RonnysPC | 23.02.2015 18:54 | Liste der Anhänge anzeigen (Anzahl: 1) Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-02-2015
Ran by Ronny at 2015-02-23 18:19:54
Running from C:\Users\Ronny\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
2.0 (HKLM\...\Free Video to GIF Converter_is1) (Version: 2.0 - www.video-gif-converter.com)
3GX (HKLM\...\{D0783152-6826-4FA7-93C3-1F0D53FD5460}) (Version: 3.03.2101 - ALIGN)
7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Acala 3GP Movies Free 4.2.7 (HKLM\...\Acala 3GP Movies Free_is1) (Version: - Acala Software)
Artisan (HKLM\...\Artisan) (Version: 0.6.0.0 - The Artisan Team)
Avidemux 2.5 (HKLM\...\Avidemux 2.5) (Version: 2.5.3.0 - )
CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform)
ClearView (HKLM\...\{A95AF23D-1875-41E7-B684-ECA583126755}) (Version: 5.3.4 - SVKSystems)
DataExplorer (HKLM\...\DataExplorer) (Version: 3.1.7 - )
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1207.101.108 - ALPS ELECTRIC CO., LTD.)
Garmin City Navigator Europe NT 2008 (HKLM\...\{EEC8205A-E3DE-4C00-B60C-48E3B9B58B13}) (Version: 10.0.0.0 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin (HKLM\...\{71DBFBF2-F7EB-4268-8485-9471D83C4E66}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
GOM Player (HKLM\...\GOM Player) (Version: 2.2.64.5211 - Gretech Corporation)
Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
HELI-X 5.0 Demo (HKLM\...\B0C9899E-7D17-46E6-9496-8333A1F8C441_is1) (Version: - Michael Schreiner)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.36 - Irfan Skiljan)
Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
JLC 7.0.0.6 (HKU\S-1-5-21-2443804570-283508326-906284146-1000\...\b87250e759877692) (Version: 7.0.0.6 - R2Prototyping)
LogView V2 (HKLM\...\LogView V2) (Version: LogView V2 2 - LogView.info - D.Schmidt / H.Hemmecke)
LogView V2 2 (HKU\S-1-5-21-2443804570-283508326-906284146-1000\...\LogView V2 2) (Version: 2 - LogView.info)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft Office Professional 2013 - de-de (HKLM\...\ProfessionalRetail - de-de) (Version: 15.0.4693.1002 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-2443804570-283508326-906284146-1000\...\SkyDriveSetup.exe) (Version: 17.0.2003.1112 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
NVIDIA 3D Vision Treiber 327.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 327.02 - NVIDIA Corporation)
NVIDIA Grafiktreiber 327.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.02 - NVIDIA Corporation)
NVIDIA nTune (HKLM\...\InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}) (Version: 1.00.0000 - NVIDIA Corporation)
NVIDIA nView 140.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 140.62 - NVIDIA Corporation)
NVIDIA WMI 2.14.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 2.14.0 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (Version: 15.0.4693.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4693.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (Version: 15.0.4693.1002 - Microsoft Corporation) Hidden
Pazera Free MOV to AVI Converter 1.6 (HKLM\...\{770103E9-E1C3-48C9-812B-2982C7070575}_is1) (Version: 1.6 - Pazera Jacek)
pdfsam (HKU\S-1-5-21-2443804570-283508326-906284146-1000\...\pdfsam) (Version: 1.1.1 - )
Recuva (HKLM\...\Recuva) (Version: 1.38 - Piriform)
Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SDFormatter (HKLM\...\{179324FF-7B16-4BA8-9836-055CAAEE4F08}) (Version: 4.0.0 - SD Association)
Shape Collage (HKLM\...\ShapeCollage) (Version: - Shape Collage Inc.)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM\...\SLABCOMM&10C4&EA60) (Version: - )
Silicon Laboratories CP210x VCP Drivers for Windows 2000/XP/2003 Server/Vista (HKLM\...\{1F50FB31-0092-4D78-A85E-F22B2502C40E}) (Version: 5.10 - Silicon Laboratories, Inc.)
