Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows Explorer stürzt bereits beim Start ständig ab

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 11.11.2014, 12:56   #1
sevrob
 
Windows Explorer stürzt bereits beim Start ständig ab - Standard

Windows Explorer stürzt bereits beim Start ständig ab



Hallo liebe community,

gestern abend war ich das letzte Mal am Rechner, Window 7 Home Edition und bereits während des Abends erschien das popup-Fenster Windows-Explorer funktioniert nicht mehr, das nach dem Neustart des Explorers wieder abstürzte. Ich habe mir nichts dabei gedacht, surfte weiter und fuhr den Rechner später runter.

Nach dem heutigen Neustart erschien das popup von Beginn an und nun kann ich im normalen Modus den Rechner nicht mehr bedienen.

Derzeit befinde ich mich abgesicherten Modus mit aktivem Netzwerk und der Windows-Explorer stürzt zwar auch ständig ab, jedoch bleiben einige Sekunden zwischen Wiederherstellung und Absturz, so daß der Rechner bedienbar ist - vor allem die browser-Funktion ist davon nicht berührt.

Folgende Schritte habe ich unternommen:

sfc/scannow: keine Konflikte

Farbar Scan:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2014
Ran by rob (administrator) on ROB-HP on 11-11-2014 12:38:34
Running from C:\Users\rob\Downloads
Loaded Profile: rob (Available profiles: rob & Administrator)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Alexander Roshal) C:\Program Files\WinRAR\WinRAR.exe
(Sysinternals - www.sysinternals.com) C:\Users\rob\AppData\Local\Temp\Rar$EXa0.938\autoruns.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Farbar) C:\Users\rob\Downloads\FSS.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2011-12-23] (IDT, Inc.)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [37888 2011-12-23] (Hewlett-Packard )
HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291096 2011-12-05] (Intel Corporation)
HKLM-x32\...\Run: [HP Software Update] => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [BATINDICATOR] => C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
HKLM-x32\...\Run: [LaunchHPOSIAPP] => C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe [385024 2009-04-04] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642728 2012-06-26] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-07-15] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [443640 2014-09-03] (BlackBerry Limited)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [RIM PeerManager] => C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe [4836088 2014-09-15] (BlackBerry Limited)
HKU\S-1-5-21-1431726855-3746062891-2353634536-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKU\S-1-5-21-1431726855-3746062891-2353634536-1001\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564016 2013-07-15] (Samsung)
HKU\S-1-5-21-1431726855-3746062891-2353634536-1001\...\Run: [KiesAirMessage] => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-1431726855-3746062891-2353634536-1001\...\Run: [AusweisApp] => C:\Program Files (x86)\AusweisApp\siqBootLoader.exe [2518656 2014-01-24] (OpenLimit SignCubes AG)
HKU\S-1-5-21-1431726855-3746062891-2353634536-1001\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-11] (AMD)
Startup: C:\Users\rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Check for TWS Updates.lnk
ShortcutTarget: Check for TWS Updates.lnk -> C:\Jts\WiseUpdt.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x36D139381F7ACD01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPDSK/4
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {71588120-FC17-4463-B07D-2C71FE6E057B} URL = hxxp://go.findrsearch.com/search/web?q={searchTerms}
SearchScopes: HKLM - {71588120-FC17-4463-B07D-2C71FE6E057B} URL = hxxp://go.findrsearch.com/search/web?q={searchTerms}
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKLM - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM - {DF9A55C8-8256-43DD-A955-AB2DE3847099} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKLM-x32 - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 - {DF9A55C8-8256-43DD-A955-AB2DE3847099} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {71588120-FC17-4463-B07D-2C71FE6E057B} URL = hxxp://go.findrsearch.com/search/web?q={searchTerms}
SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKCU - {DF9A55C8-8256-43DD-A955-AB2DE3847099} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: AusweisApp 1.12.0.0 -> {C9EE92B7-EDD5-4ad9-8029-2EC6818E653A} -> C:\Program Files (x86)\AusweisApp\siqeCardClientIE64.ols (OpenLimit SignCubes AG)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: AusweisApp 1.12.0.0 -> {C9EE92B7-EDD5-4ad9-8029-2EC6818E653A} -> C:\Program Files (x86)\AusweisApp\siqeCardClientIE32.ols (OpenLimit SignCubes AG)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-1431726855-3746062891-2353634536-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\rob\AppData\Roaming\Mozilla\Firefox\Profiles\tssh8jsy.default-1410293152314
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ddg.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Cliqz Beta - C:\Users\rob\AppData\Roaming\Mozilla\Firefox\Profiles\tssh8jsy.default-1410293152314\Extensions\cliqz@cliqz.com [2014-11-11]

