Matthias66 | 10.05.2015 21:34 | Windows 8.1 E-Mail-Sicherheitssperre ESET: Win32/Conduit.SearchProtect.I Hallo,
gestern erhielt ich folgende Mails: Code:
Wenn Sie ein Bildschirmleseprogramm verwenden, dann empfehlen wir Ihnen, folgende Seite zu verwenden: https://mm.web.de
Mail delivery failed: returning message to sender
Von:
keineantwortadresse@web.de
An:
******@web.de
Datum:
09.05.2015 06:38:05
This message was created automatically by mail delivery software. A message that you sent could not be delivered to one or more of its recipients. This is a permanent error. The following address failed: "******@hotmail.com": SMTP error from remote server after MAIL command: host: mx1.hotmail.com OU-001 (BAY004-MC6F8) Unfortunately, messages from 82.165.159.2 weren't sent. Please contact your Internet service provider since part of their network is on our block list. You can also refer your provider to hxxp://mail.live.com/mail/troubleshooting.aspx#errors.
"******@hotmail.com": SMTP error from remote server after MAIL command: host: mx1.hotmail.com OU-001 (BAY004-MC6F8) Unfortunately, messages from 82.165.159.2 weren't sent. Please contact your Internet service provider since part of their network is on our block list. You can also refer your provider to hxxp://mail.live.com/mail/troubleshooting.aspx#errors.
--- The header of the original message is following. --- Received: from [182.231.121.50] by msvc-mesg-web004.server.lan (via HTTP); Sat, 9 May 2015 06:38:01 +0200 MIME-Version: 1.0 Message-ID: <trinity-1b54b709-511b-4a09-aaa4-00bb96d746b0-1431146281718@msvc-mesg-web004>
From: ******@web.de
To: ******
Subject: Hi Friend Content-Type: text/html; charset=UTF-8 Date: Sat, 9 May 2015 06:38:01 +0200 X-Provags-ID: V03:K0:+Sc76aiMTtIiNVI9JQO38tb1OolZN/h+RoHB5CVl5KS 4oX7lnYNihgKDF7zvwB2S4XPOkoA0YGVLBESvExzJvS+wVElfY 9H6gOWkAVNN55QjYTB+31jf1GbIcu3oE34xVCrh7J0FiWjJJrc QM3xXie1gr9pRM1rLFy4YBlgMUY4gZYrKjcBkRHBEf/r1ulqEF 63sABiTyzqr035QQw0iAf6urSCc/6bpPBXal3xkPft95P20j5N i19y1K1w4tgvlr4OwDxEAdZPKpq8C1HdMJY81B2f3NUhb/h1O+ NpsPxk= X-UI-Out-Filterresults: junk:10; Code:
Wenn Sie ein Bildschirmleseprogramm verwenden, dann empfehlen wir Ihnen, folgende Seite zu verwenden: https://mm.web.de
Vorsorgliche Sicherheitssperre Ihres Postfachs!
Von:
"WEB.DE FreeMail" <keineantwortadresse@web.de>
An:
******@web.de
Datum:
09.05.2015 06:46:39
Lieber WEB.DE Nutzer, es geht um Ihre Sicherheit: Unsere automatisierten Sicherheitssysteme haben Unregelmäßigkeiten beim Zugriff auf Ihren WEB.DE Account festgestellt.Zu Ihrem persönlichen Schutz haben wir vorsorglich automatisch Ihr Postfach gesperrt. Daher werden wir Sie beim nächsten Login auffordern, Ihr Passwort zu ändern. Sollten Sie Ihre E-Mails gewöhnlich über unsere WEB.DE Mail Apps, den WEB.DE Mobile Mailer oder ein anderes E-Mail-Programm (per POP3, IMAP) abrufen, melden Sie sich bitte unter web.de an, um Ihr Passwort zu ändern.Vielen Dank für Ihre Mitarbeit! Mit freundlichen Grüßen Ihr WEB.DE Kundenmanagement
Falls Sie die Aufforderung zur Änderung Ihres Passwortes bereits erhalten und Ihr Passwort geändert haben, bitten wir Sie, auch folgende Schritte zur Sicherheit durchzuführen:
1.*
Prüfen Sie, ob Ihre Kundendaten verändert wurden. Achten Sie insbesondere auf Ihre alternative E-Mail-Adresse, an die, falls Sie einmal Ihr Passwort vergessen ein Einmal-Passwort geschickt wird. Diese finden Sie in den erweiterten Passwort-Einstellungen unter "Passwort/Konto".
