Untersuchung eines weiteren PCs im Netzwerk (PC 2 von 2) Ich habe bereits meinen PC bereinigt ( http://www.trojaner-board.de/149962-...s-meldung.html) allerdings befinden sich noch 2 weitere PCs im Netzwerk, die ich auch gerne untersuchen lassen würde, dieser ist einer davon. (Der Zweite. Es ist also kein Doppelpost des selben Problems.)
Hier das FRST-Log: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-02-2014
Ran by Maximilian (administrator) on MIKE-PC on 21-02-2014 15:52:26
Running from C:\Users\Maximilian\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9398888 2010-07-28] (Realtek Semiconductor)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-18] (Microsoft Corporation)
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-18] (Microsoft Corporation)
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\MountPoints2: F - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\MountPoints2: L - L:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\MountPoints2: {41804e8b-3f3e-11e0-bdbf-806e6f6e6963} - E:\start.exe
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\MountPoints2: {77b76acd-cbdb-11e0-a257-6cf04911833d} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\MountPoints2: {77b76ad0-cbdb-11e0-a257-6cf04911833d} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\MountPoints2: {90bce603-796f-11e0-a4af-6cf04911833d} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\MountPoints2: {90bce611-796f-11e0-a4af-6cf04911833d} - L:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\MountPoints2: {ace65999-41a1-11e0-acb5-6cf04911833d} - F:\LaunchU3.exe -a
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\MountPoints2: {aea9a08a-5ad4-11e1-8ecb-6cf04911833d} - IomegaEncryptionSetup v1.3.exe
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\MountPoints2: {ee041364-d09a-11e0-8d60-6cf04911833d} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1001\...\MountPoints2: {ee041367-d09a-11e0-8d60-6cf04911833d} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-18] (Microsoft Corporation)
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-18] (Microsoft Corporation)
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\Run: [Akamai NetSession Interface] - C:\Users\oem\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil32_11_7_700_202_Plugin.exe [813448 2013-05-25] (Adobe Systems Incorporated)
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\MountPoints2: F - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\MountPoints2: L - L:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\MountPoints2: {41804e8b-3f3e-11e0-bdbf-806e6f6e6963} - E:\start.exe
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\MountPoints2: {77b76acd-cbdb-11e0-a257-6cf04911833d} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\MountPoints2: {77b76ad0-cbdb-11e0-a257-6cf04911833d} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\MountPoints2: {90bce603-796f-11e0-a4af-6cf04911833d} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\MountPoints2: {90bce611-796f-11e0-a4af-6cf04911833d} - L:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\MountPoints2: {ace65999-41a1-11e0-acb5-6cf04911833d} - F:\LaunchU3.exe -a
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\MountPoints2: {aea9a08a-5ad4-11e1-8ecb-6cf04911833d} - IomegaEncryptionSetup v1.3.exe
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\MountPoints2: {ee041364-d09a-11e0-8d60-6cf04911833d} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3500999161-1433461041-2774453423-1009\...\MountPoints2: {ee041367-d09a-11e0-8d60-6cf04911833d} - F:\setup_vmc_lite.exe /checkApplicationPresence
==================== Internet (Whitelisted) ====================
ProxyServer: bundeskampf.com:80
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE9A279D993D5CB01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKCU - {1114651A-34DA-457B-978D-268BECE0ADBE} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie
SearchScopes: HKCU - {19F74C3A-6017-4F3F-B441-0E81804BF3A0} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {7C99FA37-C615-4E68-91A4-1CEEE113EFFB} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://int.search-results.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=NIS&chn=retail&geo=DE&ver=18
SearchScopes: HKCU - {E818378B-1490-4D59-816D-8DAA098C8C9F} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No File
Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Maximilian\AppData\Roaming\Mozilla\Firefox\Profiles\ybif58k3.default
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\coFFPlgn\ []
FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\IPSFF [2013-10-09]
========================== Services (Whitelisted) =================
R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-02] (Akamai Technologies, Inc.)
