Hallo Sandra,
alle von Dir beschriebenen Schritte sind bei meinem Rechner fehlerfrei durchgelaufen.
Hier sind nun die angegebenen Codes:
defogger_disable.log Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 18:29 on 20/10/2013 (Harald Peters)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
gmer.txt Code:
GMER Logfile:
Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-10-20 18:47:05
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD16 rev.11.0 149,05GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\HARALD~1\AppData\Local\Temp\ffdiypog.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 544 fffff80002bf0000 64 bytes [00, 00, 87, 00, 46, 69, 6C, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 610 fffff80002bf0042 4 bytes [00, 00, 00, 00]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\StarMoney 8.0 Commerzbank-Edition\ouservice\StarMoneyOnlineUpdate.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75]
.text C:\Program Files (x86)\StarMoney 8.0 Commerzbank-Edition\ouservice\StarMoneyOnlineUpdate.exe[1624] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75]
.text ... * 2
.text C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\avp.exe[1712] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077480038 5 bytes JMP 000000016e791765
.text C:\Users\Harald Peters\AppData\Roaming\Dropbox\bin\Dropbox.exe[3608] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75]
.text C:\Users\Harald Peters\AppData\Roaming\Dropbox\bin\Dropbox.exe[3608] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3808] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3808] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75]
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[1156] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75]
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[1156] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75]
.text ... * 2
.text C:\Windows\SysWOW64\msiexec.exe[6672] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007747fc50 5 bytes JMP 000000007efa1f6f
.text C:\Windows\SysWOW64\msiexec.exe[6672] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection 000000007747fc80 5 bytes JMP 000000007efa2014
.text C:\Windows\SysWOW64\msiexec.exe[6672] C:\Windows\syswow64\ws2_32.dll!GetAddrInfoW 0000000077024889 5 bytes JMP 000000007efa18c0
.text C:\Windows\SysWOW64\msiexec.exe[2260] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007747fc50 5 bytes JMP 000000007efa1f6f
.text C:\Windows\SysWOW64\msiexec.exe[2260] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection 000000007747fc80 5 bytes JMP 000000007efa2014
.text C:\Windows\SysWOW64\msiexec.exe[2260] C:\Windows\syswow64\ws2_32.dll!GetAddrInfoW 0000000077024889 5 bytes JMP 000000007efa18c0
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[10900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75]
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[10900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[10968] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75]
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[10968] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75]
.text ... * 2
.text C:\Program Files (x86)\Evernote\Evernote\Evernote.exe[10364] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75]
.text C:\Program Files (x86)\Evernote\Evernote\Evernote.exe[10364] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Windows\SysWOW64\msiexec.exe [6672:6408] 000000007efa3793
Thread C:\Windows\SysWOW64\msiexec.exe [2260:6544] 000000007efa3793
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00037a76b62b
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00037a76b62b (not active ControlSet)
---- EOF - GMER 2.1 ---- --- --- --- FRST.txt
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-10-2013
Ran by Harald Peters (administrator) on HP-LIFEBOOKP-1 on 20-10-2013 18:56:40
Running from C:\Users\Harald Peters\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 8.0 Commerzbank-Edition\ouservice\StarMoneyOnlineUpdate.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Dropbox, Inc.) C:\Users\Harald Peters\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Dr. J. Rathlev, D-24222 Schwentinental) C:\Program Files (x86)\Personal Backup 5\Persbackup.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\avp.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\avp.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\klogon: C:\Windows\system32\klogon.dll (Kaspersky Lab ZAO)
MountPoints2: {02260935-1c93-11e3-b9a8-001742f2b0eb} - G:\HTC_Sync_Manager_PC.exe
HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\avp.exe [515888 2013-02-07] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
Startup: C:\Users\Harald Peters\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Harald Peters\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Harald Peters\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\Harald Peters\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Persbackup.lnk
ShortcutTarget: Persbackup.lnk -> C:\Program Files (x86)\Personal Backup 5\Persbackup.exe (Dr. J. Rathlev, D-24222 Schwentinental)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=a5e19c4d-d5e8-4799-92f0-4d154cd52331&affid=113129&searchtype=ds&babsrc=lnkry&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6100EDFE1AF7CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=a5e19c4d-d5e8-4799-92f0-4d154cd52331&affid=113129&searchtype=ds&babsrc=lnkry&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=a5e19c4d-d5e8-4799-92f0-4d154cd52331&affid=113129&searchtype=ds&babsrc=lnkry&q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=a5e19c4d-d5e8-4799-92f0-4d154cd52331&affid=113129&searchtype=ds&babsrc=lnkry&q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=a5e19c4d-d5e8-4799-92f0-4d154cd52331&affid=113129&searchtype=ds&babsrc=lnkry&q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=a5e19c4d-d5e8-4799-92f0-4d154cd52331&affid=113129&searchtype=ds&babsrc=lnkry&q={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Tcpip\Parameters: [DhcpNameServer] 217.0.43.17 217.0.43.49
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"]},"first_run_tabs":["hxxp://www.google.com/","hxxp://welcome_page"
==================== Services (Whitelisted) =================
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\avp.exe [515888 2013-02-07] (Kaspersky Lab ZAO)
R2 HPSLPSVC; C:\Users\HARALD~1\AppData\Local\Temp\7zS1A95\hpslpsvc64.dll [1039360 2012-11-14] (Hewlett-Packard Co.)
