![]() |
|
Plagegeister aller Art und deren Bekämpfung: explorer.exe fehlermeldungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() explorer.exe fehlermeldung Hallo, liebe Helfer! Ich bin mir nicht sicher was das für eine fehlermeldung ist, sie nervt und macht mir sorgen, ansonsten funktioniert eigentlich alles nachdem ich sie schliesse... Ich habe von anfang an mozilla und habe mit windows explorer eigentlich nichts zu tun. In etwa zu der zeit, seitdem die fehlermeldung erscheint habe ich ein download von: gimp durchgeführt, vielleicht habe ich auch einfach nur die falsche version? ![]() Ich habe schritt 1. und 2. eurer anweisungen bei problemen befolgt, da ich aber nicht überreagieren möchte, sende ich euch die ergebnisse und mache erst mal nicht weiter... Vielen vielen Dank schon mal, wenn mir jemand weiterhelfen kann! Erst mal die Fehlermeldung: Problemsignatur: Problemereignisname: BEX Anwendungsname: explorer.exe Anwendungsversion: 6.1.7601.17514 Anwendungszeitstempel: 4ce796f3 Fehlermodulname: bho.dll_unloaded Fehlermodulversion: 0.0.0.0 Fehlermodulzeitstempel: 542bf70b Ausnahmeoffset: 078687c0 Ausnahmecode: c0000005 Ausnahmedaten: 00000008 Betriebsystemversion: 6.1.7601.2.1.0.768.3 Gebietsschema-ID: 1031 Zusatzinformation 1: 0a9e Zusatzinformation 2: 0a9e372d3b4ad19135b953a78882e789 Zusatzinformation 3: 0a9e Zusatzinformation 4: 0a9e372d3b4ad19135b953a78882e789 Lesen Sie unsere Datenschutzbestimmungen online: hxxp://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0407 Wenn die Onlinedatenschutzbestimmungen nicht verfügbar sind, lesen Sie unsere Datenschutzbestimmungen offline: C:\Windows\system32\de-DE\erofflps.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-11-2014 Ran by chiefmaster (administrator) on NEWUSER-7B3SBCM on 21-11-2014 00:23:20 Running from C:\Users\chiefmaster\Downloads Loaded Profile: chiefmaster (Available profiles: chiefmaster) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Panda Security) C:\Program Files\Panda USB Vaccine\USBVaccine.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe () C:\Users\chiefmaster\Downloads\Defogger.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = www.afb24.com HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA72B7D3880B5CF01 HKU\S-1-5-21-2244492678-1565340186-2046745813-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKU\S-1-5-21-2244492678-1565340186-2046745813-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity SearchScopes: HKU\S-1-5-21-2244492678-1565340186-2046745813-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity BHO: No Name -> {0025320D-4D37-4C73-9A5C-0C28F04068A3} -> C:\Users\chiefmaster\AppData\LocalLow\IE-BHO\bho.dll () BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default FF DefaultSearchEngine: Ixquick HTTPS - Deutsch FF SelectedSearchEngine: Ixquick HTTPS - Deutsch FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF user.js: detected! => C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\user.js FF SearchPlugin: C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\searchplugins\ixquick-https---deutsch.xml FF Extension: Foxi Security - C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\Extensions\foxi@securitii-dhfjs.com [2014-11-01] FF Extension: Adblock Plus - C:\Users\chiefmaster\AppData\Roaming\Mozilla\Firefox\Profiles\7sn1yoe3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-12] Chrome: ======= ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation) R2 WHService; C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe [628736 2014-10-15] () [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 b06diag; C:\Windows\system32\drivers\bxdiagx.sys [76840 2010-12-16] (Broadcom Corporation) S3 BFN7x86; C:\Windows\system32\drivers\Xeno7x86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.) S3 BFNVis32; C:\Windows\system32\drivers\XenoVx86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.) S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [150568 2012-02-22] (Broadcom Corporation) S3 bxois; C:\Windows\system32\drivers\bxois.sys [431144 2010-12-10] (Broadcom Corporation) R3 e1express; C:\Windows\System32\DRIVERS\e1e6232.sys [231640 2012-03-07] (Intel Corporation) S3 e36gbus; C:\Windows\system32\drivers\e36gbus.sys [285056 2009-06-30] (MCCI Corporation) S3 e36gmgmt; C:\Windows\system32\drivers\e36gmgmt.sys [357376 2009-06-30] (MCCI Corporation) S3 e36wgps; C:\Windows\system32\drivers\e36wgps.sys [82984 2009-07-10] (Ericsson AB) S3 ecnssndis; C:\Windows\System32\Drivers\wwanuss.sys [10240 2009-09-22] (Ericsson AB) S3 ecnssndisfltr; C:\Windows\System32\Drivers\wwanussf.sys [14848 2009-09-22] (Ericsson AB) S3 FUJ02B1; C:\Windows\system32\drivers\FUJ02B1.sys [5888 2006-11-01] (FUJITSU LIMITED) S3 GzTpHid; C:\Windows\system32\drivers\GzTpHid.sys [24576 2006-11-29] (GUNZE) S3 IFCoEMP; C:\Windows\system32\drivers\ifM60x32.sys [271120 2011-03-18] (Intel(R) Corporation) S3 