S3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.)
R2 NIS; C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R3 WinHttpAutoProxySvc; winhttp.dll [X]
==================== Drivers (Whitelisted) ====================
S3 ASUSVRC; C:\Windows\System32\DRIVERS\AsusVRC.sys [18432 2007-01-29] (ASUSTeK COMPUTER INC.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [278728 2012-06-12] ()
R1 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\BASHDefs\20140214.001\BHDrvx86.sys [1098968 2013-12-18] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1404000.028\ccSetx86.sys [134744 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-11-21] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-11-21] (Symantec Corporation)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\IPSDefs\20140219.001\IDSvix86.sys [394456 2014-01-21] (Symantec Corporation)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25416 2012-06-12] ()
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20140220.003\NAVENG.SYS [93272 2013-10-18] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20140220.003\NAVEX15.SYS [1612376 2013-10-18] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\NIS\1404000.028\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NIS\1404000.028\SRTSPX.SYS [32344 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NIS\1404000.028\SYMDS.SYS [367704 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NIS\1404000.028\SYMEFA.SYS [934488 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2013-06-19] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [36512 2013-03-05] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NIS\1404000.028\Ironx86.SYS [175264 2013-03-05] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\NIS\1404000.028\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 asusgsb; system32\drivers\asusgsb.sys [X]
S3 atkdisplf; system32\drivers\ATKDispLowFilter.sys [X]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S1 EIO; system32\DRIVERS\EIO.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-21 15:52 - 2014-02-21 15:53 - 00016146 _____ () C:\Users\Maximilian\Desktop\FRST.txt
2014-02-21 15:52 - 2014-02-21 15:52 - 00000000 ____D () C:\FRST
2014-02-21 15:51 - 2014-02-21 15:51 - 01142784 _____ (Farbar) C:\Users\Maximilian\Desktop\FRST.exe
2014-02-17 17:07 - 2014-02-17 17:07 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-16 11:14 - 2014-02-16 11:14 - 00036083 _____ () C:\Users\Valentin\Downloads\Play Kingdom Rush on A10.com.htm
2014-02-12 14:36 - 2014-02-05 09:58 - 12345344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-12 14:36 - 2014-02-05 09:56 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-12 14:36 - 2014-02-05 09:53 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-12 14:36 - 2014-02-05 09:51 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-12 14:36 - 2014-02-05 09:50 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-12 14:36 - 2014-02-05 09:49 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-12 14:36 - 2014-02-05 09:49 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-02-12 14:36 - 2014-02-05 09:48 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-12 14:36 - 2014-02-05 09:48 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-02-12 14:36 - 2014-02-05 09:48 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-12 14:36 - 2014-02-05 09:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-12 14:36 - 2014-02-05 09:48 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-12 14:36 - 2014-02-05 09:47 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-12 14:36 - 2014-02-05 09:47 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-12 14:36 - 2014-02-05 09:47 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-02-12 14:36 - 2014-02-05 09:46 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-12 13:38 - 2013-12-05 03:12 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-09 11:42 - 2014-02-09 11:42 - 00000714 _____ () C:\Users\Valentin\Desktop\WarThunder.lnk