Chrome:
=======
CHR HomePage: Default -> hxxp://go.findrsearch.com
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSearchURL: Default -> https://www.bing.com/search?setmkt=de-DE&q={searchTerms}
CHR DefaultNewTabURL: Default -> https://www.bing.com/chrome/newtab?setmkt=de-DE
CHR DefaultSuggestURL: Default -> hxxp://api.bing.com/osjson.aspx?query={searchTerms}&language={language}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll ()
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U9) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Profile: C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-06]
CHR Extension: (YouTube) - C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-12]
CHR Extension: (Google-Suche) - C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-12]
CHR Extension: (Google Wallet) - C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Google Mail) - C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 avmike; C:\Program Files\FRITZ!Fernzugang\avmike.exe [337824 2012-11-28] (AVM Berlin)
S3 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [588024 2014-09-04] (BlackBerry Limited)
S2 CalendarSynchService; C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [16384 2011-08-16] (Hewlett-Packard) [File not signed]
S2 certsrv; C:\Program Files\FRITZ!Fernzugang\certsrv.exe [143776 2012-11-28] (AVM Berlin)
S2 CLKMSVC10_38F51D56; c:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-02-25] (CyberLink)
S2 FolderSize; C:\Program Files (x86)\FolderSize\FolderSizeSvc.exe [116224 2010-04-06] (Brio) [File not signed]
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2011-12-16] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation)
S2 nwtsrv; C:\Program Files\FRITZ!Fernzugang\nwtsrv.exe [191328 2013-06-10] (AVM Berlin)
S2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [625304 2012-09-28] (Pandora.TV)
S2 RIM MDNS; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe [396024 2014-09-15] (Apple Inc.)
S2 RIM Tunnel Service; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe [1343224 2014-09-15] (BlackBerry Limited)
S3 Samsung UPD Service2; C:\Windows\System32\SUPDSvc2.exe [158208 2012-04-06] (Samsung Electronics) [File not signed]
S2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [311296 2011-12-23] (IDT, Inc.) [File not signed]
S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 blackberryncm; C:\Windows\System32\DRIVERS\blackberryncm6_AMD64.sys [24576 2014-04-15] (BlackBerry)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-09-19] (DT Soft Ltd)
R3 NWIM; C:\Windows\System32\DRIVERS\avmnwim.sys [412024 2011-07-05] (AVM Berlin)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [79872 2014-05-06] (BlackBerry Limited)
R3 rimvndis; C:\Windows\System32\Drivers\rimvndis6_AMD64.sys [17920 2014-05-07] (Research in Motion Limited)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-11 12:38 - 2014-11-11 12:38 - 02116096 _____ (Farbar) C:\Users\rob\Downloads\FRST64.exe
2014-11-11 12:38 - 2014-11-11 12:38 - 00019397 _____ () C:\Users\rob\Downloads\FRST.txt
2014-11-11 12:38 - 2014-11-11 12:38 - 00000000 ____D () C:\FRST
2014-11-11 12:37 - 2014-11-11 12:37 - 00003455 _____ () C:\Users\rob\Downloads\FSS.txt
2014-11-11 12:36 - 2014-11-11 12:36 - 00415232 _____ (Farbar) C:\Users\rob\Downloads\FSS.exe
2014-11-11 12:05 - 2014-11-11 12:05 - 00511633 _____ () C:\Users\rob\Downloads\Autoruns_1203.zip
2014-11-11 12:05 - 2014-11-11 12:05 - 00000000 ____D () C:\Users\rob\AppData\Roaming\Cliqz
2014-11-11 12:05 - 2011-05-13 11:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-11-11 12:05 - 2011-03-25 19:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-11-11 12:04 - 2014-11-11 12:04 - 01125200 _____ () C:\Users\rob\Downloads\Autoruns - CHIP-Installer.exe
2014-11-10 20:27 - 2014-11-10 20:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-06 11:46 - 2014-11-06 11:46 - 00193536 _____ () C:\Users\rob\Desktop\Bestellform-MT_FW2014_inkl_OUT_EUR-DE_AT.xls
2014-10-26 15:25 - 2014-10-26 15:25 - 00000830 _____ () C:\Users\rob\AppData\Roaming\Microsoft\Windows\Start Menu\RüSchi (Rückenschilder).lnk
2014-10-26 15:25 - 2014-10-26 15:25 - 00000812 _____ () C:\Users\rob\Desktop\Rückenschilder.lnk
2014-10-26 15:25 - 2014-10-26 15:25 - 00000806 _____ () C:\Users\rob\Desktop\RüSchi (Rückenschilder).lnk
2014-10-26 15:25 - 2014-10-26 15:25 - 00000806 _____ () C:\Users\Administrator\Desktop\RüSchi (Rückenschilder).lnk
2014-10-26 15:25 - 2014-10-26 15:25 - 00000000 ____D () C:\Applikationen
2014-10-26 15:24 - 2014-10-26 15:24 - 02695168 _____ (taktools.de) C:\Users\rob\Downloads\setup.exe
2014-10-24 22:24 - 2014-10-24 22:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_blackberryncm6_AMD64_01007.Wdf