2.*
Führen Sie einen Virenscan mit einer aktuellen Anti-Viren-Software auf allen Computern durch, über die Sie auf Ihren WEB.DE Account zugreifen. Unter www.botfrei.de stehen Ihnen verschiedene kostenfreie Virenscanner zur Verfügung, mit denen Sie Ihren Computer sicher überprüfen können.
3.*
Falls Sie Ihre E-Mails über ein Android Smartphone abrufen, sollten Sie auf Ihrem Smartphone ebenfalls einen Virenscan durchführen. Verschiedene Virenscanner können Sie sich kostenfrei im Play Store herunterladen.
Sollten Sie Änderungen in Ihren Kundendaten entdecken oder der Virenscan positiv ausgefallen sein, ändern Sie zur Sicherheit erneut Ihr Passwort. Gehen Sie dafür bitte wie folgt vor: 1. Melden Sie sich wie gewohnt bei WEB.DE an. 2. Ändern Sie unter "Passwort/Konto" Ihr Passwort. Eine ausführliche Hilfe zur Änderung des Passworts finden Sie unter: WEB.DE Hilfe: Passwort
Bei Fragen helfen wir Ihnen gerne weiter. Montags bis Freitags zwischen 8:00 und 21:00 Uhr und an den Wochenenden zwischen 10:00 und 18:00 Uhr erreichen Sie uns unter: 0900 - 1 93 23 30 (3,99 € pro Anruf, nur aus dem deutschen Festnetz erreichbar).
© 2013 WEB.DE Impressum Da ich die E-Mail nicht selbst gesendet habe, habe ich mit dem ESET-Scanner auf unseren Notebooks gesucht. Hier das Logfile von dem Rechner mit den meisten Funden sowie die normalerweise erforderlichen Logfiles, FRST.txt ist im Anhang, da zu groß:
ESET Code:
C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\cltmng.exe Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung
C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPTool64.exe Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung
C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32.dll Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung
C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32Loader.dll Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung
C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC64.dll Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung
C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC64Loader.dll Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung
C:\Program Files (x86)\LenovoBrowserGuard\Main\bin\CltMngSvc.exe Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung
C:\Program Files (x86)\LenovoBrowserGuard\Main\bin\SPTool.dll Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung
C:\Program Files (x86)\LenovoBrowserGuard\Main\bin\uninstall.exe Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung
C:\Program Files (x86)\LenovoBrowserGuard\UI\bin\cltmngui.exe Variante von Win32/Conduit.SearchProtect.Y evtl. unerwünschte Anwendung
C:\Users\Admin\AppData\Local\Temp\SPSetup.exe Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung
C:\Windows\Temp\nsb9A1E.exe Win32/Conduit.SearchProtect.R evtl. unerwünschte Anwendung
C:\Windows\Temp\nsl73A9.exe Win32/Conduit.SearchProtect.R evtl. unerwünschte Anwendung
Arbeitsspeicher Variante von Win32/Conduit.SearchProtect.Y evtl. unerwünschte Anwendung Defogger Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 19:18 on 10/05/2015 (Administrator1)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- Additions Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-05-2015
Ran by Admin at 2015-05-10 19:31:55
Running from C:\Users\Admin\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Admin (S-1-5-21-1824186178-563054429-20502543-1001 - Limited - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-1824186178-563054429-20502543-500 - Administrator - Disabled)
Administrator1 (S-1-5-21-1824186178-563054429-20502543-1002 - Administrator - Enabled) => C:\Users\Administrator1
Gast (S-1-5-21-1824186178-563054429-20502543-501 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 17.0.0.144 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Avira (HKLM-x32\...\{b5675cc4-ab8b-4945-8c1d-4c5479556d6a}) (Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.10.434 - Avira Operations GmbH & Co. KG)
Benutzerhandbücher (x32 Version: 3.0.0.3 - Lenovo) Hidden
BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
C410 (x32 Version: 140.0.353.000 - Hewlett-Packard) Hidden