2014-02-09 11:42 - 2014-02-09 11:42 - 00000000 ____D () C:\Users\Valentin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder
2014-02-09 11:42 - 2014-02-09 11:42 - 00000000 ____D () C:\Users\Valentin\AppData\Local\WarThunder
2014-02-09 11:42 - 2014-02-09 11:42 - 00000000 ____D () C:\ProgramData\WarThunder
2014-02-09 11:40 - 2014-02-09 11:40 - 04039360 _____ (2013 Gaijin Entertainment Corporation ) C:\Users\Valentin\Downloads\wt_launcher_1.0.1.322.exe
2014-02-05 00:26 - 2014-02-05 00:26 - 00036267 _____ () C:\Users\Valentin\Documents\ts3_clientui-win32-1375773286-2014-02-05 00_26_43.363693.dmp
2014-02-03 15:22 - 2007-08-31 01:56 - 03548672 _____ (Aurelain) C:\Users\Valentin\Desktop\Skillwheel.exe
2014-02-03 14:48 - 2012-01-13 17:01 - 00001342 _____ () C:\Users\Valentin\Desktop\H5_Game - Verknüpfung.lnk
2014-02-03 13:57 - 2014-02-03 14:02 - 00000000 _____ () C:\Users\Valentin\Knalle.txt
==================== One Month Modified Files and Folders =======
2014-02-21 15:53 - 2014-02-21 15:52 - 00016146 _____ () C:\Users\Maximilian\Desktop\FRST.txt
2014-02-21 15:52 - 2014-02-21 15:52 - 00000000 ____D () C:\FRST
2014-02-21 15:51 - 2014-02-21 15:51 - 01142784 _____ (Farbar) C:\Users\Maximilian\Desktop\FRST.exe
2014-02-21 14:12 - 2006-11-02 13:52 - 01658714 _____ () C:\Windows\WindowsUpdate.log
2014-02-21 14:07 - 2013-06-25 10:39 - 00000000 ____D () C:\Program Files\Common Files\Akamai
2014-02-21 14:06 - 2013-02-14 16:34 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-21 14:06 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-21 14:06 - 2006-11-02 13:47 - 00005696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-21 14:06 - 2006-11-02 13:47 - 00005696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-20 19:41 - 2006-11-02 14:01 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-17 17:07 - 2014-02-17 17:07 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-16 16:47 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-16 11:14 - 2014-02-16 11:14 - 00036083 _____ () C:\Users\Valentin\Downloads\Play Kingdom Rush on A10.com.htm
2014-02-14 20:21 - 2012-11-22 14:58 - 01589536 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-12 14:58 - 2013-08-14 17:48 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-12 14:55 - 2006-11-02 11:24 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-02-12 14:45 - 2011-02-23 13:22 - 00000680 _____ () C:\Users\oem\AppData\Local\d3d9caps.dat
2014-02-09 12:06 - 2013-02-18 16:45 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-02-09 12:06 - 2013-02-18 16:45 - 00000000 ____D () C:\Windows\system32\directx
2014-02-09 12:05 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public
2014-02-09 11:44 - 2013-04-03 08:51 - 00000000 ____D () C:\Users\Valentin\AppData\Local\CrashDumps
2014-02-09 11:42 - 2014-02-09 11:42 - 00000714 _____ () C:\Users\Valentin\Desktop\WarThunder.lnk
2014-02-09 11:42 - 2014-02-09 11:42 - 00000000 ____D () C:\Users\Valentin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder
2014-02-09 11:42 - 2014-02-09 11:42 - 00000000 ____D () C:\Users\Valentin\AppData\Local\WarThunder
2014-02-09 11:42 - 2014-02-09 11:42 - 00000000 ____D () C:\ProgramData\WarThunder
2014-02-09 11:42 - 2013-03-28 07:04 - 00000000 ____D () C:\Users\Valentin\Documents\My Games
2014-02-09 11:40 - 2014-02-09 11:40 - 04039360 _____ (2013 Gaijin Entertainment Corporation ) C:\Users\Valentin\Downloads\wt_launcher_1.0.1.322.exe