R2 StarMoney 8.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 8.0 Commerzbank-Edition\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
==================== Drivers (Whitelisted) ====================
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [464176 2011-08-18] (Kaspersky Lab ZAO)
R1 kl2; C:\Windows\System32\DRIVERS\kl2.sys [13616 2011-08-18] (Kaspersky Lab ZAO)
R1 KLFLTDEV; C:\Windows\System32\DRIVERS\klfltdev.sys [58672 2012-04-03] (Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [636720 2012-05-14] (Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [32048 2011-09-01] (Kaspersky Lab ZAO)
S3 rstescu; C:\Windows\system32\drivers\rstescu.sys [607256 2011-03-25] (Intel Corporation)
S3 rstescu1; C:\Windows\system32\drivers\rstescu1.sys [607256 2011-03-25] (Intel Corporation)
R0 rstfltr; C:\Windows\System32\drivers\rstfltr.sys [22552 2011-03-25] (Intel Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-20 18:56 - 2013-10-20 18:56 - 00000000 ____D C:\FRST
2013-10-20 18:55 - 2013-10-20 18:56 - 01954548 _____ (Farbar) C:\Users\Harald Peters\Desktop\FRST64.exe
2013-10-20 18:47 - 2013-10-20 18:47 - 00007723 _____ C:\Users\Harald Peters\Desktop\gmer.txt
2013-10-20 18:36 - 2013-10-20 18:36 - 00377856 _____ C:\Users\Harald Peters\Desktop\gmer_2.1.19163.exe
2013-10-20 18:29 - 2013-10-20 18:29 - 00000488 _____ C:\Users\Harald Peters\Desktop\defogger_disable.log
2013-10-20 18:29 - 2013-10-20 18:29 - 00000000 _____ C:\Users\Harald Peters\defogger_reenable
2013-10-20 18:28 - 2013-10-20 18:28 - 00050477 _____ C:\Users\Harald Peters\Desktop\Defogger.exe
==================== One Month Modified Files and Folders =======
2013-10-20 18:56 - 2013-10-20 18:56 - 00000000 ____D C:\FRST
2013-10-20 18:56 - 2013-10-20 18:55 - 01954548 _____ (Farbar) C:\Users\Harald Peters\Desktop\FRST64.exe
2013-10-20 18:54 - 2013-03-24 15:36 - 00000000 ____D C:\Program Files (x86)\StarMoney 8.0 Commerzbank-Edition
2013-10-20 18:54 - 2013-01-16 15:14 - 01523313 _____ C:\Windows\WindowsUpdate.log
2013-10-20 18:52 - 2013-01-19 18:08 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-10-20 18:50 - 2013-01-27 17:09 - 00000000 ____D C:\Users\Harald Peters\AppData\Roaming\Dropbox
2013-10-20 18:49 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-20 18:49 - 2009-07-14 06:51 - 00042612 _____ C:\Windows\setupact.log
2013-10-20 18:47 - 2013-10-20 18:47 - 00007723 _____ C:\Users\Harald Peters\Desktop\gmer.txt
2013-10-20 18:47 - 2013-02-16 10:35 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-20 18:36 - 2013-10-20 18:36 - 00377856 _____ C:\Users\Harald Peters\Desktop\gmer_2.1.19163.exe
2013-10-20 18:29 - 2013-10-20 18:29 - 00000488 _____ C:\Users\Harald Peters\Desktop\defogger_disable.log
2013-10-20 18:29 - 2013-10-20 18:29 - 00000000 _____ C:\Users\Harald Peters\defogger_reenable
2013-10-20 18:29 - 2013-01-16 15:28 - 00000000 ____D C:\Users\Harald Peters
2013-10-20 18:29 - 2009-07-14 06:45 - 00033712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-20 18:29 - 2009-07-14 06:45 - 00033712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-20 18:28 - 2013-10-20 18:28 - 00050477 _____ C:\Users\Harald Peters\Desktop\Defogger.exe
2013-10-20 12:33 - 2013-02-16 10:35 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-20 12:33 - 2013-01-27 16:57 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-20 12:33 - 2013-01-27 16:57 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-08 16:09 - 2013-01-19 18:08 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2013-10-07 17:05 - 2013-01-17 00:09 - 00643866 _____ C:\Windows\system32\perfh007.dat
2013-10-07 17:05 - 2013-01-17 00:09 - 00126394 _____ C:\Windows\system32\perfc007.dat
2013-10-07 17:05 - 2009-07-14 07:13 - 01472002 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-22 15:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
Some content of TEMP:
====================
