Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Nach flash Video Internet langsam (https://www.trojaner-board.de/154497-flash-video-internet-langsam.html)

Gepetto1 28.05.2014 19:18

Nach flash Video Internet langsam
 
Hallo,
ich habe folgendes seltsame Problem. Werde versuchen es möglichst genau zu beschreiben.
Also mein PC läuft völlig normal. Auch beim surfen. Speedtest zeigt volle verfügbare Geschwindigkeit.
Aber sobald ich ein z.B. eingebettetes Video (flash) anschaue, lädt das Video nur noch sehr langsam und auch das weitere surfen (egal auf welchen Seiten) geht nur noch sehr langsam. Ein Speedtest zeigt auch, dass plötzlich höchstens nur noch die Hälfte der zu verfügbaren Geschwindigkeit zur Verfügung steht.

Wenn ich einen Router reboot mache, ist alles wieder ok. Biss ich wieder ein Video anschauen möchte. Dann kommt es wieder zu o.g. Problem.

Folgendes hatte ich schon gemacht.
Mailwarebytes laufen lassen. 0 Befunde
spybot laufen lassen. 0 Befunde
Virenscan (komplett) mit AVG. 0 Befunde.
Router auf Werkseinstellung zurück gesetzt.

Problem besteht noch immer.

Also irgendwie glaube ich ja kaum, dass ich mir da was eingefangen habne könnte. Aber man weiß ja nie.
Jedenfalls wäre ich für jegliche Hilfe sehr sehr dankbar.
Habe den Eindruck, dass dieses Problem erst mit der aktuellsten flash player Version Einzug genommen hat.

Vielen Dank im Voraus

Gruß
Gepetto

schrauber 29.05.2014 05:30

hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Gepetto1 29.05.2014 06:20

Hallo Schrauber,
erst einmal vielen Dank für deine Hilfe!!!

Hier die Logdateien
FRST

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02
Ran by Philipp (administrator) on PHILIPP-PC on 29-05-2014 07:08:30
Running from C:\Users\Philipp\Desktop
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Creative Technology Ltd) C:\Windows\SysWOW64\CTxfispi.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [123400 2009-01-21] (Logitech Inc.)
HKLM-x32\...\Run: [ROC_roc_dec12] => "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-692924467-1411480276-1425026954-1000\...\Run: [AVG-Secure-Search-Update_0913b] => C:\Users\Philipp\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid 25244e8280d84c553ffe70ce58603448-eb7676c7afff319c021478f5b3eeeb2ee90e22b2 --CMPID 0913b
HKU\S-1-5-21-692924467-1411480276-1425026954-1000\...\MountPoints2: {a6d391c1-6d94-11de-9e57-806e6f6e6963} - D:\BlueBirds.exe
HKU\S-1-5-21-692924467-1411480276-1425026954-1001\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

ProxyServer: localhost:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA3FB10447E45CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={D125DFB6-F0EC-4A2D-850E-189FB9AB40BB}&mid=25244e8280d84c553ffe70ce58603448-eb7676c7afff319c021478f5b3eeeb2ee90e22b2&lang=de&ds=AVG&pr=fr&d=2012-05-31 18:04:07&v=11.1.0.7&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={D125DFB6-F0EC-4A2D-850E-189FB9AB40BB}&mid=25244e8280d84c553ffe70ce58603448-eb7676c7afff319c021478f5b3eeeb2ee90e22b2&lang=de&ds=AVG&pr=fr&d=2012-05-31 18:04:07&v=11.1.0.7&sap=dsp&q={searchTerms}
BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll No File
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll No File
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  No File
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Toolbar: HKLM-x32 - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\nizmh0ap.default-1401277717052
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_37 - C:\Windows\SysWOW64\npdeployJava1.dll No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\nizmh0ap.default-1401277717052\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-28]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-05-10]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-05-10]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []

==================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-15] ()

==================== Drivers (Whitelisted) ====================

S4 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [154256 2007-08-10] (Promise Technology, Inc.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.)
S4 fttxr5_O; C:\Windows\system32\drivers\fttxr5_o.sys [230408 2007-10-25] (Promise Technology, Inc.)
R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15680 2006-11-01] ()
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [160288 2008-04-07] (NVIDIA Corporation)
S3 SaiH0BAC; C:\Windows\System32\DRIVERS\SaiH0BAC.sys [176128 2007-07-13] (Saitek)
S3 cpuz131; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz131\cpuz_x64.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-29 07:08 - 2014-05-29 07:10 - 00011999 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-05-29 07:08 - 2014-05-29 07:08 - 00000000 ____D () C:\FRST
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:12 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Downloads\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Desktop\revosetup95.exe
2014-05-28 21:02 - 2014-05-28 21:01 - 02066944 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-05-28 21:02 - 2014-05-28 19:36 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 21:01 - 2014-05-28 21:01 - 02066944 _____ (Farbar) C:\Users\Philipp\Downloads\FRST64.exe
2014-05-28 20:47 - 2014-05-28 20:47 - 00001163 _____ () C:\Users\Philipp\Desktop\mbam.txt.txt
2014-05-28 20:38 - 2014-05-28 20:39 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-28 20:38 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-28 20:38 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-28 19:37 - 2014-05-28 21:16 - 00000000 ____D () C:\AdwCleaner
2014-05-28 19:36 - 2014-05-28 19:36 - 01327971 _____ () C:\Users\Philipp\Downloads\adwcleaner_3.211.exe
2014-05-28 16:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:02 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-28 13:48 - 2014-05-28 13:48 - 00000000 ____D () C:\Users\Philipp\Documents\Alte Firefox-Daten
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 21:55 - 2014-05-27 22:29 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 21:55 - 2014-05-27 22:28 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 21:51 - 2014-05-27 21:51 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\SpyBot Search Destroy - CHIP-Installer.exe
2014-05-27 21:44 - 2014-05-28 23:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-27 21:44 - 2014-05-27 21:44 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-27 21:44 - 2014-05-27 21:44 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-27 21:44 - 2014-05-27 21:44 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-27 20:19 - 2014-05-27 20:20 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Philipp\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-15 19:28 - 2014-05-06 02:46 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 19:28 - 2014-05-06 02:21 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 02:21 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 19:28 - 2014-05-06 01:32 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 19:28 - 2014-05-06 01:14 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 01:14 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 19:01 - 2014-03-25 18:30 - 12900864 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 19:01 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-10 18:23 - 2014-05-10 18:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-02 19:21 - 2014-05-02 19:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird

==================== One Month Modified Files and Folders =======

2014-05-29 07:10 - 2014-05-29 07:08 - 00011999 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-05-29 07:09 - 2009-07-10 14:09 - 01051431 _____ () C:\Windows\WindowsUpdate.log
2014-05-29 07:08 - 2014-05-29 07:08 - 00000000 ____D () C:\FRST
2014-05-29 07:05 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-29 07:05 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-29 07:04 - 2011-08-10 16:32 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-29 07:04 - 2008-01-21 05:26 - 00836488 _____ () C:\Windows\PFRO.log
2014-05-29 07:04 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-28 23:47 - 2006-11-02 17:42 - 00032510 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-28 23:27 - 2014-05-27 21:44 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-28 22:59 - 2011-08-10 16:32 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-28 21:16 - 2014-05-28 19:37 - 00000000 ____D () C:\AdwCleaner
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:13 - 2014-05-28 21:12 - 01016261 _____ (Thisisu) C:\Users\Philipp\Downloads\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Desktop\revosetup95.exe
2014-05-28 21:01 - 2014-05-28 21:02 - 02066944 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-05-28 21:01 - 2014-05-28 21:01 - 02066944 _____ (Farbar) C:\Users\Philipp\Downloads\FRST64.exe
2014-05-28 20:47 - 2014-05-28 20:47 - 00001163 _____ () C:\Users\Philipp\Desktop\mbam.txt.txt
2014-05-28 20:39 - 2014-05-28 20:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 19:36 - 2014-05-28 21:02 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 19:36 - 2014-05-28 19:36 - 01327971 _____ () C:\Users\Philipp\Downloads\adwcleaner_3.211.exe
2014-05-28 19:14 - 2012-05-31 17:52 - 00000000 ____D () C:\ProgramData\MFAData
2014-05-28 18:25 - 2008-05-21 15:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-28 18:25 - 2008-05-21 15:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat
2014-05-28 18:25 - 2008-05-21 15:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat
2014-05-28 14:01 - 2014-05-28 16:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:01 - 2014-05-28 14:02 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-28 13:48 - 2014-05-28 13:48 - 00000000 ____D () C:\Users\Philipp\Documents\Alte Firefox-Daten
2014-05-27 23:15 - 2013-10-01 18:40 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Avg2014
2014-05-27 22:29 - 2014-05-27 21:55 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 22:28 - 2014-05-27 21:55 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 21:51 - 2014-05-27 21:51 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\SpyBot Search Destroy - CHIP-Installer.exe
2014-05-27 21:44 - 2014-05-27 21:44 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-27 21:44 - 2014-05-27 21:44 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-27 21:44 - 2014-05-27 21:44 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-27 20:20 - 2014-05-27 20:19 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Philipp\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-19 18:56 - 2014-03-31 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-05-15 19:38 - 2009-07-08 21:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 19:34 - 2013-08-14 18:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 19:33 - 2006-11-02 14:35 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-28 20:38 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 17:54 - 2012-05-31 18:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 18:55 - 2011-08-10 16:32 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-10 18:55 - 2011-08-10 16:32 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-10 18:23 - 2014-05-10 18:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-06 02:46 - 2014-05-15 19:28 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 02:21 - 2014-05-15 19:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 02:21 - 2014-05-15 19:28 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 01:32 - 2014-05-15 19:28 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 01:14 - 2014-05-15 19:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 01:14 - 2014-05-15 19:28 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-02 19:22 - 2014-05-02 19:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-29 07:11

