Hallo schrauber,
danke für die schnelle Antwort. Hier die FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-12-2013 01
Ran by Daniel (administrator) on DANIEL on 30-12-2013 09:49:29
Running from C:\Users\Daniel\Desktop
Microsoft Windows 8 Pro (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
() C:\Program Files\GNU\GnuPG\dirmngr.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(IObit) C:\Program Files\IObit\Start Menu 8\StartMenuServices.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(IObit) C:\Program Files\IObit\Start Menu 8\StartMenu8.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x86__8wekyb3d8bbwe\LiveComm.exe
(IObit) C:\Program Files\IObit\Start Menu 8\StartMenu_Hook.exe
(IObit) C:\Program Files\IObit\Start Menu 8\InstallServices32.exe
(Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [HTC Sync Loader] - C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [659456 2013-05-13] ()
HKLM\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554408 2013-05-15] (Lavasoft)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-10-01] (Apple Inc.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [AdAwareTray] - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareTray.exe [3540312 2013-12-11] ()
HKCU\...\Run: [Google Update] - C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-03-12] (Google Inc.)
HKCU\...\Run: [VoipDiscount] - "C:\Program Files\VoipDiscount.com\VoipDiscount\VoipDiscount.exe" -nosplash -minimized
HKCU\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\Daniel\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
MountPoints2: {2e17800b-96da-11e2-afb0-0c6076c6050c} - "F:\Windows\setup.exe" /autorun
MountPoints2: {4e7861bd-8849-11e2-af9b-806e6f6e6963} - "F:\Setup.EXE"
MountPoints2: {d638f123-89ce-11e2-af9e-0c6076c6050c} - "F:\SETUP.EXE"
AppInit_DLLs: [ ] ()
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
ShortcutTarget: WISO Mein Steuer-Sparbuch heute.lnk -> C:\Program Files\WISO\Steuersoftware 2013\mshaktuell.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7D679D21581CCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\bjd8o95d.default
FF DefaultSearchEngine: Startpage HTTPS - Deutsch
FF SelectedSearchEngine: Startpage HTTPS - Deutsch
FF Homepage: https://startpage.com/do/mypage.pl?prf=8f1c2192b4626a983ae7509b96d3f224
FF Keyword.URL: https://startpage.com/do/search?prf=8f1c2192b4626a983ae7509b96d3f224&cat=web&query=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @citrixonline.com/appdetectorplugin - C:\Users\Daniel\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Daniel\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF SearchPlugin: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\bjd8o95d.default\searchplugins\duckduckgo.xml
FF SearchPlugin: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\bjd8o95d.default\searchplugins\startpage-https---deutsch.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: HTTPS-Everywhere - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\bjd8o95d.default\Extensions\https-everywhere@eff.org
FF Extension: Disconnect - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\bjd8o95d.default\Extensions\2.0@disconnect.me.xpi
FF Extension: RequestPolicy - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\bjd8o95d.default\Extensions\requestpolicy@requestpolicy.com.xpi
FF Extension: Procon Latte Content Filter - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\bjd8o95d.default\Extensions\{9D6218B8-03C7-4b91-AA43-680B305DD35C}.xpi
FF Extension: Adblock Edge - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\bjd8o95d.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Lavasoft NewTab) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\oejkcgajlodefenbbjdnaiahmbnnoole\0.9_0
CHR Extension: (Gmail) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - C:\Program Files\adawaretb\chrome-newtab-search.crx
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
S3 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [1668136 2011-12-15] (Broadcom Corporation.)
R2 CVPND; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [1528616 2010-09-27] (Cisco Systems, Inc.)