SM UniSens-E Tool (HKLM\...\{D35352AE-7C1E-470B-9AAE-A13BAA13841B}) (Version: 1.0.4.1 - SM-Modellbau)
TeamViewer 10 (HKLM\...\TeamViewer) (Version: 10.0.36897 - TeamViewer)
TrueCrypt (HKLM\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
TSDoctor (HKLM\...\{83CC8459-F239-4409-896C-17034A70EC5F}) (Version: 1.2.104 - Cypheros)
TsRemux 0.23.2 (HKLM\...\TsRemux_is1) (Version: - )
VideoConverter (HKLM\...\VideoConverter) (Version: ${VERSION} - )
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
VStabi 5.3.4 (HKLM\...\VStabi 5.3_is1) (Version: 5.3.4 - VStabi Support Center)
WinRAR 5.10 Beta 4 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2443804570-283508326-906284146-1000_Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\localserver32 -> C:\Users\Ronny\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2443804570-283508326-906284146-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Ronny\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2443804570-283508326-906284146-1000_Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\localserver32 -> C:\Users\Ronny\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2443804570-283508326-906284146-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Ronny\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2443804570-283508326-906284146-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Ronny\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2443804570-283508326-906284146-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Ronny\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2443804570-283508326-906284146-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Ronny\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\FileSyncApi.dll (Microsoft Corporation)
==================== Restore Points =========================
06-02-2015 20:13:09 Windows Update
12-02-2015 17:39:02 Windows Update
21-02-2015 10:46:06 Geplanter Prüfpunkt
22-02-2015 18:56:43 Revo Uninstaller's restore point - FlashGet(Jetcar) 1.81
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 07:13 - 2013-08-22 07:13 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {224B4534-84B9-4CB6-AFCC-642754524CBE} - System32\Tasks\{41BC8576-3517-4942-8059-F0F1672D8C8C} => pcalua.exe -a C:\PROGRA~1\FlashGet\UNWISE.EXE -c C:\PROGRA~1\FlashGet\INSTALL.LOG
Task: {2E4589AF-E105-4D15-A50E-A73E04A79EA8} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX86\OfficeC2RClient.exe [2014-12-30] (Microsoft Corporation)
Task: {795113B6-01C3-45F2-9C08-367BD91BD9E8} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX86\OfficeC2RClient.exe [2014-12-30] (Microsoft Corporation)
Task: {8B14EB57-99F7-4A9C-9092-B0D6BF1A1C2F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)
Task: {B1EA2E5A-E1CB-410C-8589-1273E4203F3F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd)
Task: {C3CB5B0B-1EF3-483B-8888-6CCAD53953CE} - System32\Tasks\Microsoft Office 15 Sync Maintenance for RONNY-PC-Ronny Ronny-PC => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-01-06] (Microsoft Corporation)
Task: {D3714F0E-F14E-4632-BBC0-D3ADBB2276AA} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-02-12] (Microsoft Corporation)
Task: {F96634F1-9301-49ED-B0F3-FBDF8DE3D92B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2014-03-21 07:29 - 2014-05-20 02:11 - 00080040 _____ () C:\Program Files\Microsoft Office 15\ClientX86\ApiClient.dll
2014-06-10 21:05 - 2014-11-15 10:49 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
2014-06-10 20:57 - 2014-11-15 10:46 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\AppVIsvStream32.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:69E87FA2
AlternateDataStreams: C:\ProgramData\TEMP:862BDB1A
AlternateDataStreams: C:\Users\Ronny\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\Ronny\Downloads\mbam-setup-2.0.4.1028.exe:BDU
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2443804570-283508326-906284146-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 192.168.178.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\Run: => "Apoint"
HKLM\...\StartupApproved\Run: => "SysTrayApp"
HKLM\...\StartupApproved\Run: => "InstallerLauncher"
HKLM\...\StartupApproved\Run: => "SDTray"
HKU\S-1-5-21-2443804570-283508326-906284146-1000\...\StartupApproved\StartupFolder: => "Hardcopy.LNK"
HKU\S-1-5-21-2443804570-283508326-906284146-1000\...\StartupApproved\StartupFolder: => "An OneNote senden.lnk"
HKU\S-1-5-21-2443804570-283508326-906284146-1000\...\StartupApproved\Run: => "NVIDIA nTune"
HKU\S-1-5-21-2443804570-283508326-906284146-1000\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-2443804570-283508326-906284146-1000\...\StartupApproved\Run: => "pdiface"
==================== Accounts: =============================
Administrator (S-1-5-21-2443804570-283508326-906284146-500 - Administrator - Disabled)
Gast (S-1-5-21-2443804570-283508326-906284146-501 - Limited - Disabled)
Ronny (S-1-5-21-2443804570-283508326-906284146-1000 - Administrator - Enabled) => C:\Users\Ronny
==================== Faulty Device Manager Devices =============
Name: Broadcom USH
Description: Broadcom USH
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/22/2015 06:56:41 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {bb22d735-884d-4605-a213-6f2a1a73462a}
Error: (02/22/2015 03:57:02 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="AMD64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="AMD64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (02/22/2015 03:57:02 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="AMD64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="AMD64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (02/22/2015 03:57:01 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="AMD64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="AMD64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (02/22/2015 02:51:31 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RONNY-PC)
Description: Bei der Aktivierung der App „DefaultBrowser_NOPUBLISHERID!Microsoft.InternetExplorer.Default“ ist folgender Fehler aufgetreten: -2144927151. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (02/22/2015 02:00:38 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RONNY-PC)
Description: Bei der Aktivierung der App „DefaultBrowser_NOPUBLISHERID!Microsoft.InternetExplorer.Default“ ist folgender Fehler aufgetreten: -2144927151. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (02/21/2015 09:38:50 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT)
Description: Die Namenszeichenfolgenwert für den Leistungsindikator in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "7558". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten.