==================== End Of Log ============================

--- --- ---

--- --- ---


Addition
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-05-2014 02
Ran by Philipp at 2014-05-29 07:10:29
Running from C:\Users\Philipp\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}

==================== Installed Programs ======================

Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Adobe Shockwave Player (HKLM-x32\...\{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}) (Version: 11.0 - Adobe Systems, Inc.)
Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4592 - AVG Technologies)
AVG 2014 (Version: 14.0.3950 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4592 - AVG Technologies) Hidden
Call of Duty: Modern Warfare 3 - Dedicated Server (HKLM-x32\...\Steam App 42750) (Version:  - Infinity Ward - Sledgehammer Games)
Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version:  - Infinity Ward - Sledgehammer Games)
Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version:  - Infinity Ward - Sledgehammer Games)
CPUID CPU-Z 1.69 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version:  - )
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version:  - )
Crysis(R) (HKLM-x32\...\{000E79B7-E725-4F01-870A-C12942B7F8E4}) (Version: 1.20.0000 - Electronic Arts)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{349F73CA-653A-43A6-AE77-970B07D6EDA0}) (Version:  - Microsoft)
Dishonored (HKLM-x32\...\Steam App 205100) (Version: 1.0 - Bethesda Softworks)
F1 2010 (HKLM-x32\...\GFWL_{434D0831-3E0C-4D03-A5D4-5E1000008400}) (Version: 1.0.0000.132 - Codemasters)
F1 2010 (x32 Version: 1.0.0000.132 - Codemasters) Hidden
F1 2010 (x32 Version: 1.0.0001.132 - Codemasters) Hidden
F1 2011 (HKLM-x32\...\GFWL_{434D0FA1-3E0C-4D03-A5D4-5E1000008100}) (Version: 1.0.0000.129 - Codemasters)
F1 2011 (x32 Version: 1.0.0000.129 - Codemasters) Hidden
F1 2011 (x32 Version: 1.0.0001.129 - Codemasters) Hidden
F1 2011 (x32 Version: 1.0.0002.129 - Codemasters) Hidden
F1 2013 (HKLM-x32\...\Steam App 223670) (Version:  - Codemasters Birmingham)
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
Flight Simulator X (HKLM-x32\...\RTMshadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version:  - )
Flight Simulator X Service Pack 1 (HKLM-x32\...\SP1shadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version:  - )
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Logitech Gaming Software 5.04 (HKLM\...\{8753DF4D-64B0-474E-9A97-0AB5585D9A53}) (Version: 5.04.110 - Logitech)
Logitech Webcam Software (HKLM\...\{987FE247-4E69-4A2E-A961-D14F901FDBF6}) (Version: 12.10.1113 - Logitech Inc.)
Logitech Webcam Software-Treiberpaket (HKLM\...\lvdrivers_12.10) (Version: 12.10.1110 - Logitech Inc.)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Flight Simulator X (x32 Version: 10.0.60905 - Microsoft Game Studios) Hidden
Microsoft Flight Simulator X: Acceleration (HKLM-x32\...\FlightSim_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version: 10.0.61637.0 - Microsoft Game Studios)
Microsoft Flight Simulator X: Acceleration (x32 Version: 10.0.61637.0 - Microsoft Game Studios) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla)
MSXML 4.0 SP2 (KB927978) (HKLM-x32\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser und SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
NVIDIA 3D Vision Controller-Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.82 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.82 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.140.952 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Systemsteuerung 331.82 (Version: 331.82 - NVIDIA Corporation) Hidden
NVIDIA Update 1.12.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.12.12 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.12.12 - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Rapture3D 2.4.9 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5854 - Realtek Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version:  - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}) (Version: 8.0.0.35 - GRISOFT, s.r.o.)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}) (Version: 9.0.0.623 - AVG Technologies CZ, s.r.o.)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)

==================== Restore Points  =========================

07-05-2013 16:31:27 Installed AVG 2013
07-05-2013 16:46:15 Removed Adobe Flash Player 9 ActiveX.
16-05-2013 16:11:59 Windows Update
26-05-2013 18:28:23 Geplanter Prüfpunkt
10-06-2013 18:33:24 Geplanter Prüfpunkt
12-06-2013 16:45:29 Windows Update
10-07-2013 16:49:49 Windows Update
14-08-2013 16:46:50 Windows Update
28-08-2013 17:18:27 Windows Update
12-09-2013 16:48:58 Windows Update
21-09-2013 17:03:11 Removed Java(TM) 6 Update 3
21-09-2013 17:04:13 Removed Java(TM) 6 Update 5
21-09-2013 17:05:11 Removed Java(TM) 6 Update 3
21-09-2013 17:14:34 Removed Java(TM) 6 Update 3
21-09-2013 17:47:47 Removed Java(TM) 6 Update 3
21-09-2013 17:48:25 Removed Java(TM) 6 Update 3
21-09-2013 18:03:31 Wiederherstellungspunkt vor Fehlerhafte Patchregistrierungsschlüssel
21-09-2013 18:05:13 Removed Java(TM) 6 Update 37
01-10-2013 16:43:39 Installed AVG 2014
01-10-2013 16:45:01 Installed AVG 2014
10-10-2013 16:42:20 Windows Update
14-10-2013 14:32:24 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
14-10-2013 14:35:51 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
14-10-2013 14:36:40 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
14-10-2013 17:14:25 DirectX wurde installiert
15-10-2013 07:39:00 Installiert Far Cry 3
31-10-2013 17:28:40 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
31-10-2013 17:32:09 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
31-10-2013 17:33:11 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
13-11-2013 17:13:00 Windows Update
20-11-2013 17:38:53 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
20-11-2013 17:43:27 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
20-11-2013 17:44:33 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
20-11-2013 17:45:57 Windows Update
21-11-2013 14:54:28 Windows Update
13-12-2013 17:19:09 Windows Update
15-01-2014 17:18:41 Windows Update
13-02-2014 17:23:08 Windows Update
13-02-2014 17:56:42 Installed AVG 2014
12-03-2014 17:37:07 Windows Update
09-04-2014 16:21:10 Windows Update
18-04-2014 17:23:25 Geplanter Prüfpunkt
30-04-2014 17:12:36 Installed AVG 2014
02-05-2014 17:19:06 Windows Update
03-05-2014 19:08:49 Geplanter Prüfpunkt
08-05-2014 19:03:11 Geplanter Prüfpunkt
14-05-2014 19:39:12 Geplanter Prüfpunkt
15-05-2014 17:27:36 Windows Update
24-05-2014 17:49:47 Geplanter Prüfpunkt
25-05-2014 17:15:51 Geplanter Prüfpunkt

==================== Hosts content: ==========================

2006-11-02 14:34 - 2006-09-18 23:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost
::1            localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {053E07D4-BF57-4777-AB86-2503FFB01905} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10] (Google Inc.)
Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {72539E3E-11DA-47CA-A173-02739CA95D54} - System32\Tasks\{DC3C511F-86D5-41EF-B546-2B08E434B6EF} => C:\Program Files (x86)\Skype\Phone\Skype.exe
Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {844584A5-E187-4702-BCCB-906B3C92C738} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {D272EFE4-B9B3-4F54-A2AA-0E2618E38D88} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10] (Google Inc.)
Task: {DE93CB4F-5D56-4AF7-8001-27E17F8F0803} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] ()
Task: {E8FC08DE-77B2-4685-AC06-5C48D657C8A2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-27] (Adobe Systems Incorporated)
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe

==================== Loaded Modules (whitelisted) =============

2013-10-15 09:59 - 2013-10-15 09:59 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2009-07-10 15:19 - 2008-12-04 12:57 - 00146432 _____ () C:\Windows\SysWOW64\APOMngr.DLL