R2 DirMngr; C:\Program Files\GNU\GnuPG\dirmngr.exe [218112 2013-05-28] ()
S2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareService.exe [494136 2013-12-11] ()
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
R2 StrartMenuService; C:\Program Files\IObit\Start Menu 8\StartMenuServices.exe [71488 2013-01-23] (IObit)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14480 2013-07-01] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S3 Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [26080 2012-10-08] (Wondershare)
R3 athr; C:\Windows\system32\DRIVERS\athr.sys [2273280 2012-06-02] (Qualcomm Atheros Communications, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [135648 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [37352 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 BasicRender; C:\Windows\System32\drivers\BasicRender.sys [24576 2012-07-26] (Microsoft Corporation)
S3 CVirtA; C:\Windows\system32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
R2 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [308859 2010-09-27] (Cisco Systems, Inc.)
R3 DNE; C:\Windows\system32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [137632 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [22432 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [242240 2013-03-27] (DT Soft Ltd)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-07-23] (GFI Software)
R1 ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [28520 2013-03-16] (Avira GmbH)
R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [340624 2013-07-17] (BitDefender S.R.L.)
S3 Maplom; No ImagePath
S3 MaplomL; No ImagePath
S3 vpnva; \SystemRoot\system32\DRIVERS\vpnva.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-30 09:49 - 2013-12-30 09:50 - 00012169 _____ C:\Users\Daniel\Desktop\FRST.txt
2013-12-30 09:49 - 2013-12-30 09:49 - 00000000 ____D C:\FRST
2013-12-30 09:48 - 2013-12-30 09:48 - 01931302 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2013-12-30 09:46 - 2013-12-30 09:46 - 00000928 _____ C:\Users\Daniel\Desktop\Neues Textdokument.txt
2013-12-30 09:40 - 2013-12-30 09:40 - 01064199 _____ (Farbar) C:\Users\Daniel\Desktop\FRST.exe
2013-12-30 09:39 - 2013-12-30 09:41 - 00000474 _____ C:\Users\Daniel\Desktop\defogger_disable.log
2013-12-30 09:39 - 2013-12-30 09:39 - 00050477 _____ C:\Users\Daniel\Desktop\Defogger.exe
2013-12-30 09:39 - 2013-12-30 09:39 - 00000156 _____ C:\Users\Daniel\defogger_reenable
2013-12-30 09:24 - 2013-12-30 09:27 - 00032090 _____ C:\Users\Daniel\Documents\Ereignisse.txt
2013-12-28 23:37 - 2013-12-28 23:37 - 00000022 _____ C:\Windows\S.dirmngr
2013-12-27 18:32 - 2013-12-27 18:34 - 00009962 _____ C:\Users\Daniel\Desktop\Mappe1.xlsx
2013-12-23 11:35 - 2013-12-23 17:39 - 00000000 ____D C:\Users\Daniel\Desktop\London 2014
2013-12-22 11:40 - 2013-12-22 11:40 - 00000103 _____ C:\Users\Daniel\Desktop\heise.txt
2013-12-20 14:20 - 2013-12-20 14:20 - 00000000 ____D C:\Users\Daniel\Documents\Bewerbungen 2013_2014
2013-12-16 19:52 - 2013-12-16 19:52 - 00425416 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-16 12:01 - 2013-12-30 09:11 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-16 12:01 - 2013-12-30 08:21 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-16 11:42 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-16 11:42 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-16 11:42 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-16 11:42 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-16 11:42 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-16 11:42 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-16 11:42 - 2013-09-28 03:57 - 00219136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-16 