IFCoEVB; C:\Windows\system32\drivers\ifP60X32.sys [62224 2011-03-18] (Intel(R) Corporation) S3 ioatdma1; C:\Windows\System32\Drivers\qd16032.sys [36552 2009-11-16] (Intel Corporation) S3 ioatdma2; C:\Windows\System32\Drivers\qd26032.sys [37576 2009-11-16] (Intel Corporation) S3 MEI; C:\Windows\system32\drivers\HECI.sys [40832 2008-06-26] (Intel Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation) R1 MpKsld861a995; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{73F06144-2B27-4273-A3AE-7CD1B3DA99D0}\MpKsld861a995.sys [39464 2014-11-20] (Microsoft Corporation) S3 risdpcie; C:\Windows\system32\drivers\risdpe86.sys [47616 2009-10-28] (REDC) S3 rixdpcie; C:\Windows\system32\drivers\rixdpe86.sys [38912 2009-09-28] (REDC) S3 wisdpen; C:\Windows\system32\drivers\wisdpen.sys [30888 2008-03-27] (Wacom Technology) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-21 00:23 - 2014-11-21 00:23 - 00008931 _____ () C:\Users\chiefmaster\Downloads\FRST.txt 2014-11-21 00:23 - 2014-11-21 00:23 - 00000000 ____D () C:\FRST 2014-11-21 00:22 - 2014-11-21 00:22 - 01108992 _____ (Farbar) C:\Users\chiefmaster\Downloads\FRST.exe 2014-11-21 00:21 - 2014-11-21 00:21 - 02117632 _____ (Farbar) C:\Users\chiefmaster\Downloads\FRST64.exe 2014-11-21 00:20 - 2014-11-21 00:20 - 00000484 _____ () C:\Users\chiefmaster\Downloads\defogger_disable.log 2014-11-21 00:20 - 2014-11-21 00:20 - 00000000 _____ () C:\Users\chiefmaster\defogger_reenable 2014-11-21 00:17 - 2014-11-21 00:17 - 00050477 _____ () C:\Users\chiefmaster\Downloads\Defogger.exe 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\ProgramData\Panda Security 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security 2014-11-20 23:44 - 2014-11-20 23:44 - 00000000 ____D () C:\Program Files\Panda USB Vaccine 2014-11-20 23:42 - 2014-11-20 23:42 - 00848856 _____ (Panda Security ) C:\Users\chiefmaster\Downloads\USBVaccineSetup.exe 2014-11-19 23:17 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-19 23:17 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-12 13:42 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-12 13:42 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-11-12 13:42 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-12 13:42 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-11-12 13:42 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-11-12 13:41 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-12 13:41 - 2014-10-14 02:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-12 13:41 - 2014-10-14 02:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-12 13:41 - 2014-10-14 02:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-12 13:41 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-12 13:41 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-12 13:41 - 2014-10-10 01:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-12 13:41 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-11-12 13:41 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-11-11 11:50 - 2014-11-11 11:50 - 00633240 _____ () C:\Windows\Minidump\111114-23290-01.dmp 2014-11-03 10:09 - 2014-11-03 10:09 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\Apps\2.0 2014-11-03 01:13 - 2014-11-03 01:13 - 00003839 _____ () C:\Users\chiefmaster\AppData\Local\recently-used.xbel 2014-11-01 01:37 - 2014-11-01 01:37 - 00001059 _____ () C:\Users\chiefmaster\Desktop\GIMP 2.lnk 2014-11-01 01:17 - 2014-11-03 01:13 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\gtk-2.0 2014-11-01 01:17 - 2014-11-01 01:17 - 00000000 ____D () C:\Users\chiefmaster\.thumbnails 2014-11-01 01:15 - 2014-11-03 01:13 - 00000000 ____D () C:\Users\chiefmaster\.gimp-2.8 2014-11-01 01:15 - 2014-11-01 01:15 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\gegl-0.2 2014-11-01 01:15 - 2014-11-01 01:15 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\fontconfig 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 __SHD () C:\Users\chiefmaster\AppData\Local\EmieUserList 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 __SHD () C:\Users\chiefmaster\AppData\Local\EmieSiteList 2014-11-01 01:03 - 2014-11-01 01:03 - 00000000 ____D () C:\Users\chiefmaster\AppData\Roaming\WHService 2014-11-01 01:02 - 2014-11-01 01:14 - 00001059 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2014-11-01 01:02 - 2014-11-01 01:03 - 00000000 ____D () C:\Users\chiefmaster\AppData\Roaming\Security Systems 2014-11-01 00:59 - 2014-11-01 01:02 - 00000000 ____D () C:\Program Files\GIMP 2 2014-11-01 00:56 - 2014-11-01 00:57 - 00370512 _____ () C:\Users\chiefmaster\Downloads\SoftonicDownloader_fuer_gimp.exe 2014-11-01 00:55 - 2014-11-01 00:55 - 00009127 _____ () C:\Users\chiefmaster\Downloads\gimp-2.8.14-setup-1.exe.torrent 2014-10-31 00:31 - 2014-10-31 00:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-10-30 11:28 - 2014-10-30 11:28 - 04423680 _____ () C:\Users\chiefmaster\Downloads\werkpaedagogisches_Projekt2012.pps ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-21 00:20 - 2014-08-11 16:07 - 00000000 ____D () C:\Users\chiefmaster 2014-11-20 23:03 - 2014-08-04 09:51 - 01728358 _____ () C:\Windows\WindowsUpdate.log 2014-11-20 21:04 - 2010-11-20 22:01 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-20 19:50 - 2009-07-14 05:34 - 00025680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-20 19:50 - 2009-07-14 05:34 - 00025680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-20 19:43 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-20 19:43 - 2009-07-14 05:39 - 00038719 _____ () C:\Windows\setupact.log 2014-11-18 23:57 - 2014-08-12 16:02 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-11-18 23:57 - 2014-08-12 16:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-11-13 13:49 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-11-13 13:31 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-11-13 13:22 - 2009-07-14 05:33 - 00284480 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-13 13:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-11-13 13:04 - 2014-08-27 08:25 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-13 13:02 - 2014-08-27 08:25 - 100445232 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-11 11:50 - 2014-10-18 16:46 - 162284285 _____ () C:\Windows\MEMORY.DMP 2014-11-11 11:50 - 2014-10-18 16:46 - 00000000 ____D () C:\Windows\Minidump 2014-11-02 18:48 - 2014-08-11 17:23 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-11-01 01:11 - 2014-08-12 16:36 - 00000000 ____D () C:\Users\chiefmaster\AppData\Local\Adobe 2014-11-01 00:57 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-10-30 12:24 - 2014-08-04 09:59 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\chiefmaster\AppData\Local\Temp\Fx6_FF_IE_Setup-Stonic-German.exe C:\Users\chiefmaster\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-16 13:59 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-11-2014 Ran by chiefmaster at 2014-11-21 00:23:57 Running from C:\Users\chiefmaster\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.223 - Adobe Systems Incorporated) Adobe Reader XI (11.0.09) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) Apple Application Support (HKLM\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}) (Version: 7.1.2.6 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Foxy Secure (HKLM\...\Foxy Secure) (Version: 6 - ) GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team) Intel(R) TV Wizard (HKLM\...\TVWiz) (Version: - Intel Corporation) iTunes (HKLM\...\{86D04316-F49A-4AF2-B3F1-A1E943886CE7}) (Version: 11.3.1.2 - Apple Inc.) Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 33.0.2 (x86 de) (HKLM\...\Mozilla Firefox 33.0.2 (x86 de)) (Version: 33.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) Mozilla Thunderbird 31.0 (x86 de) (HKLM\...\Mozilla Thunderbird 31.0 (x86 de)) (Version: 31.0 - Mozilla) OpenOffice 4.1.1 (HKLM\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) Panda USB Vaccine 1.0.1.4 (HKLM\...\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1) (Version: - Panda Security) Skype™ 6.18 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.24.0 - Synaptics Incorporated) ThinkPad Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.64.00.00 - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 18-10-2014 15:57:22 Windows Update 18-10-2014 16:02:46 Installed Java 7 Update 71 23-10-2014 19:09:32 Windows Update 27-10-2014 21:42:40 Windows Update 31-10-2014 09:38:27 Windows Update 03-11-2014 21:23:22 Windows Update 05-11-2014 08:56:48 Windows Modules Installer 09-11-2014 14:30:25 Windows Update 13-11-2014 12:01:33 Windows Update 16-11-2014 12:16:48 Windows Update 19-11-2014 22:15:25 Windows Update 20-11-2014 16:49:32 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {03DB737B-EAB3-4BBB-AF08-8B6368F04EB8} - System32\Tasks\PandaUSBVaccine => C:\Program Files\Panda USB Vaccine\RunInteractiveWin.exe [2009-09-23] () (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Loaded Modules (whitelisted) ============= 2014-07-31 11:16 - 2014-07-31 11:16 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-07-31 11:16 - 2014-07-31 11:16 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-11-01 01:03 - 2014-10-15 08:10 - 00628736 _____ () C:\Users\chiefmaster\AppData\Roaming\WHService\wh.exe 2014-11-01 01:03 - 2014-11-01 01:03 - 00374272 _____ () C:\Users\chiefmaster\AppData\Roaming\WHService\sub\default.dll 2014-10-31 00:31 - 2014-10-31 00:31 - 03649648 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2014-11-21 00:17 - 2014-11-21 00:17 - 00050477 _____ () C:\Users\chiefmaster\Downloads\Defogger.exe ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-2244492678-1565340186-2046745813-500 - Administrator - Disabled) chiefmaster (S-1-5-21-2244492678-1565340186-2046745813-1000 - Administrator - Enabled) => C:\Users\chiefmaster Gast (S-1-5-21-2244492678-1565340186-2046745813-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/21/2014 00:08:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x078687c0 ID des fehlerhaften Prozesses: 0xd10 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/20/2014 08:40:04 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x06ee87c0 ID des fehlerhaften Prozesses: 0x77c Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/20/2014 08:38:30 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x06ee87c0 ID des fehlerhaften Prozesses: 0x77c Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/20/2014 07:45:05 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2014 06:22:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2014 00:47:45 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x060187c0 ID des fehlerhaften Prozesses: 0x3b0 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/19/2014 00:41:55 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x060787c0 ID des fehlerhaften Prozesses: 0x958 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/18/2014 11:55:56 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: bho.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x542bf70b Ausnahmecode: 0xc0000005 Fehleroffset: 0x075487c0 ID des fehlerhaften Prozesses: 0x624 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/18/2014 08:55:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2947561 Error: (11/18/2014 08:55:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2947561 System errors: ============= Error: (11/20/2014 07:43:20 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 20.11.2014 um 19:41:38 unerwartet heruntergefahren. Error: (11/20/2014 06:53:48 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Empfängerdienst erreicht. Error: (11/20/2014 06:53:47 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:48 PM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1053ehRecvr-Service{D44CBB4F-743E-4818-8077-C47F666CA7EE} Error: (11/20/2014 06:53:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:45 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:45 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:44 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:43 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Error: (11/20/2014 06:53:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Center-Planerdienst erreicht. Microsoft Office Sessions: ========================= Error: (11/21/2014 00:08:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc0000005078687c0d1001d004f9c9741bc0C:\Windows\explorer.exebho.dll1a7c6674-710a-11e4-bbe0-001c251eafee Error: (11/20/2014 08:40:04 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc000000506ee87c077c01d004f1e342dfa3C:\Windows\Explorer.EXEbho.dll05a62bd5-70ed-11e4-bbe0-001c251eafee Error: (11/20/2014 08:38:30 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc000000506ee87c077c01d004f1e342dfa3C:\Windows\Explorer.EXEbho.dllcdb7826e-70ec-11e4-bbe0-001c251eafee Error: (11/20/2014 07:45:05 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2014 06:22:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2014 00:47:45 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc0000005060187c03b001d003893e16dbadC:\Windows\explorer.exebho.dll75508192-7046-11e4-b831-001c251eafee Error: (11/19/2014 00:41:55 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc0000005060787c095801d00382d6568c6fC:\Windows\explorer.exebho.dll7a7fab68-6f7c-11e4-b831-001c251eafee Error: (11/18/2014 11:55:56 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175144ce796f3bho.dll_unloaded0.0.0.0542bf70bc0000005075487c062401d00195844a0b94C:\Windows\Explorer.EXEbho.dll0d7e72af-6f76-11e4-b831-001c251eafee Error: (11/18/2014 08:55:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2947561 Error: (11/18/2014 08:55:29 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2947561 ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T7250 @ 2.00GHz Percentage of memory in use: 47% Total physical RAM: 2006.3 MB Available physical RAM: 1054.55 MB Total Pagefile: 4012.59 MB Available Pagefile: 2946.55 MB Total Virtual: 2047.88 MB Available Virtual: 1883.08 MB ==================== Drives ================================ Drive c: (Windows7) (Fixed) (Total:139.28 GB) (Free:107.7 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 532A7C54) Partition 1: (Active) - (Size=9.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=139.3 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Geändert von Ana Log (21.11.2014 um 01:25 Uhr) Grund: ergebnisse posten |
Themen zu explorer.exe fehlermeldung |
c:\windows, device driver, download, durchgeführt, ergebnisse, erscheint, explorer.exe, fehlercode 0x5, fehlercode 0xc0000005, fehlercode windows, fehlermeldung, formation, funktioniert, panda usb vaccine, probleme, pup.optional.softonic, pup.optional.softonic.a, system32, verfügbar, weiterhelfen, windows, windows explorer |