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: LogitechQuickCamRibbon => "C:\Programme\Logitech\Logitech WebCam Software\LWS.exe" /hide
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/29/2014 07:05:38 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/28/2014 06:20:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/28/2014 04:12:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/28/2014 03:35:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/28/2014 01:55:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/28/2014 01:53:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\PHILIPP\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\NIZMH0AP.DEFAULT-1401277717052\CACHE\9> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)

Error: (05/28/2014 01:53:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\PHILIPP\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\NIZMH0AP.DEFAULT-1401277717052\CACHE\9> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)

Error: (05/28/2014 01:53:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\PHILIPP\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\NIZMH0AP.DEFAULT-1401277717052\CACHE\8> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)

Error: (05/28/2014 01:53:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\PHILIPP\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\NIZMH0AP.DEFAULT-1401277717052\CACHE\8> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)

Error: (05/28/2014 01:53:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Eintrag <C:\USERS\PHILIPP\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\NIZMH0AP.DEFAULT-1401277717052\CACHE\7> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)


System errors:
=============
Error: (05/29/2014 07:07:03 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (05/29/2014 07:05:38 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt

Error: (05/28/2014 06:21:20 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (05/28/2014 06:20:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt

Error: (05/28/2014 04:13:10 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (05/28/2014 04:12:25 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt

Error: (05/28/2014 03:37:31 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (05/28/2014 03:35:53 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt

Error: (05/28/2014 01:56:44 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (05/28/2014 01:55:28 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt


Microsoft Office Sessions:
=========================
Error: (05/29/2014 07:05:38 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/28/2014 06:20:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/28/2014 04:12:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/28/2014 03:35:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/28/2014 01:55:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/28/2014 01:53:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)
C:\USERS\PHILIPP\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\NIZMH0AP.DEFAULT-1401277717052\CACHE\9

Error: (05/28/2014 01:53:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)
C:\USERS\PHILIPP\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\NIZMH0AP.DEFAULT-1401277717052\CACHE\9

Error: (05/28/2014 01:53:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)
C:\USERS\PHILIPP\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\NIZMH0AP.DEFAULT-1401277717052\CACHE\8

Error: (05/28/2014 01:53:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)
C:\USERS\PHILIPP\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\NIZMH0AP.DEFAULT-1401277717052\CACHE\8

Error: (05/28/2014 01:53:16 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
        Ein an das System angeschlossenes Gerät funktioniert nicht.  (0x8007001f)
C:\USERS\PHILIPP\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\NIZMH0AP.DEFAULT-1401277717052\CACHE\7


CodeIntegrity Errors:
===================================
  Date: 2014-05-29 07:10:25.079
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-29 07:10:24.923
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-29 07:10:24.782
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-29 07:10:24.611
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-29 07:10:24.455
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-29 07:10:24.314
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-29 07:10:24.158
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-29 07:10:24.018
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-29 07:10:23.753
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-05-29 07:10:23.612
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 32%
Total physical RAM: 6134.17 MB
Available physical RAM: 4151.09 MB
Total Pagefile: 12379.88 MB
Available Pagefile: 10474.04 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:931.51 GB) (Free:606.77 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: 61491321)
Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Mailwarebytes
Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 28.05.2014
Suchlauf-Zeit: 20:39:20
Logdatei: mwb.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.05.28.06
Rootkit Datenbank: v2014.05.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows Vista Service Pack 2
CPU: x64
Dateisystem: NTFS
Benutzer: Philipp

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 344923
Verstrichene Zeit: 7 Min, 30 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 0
(No malicious items detected)

Dateien: 0
(No malicious items detected)

Physische Sektoren: 0
(No malicious items detected)


(end)

Was bedeuten denn eigentlich diese ganzen "Ein an das System angeschlossenes Gerät funktioniert nicht." Meldungen??
Lässt das eher auf ein Hardware/Treiber Problem schließen??

Gruß
Gepetto

schrauber 29.05.2014 21:10

hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Gepetto1 30.05.2014 06:52

Guten Morgen :)

Hier Combofix

Was vielleicht noch wichtig wäre. Schon die ganze letzte Zeit ist mir folgendes aufgefallen. Wenn ich auf "Diagnose und Reperatur" (Netzwerk) klicke, steht dort, Netzwerkkonnektivitätsproblem. Des Weiteren wechselt das Netzwerksymbol häufig zwischen "Nur lokal" und "lokal und Internet" Aber ins Internet komme ich trotzdem. Das hatte ich früher auch nicht. Was könnte das bedeuten??? Was ist da nur Los?

Code:

