\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM\...\Run: [Nvtmru] => C:\Programme\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-27] (NVIDIA Corporation) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [nwiz] => C:\Programme\NVIDIA Corporation\nview\nwiz.exe /installquiet HKLM\...\Run: [SunJavaUpdateSched] => C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) HKLM\...\Run: [Download Protect] => C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\dlprotect.exe [12800 2014-06-08] () HKLM\...\Run: [GB_UPDATE] => C:\Programme\Razer\Razer Game Booster\AutoUpdate.exe [2051688 2013-06-05] () HKLM\...\Run: [UIExec] => C:\Programme\1&1 Surf-Stick\UIExec.exe [153424 2011-08-25] () HKLM\...\Run: [avgnt] => C:\Programme\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-15] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Avira Systray] => C:\Programme\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-14] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-507921405-602609370-839522115-500\...\Run: [Akamai NetSession Interface] => C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-507921405-602609370-839522115-500\...\Run: [Sony PC Companion] => C:\Programme\Sony\Sony PC Companion\PCCompanion.exe [467680 2014-07-30] (Sony) HKU\S-1-5-21-507921405-602609370-839522115-500\...\Run: [WMPNSCFG] => C:\Programme\Windows Media Player\WMPNSCFG.exe [204288 2006-11-03] (Microsoft Corporation) HKU\S-1-5-21-507921405-602609370-839522115-500\...\RunOnce: [FlashPlayerUpdate] => C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_13_0_0_214_Plugin.exe [847536 2014-06-08] (Adobe Systems Incorporated) HKU\S-1-5-21-507921405-602609370-839522115-500\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x91000000 HKU\S-1-5-21-507921405-602609370-839522115-500\...\MountPoints2: {42cf2bcf-b43d-11e3-9b06-001f3f0d9ae9} - D:\Startme.exe HKU\S-1-5-21-507921405-602609370-839522115-500\...\MountPoints2: {84736783-25f0-11e3-864b-001f3f0d9ae9} - G:\autorun.exe HKU\S-1-5-21-507921405-602609370-839522115-500\...\MountPoints2: {84736785-25f0-11e3-864b-001f3f0d9ae9} - G:\setup_vmc_lite.exe /checkApplicationPresence AppInit_DLLs: C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll File Not Found GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.trovi.com/?gd=&ctid=CT3320324&octid=EB_ORIGINAL_CTID&ISID=M583EB88F-2BA7-4DAA-9F4B-EE6F58C76EFB&SearchSource=55&CUI=&UM=5&UP=SP9AE9C487-7C44-498A-861B-05FBF30769A3&SSPV= HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - &Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1375578513794 Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\n3puny0o.default-1398317812044 FF NewTab: hxxp://www.trovi.com/?gd=&ctid=CT3320324&octid=EB_ORIGINAL_CTID&ISID=M583EB88F-2BA7-4DAA-9F4B-EE6F58C76EFB&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SP9AE9C487-7C44-498A-861B-05FBF30769A3 FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de?hl=de&gl=de FF Keyword.URL: hxxp://www.google.de/search?hl=de&gl=de&lr=&ie=UTF-8&oe=UTF-8&meta=lr=lang_de&q= FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @java.com/DTPlugin,version=10.60.2 -> C:\Programme\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.60.2 -> C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Programme\Microsoft Silverlight\3.0.40818.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Programme\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Programme\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Programme\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Programme\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF user.js: detected! => C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\n3puny0o.default-1398317812044\user.js FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [fiddlerhook@fiddler2.com] - C:\Programme\Fiddler2\FiddlerHook FF Extension: FiddlerHook - C:\Programme\Fiddler2\FiddlerHook [2014-03-11] FF HKLM\...\Firefox\Extensions: [{ACA42512-4B7C-4A02-B876-8D9E132A0159}] - C:\WINDOWS\Installer\{B1EEC033-AAD0-403E-B17D-954654ED4EC9}\{ACA42512-4B7C-4A02-B876-8D9E132A0159}.xpi FF Extension: Download Protect - C:\WINDOWS\Installer\{B1EEC033-AAD0-403E-B17D-954654ED4EC9}\{ACA42512-4B7C-4A02-B876-8D9E132A0159}.xpi [2014-09-02] Chrome: ======= CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Programme\Avira\AntiVir Desktop\sched.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Programme\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG) S2 Avira.OE.ServiceHost; C:\Programme\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-14] (Avira Operations GmbH & Co. KG) R2 AVM WLAN Connection Service; C:\Programme\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed] S3 idsvc; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [864256 2007-10-11] (Microsoft Corporation) [File not signed] R2 JavaQuickStarterService; C:\Programme\Java\jre7\bin\jqs.exe [182696 2014-05-07] (Oracle Corporation) S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [119408 2014-08-02] (Mozilla Foundation) R2 MSSQL$SQLEXPRESS; C:\Programme\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [43010392 2009-03-30] (Microsoft