11:41 - 2013-11-23 06:05 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-16 11:41 - 2013-11-07 00:18 - 03387904 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-16 11:41 - 2013-11-01 04:49 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-16 11:41 - 2013-10-25 05:45 - 00661504 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-12-16 11:41 - 2013-10-25 05:45 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-16 11:41 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-16 11:41 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-16 11:41 - 2013-10-19 05:04 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-16 11:41 - 2013-10-10 10:32 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-16 11:41 - 2013-10-10 10:30 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll
2013-12-16 11:41 - 2013-10-10 10:30 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-16 11:06 - 2013-12-16 11:07 - 00002464 _____ C:\Windows\IE9_main.log
2013-12-11 20:53 - 2013-12-11 20:53 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2013-12-11 16:29 - 2013-12-13 19:10 - 00009946 _____ C:\Users\Daniel\Desktop\CAGR.xlsx
2013-12-11 11:28 - 2013-12-11 12:17 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-12-11 11:06 - 2013-12-11 23:20 - 00009904 _____ C:\Users\Daniel\Documents\CL draw.xlsx
2013-12-11 09:38 - 2013-12-11 09:39 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-12-08 14:13 - 2013-12-28 00:11 - 00010557 _____ C:\Users\Daniel\Desktop\Huawei Phones.xlsx
2013-12-06 11:00 - 2013-12-30 09:42 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\KeePass
2013-12-06 09:53 - 2013-12-22 21:55 - 00000000 ____D C:\Users\Daniel\Documents\KeePass
2013-12-06 09:52 - 2013-12-06 09:52 - 00000000 ____D C:\Program Files\KeePass Password Safe 2
2013-12-04 08:16 - 2013-12-04 08:48 - 00000000 ____D C:\Users\Daniel\AppData\Local\GG
2013-12-04 08:16 - 2013-12-04 08:46 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\GG
2013-12-03 08:15 - 2013-12-03 08:17 - 00000000 ____D C:\Users\Daniel\Documents\strom
==================== One Month Modified Files and Folders =======
2013-12-30 09:50 - 2013-12-30 09:49 - 00012169 _____ C:\Users\Daniel\Desktop\FRST.txt
2013-12-30 09:49 - 2013-12-30 09:49 - 00000000 ____D C:\FRST
2013-12-30 09:48 - 2013-12-30 09:48 - 01931302 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2013-12-30 09:46 - 2013-12-30 09:46 - 00000928 _____ C:\Users\Daniel\Desktop\Neues Textdokument.txt
2013-12-30 09:42 - 2013-12-06 11:00 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\KeePass
2013-12-30 09:41 - 2013-12-30 09:39 - 00000474 _____ C:\Users\Daniel\Desktop\defogger_disable.log
2013-12-30 09:40 - 2013-12-30 09:40 - 01064199 _____ (Farbar) C:\Users\Daniel\Desktop\FRST.exe
2013-12-30 09:39 - 2013-12-30 09:39 - 00050477 _____ C:\Users\Daniel\Desktop\Defogger.exe
2013-12-30 09:39 - 2013-12-30 09:39 - 00000156 _____ C:\Users\Daniel\defogger_reenable
2013-12-30 09:39 - 2013-03-09 00:48 - 00000000 ____D C:\Users\Daniel
2013-12-30 09:27 - 2013-12-30 09:24 - 00032090 _____ C:\Users\Daniel\Documents\Ereignisse.txt
2013-12-30 09:11 - 2013-12-16 12:01 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-30 08:22 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\system32\sru
2013-12-30 08:21 - 2013-12-16 12:01 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-29 12:51 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\Microsoft.NET
2013-12-29 01:50 - 2013-11-26 20:41 - 00000000 ____D C:\Users\Daniel\Documents\LEG Wohnung
2013-12-29 01:50 - 2013-08-25 21:13 - 00000000 ____D C:\Users\Daniel\Documents\ryanair
2013-12-28 23:37 - 2013-12-28 23:37 - 00000022 _____ C:\Windows\S.dirmngr