ComboFix 14-05-29.01 - Philipp 30.05.2014  7:24.1.8 - x64
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.6134.4588 [GMT 2:00]
ausgeführt von:: c:\users\Philipp\Desktop\ComboFix.exe
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\tmp6670.tmp
c:\windows\SysWow64\tmp6680.tmp
c:\windows\SysWow64\tmp7148.tmp
c:\windows\SysWow64\tmp7159.tmp
.
.
(((((((((((((((((((((((  Dateien erstellt von 2014-04-28 bis 2014-05-30  ))))))))))))))))))))))))))))))
.
.
2014-05-30 05:32 . 2014-05-30 05:32        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp
2014-05-30 05:32 . 2014-05-30 05:32        --------        d-----w-        c:\users\Philipp\AppData\Local\temp
2014-05-30 05:32 . 2014-05-30 05:32        --------        d-----w-        c:\users\Gast\AppData\Local\temp
2014-05-30 05:32 . 2014-05-30 05:32        --------        d-----w-        c:\users\Default\AppData\Local\temp
2014-05-30 05:16 . 2014-05-30 05:17        --------        d-----w-        C:\32788R22FWJFW
2014-05-29 05:08 . 2014-05-29 05:16        --------        d-----w-        C:\FRST
2014-05-28 18:38 . 2014-05-28 18:39        122584        ----a-w-        c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-05-28 18:38 . 2014-05-28 18:38        --------        d-----w-        c:\program files (x86)\Malwarebytes Anti-Malware
2014-05-28 18:38 . 2014-05-12 05:26        64216        ----a-w-        c:\windows\system32\drivers\mwac.sys
2014-05-28 18:38 . 2014-05-12 05:26        91352        ----a-w-        c:\windows\system32\drivers\mbamchameleon.sys
2014-05-28 18:38 . 2014-05-12 05:25        25816        ----a-w-        c:\windows\system32\drivers\mbam.sys
2014-05-28 17:37 . 2014-05-28 19:16        --------        d-----w-        C:\AdwCleaner
2014-05-27 19:55 . 2014-05-27 20:28        --------        d-----w-        c:\programdata\Spybot - Search & Destroy
2014-05-27 19:55 . 2014-05-27 20:29        --------        d-----w-        c:\program files (x86)\Spybot - Search & Destroy 2
2014-05-27 19:44 . 2014-05-27 19:44        70832        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-27 19:44 . 2014-05-27 19:44        692400        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-27 18:26 . 2014-05-27 18:26        --------        d-----w-        c:\programdata\Malwarebytes
2014-05-15 17:28 . 2014-05-06 00:21        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2014-05-15 17:28 . 2014-05-05 23:14        2382848        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2014-05-15 17:28 . 2014-05-06 00:46        17847808        ----a-w-        c:\windows\system32\mshtml.dll
2014-05-15 17:28 . 2014-05-06 00:21        96768        ----a-w-        c:\windows\system32\mshtmled.dll
2014-05-15 17:01 . 2014-03-25 16:30        12900864        ----a-w-        c:\windows\system32\shell32.dll
2014-05-13 12:20 . 2014-05-13 12:20        235800        ----a-w-        c:\windows\system32\drivers\avgldx64.sys
2014-05-13 12:20 . 2014-05-13 12:20        273176        ----a-w-        c:\windows\system32\drivers\avgtdia.sys
2014-05-13 12:06 . 2014-05-13 12:06        323352        ----a-w-        c:\windows\system32\drivers\avgloga.sys
2014-05-13 12:05 . 2014-05-13 12:05        191768        ----a-w-        c:\windows\system32\drivers\avgidsha.sys
2014-05-13 12:05 . 2014-05-13 12:05        152344        ----a-w-        c:\windows\system32\drivers\avgdiska.sys
2014-05-13 12:05 . 2014-05-13 12:05        130328        ----a-w-        c:\windows\system32\drivers\avgmfx64.sys
2014-05-13 12:04 . 2014-05-13 12:04        236312        ----a-w-        c:\windows\system32\drivers\avgidsdrivera.sys
2014-05-13 12:04 . 2014-05-13 12:04        31512        ----a-w-        c:\windows\system32\drivers\avgrkx64.sys
2014-05-02 17:21 . 2014-05-02 17:22        --------        d-----w-        c:\program files (x86)\Mozilla Thunderbird
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-15 17:33 . 2006-11-02 12:35        93223848        ----a-w-        c:\windows\system32\mrt.exe
2014-04-15 00:34 . 2014-04-15 00:34        1070232        ----a-w-        c:\windows\SysWow64\MSCOMCTL.OCX
2014-03-08 04:06 . 2014-04-09 16:24        10926592        ----a-w-        c:\windows\system32\ieframe.dll
2014-03-08 03:49 . 2014-04-09 16:24        2334720        ----a-w-        c:\windows\system32\jscript9.dll
2014-03-08 03:41 . 2014-04-09 16:24        1347072        ----a-w-        c:\windows\system32\urlmon.dll
2014-03-08 03:40 . 2014-04-09 16:24        1392128        ----a-w-        c:\windows\system32\wininet.dll
2014-03-08 03:39 . 2014-04-09 16:24        1494528        ----a-w-        c:\windows\system32\inetcpl.cpl
2014-03-08 03:38 . 2014-04-09 16:24        237056        ----a-w-        c:\windows\system32\url.dll
2014-03-08 03:37 . 2014-04-09 16:24        85504        ----a-w-        c:\windows\system32\jsproxy.dll
2014-03-08 03:34 . 2014-04-09 16:24        173056        ----a-w-        c:\windows\system32\ieUnatt.exe
2014-03-08 03:34 . 2014-04-09 16:24        816640        ----a-w-        c:\windows\system32\jscript.dll
2014-03-08 03:33 . 2014-04-09 16:24        599040        ----a-w-        c:\windows\system32\vbscript.dll
2014-03-08 03:32 . 2014-04-09 16:24        729088        ----a-w-        c:\windows\system32\msfeeds.dll
2014-03-08 03:32 . 2014-04-09 16:24        2147840        ----a-w-        c:\windows\system32\iertutil.dll
2014-03-08 03:24 . 2014-04-09 16:24        248320        ----a-w-        c:\windows\system32\ieui.dll
2014-03-07 23:12 . 2014-04-09 16:24        1806848        ----a-w-        c:\windows\SysWow64\jscript9.dll
2014-03-07 23:02 . 2014-04-09 16:24        1427968        ----a-w-        c:\windows\SysWow64\inetcpl.cpl
2014-03-07 23:02 . 2014-04-09 16:24        1129472        ----a-w-        c:\windows\SysWow64\wininet.dll
2014-03-07 22:57 . 2014-04-09 16:24        142848        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2014-03-07 22:56 . 2014-04-09 16:24        421376        ----a-w-        c:\windows\SysWow64\vbscript.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG_UI"="c:\program files (x86)\AVG\AVG2014\avgui.exe" [2014-05-13 5181456]
"CTxfiHlp"="CTXFIHLP.EXE" [2009-02-19 24576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute        REG_MULTI_SZ          autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Themes
.
Inhalt des "geplante Tasks" Ordners
.
2014-05-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-27 19:44]
.
2014-05-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 14:32]
.
2014-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 14:32]
.
2013-01-28 c:\windows\Tasks\ROC_REG_JAN_DELETE.job
- c:\programdata\AVG January 2013 Campaign\ROC.exe [2013-01-26 21:16]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2009-01-21 123400]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = localhost:8080
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\nizmh0ap.default-1401277717052\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Wow6432Node-HKCU-Run-AVG-Secure-Search-Update_0913b - c:\users\Philipp\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe
Wow6432Node-HKLM-Run-ROC_roc_dec12 - c:\program files (x86)\AVG Secure Search\ROC_roc_dec12.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-692924467-1411480276-1425026954-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:81,49,23,48,13,c8,01,d6,2d,35,d9,5e,16,bb,9f,19,bd,57,69,a0,ec,b3,cb,
  30,98,3a,9b,ed,f1,84,2d,2a,1f,3c,47,ae,8e,e9,e4,43,a4,89,f9,cb,cd,f2,35,bc,\
"??"=hex:65,34,23,f1,ac,3e,ae,99,14,20,f8,2a,53,ca,02,2f
.
[HKEY_USERS\S-1-5-21-692924467-1411480276-1425026954-1000\Software\SecuROM\License information*]
"datasecu"=hex:40,ee,6a,e9,04,e9,b0,e0,df,a8,9f,1c,72,bb,6f,8b,f6,ac,ce,dc,ea,
  e8,dc,e8,66,d9,5c,fd,4b,ad,07,06,68,dc,1d,90,d2,94,df,19,de,51,c0,69,f7,4a,\
"rkeysecu"=hex:45,7b,59,ee,92,af,a7,84,8b,d0,67,1c,80,f5,25,9d
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
Zeit der Fertigstellung: 2014-05-30  07:38:11
ComboFix-quarantined-files.txt  2014-05-30 05:38
.
Vor Suchlauf: 35 Verzeichnis(se), 651.485.085.696 Bytes frei
Nach Suchlauf: 41 Verzeichnis(se), 651.523.588.096 Bytes frei
.
- - End Of File - - 32041F7CEA5A5E9028CC200E08FD6F76
5C616939100B85E558DA92B899A0FC36

Gruß
Gepetto

schrauber 30.05.2014 22:12

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.

Gepetto1 31.05.2014 06:41

Hi,
hier ein kurzer Statusbericht. Wenn ich mit firefox ins Netz gehe, habe ich ständig Verbindungsabbrüche! :( Bin völlig verzweifelt...

hier die logs.
Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 31.05.2014
Suchlauf-Zeit: 07:01:36
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.05.31.01
Rootkit Datenbank: v2014.05.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows Vista Service Pack 2
CPU: x64
Dateisystem: NTFS
Benutzer: Philipp

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 355619
Verstrichene Zeit: 12 Min, 53 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 0
(No malicious items detected)

Dateien: 0
(No malicious items detected)

Physische Sektoren: 0
(No malicious items detected)


(end)

Code:

# AdwCleaner v3.211 - Bericht erstellt am 31/05/2014 um 07:17:34
# Aktualisiert 26/05/2014 von Xplode
# Betriebssystem : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Benutzername : Philipp - PHILIPP-PC
# Gestartet von : C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

[!] Ordner Gelöscht : C:\Users\Gast\AppData\Local\AVG Security Toolbar
[!] Ordner Gelöscht : C:\Users\Philipp\AppData\LocalLow\AVG Security Toolbar

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CCC7A320-B3CA-4199-B1A6-9F516DD69829}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : HKCU\Software\AVG Nation toolbar
Schlüssel Gelöscht : HKCU\Software\AVG Security Toolbar
Schlüssel Gelöscht : HKCU\Software\IGearSettings
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software
Schlüssel Gelöscht : HKLM\Software\AVG Nation toolbar
Schlüssel Gelöscht : HKLM\Software\AVG Secure Search
Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar

***** [ Browser ] *****

-\\ Internet Explorer v9.0.8112.16545


-\\ Mozilla Firefox v29.0.1 (de)

[ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\sotxyr2c.default\prefs.js ]


[ Datei : C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\nizmh0ap.default-1401277717052\prefs.js ]


*************************

AdwCleaner[R0].txt - [3935 octets] - [28/05/2014 19:37:13]
AdwCleaner[R1].txt - [3995 octets] - [28/05/2014 19:47:44]
AdwCleaner[R2].txt - [4053 octets] - [28/05/2014 21:16:17]
AdwCleaner[R3].txt - [3816 octets] - [31/05/2014 07:16:51]
AdwCleaner[S0].txt - [3052 octets] - [31/05/2014 07:17:34]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3112 octets] ##########

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows (TM) Vista Home Premium x64
Ran by Philipp on 31.05.2014 at  7:23:28,69
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 31.05.2014 at  7:30:12,93
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02
Ran by Philipp (administrator) on PHILIPP-PC on 31-05-2014 07:34:05
Running from C:\Users\Philipp\Desktop
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\lpksetup.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CTxfispi.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [123400 2009-01-21] (Logitech Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE

==================== Internet (Whitelisted) ====================

ProxyServer: localhost:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA3FB10447E45CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  No File
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\nizmh0ap.default-1401277717052
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_37 - C:\Windows\SysWOW64\npdeployJava1.dll No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\nizmh0ap.default-1401277717052\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-28]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-05-10]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-05-10]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []

==================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-15] ()