2014-02-05 09:58 - 2014-02-12 14:36 - 12345344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-05 09:56 - 2014-02-12 14:36 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-05 09:53 - 2014-02-12 14:36 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-05 09:51 - 2014-02-12 14:36 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-05 09:50 - 2014-02-12 14:36 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-05 09:49 - 2014-02-12 14:36 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-05 09:49 - 2014-02-12 14:36 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-02-05 09:48 - 2014-02-12 14:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-05 09:48 - 2014-02-12 14:36 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-02-05 09:48 - 2014-02-12 14:36 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-05 09:48 - 2014-02-12 14:36 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-05 09:48 - 2014-02-12 14:36 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-05 09:47 - 2014-02-12 14:36 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-05 09:47 - 2014-02-12 14:36 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-05 09:47 - 2014-02-12 14:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-02-05 09:46 - 2014-02-12 14:36 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-05 00:26 - 2014-02-05 00:26 - 00036267 _____ () C:\Users\Valentin\Documents\ts3_clientui-win32-1375773286-2014-02-05 00_26_43.363693.dmp
2014-02-04 08:24 - 2012-02-02 08:58 - 01722980 _____ () C:\Windows\PFRO.log
2014-02-03 14:05 - 2013-02-18 16:45 - 00000765 _____ () C:\Users\Valentin\Desktop\World of Tanks.lnk
2014-02-03 14:02 - 2014-02-03 13:57 - 00000000 _____ () C:\Users\Valentin\Knalle.txt
2014-02-03 14:02 - 2012-11-22 14:56 - 00000000 ____D () C:\Users\Valentin
Files to move or delete:
====================
C:\Users\Maximilian\AppData\Roaming\desktop.ini
C:\Users\Public\BRADDPRT.DLL
C:\Users\Public\BrAdmSet.dll
C:\Users\Public\brcpy64.exe
C:\Users\Public\brdefprn.exe
C:\Users\Public\brinetdl.dll
C:\Users\Public\BRINSDRV.EXE
C:\Users\Public\BRINSDRV64.EXE
C:\Users\Public\BrRemPnP.dll
C:\Users\Public\BRSLFEXE.DAT
C:\Users\Public\BRUTL1.DLL
C:\Users\Public\Minecraft.exe
C:\Users\Public\Pdrvinst.dll
C:\Users\Public\pdwizard.exe
C:\Users\Public\printer64.exe
C:\Users\Public\PSDLL.DLL
C:\Users\Public\Ptins95.dll
C:\Users\Public\PtinsNT.dll
C:\Users\Public\PTINSNT2.DLL
C:\Users\Public\PTRCGER.DLL
C:\Users\Public\UNINST.EXE
Some content of TEMP:
====================
C:\Users\Maximilian\AppData\Local\Temp\drm_dyndata_7380015.dll
C:\Users\Maximilian\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Maximilian\AppData\Local\Temp\nvSCPAPISvr.exe
C:\Users\Maximilian\AppData\Local\Temp\nvStInst.exe
C:\Users\Maximilian\AppData\Local\Temp\_isDCE7.exe
C:\Users\Maximilian\AppData\Local\Temp\_isE32D.exe
C:\Users\oem\AppData\Local\Temp\AutoRun.exe
C:\Users\oem\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\oem\AppData\Local\Temp\EAInstall.dll
C:\Users\oem\AppData\Local\Temp\_is7F9C.exe
C:\Users\oem\AppData\Local\Temp\_isC16C.exe
C:\Users\oem\AppData\Local\Temp\_isE7CF.exe
C:\Users\Valentin\AppData\Local\Temp\i4jdel0.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-21 14:13
==================== End Of Log ============================ Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-02-2014
Ran by Maximilian at 2014-02-21 15:53:43
Running from C:\Users\Maximilian\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
==================== Installed Programs ======================
Update for Microsoft Office 2007 (KB2508958) (Version: - Microsoft)
Adobe Flash Player 11 ActiveX (Version: 11.3.300.265 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (Version: 11.7.700.202 - Adobe Systems Incorporated)
Adobe Reader X (10.1.3) - Deutsch (Version: 10.1.3 - Adobe Systems Incorporated)
Age of Mythology - The Titans Expansion (Version: - )
Age of Mythology (Version: - )
Akamai NetSession Interface (HKCU Version: - Akamai Technologies, Inc)
Akamai NetSession Interface Service (Version: - Akamai Technologies, Inc)
Assassin's Creed Brotherhood (Version: 1.03 - Ubisoft)
Aufstieg des Hexenkönigs™ (Version: - )
Autodesk Design Review 2013 (Version: 13.0.0.82 - Autodesk, Inc.)