2013-12-28 23:37 - 2012-07-26 07:04 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-28 19:58 - 2012-07-26 05:17 - 00524288 ___SH C:\Windows\system32\config\BBI
2013-12-28 00:11 - 2013-12-08 14:13 - 00010557 _____ C:\Users\Daniel\Desktop\Huawei Phones.xlsx
2013-12-27 18:34 - 2013-12-27 18:32 - 00009962 _____ C:\Users\Daniel\Desktop\Mappe1.xlsx
2013-12-24 13:43 - 2013-03-24 09:13 - 05000704 ___SH C:\Users\Daniel\Desktop\Thumbs.db
2013-12-23 17:39 - 2013-12-23 11:35 - 00000000 ____D C:\Users\Daniel\Desktop\London 2014
2013-12-22 23:33 - 2013-03-16 19:57 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype
2013-12-22 21:55 - 2013-12-06 09:53 - 00000000 ____D C:\Users\Daniel\Documents\KeePass
2013-12-22 11:40 - 2013-12-22 11:40 - 00000103 _____ C:\Users\Daniel\Desktop\heise.txt
2013-12-20 14:20 - 2013-12-20 14:20 - 00000000 ____D C:\Users\Daniel\Documents\Bewerbungen 2013_2014
2013-12-20 14:00 - 2013-03-09 00:50 - 01745416 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-19 17:18 - 2013-04-08 09:21 - 00000000 ____D C:\Users\Daniel\AppData\Local\Paint.NET
2013-12-18 15:39 - 2013-03-09 00:48 - 01791673 _____ C:\Windows\WindowsUpdate.log
2013-12-18 15:34 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\AUInstallAgent
2013-12-17 21:47 - 2013-04-28 13:35 - 00000000 ____D C:\Users\Daniel\Documents\BRIEFVERKEHR
2013-12-17 13:02 - 2013-03-23 16:03 - 00000000 ____D C:\Users\Daniel\Documents\Bewerbungen Arbeitsamt 2012_2013
2013-12-16 19:52 - 2013-12-16 19:52 - 00425416 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-16 17:57 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\rescache
2013-12-16 17:30 - 2013-03-09 00:38 - 00017648 _____ C:\Windows\PFRO.log
2013-12-16 17:29 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\system32\de-DE
2013-12-16 17:28 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\system32\SecureBootUpdates
2013-12-16 12:02 - 2013-03-12 19:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Google
2013-12-16 12:02 - 2013-03-12 11:17 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-16 12:01 - 2013-03-12 19:42 - 00000000 ____D C:\Program Files\Google
2013-12-16 11:58 - 2013-07-24 01:18 - 00000000 ____D C:\Windows\system32\MRT
2013-12-16 11:55 - 2013-03-10 22:57 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-16 11:07 - 2013-12-16 11:06 - 00002464 _____ C:\Windows\IE9_main.log
2013-12-13 19:10 - 2013-12-11 16:29 - 00009946 _____ C:\Users\Daniel\Desktop\CAGR.xlsx
2013-12-12 13:13 - 2013-05-07 20:31 - 00068728 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-12-12 13:13 - 2013-03-16 22:24 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-12-12 13:13 - 2013-03-16 22:24 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-12 08:35 - 2013-11-28 14:18 - 00000000 ____D C:\FreeOCR
2013-12-12 07:05 - 2013-03-09 00:55 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-12-11 23:20 - 2013-12-11 11:06 - 00009904 _____ C:\Users\Daniel\Documents\CL draw.xlsx
2013-12-11 20:53 - 2013-12-11 20:53 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2013-12-11 15:12 - 2013-10-30 18:02 - 00000000 ___RD C:\Users\Daniel\Desktop\MOBIstudie_new 20131210
2013-12-11 13:11 - 2013-07-25 11:05 - 00000000 ____D C:\Users\Daniel\Documents\Ernährung
2013-12-11 12:17 - 2013-12-11 11:28 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-12-11 09:39 - 2013-12-11 09:38 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-12-06 11:19 - 2013-10-17 12:35 - 00000000 ____D C:\Users\Daniel\Desktop\readings
2013-12-06 09:52 - 2013-12-06 09:52 - 00000000 ____D C:\Program Files\KeePass Password Safe 2
2013-12-04 10:37 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\system32\NDF