==================== Drivers (Whitelisted) ====================

S4 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [154256 2007-08-10] (Promise Technology, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.)
S1 Beep; No ImagePath
S4 fttxr5_O; C:\Windows\system32\drivers\fttxr5_o.sys [230408 2007-10-25] (Promise Technology, Inc.)
R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15680 2006-11-01] ()
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [160288 2008-04-07] (NVIDIA Corporation)
S3 SaiH0BAC; C:\Windows\System32\DRIVERS\SaiH0BAC.sys [176128 2007-07-13] (Saitek)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz131; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz131\cpuz_x64.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-31 07:34 - 2014-05-31 07:34 - 00010112 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-05-31 07:30 - 2014-05-31 07:30 - 00000636 _____ () C:\Users\Philipp\Desktop\JRT.txt
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-31 07:20 - 2014-05-31 07:20 - 00003200 _____ () C:\Users\Philipp\Desktop\AdwCleaner[S0].txt
2014-05-31 07:16 - 2014-05-31 07:16 - 00001165 _____ () C:\Users\Philipp\Desktop\mbam.txt
2014-05-30 15:25 - 2014-05-30 15:25 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Adobe
2014-05-30 07:40 - 2014-05-30 07:38 - 00010180 _____ () C:\Users\Philipp\Desktop\ComboFix.txt
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:17 - 2014-05-30 07:38 - 00000000 ____D () C:\Qoobox
2014-05-30 07:17 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-30 07:17 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-30 07:17 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-30 07:16 - 2014-05-30 07:37 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:16 - 2014-05-30 07:17 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-29 07:08 - 2014-05-31 07:34 - 00000000 ____D () C:\FRST
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Desktop\revosetup95.exe
2014-05-28 21:02 - 2014-05-28 21:01 - 02066944 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-05-28 21:02 - 2014-05-28 19:36 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 20:38 - 2014-05-31 07:01 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-28 20:38 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-28 20:38 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-28 19:37 - 2014-05-31 07:17 - 00000000 ____D () C:\AdwCleaner
2014-05-28 16:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:02 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-28 13:48 - 2014-05-28 13:48 - 00000000 ____D () C:\Users\Philipp\Documents\Alte Firefox-Daten
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 21:55 - 2014-05-27 22:29 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 21:55 - 2014-05-27 22:28 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 21:44 - 2014-05-31 07:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-27 21:44 - 2014-05-27 21:44 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-27 21:44 - 2014-05-27 21:44 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-27 21:44 - 2014-05-27 21:44 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 19:28 - 2014-05-06 02:46 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 19:28 - 2014-05-06 02:21 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 02:21 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 19:28 - 2014-05-06 01:32 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 19:28 - 2014-05-06 01:14 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 01:14 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 19:01 - 2014-03-25 18:30 - 12900864 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 19:01 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-10 18:23 - 2014-05-10 18:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-02 19:21 - 2014-05-02 19:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird

==================== One Month Modified Files and Folders =======

2014-05-31 07:35 - 2014-05-31 07:34 - 00010112 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-05-31 07:34 - 2014-05-29 07:08 - 00000000 ____D () C:\FRST
2014-05-31 07:33 - 2011-08-10 16:32 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-31 07:33 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-31 07:33 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-31 07:33 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-31 07:32 - 2008-01-21 05:26 - 00840278 _____ () C:\Windows\PFRO.log
2014-05-31 07:31 - 2009-07-10 14:09 - 01146666 _____ () C:\Windows\WindowsUpdate.log
2014-05-31 07:31 - 2006-11-02 17:42 - 00032510 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-31 07:30 - 2014-05-31 07:30 - 00000636 _____ () C:\Users\Philipp\Desktop\JRT.txt
2014-05-31 07:27 - 2014-05-27 21:44 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-31 07:20 - 2014-05-31 07:20 - 00003200 _____ () C:\Users\Philipp\Desktop\AdwCleaner[S0].txt
2014-05-31 07:17 - 2014-05-28 19:37 - 00000000 ____D () C:\AdwCleaner
2014-05-31 07:16 - 2014-05-31 07:16 - 00001165 _____ () C:\Users\Philipp\Desktop\mbam.txt
2014-05-31 07:05 - 2012-05-31 17:52 - 00000000 ____D () C:\ProgramData\MFAData
2014-05-31 07:01 - 2014-05-28 20:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-31 07:00 - 2011-08-10 16:32 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-30 15:25 - 2014-05-30 15:25 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Adobe
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-05-30 07:40 - 00010180 _____ () C:\Users\Philipp\Desktop\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:17 - 00000000 ____D () C:\Qoobox
2014-05-30 07:37 - 2014-05-30 07:16 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:36 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-30 07:17 - 2014-05-30 07:16 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:14 - 2008-05-21 15:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-30 07:14 - 2008-05-21 15:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat
2014-05-30 07:14 - 2008-05-21 15:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Desktop\revosetup95.exe
2014-05-28 21:01 - 2014-05-28 21:02 - 02066944 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 19:36 - 2014-05-28 21:02 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 14:01 - 2014-05-28 16:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:01 - 2014-05-28 14:02 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-28 13:48 - 2014-05-28 13:48 - 00000000 ____D () C:\Users\Philipp\Documents\Alte Firefox-Daten
2014-05-27 23:15 - 2013-10-01 18:40 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Avg2014
2014-05-27 22:29 - 2014-05-27 21:55 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 22:28 - 2014-05-27 21:55 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 21:44 - 2014-05-27 21:44 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-27 21:44 - 2014-05-27 21:44 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-27 21:44 - 2014-05-27 21:44 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-19 18:56 - 2014-03-31 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-05-15 19:38 - 2009-07-08 21:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 19:34 - 2013-08-14 18:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 19:33 - 2006-11-02 14:35 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-28 20:38 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 17:54 - 2012-05-31 18:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 18:55 - 2011-08-10 16:32 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-10 18:55 - 2011-08-10 16:32 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-10 18:23 - 2014-05-10 18:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-06 02:46 - 2014-05-15 19:28 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 02:21 - 2014-05-15 19:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 02:21 - 2014-05-15 19:28 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 01:32 - 2014-05-15 19:28 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 01:14 - 2014-05-15 19:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 01:14 - 2014-05-15 19:28 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-02 19:22 - 2014-05-02 19:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird

Some content of TEMP:
====================
C:\Users\Philipp\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-31 07:26

==================== End Of Log ============================

--- --- ---


Gruß
Gepetto

schrauber 31.05.2014 15:49


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme? :)

Gepetto1 01.06.2014 09:57

Hallo Schrauber,
ich habe das Problem eingrenzen können. Sorry, wenn ich das jetzt ein bisschen ausführlicher schreibe, aber vielleicht hilft dir das dann bei der Problembehebung.
Und noch einmal vielen Dank für deine Hilfe!!
Also... wenn ich mir firefox ins Internet gehe und KEINE Seite mit flash Inhalt aufrufe, habe ich wenige Verbindungsabbrüche. Und jetzt kommts. Sobald ich eine Seite mit flash Inhalt aufrufe, öffnen sich im Taskmanager 2mal flash player plugin.exe und 1 mal plug in container.exe. So weit so gut. Ist ja auch normal. ABER... sobald ich anschließend wieder eine Seite ohne flash aufrufe, kann ich folgendes beobachten.
Im Taskmanager schließen sich nach einiger Zeit die 2 flash exe und die plug in container exe. Und einige Sekunden später, wird die Verbindung zum Router getrennt. Dies ist reproduzierbar. Es liegt also irgendwie am firefox. Leider habe ich auch ohne flash Seiten weiter, wenn auch nicht so oft, Verbindungsabbrüche zum Router. Immer wenn der firefox läuft.

Ich werde den scan, wie von dir gewünscht, durchführen. Meinst Du es wäre sinnvoll den firefox komplett mal zu deinstallieren und wenn ja über software/deinstallieren oder mit Revo? Des Weiteren steht unter Netzwerkdiagnose" "auf diesem Computer besteht ein Netzwerkkonnektivitätsproblem". Wenn ich unter "Eigenschaften" des LAN-Adapters auf Diagnose klicke sagt er mir, dass kein Problem besteht. Soll ich eigentlich den firefox in der windows firewall einen Hacken setzen (Ausnahme) oder nicht? Ich kapier bald gar nix mehr...

Das scan Ergebnis folgt demnächst, wenn alles fertig ist.