C:\Users\Harald Peters\AppData\Local\Temp\ose00000.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-20 15:19
==================== End Of Log ============================ --- --- ---
Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-10-2013
Ran by Harald Peters at 2013-10-20 18:58:08
Running from C:\Users\Harald Peters\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Kaspersky Endpoint Security 8 für Windows (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AS: Kaspersky Endpoint Security 8 für Windows (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Endpoint Security 8 für Windows (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
==================== Installed Programs ======================
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Reader XI (11.0.02) - Deutsch (x32 Version: 11.0.02)
Audacity 2.0.3 (x32 Version: 2.0.3)
CANON iMAGE GATEWAY MyCamera Download Plugin (x32 Version: 3.1.0.1)
Canon MOV Decoder (x32 Version: 1.7.0.6)
Canon Utilities CameraWindow DC 8 (x32 Version: 8.3.0.6)
Canon Utilities CameraWindow Launcher (x32 Version: 7.5.0.2)
Canon Utilities Movie Uploader for YouTube (x32 Version: 1.1.0.4)
Canon Utilities MyCamera (x32 Version: 7.4.0.2)
Canon Utilities PhotoStitch (x32 Version: 3.1.22.46)
Dropbox (HKCU Version: 2.0.22)
ElsterFormular (x32 Version: 14.1.11318)
Evernote v. 4.6.2 (x32 Version: 4.6.2.7927)
FreeCommander 2009.02b (x32 Version: 2009.02)
FreeFileSync 5.11 (x32 Version: 5.11)
Intel(R) Graphics Media Accelerator Driver (Version: 8.15.10.1930)
Kaspersky Endpoint Security 8 für Windows (Version: 8.1.0.831)
LAME v3.99.3 (for Windows) (x32)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.4763.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.4763.1000)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
MozBackup 1.5.1 (x32)
Mozilla Maintenance Service (x32 Version: 17.0.2)
Mozilla Thunderbird 17.0.2 (x86 de) (x32 Version: 17.0.2)
Paragon Partition Manager™ 12 Free (x32 Version: 90.00.0003)
Personal Backup 5.4 (x32 Version: 5.3)
RippMe (x32 Version: 3.04)
StarMoney (x32 Version: 3.0.2.50)
StarMoney 8.0 Commerzbank-Edition (x32 Version: 8.0)
TagScanner 5.1.630 (x32)
XnView 1.99.6 (x32 Version: 1.99.6)
==================== Restore Points =========================
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {5BBB019E-790D-408A-9070-32E1AFF8C76F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-20] (Adobe Systems Incorporated)
Task: {9EB05833-90E1-4A32-873F-CBEB27C82135} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {E2BE61A0-8A00-4DD0-A38B-77883F7C2448} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2010-01-30 03:40 - 2010-01-30 03:40 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2013-03-24 15:41 - 2011-01-13 12:44 - 00232800 _____ () C:\Program Files (x86)\StarMoney 8.0 Commerzbank-Edition\ouservice\PATCHW32.dll
2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\Harald Peters\AppData\Roaming\Dropbox\bin\libcef.dll
2012-09-08 13:16 - 2012-09-08 13:16 - 00433664 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
2012-09-08 13:16 - 2012-09-08 13:16 - 00315392 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
2012-04-17 12:13 - 2012-04-17 12:13 - 00283024 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\am_facade.dll
2012-04-17 12:13 - 2012-04-17 12:13 - 01225104 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\enterprise_application_control.dll
2012-04-17 12:13 - 2012-04-17 12:13 - 00430480 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\FileCategorizer.dll
2012-04-17 12:14 - 2012-04-17 12:14 - 00143760 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\sax_xml_parser.dll
2012-04-17 12:15 - 2012-04-17 12:15 - 00278928 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\device_control_task.ppl
2012-04-17 12:16 - 2012-04-17 12:16 - 00463248 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\WebControlTask.ppl