2014-10-24 22:22 - 2014-10-24 22:22 - 00001027 _____ () C:\Users\Public\Desktop\BlackBerry Blend.lnk
2014-10-24 22:22 - 2014-10-24 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry Blend
2014-10-24 22:22 - 2014-10-24 22:22 - 00000000 ____D () C:\Program Files (x86)\BlackBerry
2014-10-24 22:21 - 2014-10-24 22:21 - 00001123 _____ () C:\Users\Public\Desktop\BlackBerry Link.lnk
2014-10-24 22:21 - 2014-10-24 22:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry Link
2014-10-24 22:20 - 2014-10-24 22:20 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-24 21:38 - 2014-10-24 21:53 - 1422971950 _____ () C:\Users\rob\Downloads\Z10_10.3.00.1418_STL100-2-3.7z
2014-10-24 20:52 - 2014-10-24 20:52 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-10-24 20:52 - 2014-10-24 20:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-10-24 20:51 - 2014-10-24 20:52 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-10-24 20:51 - 2014-10-24 20:52 - 00000000 ____D () C:\Program Files\iTunes
2014-10-24 20:51 - 2014-10-24 20:52 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-10-24 20:51 - 2014-10-24 20:51 - 00000000 ____D () C:\Program Files\iPod
2014-10-14 20:38 - 2014-10-14 20:38 - 02237270 _____ () C:\Users\rob\Downloads\Lebenslauf.odt
2014-10-14 15:29 - 2014-10-20 16:03 - 00000000 ____D () C:\Users\rob\Desktop\Fotos cafedesign
2014-10-13 14:20 - 2014-10-13 14:20 - 02100654 _____ () C:\Users\rob\Downloads\Lebenslauf Ronja Tretter-1(1).odt
2014-10-13 13:51 - 2014-10-13 13:51 - 02204943 _____ () C:\Users\rob\Downloads\Lebenslauf Ronja Tretter
2014-10-13 13:51 - 2014-10-13 13:51 - 02100654 _____ () C:\Users\rob\Downloads\Lebenslauf Ronja Tretter-1.odt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-11 12:07 - 2012-03-27 02:50 - 00696620 _____ () C:\Windows\system32\perfh007.dat
2014-11-11 12:07 - 2012-03-27 02:50 - 00147916 _____ () C:\Windows\system32\perfc007.dat
2014-11-11 12:07 - 2009-07-14 06:13 - 01612484 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-11 12:04 - 2012-09-18 11:41 - 00000000 ____D () C:\Users\rob\AppData\Local\CrashDumps
2014-11-11 12:00 - 2012-09-17 18:01 - 01615538 _____ () C:\Windows\WindowsUpdate.log
2014-11-11 11:56 - 2014-09-29 15:36 - 00000000 ____D () C:\Users\rob\.ausweisapp
2014-11-11 11:56 - 2013-09-30 10:17 - 00000374 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-11-11 11:56 - 2013-02-10 21:33 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-11 11:56 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-11 11:56 - 2009-07-14 05:51 - 00618110 _____ () C:\Windows\setupact.log
2014-11-11 11:55 - 2013-02-10 21:33 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-11 11:55 - 2009-07-14 05:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-11 11:55 - 2009-07-14 05:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-11 11:54 - 2012-09-18 12:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-11 11:54 - 2012-09-18 10:48 - 00000166 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-11-11 07:46 - 2012-09-18 11:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-10 23:20 - 2014-01-22 09:52 - 00000000 ____D () C:\rsPOS
2014-11-10 23:11 - 2013-08-08 11:21 - 00613888 _____ () C:\Users\rob\Desktop\Statistik LuLa Essen.xls
2014-11-10 23:05 - 2012-09-17 18:06 - 00003914 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{5AD2326C-A651-4B3F-A20E-FE3C59342D29}
2014-11-10 14:11 - 2012-08-16 16:33 - 00000099 _____ () C:\Users\Public\LMDebug.log
2014-11-10 12:38 - 2012-08-16 11:40 - 00000000 ____D () C:\Users\rob\Desktop\LULA G
2014-11-03 15:23 - 2012-11-03 22:46 - 00000000 ____D () C:\Users\rob\AppData\Roaming\vlc
2014-11-03 14:46 - 2012-10-11 18:24 - 00000000 ____D () C:\Users\rob\AppData\Roaming\Skype
2014-10-28 10:03 - 2010-11-21 04:47 - 00763214 _____ () C:\Windows\PFRO.log
2014-10-27 23:55 - 2012-09-18 11:42 - 00000000 ____D () C:\Users\rob\AppData\Roaming\WildTangent
2014-10-27 23:55 - 2012-03-27 03:10 - 00000000 ____D () C:\ProgramData\WildTangent
2014-10-27 23:55 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-27 21:03 - 2012-10-29 19:03 - 00000000 ____D () C:\ProgramData\Recovery
2014-10-24 20:51 - 2013-12-25 13:10 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-10-24 20:51 - 2012-09-18 11:56 - 00000000 ____D () C:\ProgramData\Apple
2014-10-24 20:51 - 2012-09-18 11:56 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-10-22 20:38 - 2014-08-26 10:26 - 00051200 _____ () C:\Users\rob\Desktop\Brainstorming Bauvorhaben.xls
2014-10-22 10:06 - 2013-02-10 21:33 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-22 10:06 - 2013-02-10 21:33 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-14 21:04 - 2014-09-28 09:20 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