Corporation) S4 MSSQLServerADHelper100; C:\Programme\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [47128 2009-07-21] (Microsoft Corporation) R2 nvUpdatusService; C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [1889568 2013-07-27] (NVIDIA Corporation) S3 Sony PC Companion; C:\Programme\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) S4 SQLAgent$SQLEXPRESS; C:\Programme\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [366936 2009-03-30] (Microsoft Corporation) S4 SQLBrowser; C:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe [254808 2009-03-30] (Microsoft Corporation) R2 SQLWriter; C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe [98840 2008-07-10] (Microsoft Corporation) R2 UI Assistant Service; C:\Programme\1&1 Surf-Stick\AssistantServices.exe [270672 2011-08-25] () R2 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-11-03] (Microsoft Corporation) S3 globalUpdatem; C:\Programme\globalUpdate\Update\GoogleUpdate.exe /medsvc [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 ALCXSENS; C:\WINDOWS\System32\drivers\ALCXSENS.SYS [400384 2004-11-11] (Sensaura) [File not signed] R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [622172 2004-11-11] (Realtek Semiconductor Corp.) [File not signed] R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [97648 2014-08-15] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [136216 2014-08-15] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37352 2014-08-15] (Avira Operations GmbH & Co. KG) S3 avmeject; C:\WINDOWS\System32\drivers\avmeject.sys [4352 2010-10-22] (AVM Berlin) [File not signed] S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation) R3 FWLANUSB; C:\WINDOWS\System32\DRIVERS\fwlanusb.sys [265088 2010-10-22] (AVM GmbH) S3 massfilter; C:\WINDOWS\System32\drivers\massfilter.sys [9216 2011-03-26] (MBB Incorporated) S1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2014-08-15] (Avira GmbH) S3 WinRing0_1_2_0; C:\Programme\Razer\Razer Game Booster\Driver\WinRing0.sys [14416 2012-08-01] (OpenLibSys.org) S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [X] U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-02 23:22 - 2014-09-02 23:22 - 00001595 _____ () C:\Dokumente und Einstellungen\Administrator\Desktop\Drakensang Online.lnk 2014-09-02 23:22 - 2014-09-02 23:22 - 00000000 ____D () C:\Programme\Drakensang Online 2014-09-02 23:22 - 2014-09-02 23:22 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Drakensang Online 2014-08-30 20:27 - 2014-08-30 20:27 - 00000531 _____ () C:\WINDOWS\wmsetup.log 2014-08-30 19:38 - 2014-08-30 19:38 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Desktop\Sd-Karte 2014-08-30 13:16 - 2014-08-30 13:16 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Desktop\Programme 2014-08-28 18:34 - 2014-08-28 18:34 - 00000000 ____D () C:\UserData 2014-08-28 18:34 - 2010-09-06 21:12 - 00000557 _____ () C:\NetworkCfg.xml 2014-08-28 18:31 - 2014-08-28 18:33 - 00000000 ____D () C:\Programme\1&1 Surf-Stick 2014-08-28 18:31 - 2014-08-28 18:31 - 00000000 ____D () C:\WINDOWS\system32\SupportAppCB 2014-08-28 18:31 - 2014-08-28 18:31 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\1&1 Surf-Stick 2014-08-28 18:31 - 2011-03-26 10:37 - 00107776 _____ (ZTE Incorporated) C:\WINDOWS\system32\Drivers\ZTEusbser6k.sys 2014-08-28 18:31 - 2011-03-26 10:37 - 00107776 _____ (ZTE Incorporated) C:\WINDOWS\system32\Drivers\ZTEusbnmea.sys 2014-08-28 18:31 - 2011-03-26 10:37 - 00107776 _____ (ZTE Incorporated) C:\WINDOWS\system32\Drivers\ZTEusbmdm6k.sys 2014-08-28 18:31 - 2011-03-26 10:37 - 00009216 _____ (MBB Incorporated) C:\WINDOWS\system32\Drivers\massfilter.sys 2014-08-27 19:52 - 2014-08-27 19:52 - 00000000 ____D () C:\FRST 2014-08-27 19:50 - 2014-08-27 19:50 - 00000000 _____ () C:\Dokumente und Einstellungen\Administrator\defogger_reenable 2014-08-27 18:55 - 2014-08-27 19:48 - 00000000 ____D () C:\WINDOWS\system32\NtmsData 2014-08-27 18:52 - 2014-08-27 18:52 - 00000834 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Avira.lnk 2014-08-27 18:52 - 2014-08-27 18:52 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Package Cache 2014-08-27 18:51 - 2014-08-27 18:51 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Avira 2014-08-27 18:50 - 2014-08-27 18:52 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Avira 2014-08-27 18:50 - 2014-08-27 18:50 - 00001671 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Avira Control Center.lnk 2014-08-27 18:49 - 2014-08-27 18:52 - 00000000 ____D () C:\Programme\Avira 2014-08-27 18:49 - 2014-08-27 18:52 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira 2014-08-27 18:49 - 2014-08-15 10:30 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2014-08-27 18:49 - 2014-08-15 10:30 - 00097648 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2014-08-27 18:49 - 2014-08-15 10:30 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys 2014-08-27 18:49 - 2014-08-15 10:30 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys 2014-08-14 01:58 - 2014-08-27 02:29 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Battle.net 2014-08-14 01:58 - 2014-08-14 03:16 