Error: (02/21/2015 09:38:50 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT)
Description: Die Namenszeichenfolgenwert für den Leistungsindikator in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "7558". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten.
Error: (02/21/2015 09:38:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT)
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich.
Error: (02/21/2015 09:38:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT)
Description: Die Namenszeichenfolgenwert für den Leistungsindikator in der Registrierung ist falsch formatiert. Die falsch formatierte Zeichenfolge ist "7558". Das erste DWORD im Datenbereich enthält den Indexwert für die falsch formatierte Zeichenfolge, während das zweite und dritte DWORD im Datenbereich die letzten gültigen Indexwerte enthalten.
System errors:
=============
Error: (02/23/2015 06:07:33 PM) (Source: WudfUsbccidDriver) (EventID: 11) (User: NT-AUTORITÄT)
Description: 0x810x10x10xfb0x00x0
Error: (02/23/2015 05:58:05 PM) (Source: WudfUsbccidDriver) (EventID: 11) (User: NT-AUTORITÄT)
Description: 0x810x10x10xfb0x00x0
Error: (02/22/2015 10:24:29 PM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
Error: (02/22/2015 09:12:29 PM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (02/22/2015 08:34:18 PM) (Source: WudfUsbccidDriver) (EventID: 11) (User: NT-AUTORITÄT)
Description: 0x810x10x10xfb0x00x0
Error: (02/22/2015 07:33:28 PM) (Source: WudfUsbccidDriver) (EventID: 11) (User: NT-AUTORITÄT)
Description: 0x810x10x10xfb0x00x0
Error: (02/22/2015 06:30:25 PM) (Source: WudfUsbccidDriver) (EventID: 11) (User: NT-AUTORITÄT)
Description: 0x810x10x10xfb0x00x0
Error: (02/22/2015 04:39:00 PM) (Source: WudfUsbccidDriver) (EventID: 11) (User: NT-AUTORITÄT)
Description: 0x810x10x10xfb0x00x0
Error: (02/22/2015 11:28:11 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "ESET Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (02/22/2015 09:17:39 AM) (Source: WudfUsbccidDriver) (EventID: 11) (User: NT-AUTORITÄT)
Description: 0x810x10x10xfb0x00x0
Microsoft Office Sessions:
=========================
Error: (02/22/2015 06:56:41 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {bb22d735-884d-4605-a213-6f2a1a73462a}
Error: (02/22/2015 03:57:02 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="AMD64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\NVIDIA nTune Performance Application\Win64\nvcplUIR.dll
Error: (02/22/2015 03:57:02 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="AMD64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\NVIDIA nTune Performance Application\Win64\nvExpBar.dll
Error: (02/22/2015 03:57:01 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="AMD64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\NVIDIA nTune Performance Application\Win64\nvCplUI.exe
Error: (02/22/2015 02:51:31 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RONNY-PC)
Description: DefaultBrowser_NOPUBLISHERID!Microsoft.InternetExplorer.Default-2144927151
Error: (02/22/2015 02:00:38 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RONNY-PC)
Description: DefaultBrowser_NOPUBLISHERID!Microsoft.InternetExplorer.Default-2144927151
Error: (02/21/2015 09:38:50 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT)
Description: 755816861D0000841D0000851D000070010000
Error: (02/21/2015 09:38:50 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT)
Description: 755816861D0000841D0000851D000070010000
Error: (02/21/2015 09:38:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT)
Description: WmiApRplWmiApRpl8F2030000E5050000
Error: (02/21/2015 09:38:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT-AUTORITÄT)
Description: 755816861D0000841D0000851D00002D010000
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU T9400 @ 2.53GHz
Percentage of memory in use: 29%
Total physical RAM: 3571.9 MB
Available physical RAM: 2529.72 MB
Total Pagefile: 7155.9 MB
Available Pagefile: 5950.11 MB
Total Virtual: 2047.88 MB
Available Virtual: 1893.38 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:61.03 GB) (Free:11.01 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Daten) (Fixed) (Total:87.89 GB) (Free:55.51 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149.1 GB) (Disk ID: D8000000)
Partition 1: (Not Active) - (Size=133 MB) - (Type=DE)
Partition 2: (Active) - (Size=61 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=87.9 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Es ist noch ein weiterer Windows 8.1 Rechner (engl. Sprache und Tastatur) als Gastzugang per WLAN im Netz. Auf diesem Rechner habe ich am Wochenende Malwarebytes installiert und folgenden Fund (siehe angehängte Grafik) gemacht sowie in die Quarantäne verschieben lassen. Daraufhin wurde an dem Notebook noch ein vollständiger MS Defender Virensuchlauf durchgeführt. Weitere Aktionen wurden an seinem Notebook nicht ausgeführt. Ich hatte gestern auf meinem Notebook mit Hilfe des Revo Uninstallers die Reste von folgender Programme versucht zu entfernen:
FlashGet (JetCar) 1.81
Snap.Do |