Files to move or delete:
====================
C:\Users\rob\backup registry cccleaner.reg
C:\Users\rob\cc_20090521_002650.reg


Some content of TEMP:
====================
C:\Users\rob\AppData\Local\Temp\AskSLib.dll
C:\Users\rob\AppData\Local\Temp\avgnt.exe
C:\Users\rob\AppData\Local\Temp\BlackBerryDeviceManager.exe
C:\Users\rob\AppData\Local\Temp\BlackBerryLauncher.exe
C:\Users\rob\AppData\Local\Temp\extension2711884361425534035.dll
C:\Users\rob\AppData\Local\Temp\extension7209162655509904511.dll
C:\Users\rob\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\rob\AppData\Local\Temp\PIPInstaller_PTV_.exe
C:\Users\rob\AppData\Local\Temp\Scan2PdfSetup.exe
C:\Users\rob\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\rob\AppData\Local\Temp\uninstall.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-05 11:11

==================== End Of Log ============================

Farbar Recovery Scan:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2014
Ran by rob (administrator) on ROB-HP on 11-11-2014 12:38:34
Running from C:\Users\rob\Downloads
Loaded Profile: rob (Available profiles: rob & Administrator)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Alexander Roshal) C:\Program Files\WinRAR\WinRAR.exe
(Sysinternals - www.sysinternals.com) C:\Users\rob\AppData\Local\Temp\Rar$EXa0.938\autoruns.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Farbar) C:\Users\rob\Downloads\FSS.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2011-12-23] (IDT, Inc.)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [37888 2011-12-23] (Hewlett-Packard )
HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291096 2011-12-05] (Intel Corporation)
HKLM-x32\...\Run: [HP Software Update] => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [BATINDICATOR] => C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
HKLM-x32\...\Run: [LaunchHPOSIAPP] => C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe [385024 2009-04-04] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642728 2012-06-26] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-07-15] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [443640 2014-09-03] (BlackBerry Limited)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [RIM PeerManager] => C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe [4836088 2014-09-15] (BlackBerry Limited)
HKU\S-1-5-21-1431726855-3746062891-2353634536-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKU\S-1-5-21-1431726855-3746062891-2353634536-1001\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564016 2013-07-15] (Samsung)
HKU\S-1-5-21-1431726855-3746062891-2353634536-1001\...\Run: [KiesAirMessage] => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-1431726855-3746062891-2353634536-1001\...\Run: [AusweisApp] => C:\Program Files (x86)\AusweisApp\siqBootLoader.exe [2518656 2014-01-24] (OpenLimit SignCubes AG)
HKU\S-1-5-21-1431726855-3746062891-2353634536-1001\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-11] (AMD)
Startup: C:\Users\rob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Check for TWS Updates.lnk
ShortcutTarget: Check for TWS Updates.lnk -> C:\Jts\WiseUpdt.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x36D139381F7ACD01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPDSK/4
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {71588120-FC17-4463-B07D-2C71FE6E057B} URL = hxxp://go.findrsearch.com/search/web?q={searchTerms}
SearchScopes: HKLM - {71588120-FC17-4463-B07D-2C71FE6E057B} URL = hxxp://go.findrsearch.com/search/web?q={searchTerms}
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKLM - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM - {DF9A55C8-8256-43DD-A955-AB2DE3847099} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKLM-x32 - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 - {DF9A55C8-8256-43DD-A955-AB2DE3847099} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {71588120-FC17-4463-B07D-2C71FE6E057B} URL = hxxp://go.findrsearch.com/search/web?q={searchTerms}
SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKCU - {DF9A55C8-8256-43DD-A955-AB2DE3847099} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: AusweisApp 1.12.0.0 -> {C9EE92B7-EDD5-4ad9-8029-2EC6818E653A} -> C:\Program Files (x86)\AusweisApp\siqeCardClientIE64.ols (OpenLimit SignCubes AG)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: AusweisApp 1.12.0.0 -> {C9EE92B7-EDD5-4ad9-8029-2EC6818E653A} -> C:\Program Files (x86)\AusweisApp\siqeCardClientIE32.ols (OpenLimit SignCubes AG)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-1431726855-3746062891-2353634536-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\rob\AppData\Roaming\Mozilla\Firefox\Profiles\tssh8jsy.default-1410293152314
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ddg.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Cliqz Beta - C:\Users\rob\AppData\Roaming\Mozilla\Firefox\Profiles\tssh8jsy.default-1410293152314\Extensions\cliqz@cliqz.com [2014-11-11]