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Battle.net 2014-08-14 01:57 - 2014-09-01 20:17 - 00000000 ____D () C:\Programme\Battle.net 2014-08-14 01:57 - 2014-08-14 01:57 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Battle.net 2014-08-13 17:53 - 2014-08-30 18:25 - 00000232 _____ () C:\WINDOWS\setupact.log 2014-08-13 17:53 - 2014-08-13 17:53 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-08-02 13:48 - 2014-08-02 13:48 - 00000000 ____D () C:\Programme\Mozilla Firefox ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-02 23:22 - 2014-09-02 23:22 - 00001595 _____ () C:\Dokumente und Einstellungen\Administrator\Desktop\Drakensang Online.lnk 2014-09-02 23:22 - 2014-09-02 23:22 - 00000000 ____D () C:\Programme\Drakensang Online 2014-09-02 23:22 - 2014-09-02 23:22 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Drakensang Online 2014-09-02 23:22 - 2013-08-04 01:21 - 00000000 ___RD () C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme 2014-09-02 23:19 - 2013-08-04 01:13 - 01522911 _____ () C:\WINDOWS\WindowsUpdate.log 2014-09-02 20:18 - 2014-06-11 01:04 - 00000728 __RSH () C:\Dokumente und Einstellungen\All Users\ntuser.pol 2014-09-01 20:18 - 2013-08-04 02:05 - 01421688 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-09-01 20:17 - 2014-08-14 01:57 - 00000000 ____D () C:\Programme\Battle.net 2014-09-01 20:14 - 2014-06-13 01:18 - 00006177 _____ () C:\autoupdate.log 2014-09-01 20:14 - 2013-08-04 02:09 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-09-01 20:14 - 2013-08-04 02:09 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-09-01 20:14 - 2013-08-04 01:20 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-09-01 20:14 - 2004-11-11 14:00 - 00002278 _____ () C:\WINDOWS\system32\wpa.dbl 2014-09-01 17:38 - 2013-08-04 01:21 - 00000190 ___SH () C:\Dokumente und Einstellungen\Administrator\ntuser.ini 2014-08-31 19:48 - 2013-08-05 12:47 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\vlc 2014-08-31 19:46 - 2013-08-05 12:40 - 00043520 _____ () C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-08-30 20:27 - 2014-08-30 20:27 - 00000531 _____ () C:\WINDOWS\wmsetup.log 2014-08-30 19:38 - 2014-08-30 19:38 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Desktop\Sd-Karte 2014-08-30 18:25 - 2014-08-13 17:53 - 00000232 _____ () C:\WINDOWS\setupact.log 2014-08-30 13:16 - 2014-08-30 13:16 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Desktop\Programme 2014-08-29 15:40 - 2014-06-19 14:05 - 00044416 _____ () C:\WINDOWS\DPINST.LOG 2014-08-29 15:39 - 2014-03-27 07:23 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Sony 2014-08-29 15:39 - 2014-03-07 23:22 - 00000000 ___HD () C:\Programme\InstallShield Installation Information 2014-08-29 02:51 - 2013-08-04 01:21 - 00000000 ___RD () C:\Dokumente und Einstellungen\Administrator\Eigene Dateien\Eigene Bilder 2014-08-28 18:34 - 2014-08-28 18:34 - 00000000 ____D () C:\UserData 2014-08-28 18:33 - 2014-08-28 18:31 - 00000000 ____D () C:\Programme\1&1 Surf-Stick 2014-08-28 18:31 - 2014-08-28 18:31 - 00000000 ____D () C:\WINDOWS\system32\SupportAppCB 2014-08-28 18:31 - 2014-08-28 18:31 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\1&1 Surf-Stick 2014-08-27 19:53 - 2013-08-04 01:21 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp 2014-08-27 19:52 - 2014-08-27 19:52 - 00000000 ____D () C:\FRST 2014-08-27 19:50 - 2014-08-27 19:50 - 00000000 _____ () C:\Dokumente und Einstellungen\Administrator\defogger_reenable 2014-08-27 19:50 - 2013-08-04 01:21 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator 2014-08-27 19:48 - 2014-08-27 18:55 - 00000000 ____D () C:\WINDOWS\system32\NtmsData 2014-08-27 19:02 - 2013-08-14 21:31 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\TS3Client 2014-08-27 19:00 - 2013-08-04 03:45 - 00014982 _____ () C:\WINDOWS\system32\nvAppTimestamps 2014-08-27 18:56 - 2014-06-08 01:21 - 00079146 _____ () C:\WINDOWS\setupapi.log 2014-08-27 18:55 - 2014-06-08 00:55 - 00003444 _____ () C:\WINDOWS\Tasks\299645da-100d-4ab3-9773-37fcadaceb04-3.job 2014-08-27 18:55 - 2014-06-08 00:55 - 00002166 _____ () C:\WINDOWS\Tasks\299645da-100d-4ab3-9773-37fcadaceb04-4.job 2014-08-27 18:55 - 2014-06-08 00:55 - 00001404 _____ () C:\WINDOWS\Tasks\299645da-100d-4ab3-9773-37fcadaceb04-5.job 2014-08-27 18:55 - 2014-06-08 00:55 - 00001376 _____ () C:\WINDOWS\Tasks\299645da-100d-4ab3-9773-37fcadaceb04-1.job 2014-08-27 18:55 - 2014-06-08 00:55 - 00001330 _____ () C:\WINDOWS\Tasks\299645da-100d-4ab3-9773-37fcadaceb04-2.job 2014-08-27 18:55 - 2013-08-04 02:54 - 00000000 ____D () C:\WINDOWS\repair 2014-08-27 18:55 - 2013-08-04 01:20 - 00032528 _____ () C:\WINDOWS\SchedLgU.Txt 2014-08-27 18:55 - 2013-08-04 01:11 - 00000000 ____D () C:\WINDOWS\Registration 2014-08-27 18:52 - 2014-08-27 18:52 - 00000834 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Avira.lnk 2014-08-27 18:52 - 2014-08-27 18:52 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Package Cache 2014-08-27 18:52 - 2014-08-27 18:50 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Avira 2014-08-27 18:52 - 2014-08-27 18:49 - 00000000 ____D () C:\Programme\Avira 2014-08-27 18:52 - 2014-08-27 18:49 