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5143 - CDBurnerXP)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.28.50 - Conexant)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.32.00 - Lenovo Inc.) Hidden
Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.21 - Lenovo)
Energy Manager (x32 Version: 1.5.0.21 - Lenovo) Hidden
Fax (x32 Version: 140.0.307.000 - Hewlett-Packard) Hidden
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
Hightail for Lenovo (HKLM\...\{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}) (Version: 2.4.97.2857 - Hightail, Inc.)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Photosmart Prem C410 All-In-One Driver Software 14.0 Rel. 7 (HKLM\...\{951AF289-1B6A-44CA-B4F3-259BFC49148F}) (Version: 14.0 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPAppStudio (x32 Version: 140.0.95.000 - Hewlett-Packard) Hidden
HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) Sideband Fabric Device Driver (HKLM-x32\...\C5A8BC6E-723A-4C0F-96E1-C426D1A4BCA9) (Version: 1.0.0.1002 - Intel Corporation)
Intel(R) Trusted Execution Engine (HKLM\...\{176E2755-0A17-42C6-88E2-192AB2131278}) (Version: 1.0.0.1064 - Intel Corporation)
Java 7 Update 79 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417079FF}) (Version: 7.0.790 - Oracle)
Java 7 Update 79 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217079FF}) (Version: 7.0.790 - Oracle)
Lenovo Browser Guard (HKLM-x32\...\LenovoBrowserGuard) (Version: 2.16.50.5 - ClientConnect LTD)
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.25.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10264 - Realtek Semiconductor Corp.)
Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 1.0.17.0 - Lenovo)
Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2326 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2326 - CyberLink Corp.) Hidden
Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.0 - Lenovo)
Lenovo PhoneCompanion (x32 Version: 1.2.0.0 - Lenovo) Hidden
Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.)
Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo SHAREit (HKLM-x32\...\Lenovo SHAREit_is1) (Version: 2.0.5.0 - Lenovo Group Limited)
Lenovo Solution Center (HKLM\...\{2F45A217-E9C7-4984-B0AC-5BE31FF4712B}) (Version: 2.4.003.00 - Lenovo Group Limited)
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.0.0.65 - Lenovo)
Lenovo Updates (x32 Version: 1.0.0.65 - Lenovo) Hidden
Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.0.14.1061 - Lenovo)
Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.6122.5000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.7140.5002 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 37.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 en-US)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.6.0 - Mozilla)
Mozilla Thunderbird 31.6.0 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 31.6.0 (x86 en-US)) (Version: 31.6.0 - Mozilla)
Network64 (Version: 140.0.306.000 - Hewlett-Packard) Hidden
Nitro Pro 9 (HKLM\...\{4C32F7E8-A65F-4D3C-9153-9F3B57CB6872}) (Version: 9.0.5.9 - Nitro)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.)
PS_AIO_07_C410_SW_Min (x32 Version: 140.0.365.000 - Hewlett-Packard) Hidden
QuickTransfer (x32 Version: 140.0.98.000 - Hewlett-Packard) Hidden
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.805.806.012214 - REALTEK Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.39053 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0238 - REALTEK Semiconductor Corp.)
Rossmann Fotowelt Software (HKLM-x32\...\Rossmann Fotowelt Software) (Version: 4.14.5. - ORWO Net)
Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
Secunia PSI (2.0.0.4003) (HKLM-x32\...\Secunia PSI) (Version: 2.0.0.4003 - Secunia)
Skypeâ„¢ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden
Start Menu (HKU\S-1-5-21-1824186178-563054429-20502543-1001\...\Pokki) (Version: 0.269.2.471 - Pokki)
Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.14.74 - Synaptics Incorporated)
Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden
Windows-Treiberpaket - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
ATTENTION: System Restore is disabled.