2013-12-04 08:48 - 2013-12-04 08:16 - 00000000 ____D C:\Users\Daniel\AppData\Local\GG
2013-12-04 08:46 - 2013-12-04 08:16 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\GG
2013-12-04 01:53 - 2013-11-20 08:42 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-12-04 01:53 - 2013-11-20 08:42 - 00078304 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-12-03 08:17 - 2013-12-03 08:15 - 00000000 ____D C:\Users\Daniel\Documents\strom
Some content of TEMP:
====================
C:\Users\Daniel\AppData\Local\Temp\avgnt.exe
C:\Users\Daniel\AppData\Local\Temp\c4c7a9a7-54f5-4366-a054-80070c456d4f.exe
C:\Users\Daniel\AppData\Local\Temp\drm_dyndata_7400004.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-28 12:39
==================== End Of Log ============================ --- --- ---
und auch die Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-12-2013 01
Ran by Daniel at 2013-12-30 09:50:54
Running from C:\Users\Daniel\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Ad-Aware Antivirus (Disabled - Out of date) {D87B6541-12A1-DAEA-0033-9B8057AAB996}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Ad-Aware Antivirus (Disabled - Out of date) {631A84A5-349B-D564-3A83-A0F22C2DF32B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Ad-Aware Firewall (Disabled) {E040E464-58CE-DBB2-2B6C-32B5A979FEED}
==================== Installed Programs ======================
Ad-Aware Antivirus (Version: 11.1.5152.0 - Lavasoft)
Ad-Aware Browsing Protection (Version: 1.0.1.106 - Lavasoft)
AdAwareInstaller (Version: 11.1.5152.0 - Lavasoft)
AdAwareUpdater (Version: 11.1.5152.0 - Lavasoft)
Adobe AIR (Version: 3.7.0.1530 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05 - Adobe Systems Incorporated)
Amazon MP3-Downloader 1.0.18 (Version: 1.0.18 - Amazon Services LLC)
AntimalwareEngine (Version: 2.6.0.0 - Lavasoft)
Apple Application Support (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (Version: 2.1.3.127 - Apple Inc.)
Audio MP3 Editor 6.30 (Version: - audio2x.com)
Avira Free Antivirus (Version: 14.0.2.286 - Avira)
Bonjour (Version: 3.0.0.10 - Apple Inc.)
Canon MG8100 series MP Drivers (Version: - )
Cisco Systems VPN Client 5.0.07.0410 (Version: 5.0.7 - Cisco Systems, Inc.)
DAEMON Tools Lite (Version: 4.47.1.0333 - Disc Soft Ltd)
Dr Kawashima (Version: 1.0 - )
FileZilla Client 3.2.7.1 (Version: 3.2.7.1 - )
Free Mouse and Keyboard Recorder 3.1.3.2 (Version: - Robot-Soft.com, Inc.)
Free YouTube to MP3 Converter version 3.12.3.610 (Version: 3.12.3.610 - DVDVideoSoft Ltd.)
G*Power 3.1.6 (Version: 3.1.6 - Franz Faul, Uni Kiel, Germany)
Google Chrome (Version: 31.0.1650.63 - Google Inc.)
Google Update Helper (Version: 1.3.22.3 - Google Inc.)
Gpg4win (2.1.1) (Version: 2.1.1 - The Gpg4win Project)
HTC BMP USB Driver (Version: 1.0.5375 - HTC)
HTC Driver Installer (Version: 4.1.0.001 - HTC Corporation)
HTC Sync (Version: 3.3.53 - HTC Corporation)
IBM SPSS Statistics 21 (Version: 21.0.0.0 - IBM Corp)
IPTInstaller (Version: 4.0.8 - HTC)
iTunes (Version: 11.1.1.11 - Apple Inc.)
KeePass Password Safe 2.24 (Version: 2.24 - Dominik Reichl)
Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft)
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft)
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (Version: 24.2.0 - Mozilla)
Mozilla Thunderbird 24.2.0 (x86 de) (Version: 24.2.0 - Mozilla)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0 - Microsoft Corporation)
Paint.NET v3.5.10 (Version: 3.60.0 - dotPDN LLC)
PDFCreator (Version: 1.7.0 - pdfforge)
Skype™ 6.11 (Version: 6.11.102 - Skype Technologies S.A.)
Start Menu 8 (Version: 1.0.0.0 - IObit)
SuperMailer 7.10 (Version: 7.10 - Mirko Boeer Softwareentwicklungen)
TweetDeck (Version: 3.2.2 - Twitter, Inc.)