2012-04-17 12:13 - 2012-04-17 12:13 - 00262544 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\device_control.dll
2012-04-17 12:14 - 2012-04-17 12:14 - 00311696 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\network_services.dll
2012-04-17 12:13 - 2012-04-17 12:13 - 00422288 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Endpoint Security 8 für Windows\categorizer_facade.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Boot.BAK:KAVICHS
AlternateDataStreams: C:\fpRedmon.log:KAVICHS
AlternateDataStreams: C:\SerialSync.txt:KAVICHS
AlternateDataStreams: C:\update.phone-setup.log:KAVICHS
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Fingerprint Sensor
Description: Fingerprint Sensor
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/20/2013 06:50:38 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/08/2013 08:09:50 PM) (Source: Application Error) (User: )
Description: Aus einem der folgenden Gründe kann nicht auf die Datei "" zugegriffen werden:
Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger mit der gespeicherten Datei bzw. den auf dem Computer installierten
Speichertreibern, oder der Datenträger fehlt.
Das Programm Windows Media Player-Netzwerkfreigabedienst wurde wegen dieses Fehlers geschlossen.
Programm: Windows Media Player-Netzwerkfreigabedienst
Datei:
Der Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet.
Benutzeraktion
1. Öffnen Sie die Datei erneut.
Diese Situation ist eventuell ein temporäres Problem, das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird.
2.
Wenn Sie weiterhin nicht auf die Datei zugreifen können und
- diese sich im Netzwerk befindet,
dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem besteht und dass eine Verbindung mit dem Server hergestellt werden kann.
- diese sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet, überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist.
3. Überprüfen und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE.
4. Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin besteht.
5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt.
Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware, um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt.
Zusätzliche Daten
Fehlerwert: C000000E
Datenträgertyp: 0
Error: (10/08/2013 08:09:50 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: wmpnetwk.exe, Version: 12.0.7601.17514, Zeitstempel: 0x4ce7ae7f
Name des fehlerhaften Moduls: GDI32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c651
Ausnahmecode: 0xc0000006
Fehleroffset: 0x0000000000013164
ID des fehlerhaften Prozesses: 0xa84
Startzeit der fehlerhaften Anwendung: 0xwmpnetwk.exe0
Pfad der fehlerhaften Anwendung: wmpnetwk.exe1
Pfad des fehlerhaften Moduls: wmpnetwk.exe2
Berichtskennung: wmpnetwk.exe3
Error: (09/24/2013 07:00:31 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: wmpnetwk.exe, Version: 12.0.7601.17514, Zeitstempel: 0x4ce7ae7f
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb164a
Ausnahmecode: 0xc0000374
Fehleroffset: 0x00000000000c4102
ID des fehlerhaften Prozesses: 0xcc4
Startzeit der fehlerhaften Anwendung: 0xwmpnetwk.exe0
Pfad der fehlerhaften Anwendung: wmpnetwk.exe1
Pfad des fehlerhaften Moduls: wmpnetwk.exe2
Berichtskennung: wmpnetwk.exe3
Error: (09/13/2013 06:41:03 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/30/2013 03:31:16 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/16/2013 05:30:54 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/24/2013 05:17:14 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/20/2013 10:30:44 AM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: Microsoft.Build.Tasks, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil . Error code = 0x80070005
Error: (05/19/2013 06:17:18 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (10/20/2013 06:49:26 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 20.10.2013 um 18:47:33 unerwartet heruntergefahren.