Chrome:
=======
CHR HomePage: Default -> hxxp://go.findrsearch.com
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSearchURL: Default -> https://www.bing.com/search?setmkt=de-DE&q={searchTerms}
CHR DefaultNewTabURL: Default -> https://www.bing.com/chrome/newtab?setmkt=de-DE
CHR DefaultSuggestURL: Default -> hxxp://api.bing.com/osjson.aspx?query={searchTerms}&language={language}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll ()
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U9) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Profile: C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-06]
CHR Extension: (YouTube) - C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-12]
CHR Extension: (Google-Suche) - C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-12]
CHR Extension: (Google Wallet) - C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Google Mail) - C:\Users\rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 avmike; C:\Program Files\FRITZ!Fernzugang\avmike.exe [337824 2012-11-28] (AVM Berlin)
S3 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [588024 2014-09-04] (BlackBerry Limited)
S2 CalendarSynchService; C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [16384 2011-08-16] (Hewlett-Packard) [File not signed]
S2 certsrv; C:\Program Files\FRITZ!Fernzugang\certsrv.exe [143776 2012-11-28] (AVM Berlin)
S2 CLKMSVC10_38F51D56; c:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-02-25] (CyberLink)
S2 FolderSize; C:\Program Files (x86)\FolderSize\FolderSizeSvc.exe [116224 2010-04-06] (Brio) [File not signed]
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2011-12-16] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation)
S2 nwtsrv; C:\Program Files\FRITZ!Fernzugang\nwtsrv.exe [191328 2013-06-10] (AVM Berlin)
S2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [625304 2012-09-28] (Pandora.TV)
S2 RIM MDNS; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe [396024 2014-09-15] (Apple Inc.)
S2 RIM Tunnel Service; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe [1343224 2014-09-15] (BlackBerry Limited)
S3 Samsung UPD Service2; C:\Windows\System32\SUPDSvc2.exe [158208 2012-04-06] (Samsung Electronics) [File not signed]
S2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [311296 2011-12-23] (IDT, Inc.) [File not signed]
S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 blackberryncm; C:\Windows\System32\DRIVERS\blackberryncm6_AMD64.sys [24576 2014-04-15] (BlackBerry)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-09-19] (DT Soft Ltd)
R3 NWIM; C:\Windows\System32\DRIVERS\avmnwim.sys [412024 2011-07-05] (AVM Berlin)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [79872 2014-05-06] (BlackBerry Limited)
R3 rimvndis; C:\Windows\System32\Drivers\rimvndis6_AMD64.sys [17920 2014-05-07] (Research in Motion Limited)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-11 12:38 - 2014-11-11 12:38 - 02116096 _____ (Farbar) C:\Users\rob\Downloads\FRST64.exe
2014-11-11 12:38 - 2014-11-11 12:38 - 00019397 _____ () C:\Users\rob\Downloads\FRST.txt
2014-11-11 12:38 - 2014-11-11 12:38 - 00000000 ____D () C:\FRST