Update for 2007 Microsoft Office System (KB967642) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (Version: - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (Version: - Microsoft)
WISO Steuer-Sparbuch 2013 (Version: 20.00.8137 - Buhl Data Service GmbH)
Zattoo4 4.0.5 (Version: 4.0.5 - Zattoo Inc.)
==================== Restore Points =========================
24-12-2013 11:22:14 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2012-07-26 05:17 - 2012-07-26 05:17 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {1E84DCB8-8C84-4436-A108-209A65086823} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {545C008C-4471-44F8-AD15-96CB8BB2BB0C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {56F59500-C4D1-4720-859F-13B4998AA792} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {57D2302A-1EEF-4DAF-ABE0-B88A7155AA48} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-16] (Google Inc.)
Task: {642D7677-A73F-4E7A-8AD8-C197F1DD0B91} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2013-05-13] ()
Task: {695E2C16-8234-4EF3-9FBF-E5793DC57DAF} - System32\Tasks\Dealply => C:\Users\Daniel\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {6DE6559D-9AFD-41AC-8F73-75B115A9EB33} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\PROGRA~1\AD-AWA~1\AdAwareLauncher.exe
Task: {99768757-32DC-4E02-BE1E-2FE4783695EE} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {A74D3C99-B882-4906-8C81-3964363CA19C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-16] (Google Inc.)
Task: {DC151D76-F05D-44CF-863A-CF3F85CD6A43} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\System32\NotificationUI.exe [2013-08-16] (Microsoft Corporation)
Task: {EF9592CE-7796-47A6-9CD5-8630640D45BB} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: C:\Windows\Tasks\Dealply.job => C:\Users\Daniel\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2687151079-2647899646-3801684616-1001Core.job => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2009-08-23 18:58 - 2009-08-23 18:58 - 00094208 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2013-03-16 22:42 - 2013-01-19 17:03 - 00348992 _____ () C:\Program Files\IObit\Start Menu 8\madExcept_.bpl
2013-03-16 22:42 - 2013-01-19 17:02 - 00183616 _____ () C:\Program Files\IObit\Start Menu 8\madBasic_.bpl
2013-03-16 22:42 - 2013-01-19 17:02 - 00051008 _____ () C:\Program Files\IObit\Start Menu 8\madDisAsm_.bpl
2013-03-28 11:44 - 2013-03-28 11:45 - 00140184 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x86__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll
2013-12-11 09:38 - 2013-12-11 09:39 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: Broadcom Bluetooth 3.0 USB
Description: Broadcom Bluetooth 3.0 USB
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Broadcom
Service: BTHUSB
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Cisco Systems VPN Adapter
Description: Cisco Systems VPN Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: CVirtA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/29/2013 00:51:15 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
Die abhängige Assemblierung "Microsoft.VC90.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (12/26/2013 01:51:59 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: DANIEL)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (12/26/2013 01:51:59 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: DANIEL)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (12/26/2013 01:51:59 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: DANIEL)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (12/26/2013 01:51:59 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: DANIEL)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (12/25/2013 09:49:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: DANIEL)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (12/25/2013 09:49:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: DANIEL)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (12/25/2013 09:49:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: DANIEL)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (12/25/2013 09:49:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: DANIEL)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (12/24/2013 01:49:43 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7956
System errors:
=============
Error: (12/29/2013 10:52:46 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst NlaSvc erreicht.
Error: (12/29/2013 01:59:24 PM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "MARYSIA",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{CFA99ABB-1E49-4AEB-A589-C887D477E6-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (12/27/2013 09:47:12 PM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "MARYSIA",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{CFA99ABB-1E49-4AEB-A589-C887D477E6-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (12/23/2013 05:34:59 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 23.12.2013 um 17:11:50 unerwartet heruntergefahren.