Check "winmgmt" service or repair WMI.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job =>
==================== Loaded Modules (whitelisted) ==============
2014-10-09 19:18 - 2010-10-26 06:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
2014-03-12 10:37 - 2014-03-07 18:21 - 00080312 _____ () C:\WINDOWS\system32\igfxexps.dll
2014-03-26 12:50 - 2014-10-09 20:15 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll
2012-02-07 21:54 - 2012-02-07 21:54 - 00078624 _____ () C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
2015-03-23 00:01 - 2015-03-23 00:01 - 00028160 _____ () C:\Users\Admin\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.PerfTrack\3aa4cbea7adc836ff7968cf73ce11027\Microsoft.PerfTrack.ni.dll
2015-03-23 00:00 - 2015-03-23 00:00 - 00347136 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\1b6c35238563de0cb93d3ed0826a69a3\Windows.Globalization.ni.dll
2015-03-23 00:00 - 2015-03-23 00:00 - 00363520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\b3972424579e18e6699549ecb948c4ef\Windows.Foundation.ni.dll
2015-03-23 00:00 - 2015-03-23 00:00 - 00207872 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.System\5ab6059d1e922dc371685c5207f6f7a6\Windows.System.ni.dll
2015-03-23 00:00 - 2015-03-23 00:00 - 01278464 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Storage\eea3e743a58cb4d556fe113d6336020b\Windows.Storage.ni.dll
2015-03-23 00:00 - 2015-03-23 00:00 - 01782272 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\f1407bb1d381cf5dee299c4e5f0fdf9d\Windows.ApplicationModel.ni.dll
2014-10-09 19:41 - 2014-10-09 19:41 - 00551440 _____ () C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\SqliteWrapper.dll
2014-10-09 19:41 - 2014-10-09 19:41 - 00660920 _____ () C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Sqlite3.dll
2015-03-23 00:00 - 2015-03-23 00:00 - 01459712 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.UI\5c9c0b89a558d0e589c254af6b1ca238\Windows.UI.ni.dll
2015-05-07 08:16 - 2015-05-07 08:16 - 00280064 _____ () C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Microsoft.Bing.AppEx.Telemetry.winmd
2015-03-23 00:00 - 2015-03-23 00:00 - 00632320 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Security\2333488328d673bea8d60a9f2e84759c\Windows.Security.ni.dll
2015-03-23 00:01 - 2015-03-23 00:01 - 00117248 _____ () C:\Users\Admin\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\SqliteWrapper\696bd1d3763da57b5fd727587a8edb94\SqliteWrapper.ni.dll
2015-03-23 00:00 - 2015-03-23 00:00 - 01259520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Networking\84819467f44d3da49aa14236af8fcc9a\Windows.Networking.ni.dll
2015-03-23 00:00 - 2015-03-23 00:00 - 01383936 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Web\87bd4b0afae2a321640d4aba350d58a4\Windows.Web.ni.dll
2015-03-23 00:00 - 2015-03-23 00:00 - 00467456 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Graphics\f4031c5dbdde97cb4a0c7572cc0d1f29\Windows.Graphics.ni.dll
2015-05-07 08:16 - 2015-05-07 08:16 - 00029696 _____ () C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Microsoft.AppEx.Sports.BaseEnums.winmd
2015-05-07 08:16 - 2015-05-07 08:16 - 00822800 _____ () C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Microsoft.AppEx.Sports.Schemas.winmd
2015-03-23 00:01 - 2015-03-23 00:01 - 02019840 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Devices\271d406467b9db0758ea399495d00731\Windows.Devices.ni.dll
2015-05-07 08:16 - 2015-05-07 08:16 - 00015360 _____ () C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Microsoft.AppEx.Sports.TransformEngine.BaseSchemas.winmd
2015-05-07 08:16 - 2015-05-07 08:16 - 00029712 _____ () C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Microsoft.AppEx.Sports.SportsEnums.winmd
2013-08-22 09:19 - 2013-08-22 08:54 - 00050176 _____ () C:\WINDOWS\system32\WinMetadata\Windows.Data.winmd
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Users\Admin\OneDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VisualDiscovery => ""="service"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1824186178-563054429-20502543-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Admin\Pictures\city.jpg
DNS Servers: 192.168.2.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1824186178-563054429-20502543-1001\...\StartupApproved\Run: => "Skype"
==================== FirewallRules (whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{C8CC5675-45EB-4AA2-9429-A704477FE24B}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{1B917AC1-C927-49DF-AE60-7F45F1049FE2}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{4D687A33-209F-4FB4-BF2C-A718763F6B3A}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{A799BDB5-3BD8-4B0B-8D63-92AAA7BC2245}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{A1079FEA-13CF-4ADF-9EBF-9C1F9AD0BDC2}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{CE7CA87D-F971-45F0-8D5B-EA6A5D6F1F00}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe
FirewallRules: [{D08AAED7-5813-44AB-BB9A-0B23DC944265}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe
FirewallRules: [{470430C7-FB33-4CA4-B366-263BCEC90ECB}] => (Allow) LPort=55100
FirewallRules: [{EE49414F-328D-4FD1-9318-F82B2BEE715E}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
FirewallRules: [TCP Query User{E1E8BEAC-1C3C-40DC-9D5C-0A231FC160C2}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{9D593291-CDC1-4126-963E-D89ADBE87F7F}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{42297120-CD7D-4B3A-B8F0-0B78526A834F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{69546AF3-D3D9-44C3-91B5-A4BA1AFD5D50}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{CAFBB945-E005-40C3-9601-4BED30754AFE}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{4652594E-832C-450B-95AC-8FCC448FECC8}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{DF8D4478-3167-411C-AF85-79B89A83CEDB}] => (Allow) C:\Users\Administrator1\AppData\Local\Temp\7zS35BD\setup\hpznui40.exe
FirewallRules: [{A943A8C2-F25E-4048-A08E-08507E9B4852}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{B86D864C-425F-4151-808B-C3B2F2784E4F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{A43A40D3-8A4D-40A9-8E55-7BC6BC88F945}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{6A911B6A-9158-4D9C-A384-50F2C1033CD8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{7259F5A3-90A4-42D3-BE5C-B395DCE8E1AD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{3DEBAC79-54D1-4D8B-BEFC-02F06C92F030}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{38A94F34-32C1-4EF1-9441-049545A82612}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{E004699D-C899-4373-8BC5-61B52848661E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{97BE87C0-7954-4A02-B13A-123C6429D694}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{1CBE7FF8-69A3-438B-BC16-3A791B8326FA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{FB1568EB-4149-4784-91A4-CDDFF10AAE96}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{B9B8DA87-AAE2-42F0-9A99-194E0B4E9FD9}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{5FA299C4-9A4D-436C-8965-6095CB4BCB84}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{E63F601C-FA63-40BC-807B-F5634032500B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{B5E13F3C-17E5-4D39-BC51-FF6E93E29DA7}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
==================== Faulty Device Manager Devices =============
Name: Photosmart Prem C410 series
Description: Photosmart Prem C410 series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Photosmart Prem C410 series
Description: Photosmart Prem C410 series
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: HP
Service: StillCam
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (05/10/2015 07:14:49 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifest.
Error: (05/10/2015 06:26:30 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (05/10/2015 02:42:01 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifest.
Error: (05/09/2015 10:57:40 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifest.
Error: (05/09/2015 10:57:29 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifest.
Error: (05/09/2015 10:57:22 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifest.
Error: (05/09/2015 10:57:22 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifest.
Error: (05/09/2015 10:49:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm soffice.bin, Version 4.0.9774.500 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 26c4
Startzeit: 01d0869e8c53bcc9
Endzeit: 157
Anwendungspfad: C:\Program Files (x86)\OpenOffice 4\program\soffice.bin
Berichts-ID: e3da1752-f68c-11e4-826b-1008b19fbf7c
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (05/09/2015 11:21:21 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (05/09/2015 10:34:10 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: Lenovo-PC)
Description: Die App „microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe+Microsoft.WindowsLive.Calendar“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.
System errors:
=============
Error: (05/01/2015 03:34:16 AM) (Source: DCOM) (EventID: 10010) (User: Lenovo-PC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (05/01/2015 03:33:45 AM) (Source: DCOM) (EventID: 10010) (User: Lenovo-PC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (04/30/2015 06:39:08 AM) (Source: DCOM) (EventID: 10010) (User: Lenovo-PC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (04/30/2015 06:38:38 AM) (Source: DCOM) (EventID: 10010) (User: Lenovo-PC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (04/28/2015 11:18:12 PM) (Source: DCOM) (EventID: 10010) (User: Lenovo-PC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (04/28/2015 11:17:41 PM) (Source: DCOM) (EventID: 10010) (User: Lenovo-PC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (04/28/2015 06:36:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (04/28/2015 06:36:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Presentation Foundation-Schriftartcache 3.0.0.0 erreicht.