Autodesk Design Review 2013 (Version: 13.0.0.82 - Autodesk, Inc.) Hidden
Autodesk Design Review Browser Add-on v1.2 (Version: 1.2.0 - Autodesk)
Brother BRAdmin Light 1.22.0003 (Version: 1.22.0003 - Brother)
Brother Driver Deployment Wizard (Version: 1.09.000 - Brother)
Brother MFL-Pro Suite MFC-J6510DW (Version: 2.0.0.0 - Brother Industries, Ltd.)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Der Herr der Ringe® - Die Eroberung™ (Version: 1.0.0.1 - Electronic Arts)
Die Schlacht um Mittelerde(tm) (Version: - )
Die Schlacht um Mittelerde™ II (Version: - )
DIE SIEDLER - Aufstieg eines Königreichs (Version: 1.00.0000 - Ubisoft)
DIE SIEDLER - Das Erbe der Könige (Alle Produkte) (Version: 1.00.0000 - Blue Byte)
DWG TrueView 2013 (Version: 19.0.55.0 - Autodesk)
DWG TrueView 2013 (Version: 19.0.55.0 - Autodesk) Hidden
FaceFilter Studio Brother Edition (Version: 1.0 - )
Feedback Tool (Version: 1.1.0 - Microsoft Corporation)
Feedback Tool (Version: 1.2.0 - Microsoft Corporation)
Free 3GP Video Converter version 4.0.3.815 (Version: - DVDVideoSoft Ltd.)
Free Audio Converter version 2.3.3.908 (Version: - DVDVideoSoft Ltd.)
Free YouTube Download version 3.0.13.815 (Version: - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.10.11.923 (Version: - DVDVideoSoft Ltd.)
Heroes of Might & Magic V: Hammers of Fate (Version: - )
Heroes of Might and Magic V - Tribes of the East (Version: - )
Heroes of Might and Magic V (Version: - )
Java Auto Updater (Version: 2.1.6.0 - Sun Microsystems, Inc.) Hidden
Java(TM) 7 Update 5 (Version: 7.0.50 - Oracle)
JavaFX 2.1.1 (Version: 2.1.1 - Oracle Corporation)
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 1.1 (Version: - )
Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 1.1 Security Update (KB2833941) (Version: - )
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0 - Microsoft Corp.)
Might & Magic Heroes VI (Version: 1.1 - Ubisoft)
Mozilla Firefox 27.0.1 (x86 de) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (Version: 27.0.1 - Mozilla)
MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML4 Parser (Version: 1.0.0 - Microsoft Game Studios)
Need for Speed™ Carbon (Version: - )
Norton Internet Security (Version: 20.4.0.40 - Symantec Corporation)
NVIDIA 3D Vision Controller Driver (Version: 280.19 - NVIDIA Corporation) Hidden
NVIDIA 3D Vision Controller-Treiber 320.18 (Version: 320.18 - NVIDIA Corporation)
NVIDIA Grafiktreiber 320.18 (Version: 320.18 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.124.810 - NVIDIA Corporation) Hidden
NVIDIA PhysX (Version: 9.12.1031 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.12.1031 (Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA Systemsteuerung 320.18 (Version: 320.18 - NVIDIA Corporation) Hidden
NVIDIA Update 1.11.3 (Version: 1.11.3 - NVIDIA Corporation)
PaperPort Image Printer (Version: 1.00.0001 - Nuance Communications, Inc.)
Picasa 3 (Version: 3.9 - Google, Inc.)
Realtek High Definition Audio Driver (Version: 6.0.1.6167 - Realtek Semiconductor Corp.)