Error: (12/22/2013 01:29:34 PM) (Source: DCOM) (User: DANIEL)
Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}DanielDanielS-1-5-21-2687151079-2647899646-3801684616-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (12/22/2013 01:13:13 PM) (Source: NetBT) (User: )
Description: Der Name "WORKGROUP :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.239
registriert werden. Der Computer mit IP-Adresse 192.168.1.233 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (12/22/2013 01:12:32 PM) (Source: NetBT) (User: )
Description: Der Name "WORKGROUP :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.239
registriert werden. Der Computer mit IP-Adresse 192.168.1.233 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (12/22/2013 01:11:52 PM) (Source: NetBT) (User: )
Description: Der Name "WORKGROUP :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.239
registriert werden. Der Computer mit IP-Adresse 192.168.1.233 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (12/21/2013 10:20:36 AM) (Source: NetBT) (User: )
Description: Es ist ein Initialisierungsfehler aufgetreten, da der Treiber nicht erstellt werden konnte.
Verwenden Sie die Zeichenfolge "1226B6199CCE", um die Schnittstelle zu identifizieren, die nicht initialisiert werden
konnte. Sie stellt die MAC-Adresse der Schnittstelle mit dem Initialisierungsfehler oder die
GUID (Globally Unique Interface Identifier) dar, wenn NetBT keine Zuordnung
von der GUID zur MAC-Adresse herstellen konnte. Wenn weder die MAC-Adresse noch die GUID verfügbar
waren, dann stellt die Zeichenfolge einen Clustergerätenamen dar.
Error: (12/21/2013 10:20:36 AM) (Source: NetBT) (User: )
Description: Es ist ein Initialisierungsfehler aufgetreten, da der Treiber nicht erstellt werden konnte.
Verwenden Sie die Zeichenfolge "1226B6199CCE", um die Schnittstelle zu identifizieren, die nicht initialisiert werden
konnte. Sie stellt die MAC-Adresse der Schnittstelle mit dem Initialisierungsfehler oder die
GUID (Globally Unique Interface Identifier) dar, wenn NetBT keine Zuordnung
von der GUID zur MAC-Adresse herstellen konnte. Wenn weder die MAC-Adresse noch die GUID verfügbar
waren, dann stellt die Zeichenfolge einen Clustergerätenamen dar.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 44%
Total physical RAM: 3032.61 MB
Available physical RAM: 1692.54 MB
Total Pagefile: 3608.61 MB
Available Pagefile: 2174.38 MB
Total Virtual: 2047.88 MB
Available Virtual: 1839.39 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:97.66 GB) (Free:55.66 GB) NTFS
Drive d: () (Fixed) (Total:134.89 GB) (Free:48.09 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 955F5340)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=135 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=98 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Vorsorglich poste ich auch einmal den GMER Log: Code:
Windows 6.2.9200 \Device\Harddisk0\DR0 -> \Device\00000044 ST9250315AS rev.0001SDM1 232,89GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Daniel\AppData\Local\Temp\uwldapog.sys
---- System - GMER 2.1 ----
SSDT 8FCA6E87 ZwTerminateProcess
SSDT 8FCA6EFA ZwSystemDebugControl
SSDT 8FCA6EF5 ZwSetSecurityObject
SSDT 8FCA6EEB ZwSetContextThread
SSDT 8FCA6EF0 ZwRequestWaitReplyPort
SSDT 8FCA6EE6 ZwCreateSection
INT 0x60 ? 94CEF054
INT 0x61 ? 94CD9894
INT 0x70 ? 94CEF314
INT 0x81 ? 94CEF894
INT 0x91 ? 94CD9314
INT 0xA2 ? 94D6CB54
---- Kernel code sections - GMER 2.1 ----
.text ntoskrnl.exe!ZwReplacePartitionUnit + 26B1 8174BAB5 1 Byte [06]
.text ntoskrnl.exe!KiDispatchInterrupt + 66A 8175039A 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\RNG@RNGAuxiliarySeed 193294753
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0c6076c6050c
---- EOF - GMER 2.1 ---- Im Voraus ein :dankeschoen: für Deine freundliche Hilfe!
avir |