Gruß
Gepetto

Hallo Schrauber,
hier die logs.
Code:

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=54a4577ee06dec40ba95c682ab0ff24b
# engine=18495
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-06-01 08:40:22
# local_time=2014-06-01 10:40:22 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode_1='AVG AntiVirus Free Edition 2014'
# compatibility_mode=1051 16777213 100 98 49418 88746006 0 0
# compatibility_mode_1=''
# compatibility_mode=5892 16776574 100 100 100292362 239135928 0 0
# scanned=227193
# found=3
# cleaned=0
# scan_time=13729
sh=E8CD33623287C08C7CC3662A042E45522654BB30 ft=1 fh=7cd3b160b0dbd4bd vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Philipp\Downloads\FreeYouTubeToMP3Converter(1).exe"
sh=D20146018CC2327122B2692E355F353DFA6D571A ft=1 fh=641303b82d1a41cf vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Philipp\Downloads\FreeYouTubeToMP3Converter_3.10.17.exe"
sh=6540107955BCE3573D82D4C84F9925D32023474C ft=1 fh=bfad9279c37daeed vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Philipp\Downloads\GPU Z - CHIP-Downloader.exe"

Code:

Results of screen317's Security Check version 0.99.83 
 Windows Vista Service Pack 2 x64 (UAC is enabled) 
 Internet Explorer 9 
 Internet Explorer 8 
``````````````Antivirus/Firewall Check:``````````````
AVG AntiVirus Free Edition 2014 
 Antivirus out of date! 
`````````Anti-malware/Other Utilities Check:`````````
 Adobe Flash Player        13.0.0.214 
 Adobe Reader 9 Adobe Reader out of Date!
 Mozilla Firefox (29.0.1)
 Mozilla Thunderbird (24.5.0)
````````Process Check: objlist.exe by Laurent```````` 
 AVG avgwdsvc.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-06-2014
Ran by Philipp (administrator) on PHILIPP-PC on 01-06-2014 10:48:33
Running from C:\Users\Philipp\Desktop
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Creative Technology Ltd) C:\Windows\SysWOW64\CTxfispi.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [123400 2009-01-21] (Logitech Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKU\S-1-5-21-692924467-1411480276-1425026954-1001\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

ProxyServer: localhost:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA3FB10447E45CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  No File
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\nizmh0ap.default-1401277717052
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_37 - C:\Windows\SysWOW64\npdeployJava1.dll No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\nizmh0ap.default-1401277717052\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-28]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-05-10]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-05-10]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []

==================== Services (Whitelisted) =================

S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-15] ()

==================== Drivers (Whitelisted) ====================

S4 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [154256 2007-08-10] (Promise Technology, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.)
S1 Beep; No ImagePath
S4 fttxr5_O; C:\Windows\system32\drivers\fttxr5_o.sys [230408 2007-10-25] (Promise Technology, Inc.)
R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15680 2006-11-01] ()
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [160288 2008-04-07] (NVIDIA Corporation)
S3 SaiH0BAC; C:\Windows\System32\DRIVERS\SaiH0BAC.sys [176128 2007-07-13] (Saitek)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz131; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz131\cpuz_x64.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-01 10:48 - 2014-06-01 10:48 - 00010183 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-01 10:48 - 2014-06-01 10:48 - 00000000 ____D () C:\Users\Philipp\Desktop\FRST-OlderVersion
2014-06-01 10:47 - 2014-06-01 10:47 - 00000822 _____ () C:\Users\Philipp\Desktop\checkup.txt
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-05-31 21:17 - 2014-05-31 21:17 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-05-31 21:16 - 2014-05-31 21:15 - 00854367 _____ () C:\Users\Philipp\Desktop\SecurityCheck.exe
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-31 07:30 - 2014-05-31 07:30 - 00000636 _____ () C:\Users\Philipp\Desktop\JRT.txt
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-31 07:20 - 2014-05-31 07:20 - 00003200 _____ () C:\Users\Philipp\Desktop\AdwCleaner[S0].txt
2014-05-31 07:16 - 2014-05-31 07:16 - 00001165 _____ () C:\Users\Philipp\Desktop\mbam.txt
2014-05-30 15:25 - 2014-05-30 15:25 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Adobe
2014-05-30 07:40 - 2014-05-30 07:38 - 00010180 _____ () C:\Users\Philipp\Desktop\ComboFix.txt
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-06-01 10:48 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:17 - 2014-05-30 07:38 - 00000000 ____D () C:\Qoobox
2014-05-30 07:17 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-30 07:17 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-30 07:17 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-30 07:16 - 2014-05-30 07:37 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:16 - 2014-05-30 07:17 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-29 07:08 - 2014-06-01 10:48 - 00000000 ____D () C:\FRST
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Desktop\revosetup95.exe
2014-05-28 21:02 - 2014-06-01 10:48 - 02067456 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-05-28 21:02 - 2014-05-28 19:36 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 20:38 - 2014-05-31 07:01 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-28 20:38 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-28 20:38 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-28 19:37 - 2014-05-31 07:17 - 00000000 ____D () C:\AdwCleaner
2014-05-28 16:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:02 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-28 13:48 - 2014-05-28 13:48 - 00000000 ____D () C:\Users\Philipp\Documents\Alte Firefox-Daten
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 21:55 - 2014-05-27 22:29 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 21:55 - 2014-05-27 22:28 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 21:44 - 2014-06-01 10:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-27 21:44 - 2014-05-27 21:44 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-27 21:44 - 2014-05-27 21:44 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-27 21:44 - 2014-05-27 21:44 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 19:28 - 2014-05-06 02:46 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 19:28 - 2014-05-06 02:21 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 02:21 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 19:28 - 2014-05-06 01:32 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 19:28 - 2014-05-06 01:14 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 01:14 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 19:01 - 2014-03-25 18:30 - 12900864 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 19:01 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-10 18:23 - 2014-05-10 18:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-02 19:21 - 2014-05-02 19:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird

==================== One Month Modified Files and Folders =======

2014-06-01 10:48 - 2014-06-01 10:48 - 00010183 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-01 10:48 - 2014-06-01 10:48 - 00000000 ____D () C:\Users\Philipp\Desktop\FRST-OlderVersion
2014-06-01 10:48 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-06-01 10:48 - 2014-05-29 07:08 - 00000000 ____D () C:\FRST
2014-06-01 10:48 - 2014-05-28 21:02 - 02067456 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-06-01 10:47 - 2014-06-01 10:47 - 00000822 _____ () C:\Users\Philipp\Desktop\checkup.txt
2014-06-01 10:36 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-01 10:36 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-01 10:27 - 2014-05-27 21:44 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-01 10:00 - 2011-08-10 16:32 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-01 07:11 - 2009-07-10 14:09 - 01203915 _____ () C:\Windows\WindowsUpdate.log
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-06-01 06:42 - 2012-05-31 17:52 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-01 06:36 - 2011-08-10 16:32 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-01 06:36 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-01 06:35 - 2008-01-21 05:26 - 00841756 _____ () C:\Windows\PFRO.log
2014-05-31 21:21 - 2006-11-02 17:42 - 00032510 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-31 21:17 - 2014-05-31 21:17 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-05-31 21:15 - 2014-05-31 21:16 - 00854367 _____ () C:\Users\Philipp\Desktop\SecurityCheck.exe
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-31 07:30 - 2014-05-31 07:30 - 00000636 _____ () C:\Users\Philipp\Desktop\JRT.txt
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-31 07:20 - 2014-05-31 07:20 - 00003200 _____ () C:\Users\Philipp\Desktop\AdwCleaner[S0].txt
2014-05-31 07:17 - 2014-05-28 19:37 - 00000000 ____D () C:\AdwCleaner
2014-05-31 07:16 - 2014-05-31 07:16 - 00001165 _____ () C:\Users\Philipp\Desktop\mbam.txt
2014-05-31 07:01 - 2014-05-28 20:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-30 15:25 - 2014-05-30 15:25 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Adobe
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-05-30 07:40 - 00010180 _____ () C:\Users\Philipp\Desktop\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:17 - 00000000 ____D () C:\Qoobox
2014-05-30 07:37 - 2014-05-30 07:16 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:36 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-30 07:17 - 2014-05-30 07:16 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:14 - 2008-05-21 15:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-30 07:14 - 2008-05-21 15:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat
2014-05-30 07:14 - 2008-05-21 15:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Desktop\revosetup95.exe
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 19:36 - 2014-05-28 21:02 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 14:01 - 2014-05-28 16:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:01 - 2014-05-28 14:02 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-28 13:48 - 2014-05-28 13:48 - 00000000 ____D () C:\Users\Philipp\Documents\Alte Firefox-Daten
2014-05-27 23:15 - 2013-10-01 18:40 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Avg2014