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira 2014-08-27 18:51 - 2014-08-27 18:51 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Avira 2014-08-27 18:50 - 2014-08-27 18:50 - 00001671 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Avira Control Center.lnk 2014-08-27 18:50 - 2013-08-04 02:05 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme 2014-08-27 18:49 - 2013-08-04 02:05 - 00000000 ___RD () C:\Programme 2014-08-27 02:29 - 2014-08-14 01:58 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Battle.net 2014-08-18 18:14 - 2013-08-04 03:43 - 00000190 ___SH () C:\Dokumente und Einstellungen\UpdatusUser\ntuser.ini 2014-08-15 10:30 - 2014-08-27 18:49 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2014-08-15 10:30 - 2014-08-27 18:49 - 00097648 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2014-08-15 10:30 - 2014-08-27 18:49 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys 2014-08-15 10:30 - 2014-08-27 18:49 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys 2014-08-14 03:23 - 2013-12-10 16:51 - 00000000 ____D () C:\Programme\Gemeinsame Dateien\Blizzard Entertainment 2014-08-14 03:23 - 2013-12-10 16:51 - 00000000 ____D () C:\Programme\Diablo III 2014-08-14 03:16 - 2014-08-14 01:58 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Battle.net 2014-08-14 01:57 - 2014-08-14 01:57 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Battle.net 2014-08-13 17:53 - 2014-08-13 17:53 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-08-10 03:24 - 2013-08-04 01:20 - 00000190 ___SH () C:\Dokumente und Einstellungen\LocalService\ntuser.ini 2014-08-03 16:10 - 2013-08-04 02:54 - 00000000 _____ () C:\WINDOWS\MEMORY.DMP 2014-08-03 14:16 - 2013-08-04 20:48 - 00000000 ____D () C:\Programme\Mozilla Maintenance Service 2014-08-03 03:54 - 2013-08-06 12:04 - 00000000 ____D () C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\dvdcss 2014-08-02 13:48 - 2014-08-02 13:48 - 00000000 ____D () C:\Programme\Mozilla Firefox Some content of TEMP: ==================== C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\AUTORUN.EXE C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\AUTORUNGUI.DLL C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\avgnt.exe C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\drm_dialogs.dll C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\drm_dyndata_7340014.dll C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\drm_dyndata_7380012.dll C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\nsa25A.exe C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\nsd25F.exe C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\nsf262.exe C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\nsj257.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================ Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:26-08-2014 Ran by Administrator at 2014-08-27 19:53:43 Running from C:\Dokumente und Einstellungen\Administrator\Eigene Dateien\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Disabled - Up to date) {AD166499-45F9-482A-A743-FDD3350758C7} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 1&1 Surf-Stick (HKLM\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.2 - ) Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc) Avira (HKLM\...\{df495620-2ba9-412d-828d-b27f020d9fc8}) (Version: 1.1.18.28431 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.18.28431 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.6.570 - Avira) AVM FRITZ!WLAN (HKLM\...\AVMWLANCLI) (Version: - AVM Berlin) Battle.net (HKLM\...\Battle.net) (Version: - Blizzard Entertainment) CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform) Cheat Engine 6.1 (HKLM\...\Cheat Engine 6.1_is1) (Version: - Dark Byte) Diablo III (HKLM\...\Diablo III) (Version: - Blizzard Entertainment) Download Protect (HKCU\...\{132401a7-2006-4342-b43c-ccf5f02c2b01}) (Version: - Download Protect) Drakensang Online (HKLM\...\Drakensang Online) (Version: - ) Farm Frenzy 2 (HKLM\...\Farm Frenzy 2) (Version: - ) Farm Frenzy 3 (HKLM\...\Farm Frenzy 3) (Version: - ) Fiddler (HKLM\...\Fiddler2) (Version: 2.4.6.2 - Telerik) Google Update Helper (Version: 1.3.25.0 - Google Inc.) Hidden HighMAT-Erweiterung für den Microsoft Windows XP-Assistenten zum Schreiben von CDs (HKLM\...\{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}) (Version: 1.1.1905.1 - Microsoft Corporation) Hotfix für Windows XP (KB942288-v3) (HKLM\...\KB942288-v3) (Version: 3 - Microsoft Corporation) Java 7 Update 60 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.600 - Oracle) Java Auto Updater (Version: 2.1.60.19 - Oracle, Inc.) Hidden League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (Version: 3.0.1 - Riot Games ) Hidden Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 1.1 German Language Pack (HKLM\...\{E78BFA60-5393-4C38-82AB-E8019E464EB4}) (Version: 1.1.4322 - Microsoft) Microsoft .NET Framework 2.0 Service Pack 1 (HKLM\...\{B508B3F1-A24A-32C0-B310-85786919EF28}) (Version: 2.1.21022 - Microsoft Corporation) Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - DEU (HKLM\...