Segoe UI (Version: 15.4.2271.0615 - Microsoft Corp) Hidden
Steam (Version: 1.0.0.0 - Valve Corporation)
The Elder Scrolls V: Skyrim (Version: - Bethesda Game Studios)
TuneUp Utilities Language Pack (de-DE) (Version: 10.0.4300.9 - TuneUp Software) Hidden
Ubisoft Game Launcher (Version: 1.0.0.0 - UBISOFT)
Uninstall 1.0.0.1 (Version: - )
Update for 2007 Microsoft Office System (KB967642) (Version: - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (Version: 3 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (Version: - Microsoft)
VLC media player 2.0.1 (Version: 2.0.1 - VideoLAN)
Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Family Safety (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger Companion Core (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
WinRAR 4.20 (32-Bit) (Version: 4.20.0 - win.rar GmbH)
WISO Steuer-Sparbuch 2012 (Version: 19.00.7303 - Buhl Data Service GmbH)
WISO Steuer-Sparbuch 2013 (Version: 20.00.8137 - Buhl Data Service GmbH)
World of Tanks (Version: - Wargaming.net)
==================== Restore Points =========================
19-07-2013 17:40:17 Geplanter Prüfpunkt
04-08-2013 17:41:04 Geplanter Prüfpunkt
11-08-2013 08:46:43 Installed MSXML 4.0 SP3 Parser
11-08-2013 08:48:57 Microsoft Visual C++ 2005 Redistributable wird installiert
11-08-2013 08:50:58 Installed Nuance PaperPort 12
11-08-2013 08:53:21 Installed Nuance PDF Viewer Plus.
11-08-2013 08:53:33 Gerätetreiber-Paketinstallation: Brother Bildverarbeitungsgeräte
11-08-2013 08:57:20 Gerätetreiber-Paketinstallation: Brother Anschlüsse (COM & LPT)
11-08-2013 08:58:34 Installiert Brother Software Suite
11-08-2013 09:00:46 Gerätetreiber-Paketinstallation: Brother Bildverarbeitungsgeräte
11-08-2013 09:01:07 Gerätetreiber-Paketinstallation: Brother Drucker
11-08-2013 09:01:43 Gerätetreiber-Paketinstallation: Brother Anschlüsse (COM & LPT)
11-08-2013 09:02:37 Gerätetreiber-Paketinstallation: Brother Drucker
11-08-2013 09:36:58 Gerätetreiber-Paketinstallation: Brother Drucker
11-08-2013 10:47:12 Installiert FaceFilter Studio
11-08-2013 11:03:28 Installiert BRAdmin Light
11-08-2013 11:14:21 Installiert Brother Software Suite
12-08-2013 12:16:31 Removed PaperPort Image Printer
12-08-2013 12:17:15 Removed Nuance PaperPort 12
12-08-2013 12:19:55 Removed Nuance PDF Viewer Plus.
12-08-2013 12:21:04 Installed Nuance PaperPort 12
12-08-2013 12:22:47 Installed Nuance PDF Viewer Plus.
12-08-2013 12:23:34 Installed PaperPort Image Printer
12-08-2013 12:26:14 Installiert Brother Software Suite
12-08-2013 12:27:28 Gerätetreiber-Paketinstallation: Brother Bildverarbeitungsgeräte
12-08-2013 12:42:18 Windows Update
12-08-2013 15:03:33 Removed Nuance PaperPort 12
12-08-2013 15:06:03 Removed Nuance PDF Viewer Plus.
14-08-2013 16:18:03 Windows Update
28-08-2013 16:19:25 Windows Update
08-09-2013 11:21:14 Geplanter Prüfpunkt
13-09-2013 20:54:52 Windows Update
14-09-2013 08:02:47 Windows Update
19-09-2013 09:08:24 Geplanter Prüfpunkt
05-10-2013 09:11:11 Geplanter Prüfpunkt
12-10-2013 18:38:19 Windows Update
12-10-2013 20:08:48 Windows Update
21-10-2013 17:21:25 Geplanter Prüfpunkt
27-10-2013 18:26:17 Geplanter Prüfpunkt
14-11-2013 15:47:16 Windows Update
16-11-2013 19:36:32 Geplanter Prüfpunkt
22-11-2013 18:27:52 Geplanter Prüfpunkt
12-12-2013 17:32:42 Windows Update
22-12-2013 19:49:18 Geplanter Prüfpunkt
15-01-2014 20:44:27 Windows Update
12-02-2014 13:35:26 Windows Update
==================== Hosts content: ==========================
2006-11-02 11:23 - 2012-06-23 13:25 - 00000850 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 www.facebook.com
127.0.0.1 platform.twitter.com
127.0.0.1 www.twitter.com
127.0.0.1 plusone.google.com
==================== Scheduled Tasks (whitelisted) =============
Task: {1148AE44-231E-45A8-A718-778A6AE1123E} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-17] (Sun Microsystems, Inc.)