2014-11-11 12:37 - 2014-11-11 12:37 - 00003455 _____ () C:\Users\rob\Downloads\FSS.txt
2014-11-11 12:36 - 2014-11-11 12:36 - 00415232 _____ (Farbar) C:\Users\rob\Downloads\FSS.exe
2014-11-11 12:05 - 2014-11-11 12:05 - 00511633 _____ () C:\Users\rob\Downloads\Autoruns_1203.zip
2014-11-11 12:05 - 2014-11-11 12:05 - 00000000 ____D () C:\Users\rob\AppData\Roaming\Cliqz
2014-11-11 12:05 - 2011-05-13 11:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-11-11 12:05 - 2011-03-25 19:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-11-11 12:04 - 2014-11-11 12:04 - 01125200 _____ () C:\Users\rob\Downloads\Autoruns - CHIP-Installer.exe
2014-11-10 20:27 - 2014-11-10 20:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-06 11:46 - 2014-11-06 11:46 - 00193536 _____ () C:\Users\rob\Desktop\Bestellform-MT_FW2014_inkl_OUT_EUR-DE_AT.xls
2014-10-26 15:25 - 2014-10-26 15:25 - 00000830 _____ () C:\Users\rob\AppData\Roaming\Microsoft\Windows\Start Menu\RüSchi (Rückenschilder).lnk
2014-10-26 15:25 - 2014-10-26 15:25 - 00000812 _____ () C:\Users\rob\Desktop\Rückenschilder.lnk
2014-10-26 15:25 - 2014-10-26 15:25 - 00000806 _____ () C:\Users\rob\Desktop\RüSchi (Rückenschilder).lnk
2014-10-26 15:25 - 2014-10-26 15:25 - 00000806 _____ () C:\Users\Administrator\Desktop\RüSchi (Rückenschilder).lnk
2014-10-26 15:25 - 2014-10-26 15:25 - 00000000 ____D () C:\Applikationen
2014-10-26 15:24 - 2014-10-26 15:24 - 02695168 _____ (taktools.de) C:\Users\rob\Downloads\setup.exe
2014-10-24 22:24 - 2014-10-24 22:24 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_blackberryncm6_AMD64_01007.Wdf
2014-10-24 22:22 - 2014-10-24 22:22 - 00001027 _____ () C:\Users\Public\Desktop\BlackBerry Blend.lnk
2014-10-24 22:22 - 2014-10-24 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry Blend
2014-10-24 22:22 - 2014-10-24 22:22 - 00000000 ____D () C:\Program Files (x86)\BlackBerry
2014-10-24 22:21 - 2014-10-24 22:21 - 00001123 _____ () C:\Users\Public\Desktop\BlackBerry Link.lnk
2014-10-24 22:21 - 2014-10-24 22:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry Link
2014-10-24 22:20 - 2014-10-24 22:20 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-24 21:38 - 2014-10-24 21:53 - 1422971950 _____ () C:\Users\rob\Downloads\Z10_10.3.00.1418_STL100-2-3.7z
2014-10-24 20:52 - 2014-10-24 20:52 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-10-24 20:52 - 2014-10-24 20:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-10-24 20:51 - 2014-10-24 20:52 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-10-24 20:51 - 2014-10-24 20:52 - 00000000 ____D () C:\Program Files\iTunes
2014-10-24 20:51 - 2014-10-24 20:52 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-10-24 20:51 - 2014-10-24 20:51 - 00000000 ____D () C:\Program Files\iPod
2014-10-14 20:38 - 2014-10-14 20:38 - 02237270 _____ () C:\Users\rob\Downloads\Lebenslauf.odt
2014-10-14 15:29 - 2014-10-20 16:03 - 00000000 ____D () C:\Users\rob\Desktop\Fotos cafedesign
2014-10-13 14:20 - 2014-10-13 14:20 - 02100654 _____ () C:\Users\rob\Downloads\Lebenslauf Ronja Tretter-1(1).odt
2014-10-13 13:51 - 2014-10-13 13:51 - 02204943 _____ () C:\Users\rob\Downloads\Lebenslauf Ronja Tretter