\{9309DD7E-EBFE-3C95-8B47-30D3A012F606}) (Version: 2.1.21022 - Microsoft Corporation) Microsoft .NET Framework 3.0 Service Pack 1 (HKLM\...\{2BA00471-0328-3743-93BD-FA813353A783}) (Version: 3.1.21022 - Microsoft Corporation) Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - DEU (HKLM\...\{A1071AEB-B0EF-3F5F-BC84-83A270EBE496}) (Version: 3.1.21022 - Microsoft Corporation) Microsoft .NET Framework 3.5 (HKLM\...\Microsoft .NET Framework 3.5) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 (Version: 3.5.21022 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 Language Pack - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack - deu (Version: 3.5.21022 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation) Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.0 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.0 Language Pack - DEU) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 (Version: - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 3.0.40818.0 - Microsoft Corporation) Microsoft SQL Server 2008 (HKLM\...\Microsoft SQL Server 10 Release) (Version: - Microsoft Corporation) Microsoft SQL Server 2008 (Version: - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Browser (HKLM\...\{4AF2248C-B3DF-46FB-9596-87F5DB193689}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 Common Files (Version: 10.0.1600.22 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Common Files (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Services (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Shared (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Native Client (HKLM\...\{1C2B3CEA-482E-4453-B3E2-C9731337828A}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (HKLM\...\{A106D33E-6B43-42C0-9BFC-D03303261FA7}) (Version: 10.50.1447.4 - Microsoft Corporation) Microsoft SQL Server 2008 RsFx Driver (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server Compact 3.5 SP2 DEU (HKLM\...\{0125D081-30D0-4A97-82A8-C28D444B6256}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server System CLR Types (HKLM\...\{5A08C9D1-37AD-4A8D-90D3-33F92C578AA5}) (Version: 10.50.1447.4 - Microsoft Corporation) Microsoft SQL Server VSS Writer (HKLM\...\{D074DC76-F6C9-440E-A1D0-1DE958417FDB}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation) Microsoft Visual C# 2010 Express - DEU (HKLM\...\Microsoft Visual C# 2010 Express - DEU) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C# 2010 Express - DEU (Version: 10.0.30319 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM\...\{616C6F39-4CE1-3434-A665-2F6A04C09A7F}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Windows-Journal-Viewer (HKLM\...\{43DCF766-6838-4F9A-8C91-D92DA586DFA7}) (Version: 1.5.2315.3 - Microsoft) Mouse Recorder Pro 2.0.7.4 (HKLM\...\{889E44CE-435C-4D37-B302-A7E43339E5FA}_is1) (Version: - Nemex Studios) Mozilla Firefox 31.0 (x86 de) (HKLM\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) NVIDIA GeForce Experience 1.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.6 - NVIDIA Corporation) NVIDIA Grafiktreiber 320.18 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 320.18 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.131.854 - NVIDIA Corporation) Hidden NVIDIA nView 140.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 140.54 - NVIDIA Corporation) NVIDIA PhysX (Version: 9.13.0604 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.0604 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0604 - NVIDIA Corporation) NVIDIA Systemsteuerung 320.18 (Version: 320.18 - NVIDIA Corporation) Hidden NVIDIA Update 7.2.17 (Version: 7.2.17 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 7.2.17 - NVIDIA Corporation) Hidden Pando Media Booster (HKLM\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.) Prince of Persia T2T (HKLM\...\{DFFE2B1F-07E0-45A9-8801-CD8514CAA876}) (Version: - ) PSHD-9.9 (HKLM\...\PSHD-9.9) (Version: 1.34.5.29 - PlusVHD) raving reyven (HKLM\...\raving reyven) (Version: 2014.03.27.174842 - raving reyven) Razer Game Booster (HKLM\...\Razer Game Booster_is1) (Version: 3.7 - Razer USA Ltd) Search Protect (HKLM\...\SearchProtect) (Version: 2.13.3.38 - Client Connect LTD) <==== ATTENTION Service Pack 1 für SQL Server 2008 (KB 968369) (HKLM\...\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2618444) (HKLM\...\KB2618444-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2744842) (HKLM\...\KB2744842-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2846071) (HKLM\...\KB2846071-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB982381) (HKLM\...\KB982381-IE8) (Version: 1 - Microsoft Corporation) Sony PC Companion 2.10.221 (HKLM\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.221 - Sony) Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Tactical Ops (HKLM\...\Tactical Ops) (Version: - Infogrames) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Unterstützungsdateien für Microsoft SQL Server 2008-Setup (HKLM\...\{9AA2D735-3375-42D4-9A61-3FFEF82599D6}) (Version: 10.1.2731.0 - Microsoft Corporation) Update für Windows Internet Explorer 8 (KB2598845) (HKLM\...\KB2598845-IE8) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2467659) (HKLM\...