Task: {18F92A2F-5E10-4061-8D70-7B7C66B45015} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03] (Adobe Systems Incorporated)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {36376508-7F3A-4095-A570-E79513DE3730} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - oem => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {3EB3C5BE-6422-45D3-A965-34FD2EFC4877} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-18] (Microsoft Corporation)
Task: {4D7BC85C-5A41-4963-8CDD-6D9D55F757DB} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => BthUdTask.exe
Task: {5B9A49D9-0D83-4E57-8E87-E0D440D0331B} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {665915DF-130C-4DA9-8DF0-4A5DB722C80C} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation)
Task: {809E246A-1963-4CF4-9780-FD61FE08F721} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {91F45DC8-A8BD-4FBE-918C-174125DB4208} - System32\Tasks\Microsoft\Windows\RestartManager\{1500A2FA-ABA7-47af-8AED-65E81912AAAC} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation)
Task: {94118A2B-F968-4808-ADB7-23649D7FA1FB} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Maximilian => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] ()
Task: {FC62CD7D-4F74-4CD2-AD91-EA798D5FF974} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
==================== Loaded Modules (whitelisted) =============
2013-08-11 09:59 - 2009-02-27 15:38 - 00139264 ____R () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
2013-06-11 15:10 - 2012-05-30 07:51 - 00699280 ____R () C:\PROGRAM FILES\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\wincfi39.dll
2014-02-17 17:07 - 2014-02-17 17:07 - 03578992 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2013-06-11 15:10 - 2012-05-30 07:51 - 00699280 ____R () C:\Program Files\Norton Internet Security\Engine\20.4.0.40\wincfi39.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WISO Mein Steuer-Sparbuch heute.lnk => C:\Windows\pss\WISO Mein Steuer-Sparbuch heute.lnk.CommonStartup
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\oem\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: BrStsMon00 => C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: ControlCenter4 => C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
MSCONFIG\startupreg: IndexSearch => "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: KiesPDLR => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "D:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
MSCONFIG\startupreg: PaperPort PTD => "C:\Program Files\Nuance\PaperPort\pptd40nt.exe"
MSCONFIG\startupreg: PDF5 Registry Controller => C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe
MSCONFIG\startupreg: PDFHook => C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe
MSCONFIG\startupreg: PPort12reminder => "C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (02/09/2014 11:42:49 AM) (Source: Application Error) (User: )
Description: Fehlerhafte Anwendung launcher.exe_War Thunder, Version 1.0.1.185, Zeitstempel 0x52e77809, fehlerhaftes Modul launcher.exe, Version 1.0.1.185, Zeitstempel 0x52e77809, Ausnahmecode 0x80000003, Fehleroffset 0x0009acc5,
Prozess-ID 0xa64, Anwendungsstartzeit launcher.exe_War Thunder0.
Error: (02/07/2014 08:06:17 PM) (Source: Application Error) (User: )
Description: Fehlerhafte Anwendung H5_Game.exe, Version 3.1.2.98, Zeitstempel 0x48469f9f, fehlerhaftes Modul H5_Game.exe, Version 3.1.2.98, Zeitstempel 0x48469f9f, Ausnahmecode 0xc0000005, Fehleroffset 0x008e0823,
Prozess-ID 0xe00, Anwendungsstartzeit H5_Game.exe0.