2014-10-13 13:51 - 2014-10-13 13:51 - 02100654 _____ () C:\Users\rob\Downloads\Lebenslauf Ronja Tretter-1.odt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-11 12:07 - 2012-03-27 02:50 - 00696620 _____ () C:\Windows\system32\perfh007.dat
2014-11-11 12:07 - 2012-03-27 02:50 - 00147916 _____ () C:\Windows\system32\perfc007.dat
2014-11-11 12:07 - 2009-07-14 06:13 - 01612484 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-11 12:04 - 2012-09-18 11:41 - 00000000 ____D () C:\Users\rob\AppData\Local\CrashDumps
2014-11-11 12:00 - 2012-09-17 18:01 - 01615538 _____ () C:\Windows\WindowsUpdate.log
2014-11-11 11:56 - 2014-09-29 15:36 - 00000000 ____D () C:\Users\rob\.ausweisapp
2014-11-11 11:56 - 2013-09-30 10:17 - 00000374 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-11-11 11:56 - 2013-02-10 21:33 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-11 11:56 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-11 11:56 - 2009-07-14 05:51 - 00618110 _____ () C:\Windows\setupact.log
2014-11-11 11:55 - 2013-02-10 21:33 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-11 11:55 - 2009-07-14 05:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-11 11:55 - 2009-07-14 05:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-11 11:54 - 2012-09-18 12:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-11 11:54 - 2012-09-18 10:48 - 00000166 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-11-11 07:46 - 2012-09-18 11:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-10 23:20 - 2014-01-22 09:52 - 00000000 ____D () C:\rsPOS
2014-11-10 23:11 - 2013-08-08 11:21 - 00613888 _____ () C:\Users\rob\Desktop\Statistik LuLa Essen.xls
2014-11-10 23:05 - 2012-09-17 18:06 - 00003914 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{5AD2326C-A651-4B3F-A20E-FE3C59342D29}
2014-11-10 14:11 - 2012-08-16 16:33 - 00000099 _____ () C:\Users\Public\LMDebug.log
2014-11-10 12:38 - 2012-08-16 11:40 - 00000000 ____D () C:\Users\rob\Desktop\LULA G
2014-11-03 15:23 - 2012-11-03 22:46 - 00000000 ____D () C:\Users\rob\AppData\Roaming\vlc
2014-11-03 14:46 - 2012-10-11 18:24 - 00000000 ____D () C:\Users\rob\AppData\Roaming\Skype
2014-10-28 10:03 - 2010-11-21 04:47 - 00763214 _____ () C:\Windows\PFRO.log
2014-10-27 23:55 - 2012-09-18 11:42 - 00000000 ____D () C:\Users\rob\AppData\Roaming\WildTangent
2014-10-27 23:55 - 2012-03-27 03:10 - 00000000 ____D () C:\ProgramData\WildTangent
2014-10-27 23:55 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-27 21:03 - 2012-10-29 19:03 - 00000000 ____D () C:\ProgramData\Recovery
2014-10-24 20:51 - 2013-12-25 13:10 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-10-24 20:51 - 2012-09-18 11:56 - 00000000 ____D () C:\ProgramData\Apple
2014-10-24 20:51 - 2012-09-18 11:56 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-10-22 20:38 - 2014-08-26 10:26 - 00051200 _____ () C:\Users\rob\Desktop\Brainstorming Bauvorhaben.xls
2014-10-22 10:06 - 2013-02-10 21:33 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-22 10:06 - 2013-02-10 21:33 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-14 21:04 - 2014-09-28 09:20 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