Error: (10/20/2013 06:49:13 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden gelöscht, weil der Schattenkopiespeicher nicht rechtzeitig vergrößert wurde. Sie sollten die E/A-Last auf dem System verringern oder ein Schattenkopie-Speichervolume, von dem keine Schattenkopie erstellt wird, auswählen.
Error: (10/08/2013 08:09:55 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (10/06/2013 08:33:56 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Netman erreicht.
Error: (09/24/2013 07:00:52 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (09/13/2013 06:40:11 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 13.09.2013 um 18:38:21 unerwartet heruntergefahren.
Error: (09/13/2013 06:39:58 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden gelöscht, weil der Schattenkopiespeicher nicht rechtzeitig vergrößert wurde. Sie sollten die E/A-Last auf dem System verringern oder ein Schattenkopie-Speichervolume, von dem keine Schattenkopie erstellt wird, auswählen.
Error: (08/27/2013 05:23:38 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst lmhosts erreicht.
Error: (08/11/2013 10:46:27 AM) (Source: DCOM) (User: HP-LifebookP-1)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}HP-LifebookP-1Harald PetersS-1-5-21-3220388816-3851943047-4274909068-1000LocalHost (unter Verwendung von LRPC)
Error: (07/30/2013 03:30:10 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 30.07.2013 um 15:27:54 unerwartet heruntergefahren.
Microsoft Office Sessions:
=========================
Error: (10/20/2013 06:50:38 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/08/2013 08:09:50 PM) (Source: Application Error)(User: )
Description: Windows Media Player-NetzwerkfreigabedienstC000000E0
Error: (10/08/2013 08:09:50 PM) (Source: Application Error)(User: )
Description: wmpnetwk.exe12.0.7601.175144ce7ae7fGDI32.dll6.1.7601.175144ce7c651c00000060000000000013164a8401ceb8e31cde01caC:\Program Files\Windows Media Player\wmpnetwk.exeC:\Windows\system32\GDI32.dlld266ece8-3044-11e3-b9a8-001742f2b0eb
Error: (09/24/2013 07:00:31 AM) (Source: Application Error)(User: )
Description: wmpnetwk.exe12.0.7601.175144ce7ae7fntdll.dll6.1.7601.1822951fb164ac000037400000000000c4102cc401ceb0a0389650aeC:\Program Files\Windows Media Player\wmpnetwk.exeC:\Windows\SYSTEM32\ntdll.dll3c507e18-24d6-11e3-b9a8-001742f2b0eb
Error: (09/13/2013 06:41:03 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/30/2013 03:31:16 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/16/2013 05:30:54 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/24/2013 05:17:14 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/20/2013 10:30:44 AM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: Microsoft.Build.Tasks, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil . Error code = 0x80070005
Microsoft.Build.Tasks, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil
Error: (05/19/2013 06:17:18 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Percentage of memory in use: 40%
Total physical RAM: 4086.36 MB
Available physical RAM: 2431 MB
Total Pagefile: 8170.91 MB
Available Pagefile: 6465.51 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (SYSTEM) (Fixed) (Total:78.58 GB) (Free:39.55 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATEN) (Fixed) (Total:70.46 GB) (Free:65.31 GB) NTFS
Drive f: (DATEN-2) (Fixed) (Total:596.17 GB) (Free:497.78 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: A2A7A2A7)
Partition 1: (Active) - (Size=79 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=70 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 596 GB) (Disk ID: 49962155)
Partition 1: (Active) - (Size=596 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Viel Erfolg bei der Suche
Tom |