\KB2467659) (Version: 1 - Microsoft Corporation) Vampires Dawn II: Ancient Blood (HKLM\...\{23E49254-B48D-4422-93A1-5F26F02A0A69}_is1) (Version: Vampires Dawn 2 - Version 1.23 - Brianum/Dawnatic) Vampires Dawn: Reign of Blood (HKLM\...\{CF55095E-07AA-432E-8376-CEF71D70746A}_is1) (Version: Vampires Dawn: Reign of Blood 1.31 - Brianum) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (HKLM\...\{CFCB8616-A5D1-4281-80E8-389F685BFAE2}) (Version: 4.0.8080.0 - Microsoft Corporation) VLC media player 1.0.1 (HKLM\...\VLC media player) (Version: 1.0.1 - VideoLAN Team) WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden Winamp (HKLM\...\Winamp) (Version: 5.666 - Nullsoft, Inc) Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation) Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - ) Windows Media Format 11 runtime (Version: - Microsoft Corporation) Hidden Windows Media Player 11 (HKLM\...\Windows Media Player) (Version: - ) Windows Media Player 11 (Version: - Microsoft Corporation) Hidden Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031514 - Microsoft Corporation) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) XML Paper Specification Shared Components Language Pack 1.0 (Version: - Microsoft Corporation) Hidden XML Paper Specification Shared Components Pack 1.0 (Version: - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-507921405-602609370-839522115-500_Classes\CLSID\{31261F21-2B16-45EE-BEAB-07C4CFA18B65}\InprocServer32 -> C:\Programme\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CustomCLSID: HKU\S-1-5-21-507921405-602609370-839522115-500_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS) ==================== Restore Points ========================= 02-06-2014 22:37:42 Systemprüfpunkt 04-06-2014 12:16:07 Systemprüfpunkt 12-06-2014 23:47:11 Microsoft Visual C++ 2005 Redistributable wird installiert 12-06-2014 23:48:52 ProductName from default.wxl installiert 15-06-2014 11:28:43 Need for Speed™ SHIFT entfernt 19-06-2014 12:05:11 Sony PC Companion 29-06-2014 19:39:44 Systemprüfpunkt 01-07-2014 01:47:42 Systemprüfpunkt 02-07-2014 03:59:00 Systemprüfpunkt 04-07-2014 02:50:33 Systemprüfpunkt 05-07-2014 03:08:50 Systemprüfpunkt 06-07-2014 03:11:54 Systemprüfpunkt 07-07-2014 03:27:16 Systemprüfpunkt 08-07-2014 11:41:25 Systemprüfpunkt 21-07-2014 01:10:27 Systemprüfpunkt 22-07-2014 23:27:36 Systemprüfpunkt 24-07-2014 19:50:17 Systemprüfpunkt 27-07-2014 20:28:15 Systemprüfpunkt 29-07-2014 03:57:22 Systemprüfpunkt 30-07-2014 04:53:35 Systemprüfpunkt 31-07-2014 05:01:23 Systemprüfpunkt 02-08-2014 04:06:49 Systemprüfpunkt 03-08-2014 06:50:05 Systemprüfpunkt 04-08-2014 11:01:25 Systemprüfpunkt 05-08-2014 16:07:10 Systemprüfpunkt 06-08-2014 17:20:38 Systemprüfpunkt 08-08-2014 23:41:47 Installiert Arc 11-08-2014 01:54:06 Systemprüfpunkt 12-08-2014 12:46:19 Systemprüfpunkt 13-08-2014 19:55:38 Systemprüfpunkt 15-08-2014 05:57:01 Systemprüfpunkt 16-08-2014 05:57:14 Systemprüfpunkt 17-08-2014 06:45:15 Systemprüfpunkt 18-08-2014 10:15:33 Systemprüfpunkt 19-08-2014 10:20:13 Systemprüfpunkt 19-08-2014 18:32:48 Entfernt Arc 27-08-2014 02:19:03 Systemprüfpunkt 28-08-2014 16:31:30 Installiert 1&1 Surf-Stick 29-08-2014 13:40:30 Sony PC Companion 31-08-2014 00:13:09 Systemprüfpunkt 01-09-2014 19:34:11 Systemprüfpunkt 27-08-2014 01:15:16 Systemprüfpunkt ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2004-11-11 14:00 - 2004-11-11 14:00 - 00000820 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\299645da-100d-4ab3-9773-37fcadaceb04-1.job => C:\Programme\PSHD-9.9\PSHD-9.9-codedownloader.exe Task: C:\WINDOWS\Tasks\299645da-100d-4ab3-9773-37fcadaceb04-2.job => C:\Programme\PSHD-9.9\299645da-100d-4ab3-9773-37fcadaceb04-2.exe Task: C:\WINDOWS\Tasks\299645da-100d-4ab3-9773-37fcadaceb04-3.job => C:\Programme\PSHD-9.9\299645da-100d-4ab3-9773-37fcadaceb04-3.exe Task: C:\WINDOWS\Tasks\299645da-100d-4ab3-9773-37fcadaceb04-4.job => C:\Programme\PSHD-9.9\299645da-100d-4ab3-9773-37fcadaceb04-4.exe Task: C:\WINDOWS\Tasks\299645da-100d-4ab3-9773-37fcadaceb04-5.job => C:\Programme\PSHD-9.9\299645da-100d-4ab3-9773-37fcadaceb04-5.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-25 15:23 - 2008-09-16 20:18 - 00132608 _____ () C:\Programme\WinRAR\rarext.dll 2014-08-28 18:31 - 2011-08-25 10:50 - 00270672 _____ () C:\Programme\1&1 Surf-Stick\AssistantServices.exe 2014-06-08 00:56 - 2014-06-08 00:56 - 00012800 _____ () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\dlprotect.exe 2014-08-28 18:31 - 2011-08-25 10:50 - 00153424 _____ () C:\Programme\1&1 Surf-Stick\UIExec.exe 2014-03-27 07:23 - 2012-04-30 11:57 - 00039936 _____ () C:\Programme\Sony\Sony PC Companion\TMonitorAPI.dll 2014-03-27 07:23 - 2013-09-13 11:02 - 00208896 _____ () C:\Programme\Sony\Sony PC Companion\MExplorer.dll 2014-03-27 07:23 - 2014-06-23 09:07 - 00113376 _____ () C:\Programme\Sony\Sony PC Companion\PCCompanionInfo.exe 2004-11-11 14:00 - 2008-04-14 07:52 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll 2014-08-27 18:52 - 2014-07-14 16:49 - 00049744 _____ () C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2014-07-14 16:49 - 2014-07-14 16:49 - 00137296 _____ () C:\Programme\Avira\My Avira\Avira.OE.NativeCore.dll 2014-08-02 13:48 - 2014-08-02 13:48 - 03800688 _____ () C:\Programme\Mozilla Firefox\mozjs.dll 2014-02-28 15:33 - 2014-02-28 15:33 - 00148480 _____ () C:\Programme\TeamSpeak 3 Client\quazip.