Error: (02/07/2014 08:03:19 PM) (Source: Application Error) (User: )
Description: Fehlerhafte Anwendung H5_Game.exe, Version 3.1.2.98, Zeitstempel 0x48469f9f, fehlerhaftes Modul H5_Game.exe, Version 3.1.2.98, Zeitstempel 0x48469f9f, Ausnahmecode 0xc0000005, Fehleroffset 0x008e0823,
Prozess-ID 0x474, Anwendungsstartzeit H5_Game.exe0.
Error: (02/04/2014 07:11:33 PM) (Source: Application Error) (User: )
Description: Fehlerhafte Anwendung H5_Game.exe, Version 3.1.2.98, Zeitstempel 0x48469f9f, fehlerhaftes Modul H5_Game.exe, Version 3.1.2.98, Zeitstempel 0x48469f9f, Ausnahmecode 0xc0000005, Fehleroffset 0x008393bb,
Prozess-ID 0xc88, Anwendungsstartzeit H5_Game.exe0.
Error: (01/15/2014 04:54:44 PM) (Source: Application Error) (User: )
Description: Fehlerhafte Anwendung FlashPlayerPlugin_11_7_700_202.exe, Version 11.7.700.202, Zeitstempel 0x51801fef, fehlerhaftes Modul ShimEng.dll_unloaded, Version 0.0.0.0, Zeitstempel 0x4549bdb7, Ausnahmecode 0xc0000005, Fehleroffset 0x6d024618,
Prozess-ID 0x9f4, Anwendungsstartzeit FlashPlayerPlugin_11_7_700_202.exe0.
Error: (01/14/2014 04:08:20 PM) (Source: Application Error) (User: )
Description: Fehlerhafte Anwendung FlashPlayerPlugin_11_7_700_202.exe, Version 11.7.700.202, Zeitstempel 0x51801fef, fehlerhaftes Modul ShimEng.dll_unloaded, Version 0.0.0.0, Zeitstempel 0x4549bdb7, Ausnahmecode 0xc0000005, Fehleroffset 0x6c534618,
Prozess-ID 0xd04, Anwendungsstartzeit FlashPlayerPlugin_11_7_700_202.exe0.
System errors:
=============
Error: (02/21/2014 03:42:19 PM) (Source: Service Control Manager) (User: )
Description: Windows Media Player-NetzwerkfreigabedienstUPnP-Gerätehost%%1058
Error: (02/21/2014 02:07:50 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032
Error: (02/21/2014 02:07:48 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (02/21/2014 02:06:34 PM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 192.168.1.5 für die Netzwerkkarte mit der Netzwerkadresse 6CF04911833D wurde durch den DHCP-Server 192.168.1.1 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).
Error: (02/20/2014 04:17:14 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032
Error: (02/20/2014 04:16:55 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (02/20/2014 04:15:40 PM) (Source: Dhcp) (User: )
Description: Die IP-Adresslease 192.168.1.3 für die Netzwerkkarte mit der Netzwerkadresse 6CF04911833D wurde durch den DHCP-Server 192.168.1.1 abgelehnt (der DHCP-Server hat eine DHCPNACK-Meldung gesendet).
Error: (02/19/2014 04:21:33 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (02/19/2014 04:21:31 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032
Error: (02/19/2014 02:31:17 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Microsoft Office Sessions:
=========================
Error: (09/05/2011 05:09:08 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 494 seconds with 480 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Percentage of memory in use: 44%
Total physical RAM: 3069.77 MB
Available physical RAM: 1702.61 MB
Total Pagefile: 6366.05 MB
Available Pagefile: 5111.18 MB
Total Virtual: 2047.88 MB
Available Virtual: 1902.87 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:488.28 GB) (Free:348.91 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: () (Fixed) (Total:443.23 GB) (Free:345.22 GB) NTFS
Drive e: (FINDUS3) (CDROM) (Total:0.11 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: 82E6F4A1)
Partition 1: (Active) - (Size=488 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=443 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Danke im Voraus :) |