Error: (04/28/2015 06:31:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "VisualDiscovery" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (04/27/2015 05:09:15 PM) (Source: DCOM) (EventID: 10010) (User: Lenovo-PC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Microsoft Office Sessions:
=========================
Error: (05/10/2015 07:14:49 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifestC:\Users\Admin\Downloads\esetsmartinstaller_deu(2).exe
Error: (05/10/2015 06:26:30 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (05/10/2015 02:42:01 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe
Error: (05/09/2015 10:57:40 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifestC:\Users\Admin\Downloads\esetsmartinstaller_deu(2).exe
Error: (05/09/2015 10:57:29 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifestC:\Users\Admin\Downloads\esetsmartinstaller_deu(2).exe
Error: (05/09/2015 10:57:22 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifestC:\Users\Admin\Downloads\esetsmartinstaller_deu(2).exe
Error: (05/09/2015 10:57:22 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_a9ed7f470139b3c1.manifestC:\Users\Admin\Downloads\esetsmartinstaller_deu(2).exe
Error: (05/09/2015 10:49:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: soffice.bin4.0.9774.50026c401d0869e8c53bcc9157C:\Program Files (x86)\OpenOffice 4\program\soffice.bine3da1752-f68c-11e4-826b-1008b19fbf7c
Error: (05/09/2015 11:21:21 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (05/09/2015 10:34:10 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: Lenovo-PC)
Description: microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe+Microsoft.WindowsLive.Calendar
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU N2830 @ 2.16GHz
Percentage of memory in use: 53%
Total physical RAM: 3979.21 MB
Available physical RAM: 1853.86 MB
Total Pagefile: 6370.06 MB
Available Pagefile: 3411.78 MB
Total Virtual: 131072 MB
Available Virtual: 131071.78 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:425.17 GB) (Free:379.43 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.16 GB) NTFS
Drive e: (Firmung 2015) (CDROM) (Total:1.67 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
==================== End Of Log ============================ Gmer Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-05-10 20:25:19
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000021 WDC_WD5000LPCX-24C6HT0 rev.02.01A02 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\fxlyrpog.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff960000f1a00 15 bytes [00, 2E, F4, 01, 80, A0, 6E, ...]
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 17 fffff960000f1a11 10 bytes [5E, FC, FF, 00, BB, C7, 00, ...]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [496:5264] fffff960008f72d0
---- Processes - GMER 2.1 ----
Library C:\Users\Admin\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.PerfTrack\3aa4cbea7adc836ff7968cf73ce11027\Microsoft.PerfTrack.ni.dll (*** suspicious ***) @ C:\WINDOWS\system32\wwahost.exe [9680](2015-03-22 22:01:35) 00007ffd04f40000
Library C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Microsoft.Bing.AppEx.Telemetry.winmd (*** suspicious ***) @ C:\WINDOWS\system32\wwahost.exe [9680] (FILE NOT FOUND) 0000001a249e0000
Library C:\Users\Admin\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\SqliteWrapper\696bd1d3763da57b5fd727587a8edb94\SqliteWrapper.ni.dll (*** suspicious ***) @ C:\WINDOWS\system32\wwahost.exe [9680](2015-03-22 22:01:41) 00007ffd006a0000
Library C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Microsoft.AppEx.Sports.BaseEnums.winmd (*** suspicious ***) @ C:\WINDOWS\system32\wwahost.exe [9680] (FILE NOT FOUND) 0000001a27620000
Library C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Microsoft.AppEx.Sports.Schemas.winmd (*** suspicious ***) @ C:\WINDOWS\system32\wwahost.exe [9680] (FILE NOT FOUND) 0000001a27c10000
Library C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Microsoft.AppEx.Sports.TransformEngine.BaseSchemas.winmd (*** suspicious ***) @ C:\WINDOWS\system32\wwahost.exe [9680] (FILE NOT FOUND) 0000001a24dc0000
Library C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Microsoft.AppEx.Sports.SportsEnums.winmd (*** suspicious ***) @ C:\WINDOWS\system32\wwahost.exe [9680] (FILE NOT FOUND) 0000001a250c0000
Library C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.315_x64__8wekyb3d8bbwe\Newtonsoft.Json.DLL (*** suspicious ***) @ C:\WINDOWS\system32\wwahost.exe [9680] (FILE NOT FOUND) 0000001a28f40000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- Bei gmer kamen 3x Meldungen
"Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird:
c:\windows\system32\config\system (1x am Anfang, 1x während des Scans)
c:\users\administrator1\ntuser.dat (1x während des Scans)"
Schon mal im voraus vielen Dank für die Bereitschaft, mir und den anderen Hilfesuchenden zu helfen!
Matthias |