Files to move or delete:
====================
C:\Users\rob\backup registry cccleaner.reg
C:\Users\rob\cc_20090521_002650.reg


Some content of TEMP:
====================
C:\Users\rob\AppData\Local\Temp\AskSLib.dll
C:\Users\rob\AppData\Local\Temp\avgnt.exe
C:\Users\rob\AppData\Local\Temp\BlackBerryDeviceManager.exe
C:\Users\rob\AppData\Local\Temp\BlackBerryLauncher.exe
C:\Users\rob\AppData\Local\Temp\extension2711884361425534035.dll
C:\Users\rob\AppData\Local\Temp\extension7209162655509904511.dll
C:\Users\rob\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\rob\AppData\Local\Temp\PIPInstaller_PTV_.exe
C:\Users\rob\AppData\Local\Temp\Scan2PdfSetup.exe
C:\Users\rob\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\rob\AppData\Local\Temp\uninstall.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-05 11:11

==================== End Of Log ============================

Angeblich gibt es nichts zu fixen. Nun weiß ich nicht mehr weiter.

Für Hilfe wäre ich sehr dankbar.

Gruß, r

 

Themen zu Windows Explorer stürzt bereits beim Start ständig ab
fehlercode 0xc0000005, fehlercode windows, funktioniert nicht mehr, html/scrinject.b.gen, js/securitydisabler.a.gen, pandora service entfernen, tunnel, win32/installmonetizer.aq, win32/softonicdownloader.d, win32/toolbar.conduit.b, win32/toolbar.searchsuite, window 7




Ähnliche Themen: Windows Explorer stürzt bereits beim Start ständig ab


  1. Windows XP: Datei-Explorer stürzt ständig ab
    Log-Analyse und Auswertung - 30.07.2014 (19)
  2. Vista: Windows Explorer stürzt nacht Start ab (Dauerschleife)
    Log-Analyse und Auswertung - 01.03.2014 (7)
  3. windows explorer stürzt ständig ab und nur prozesse werden gestartet aber keine anwendungen
    Plagegeister aller Art und deren Bekämpfung - 06.12.2013 (1)
  4. Windows 7, langsames Hochfahren, hohe CPU-Auslastung (>60%) bereits bei Sitzungs-Start
    Log-Analyse und Auswertung - 07.11.2013 (9)
  5. Windows Explorer stürzt machmal beim Rechtsklick auf irgendwelche Dateien ab
    Log-Analyse und Auswertung - 14.10.2013 (2)
  6. Windows 7 64 bit:Computer sehr langsam und explorer.exe stürzt ständig ab
    Log-Analyse und Auswertung - 01.09.2013 (9)
  7. Vista Windows Explorer stürzt als ab...nur beim Ordner Bilder
    Plagegeister aller Art und deren Bekämpfung - 28.01.2013 (7)
  8. "Explorer.exe" stürzt nach start von Windows 7 ab
    Log-Analyse und Auswertung - 15.10.2012 (1)
  9. Windows Explorer stürzt bei pc start immer wieder ab und lädt sich neu
    Plagegeister aller Art und deren Bekämpfung - 12.04.2012 (1)
  10. Firefox stürzt beim Start ständig ab
    Log-Analyse und Auswertung - 05.10.2010 (1)
  11. explorer.exe stürzt ständig ab
    Log-Analyse und Auswertung - 20.09.2010 (12)
  12. Rootkid.Agend gefunden - Internet stürzt beim Start eines PC ab
    Plagegeister aller Art und deren Bekämpfung - 30.08.2010 (3)
  13. Explorer stürzt ständig ab und ständige angriffe auf meinen rechner
    Plagegeister aller Art und deren Bekämpfung - 24.04.2010 (6)
  14. Explorer stürzt ständig ab - Virus, Trojaner?
    Log-Analyse und Auswertung - 09.03.2010 (1)
  15. Rechner total langsam und explorer stürzt ständig ab, bin hilflos
    Mülltonne - 31.10.2008 (0)
  16. Internet Explorer stürzt ständig ab
    Log-Analyse und Auswertung - 18.12.2007 (4)
  17. PC stürzt bereits beim Ladevorgang ab!
    Alles rund um Windows - 17.09.2005 (5)

Zum Thema Windows Explorer stürzt bereits beim Start ständig ab - Hallo liebe community, gestern abend war ich das letzte Mal am Rechner, Window 7 Home Edition und bereits während des Abends erschien das popup-Fenster Windows-Explorer funktioniert nicht mehr, das nach - Windows Explorer stürzt bereits beim Start ständig ab...
Archiv
Du betrachtest: Windows Explorer stürzt bereits beim Start ständig ab auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.