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00864768 _____ () C:\Programme\TeamSpeak 3 Client\platforms\qwindows.dll 2014-02-27 15:45 - 2014-02-27 15:45 - 00677376 _____ () C:\Programme\TeamSpeak 3 Client\sqldrivers\qsqlite.dll 2014-02-28 15:41 - 2014-02-28 15:41 - 00092104 _____ () C:\Programme\TeamSpeak 3 Client\soundbackends\directsound_win32.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00025600 _____ () C:\Programme\TeamSpeak 3 Client\imageformats\qgif.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00242688 _____ () C:\Programme\TeamSpeak 3 Client\imageformats\qjpeg.dll 2014-02-28 15:42 - 2014-02-28 15:42 - 00477128 _____ () C:\Programme\TeamSpeak 3 Client\plugins\clientquery_plugin.dll 2014-02-28 15:42 - 2014-02-28 15:42 - 00483784 _____ () C:\Programme\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll 2014-02-27 15:46 - 2014-02-27 15:46 - 00123904 _____ () C:\Programme\TeamSpeak 3 Client\accessible\qtaccessiblewidgets.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ==================== Faulty Device Manager Devices ============= Name: PS/2-kompatible Maus Description: PS/2-kompatible Maus Class Guid: {4D36E96F-E325-11CE-BFC1-08002BE10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Standardtastatur (101/102 Tasten) oder Microsoft Natural Keyboard (PS/2) Description: Standardtastatur (101/102 Tasten) oder Microsoft Natural Keyboard (PS/2) Class Guid: {4D36E96B-E325-11CE-BFC1-08002BE10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (08/27/2014 06:54:57 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetExportedValueFromLazy[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/27/2014 06:54:08 PM) (Source: .NET Runtime 4.0 Error Reporting) (EventID: 5000) (User: ) Description: EventType clr20r3, P1 avira.oe.servicehost.exe, P2 1.1.18.28431, P3 53c3ed8f, P4 system.componentmodel.composition, P5 4.0.0.0, P6 4ba1f401, P7 2a8, P8 9, P9 clr20r30, P10 clr20r31. Error: (08/27/2014 06:53:55 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetExportedValueFromLazy[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/27/2014 06:53:11 PM) (Source: .NET Runtime 4.0 Error Reporting) (EventID: 5000) (User: ) Description: EventType clr20r3, P1 avira.oe.servicehost.exe, P2 1.1.18.28431, P3 53c3ed8f, P4 system.componentmodel.composition, P5 4.0.0.0, P6 4ba1f401, P7 2a8, P8 9, P9 clr20r30, P10 clr20r31. Error: (08/27/2014 06:52:58 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetExportedValueFromLazy[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/27/2014 00:07:33 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Stillstehende Anwendung thinclient.exe, Version 0.0.0.0, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error: (09/01/2014 01:06:03 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Stillstehende Anwendung drakensangonline.exe, Version 0.0.0.0, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error: (08/30/2014 07:38:08 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Stillstehende Anwendung explorer.exe, Version 6.0.2900.5512, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error: (08/30/2014 06:23:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlgeschlagene Anwendung drwtsn32.exe, Version 5.1.2600.0, fehlgeschlagenes Modul dbghelp.dll, Version 5.1.2600.5512, Fehleradresse 0x0001295d. Das medienspezifische Ereignis für [drwtsn32.exe!ws!] wird verarbeitet. Error: (08/30/2014 06:22:49 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlgeschlagene Anwendung explorer.exe, Version 6.0.2900.5512, fehlgeschlagenes Modul shell32.dll, Version 6.0.2900.5512, Fehleradresse 0x0002adc4. Das medienspezifische Ereignis für [explorer.exe!ws!] wird verarbeitet. System errors: ============= Error: (08/27/2014 07:18:34 PM) (Source: DCOM) (EventID: 10001) (User: WINDOWSPC) Description: Ein DCOM-Server konnte nicht gestartet werden: {AD1B0A76-DBB2-45C2-8403-45B8DD7FD503} als /. Fehler: "%%2" aufgetreten beim Starten dieses Befehls: "C:\Programme\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe" -Embedding Error: (08/27/2014 07:11:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Download Protect Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (08/27/2014 07:11:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "dmload Cpqarray Systemwiederherstellungsdienst" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (08/27/2014 06:54:57 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. Error: (08/27/2014 06:53:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Starten Sie den Dienst neu.. Error: (08/27/2014 06:52:59 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Starten Sie den Dienst neu.. Error: (08/27/2014 06:18:34 PM) (Source: DCOM) (EventID: 10001) (User: WINDOWSPC) Description: Ein DCOM-Server konnte nicht gestartet werden: {AD1B0A76-DBB2-45C2-8403-45B8DD7FD503} als /. Fehler: "%%2" aufgetreten beim Starten dieses Befehls: "C:\Programme\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe" -Embedding Error: (08/27/2014 05:18:34 PM) (Source: DCOM) (EventID: 10001) (User: WINDOWSPC) Description: Ein DCOM-Server konnte nicht gestartet werden: {AD1B0A76-DBB2-45C2-8403-45B8DD7FD503} als /. Fehler: "%%2" aufgetreten beim Starten dieses Befehls: "C:\Programme\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe" -Embedding Error: (08/27/2014 04:18:34 PM) (Source: DCOM) (EventID: 10001) (User: WINDOWSPC) Description: Ein DCOM-Server konnte nicht gestartet werden: {AD1B0A76-DBB2-45C2-8403-45B8DD7FD503} als /. Fehler: "%%2" aufgetreten beim Starten dieses Befehls: "C:\Programme\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe" -Embedding Error: (08/27/2014 03:18:34 PM) (Source: DCOM) (EventID: 10001) (User: WINDOWSPC) Description: Ein DCOM-Server konnte nicht gestartet werden: {AD1B0A76-DBB2-45C2-8403-45B8DD7FD503} als /. Fehler: "%%2" aufgetreten beim Starten dieses Befehls: "C:\Programme\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe" -Embedding Microsoft Office Sessions: ========================= Error: (08/27/2014 06:54:57 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetExportedValueFromLazy[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/27/2014 06:54:08 PM) (Source: .NET Runtime 4.0 Error Reporting) (EventID: 5000) (User: ) Description: clr20r3avira.oe.servicehost.exe1.1.18.2843153c3ed8fsystem.componentmodel.composition4.0.0.04ba1f4012a89ha2r5vsskg1rxuacxv143hzfuv1ct25uNIL Error: (08/27/2014 06:53:55 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetExportedValueFromLazy[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/27/2014 06:53:11 PM) (Source: .NET Runtime 4.0 Error Reporting) (EventID: 5000) (User: ) Description: clr20r3avira.oe.servicehost.exe1.1.18.2843153c3ed8fsystem.componentmodel.composition4.0.0.04ba1f4012a89ha2r5vsskg1rxuacxv143hzfuv1ct25uNIL Error: (08/27/2014 06:52:58 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Anwendung: Avira.OE.ServiceHost.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.ComponentModel.Composition.CompositionException Stapel: bei System.ComponentModel.Composition.Hosting.CompositionServices.GetExportedValueFromComposedPart(System.ComponentModel.Composition.Hosting.ImportEngine, System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider.GetExportedValue(System.ComponentModel.Composition.Primitives.ComposablePart, System.ComponentModel.Composition.Primitives.ExportDefinition, Boolean) bei System.ComponentModel.Composition.Hosting.CatalogExportProvider+CatalogExport.GetExportedValueCore() bei System.ComponentModel.Composition.Primitives.Export.get_Value() bei System.ComponentModel.Composition.ExportServices.GetExportedValueFromLazy[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.ComponentModel.Composition.Primitives.Export) bei System.ComponentModel.Composition.Hosting.ExportProvider.GetExportedValuesCore[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String) bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object) bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() bei System.Threading.ThreadPoolWorkQueue.Dispatch() bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (08/27/2014 00:07:33 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: thinclient.exe0.0.0.0hungapp0.0.0.000000000 Error: (09/01/2014 01:06:03 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: drakensangonline.exe0.0.0.0hungapp0.0.0.000000000 Error: (08/30/2014 07:38:08 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: explorer.exe6.0.2900.5512hungapp0.0.0.000000000 Error: (08/30/2014 06:23:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: drwtsn32.exe5.1.2600.0dbghelp.dll5.1.2600.55120001295d Error: (08/30/2014 06:22:49 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.0.2900.5512shell32.dll6.0.2900.55120002adc4 ==================== Memory info =========================== Processor: Intel(R) Pentium(R) 4 CPU 3.20GHz Percentage of memory in use: 35% Total physical RAM: 2687.43 MB Available physical RAM: 1730.63 MB Total Pagefile: 4580.2 MB Available Pagefile: 3595.58 MB Total Virtual: 2047.88 MB Available Virtual: 1939.56 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:37.26 GB) (Free:3.6 GB) NTFS ==>[Drive with boot components (Windows XP)] Drive h: (Chris) (Fixed) (Total:1397.26 GB) (Free:924.58 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 37.3 GB) (Disk ID: FDE45ACA) Partition 1: (Active) - (Size=37.3 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 1397.3 GB) (Disk ID: C8E00DAA) Partition 1: (Not Active) - (Size=1397.3 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
28.08.2014, 12:47 | #4 |
/// the machine /// TB-Ausbilder | Windos XP Professionell SP3 läuft nicht flüssig und hängt sich mehrmals auf hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windos XP Professionell SP3 läuft nicht flüssig und hängt sich mehrmals auf |
ahnung, automatisch, brauch, dos, einfach, freund, gen, home, hängt, lange, langsam, laufen, mauszeiger, melde, nicht mehr, professionell, ruckel, seite, sp3, spiele, system, taskleiste, verschwindet, vorhanden, öffnen |