2014-05-27 22:29 - 2014-05-27 21:55 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 22:28 - 2014-05-27 21:55 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 21:44 - 2014-05-27 21:44 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-27 21:44 - 2014-05-27 21:44 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-27 21:44 - 2014-05-27 21:44 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-19 18:56 - 2014-03-31 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-05-15 19:38 - 2009-07-08 21:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 19:34 - 2013-08-14 18:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 19:33 - 2006-11-02 14:35 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-28 20:38 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 17:54 - 2012-05-31 18:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 18:55 - 2011-08-10 16:32 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-10 18:55 - 2011-08-10 16:32 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-10 18:23 - 2014-05-10 18:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-06 02:46 - 2014-05-15 19:28 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 02:21 - 2014-05-15 19:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 02:21 - 2014-05-15 19:28 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 01:32 - 2014-05-15 19:28 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 01:14 - 2014-05-15 19:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 01:14 - 2014-05-15 19:28 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-02 19:22 - 2014-05-02 19:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird

Some content of TEMP:
====================
C:\Users\Philipp\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-06-01 06:43

==================== End Of Log ============================

--- --- ---

--- --- ---


Hoffe das hilft dir.

Was sagst du denn zu meiner Beobachtung, die ich im vorherigen post geschrieben habe?

Das Problem besteht nämlich immer noch!! Wenn ich den Rechner starte (LAN) wird die Verbindung zum Netz aufgebaut. Es wird mir dennoch angezeigt, dass ein Netzwerkkonnektivitätsproblem besteht. Leitung steht trotzdem. Wenn ich per thunderbird mails abfrage, bleibt die Leitung bestehen. Keinnerlei Verbindungsabbrüche.

Aber sobald ich firefox starte, beginnen die Verbindungsabbrüche. So wie gerade auch :(

Soll ich den mal deinstallieren? Wenn ja wie am besten? Habe innerhalb der letzten Minute mindestens 6 Verbindugsabbrüche. Router verbindet sich immer wieder von selbst.

Gruß Gepetto

schrauber 02.06.2014 10:03

Revo Uninstaller - Download - Filepony
damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren.

Dann:
https://support.mozilla.org/de/kb/fi...einfach-loesen



Und schau mal in den Eigenschaften der Netzwerkverbindung ob TCPIPv4 UND das TCPIPv6 aktiviert sind.

Gepetto1 02.06.2014 13:57

Hallo Schrauber,
also habe mit Revo den firefox deinstalliert und alle Reste entfernen lassen.
Wenn ich die Netzwerk-Diagnose laufen lasse, heißt es immer noch, dass auf diesem Computer ein Netzwerkkonnektivitätsproblem besteht.
Trotzdem steht die Leitung und im Netzwerkcenter sieht auch alles "normal" aus. Kein rotes Kreuz oder so. Computer---Netzwerk---Internet. Alles ok.

Habe firefox aber noch nicht neu installiert. Soll ich wirklich?
Habe mir Opera installiert und damit habe ich absolut keine Leitungsunterbrechungen mehr.

Folgende Ordner habe ich noch gefunden. Diese wurden durch Revo nicht gelöscht.
Unter AppData-Local- gibt es noch den Ordner Mozilla mit Unterordner firefox. Dieser ist leer.
Unter AppData-Roaming gibt es auch noch einen Ordner Mozilla. In diesem befindet sich eine registry.dat und der Ordner Extensions mit einem Unterordner {3550f703-e582-4d05-9a08-453d09bdfdc6}. Dieser ist auch leer.

Soll ich die beiden Ordner auch noch händisch löschen????

Außerdem gibt es bei Revo noch Mozilla Maintenance Service. Dies könnte ich mit Revo auch noch deinstallieren lassen. Soll ich???

Gruß
Gepetto

Ach ja und den Hacken bei TCPIPv6 hatte ich schon früher rausgenommen. Ändert sich aber auch nix, wenn ich ihn setzte.

schrauber 03.06.2014 10:07

die Ordner kannste löschen, den Service mit Revo deinstallieren.

Firefox braucht IPv6.

Gepetto1 03.06.2014 13:22

Hi,
habe die Ordner und den Service gelöscht.
Es wird immer noch, bei Rechtsklick auf die kleinen Monitorsymbole rechts in der Taskleiste, wenn ich dort auf "Diagnose und Reparatur" klicke angezeigt, dass auf diesem Computer ein Netzwerkkonnektivitätsproblem besteht.
Ich versteh echt nicht, wieso. Aber die Leitung steht. Sieht man auch im Netzwerk- und Freigabecenter. Bei IPv6 steht allerdings "Eingeschränkt" Liegt das ectl. am alten Router? Speedport 502V?
Soll mich das denn jetzt weiter beunruhigen???
Wie sieht es denn jetzt aus? Ist mein Rechner denn soweit "clean"?
Und soll ich alles (z.B. Combofix etc.) wieder deinstallieren?
Hänge noch einmal ein frisches log an.


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014
Ran by Philipp (administrator) on PHILIPP-PC on 03-06-2014 14:12:40
Running from C:\Users\Philipp\Desktop
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CTxfispi.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
() C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [123400 2009-01-21] (Logitech Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKU\S-1-5-21-692924467-1411480276-1425026954-1001\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter

==================== Internet (Whitelisted) ====================

ProxyServer: localhost:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA3FB10447E45CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  No File
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_37 - C:\Windows\SysWOW64\npdeployJava1.dll No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()

==================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-15] ()

==================== Drivers (Whitelisted) ====================

S4 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [154256 2007-08-10] (Promise Technology, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.)
S1 Beep; No ImagePath
S4 fttxr5_O; C:\Windows\system32\drivers\fttxr5_o.sys [230408 2007-10-25] (Promise Technology, Inc.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15680 2006-11-01] ()
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [160288 2008-04-07] (NVIDIA Corporation)
S3 SaiH0BAC; C:\Windows\System32\DRIVERS\SaiH0BAC.sys [176128 2007-07-13] (Saitek)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz131; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz131\cpuz_x64.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 lvpopf64; system32\DRIVERS\lvpopf64.sys [X]
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
S3 LVRS64; system32\DRIVERS\lvrs64.sys [X]
S3 LVUVC64; system32\DRIVERS\lvuvc64.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-03 14:12 - 2014-06-03 14:13 - 00009069 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-03 14:04 - 2014-06-03 14:04 - 00003898 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401625260
2014-06-02 20:59 - 2014-06-02 21:50 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\eM Client
2014-06-02 20:58 - 2014-06-02 20:58 - 00000884 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2014-06-02 20:58 - 2014-06-02 20:58 - 00000000 ____D () C:\Program Files (x86)\eM Client
2014-06-02 20:56 - 2014-06-02 20:57 - 14995456 _____ () C:\Users\Philipp\Downloads\setup.msi
2014-06-02 15:31 - 2014-06-02 21:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-02 15:31 - 2014-06-02 15:31 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-02 15:31 - 2014-06-02 15:31 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-02 15:31 - 2014-06-02 15:31 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\Users\Philipp\Documents\Mail
2014-06-02 14:09 - 2014-06-02 14:09 - 00001106 _____ () C:\Users\Philipp\Desktop\Revo Uninstaller.lnk
2014-06-02 14:09 - 2014-06-02 14:09 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-01 20:30 - 2014-06-01 20:30 - 00000000 ____D () C:\Users\Philipp\Documents\Local Folders
2014-06-01 14:21 - 2014-06-03 14:04 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-01 14:21 - 2014-06-01 14:21 - 00000846 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Opera Software
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Opera Software
2014-06-01 11:16 - 2014-06-01 11:16 - 00000525 _____ () C:\Users\Philipp\Desktop\firewall.txt
2014-06-01 10:48 - 2014-06-03 14:12 - 00000000 ____D () C:\Users\Philipp\Desktop\FRST-OlderVersion
2014-06-01 10:47 - 2014-06-01 10:47 - 00000822 _____ () C:\Users\Philipp\Desktop\checkup.txt
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-05-31 21:17 - 2014-05-31 21:17 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-05-31 21:16 - 2014-05-31 21:15 - 00854367 _____ () C:\Users\Philipp\Desktop\SecurityCheck.exe
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-31 07:30 - 2014-05-31 07:30 - 00000636 _____ () C:\Users\Philipp\Desktop\JRT.txt
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-31 07:20 - 2014-05-31 07:20 - 00003200 _____ () C:\Users\Philipp\Desktop\AdwCleaner[S0].txt
2014-05-31 07:16 - 2014-05-31 07:16 - 00001165 _____ () C:\Users\Philipp\Desktop\mbam.txt
2014-05-30 07:40 - 2014-05-30 07:38 - 00010180 _____ () C:\Users\Philipp\Desktop\ComboFix.txt
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-06-03 14:13 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:17 - 2014-05-30 07:38 - 00000000 ____D () C:\Qoobox
2014-05-30 07:17 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-30 07:17 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-30 07:17 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-30 07:16 - 2014-05-30 07:37 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:16 - 2014-05-30 07:17 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-29 07:08 - 2014-06-03 14:12 - 00000000 ____D () C:\FRST
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 21:02 - 2014-06-03 14:12 - 02068992 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-05-28 21:02 - 2014-05-28 19:36 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 20:38 - 2014-06-01 18:40 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-28 20:38 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-28 20:38 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-28 19:37 - 2014-06-02 16:16 - 00000000 ____D () C:\AdwCleaner
2014-05-28 16:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:02 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 21:55 - 2014-05-27 22:29 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 21:55 - 2014-05-27 22:28 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 19:28 - 2014-05-06 02:46 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 19:28 - 2014-05-06 02:21 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 02:21 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 19:28 - 2014-05-06 01:32 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 19:28 - 2014-05-06 01:14 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 01:14 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 19:01 - 2014-03-25 18:30 - 12900864 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 19:01 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys

==================== One Month Modified Files and Folders =======

2014-06-03 14:13 - 2014-06-03 14:12 - 00009069 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-03 14:13 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-06-03 14:12 - 2014-06-01 10:48 - 00000000 ____D () C:\Users\Philipp\Desktop\FRST-OlderVersion
2014-06-03 14:12 - 2014-05-29 07:08 - 00000000 ____D () C:\FRST
2014-06-03 14:12 - 2014-05-28 21:02 - 02068992 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-06-03 14:11 - 2009-07-10 14:09 - 01342541 _____ () C:\Windows\WindowsUpdate.log
2014-06-03 14:04 - 2014-06-03 14:04 - 00003898 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401625260
2014-06-03 14:04 - 2014-06-01 14:21 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-03 14:00 - 2011-08-10 16:32 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-03 13:54 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-03 13:54 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-03 13:53 - 2011-08-10 16:32 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-03 13:53 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-02 21:51 - 2006-11-02 17:42 - 00032510 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-02 21:50 - 2014-06-02 20:59 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\eM Client
2014-06-02 21:26 - 2014-06-02 15:31 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-02 20:58 - 2014-06-02 20:58 - 00000884 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2014-06-02 20:58 - 2014-06-02 20:58 - 00000000 ____D () C:\Program Files (x86)\eM Client
2014-06-02 20:57 - 2014-06-02 20:56 - 14995456 _____ () C:\Users\Philipp\Downloads\setup.msi
2014-06-02 19:56 - 2008-01-21 05:26 - 00846494 _____ () C:\Windows\PFRO.log
2014-06-02 19:54 - 2010-04-19 15:57 - 00008843 _____ () C:\Windows\system32\lvcoinst.log
2014-06-02 19:53 - 2010-04-19 15:56 - 00000000 ____D () C:\ProgramData\LogiShrd
2014-06-02 19:53 - 2009-07-22 15:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-06-02 19:20 - 2012-05-31 17:52 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-02 16:16 - 2014-05-28 19:37 - 00000000 ____D () C:\AdwCleaner
2014-06-02 15:32 - 2009-07-10 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Adobe
2014-06-02 15:31 - 2014-06-02 15:31 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-02 15:31 - 2014-06-02 15:31 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-02 15:31 - 2014-06-02 15:31 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-02 15:31 - 2008-05-21 11:53 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\Users\Philipp\Documents\Mail
2014-06-02 14:19 - 2009-07-10 20:41 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Mozilla
2014-06-02 14:09 - 2014-06-02 14:09 - 00001106 _____ () C:\Users\Philipp\Desktop\Revo Uninstaller.lnk
2014-06-02 14:09 - 2014-06-02 14:09 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-01 20:30 - 2014-06-01 20:30 - 00000000 ____D () C:\Users\Philipp\Documents\Local Folders
2014-06-01 18:40 - 2014-05-28 20:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-01 14:21 - 2014-06-01 14:21 - 00000846 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Opera Software
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Opera Software
2014-06-01 11:16 - 2014-06-01 11:16 - 00000525 _____ () C:\Users\Philipp\Desktop\firewall.txt
2014-06-01 10:47 - 2014-06-01 10:47 - 00000822 _____ () C:\Users\Philipp\Desktop\checkup.txt
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-05-31 21:17 - 2014-05-31 21:17 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-05-31 21:15 - 2014-05-31 21:16 - 00854367 _____ () C:\Users\Philipp\Desktop\SecurityCheck.exe
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-31 07:30 - 2014-05-31 07:30 - 00000636 _____ () C:\Users\Philipp\Desktop\JRT.txt
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-31 07:20 - 2014-05-31 07:20 - 00003200 _____ () C:\Users\Philipp\Desktop\AdwCleaner[S0].txt
2014-05-31 07:16 - 2014-05-31 07:16 - 00001165 _____ () C:\Users\Philipp\Desktop\mbam.txt
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-05-30 07:40 - 00010180 _____ () C:\Users\Philipp\Desktop\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:17 - 00000000 ____D () C:\Qoobox
2014-05-30 07:37 - 2014-05-30 07:16 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:36 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-30 07:17 - 2014-05-30 07:16 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:14 - 2008-05-21 15:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-30 07:14 - 2008-05-21 15:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat
2014-05-30 07:14 - 2008-05-21 15:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 19:36 - 2014-05-28 21:02 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 14:01 - 2014-05-28 16:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:01 - 2014-05-28 14:02 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-27 23:15 - 2013-10-01 18:40 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Avg2014
2014-05-27 22:29 - 2014-05-27 21:55 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 22:28 - 2014-05-27 21:55 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-19 18:56 - 2014-03-31 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-05-15 19:38 - 2009-07-08 21:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 19:34 - 2013-08-14 18:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 19:33 - 2006-11-02 14:35 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-28 20:38 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-10 18:55 - 2011-08-10 16:32 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-10 18:55 - 2011-08-10 16:32 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-06 02:46 - 2014-05-15 19:28 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 02:21 - 2014-05-15 19:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 02:21 - 2014-05-15 19:28 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 01:32 - 2014-05-15 19:28 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 01:14 - 2014-05-15 19:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 01:14 - 2014-05-15 19:28 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

Some content of TEMP:
====================
C:\Users\Philipp\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-06-03 14:00

==================== End Of Log ============================

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-06-2014
Ran by Philipp at 2014-06-03 14:13:42
Running from C:\Users\Philipp\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}

==================== Installed Programs ======================

Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4592 - AVG Technologies)
AVG 2014 (Version: 14.0.3955 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4592 - AVG Technologies) Hidden
Call of Duty: Modern Warfare 3 - Dedicated Server (HKLM-x32\...\Steam App 42750) (Version:  - Infinity Ward - Sledgehammer Games)
Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version:  - Infinity Ward - Sledgehammer Games)
Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version:  - Infinity Ward - Sledgehammer Games)
CPUID CPU-Z 1.69 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version:  - )
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version:  - )
Crysis(R) (HKLM-x32\...\{000E79B7-E725-4F01-870A-C12942B7F8E4}) (Version: 1.20.0000 - Electronic Arts)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{349F73CA-653A-43A6-AE77-970B07D6EDA0}) (Version:  - Microsoft)
Dishonored (HKLM-x32\...\Steam App 205100) (Version: 1.0 - Bethesda Softworks)
eM Client (HKLM-x32\...\{356ECCC7-5485-44F4-B141-AA83DFE02E47}) (Version: 6.0.20320.0 - eM Client Inc.)
F1 2010 (HKLM-x32\...\GFWL_{434D0831-3E0C-4D03-A5D4-5E1000008400}) (Version: 1.0.0000.132 - Codemasters)
F1 2010 (x32 Version: 1.0.0000.132 - Codemasters) Hidden
F1 2010 (x32 Version: 1.0.0001.132 - Codemasters) Hidden
F1 2011 (HKLM-x32\...\GFWL_{434D0FA1-3E0C-4D03-A5D4-5E1000008100}) (Version: 1.0.0000.129 - Codemasters)
F1 2011 (x32 Version: 1.0.0000.129 - Codemasters) Hidden
F1 2011 (x32 Version: 1.0.0001.129 - Codemasters) Hidden
F1 2011 (x32 Version: 1.0.0002.129 - Codemasters) Hidden
F1 2013 (HKLM-x32\...\Steam App 223670) (Version:  - Codemasters Birmingham)
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
Flight Simulator X (HKLM-x32\...\RTMshadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version:  - )
Flight Simulator X Service Pack 1 (HKLM-x32\...\SP1shadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version:  - )
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Logitech Gaming Software 5.04 (HKLM\...\{8753DF4D-64B0-474E-9A97-0AB5585D9A53}) (Version: 5.04.110 - Logitech)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Flight Simulator X (x32 Version: 10.0.60905 - Microsoft Game Studios) Hidden
Microsoft Flight Simulator X: Acceleration (HKLM-x32\...\FlightSim_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version: 10.0.61637.0 - Microsoft Game Studios)
Microsoft Flight Simulator X: Acceleration (x32 Version: 10.0.61637.0 - Microsoft Game Studios) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla)
MSXML 4.0 SP2 (KB927978) (HKLM-x32\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser und SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
NVIDIA 3D Vision Controller-Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.82 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.82 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.140.952 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Systemsteuerung 331.82 (Version: 331.82 - NVIDIA Corporation) Hidden
NVIDIA Update 1.12.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.12.12 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.12.12 - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Opera Stable 22.0.1471.50 (HKLM-x32\...\Opera 22.0.1471.50) (Version: 22.0.1471.50 - Opera Software ASA)
Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Rapture3D 2.4.9 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5854 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version:  - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}) (Version: 8.0.0.35 - GRISOFT, s.r.o.)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}) (Version: 9.0.0.623 - AVG Technologies CZ, s.r.o.)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)

==================== Restore Points  =========================

10-06-2013 18:33:24 Geplanter Prüfpunkt
12-06-2013 16:45:29 Windows Update
10-07-2013 16:49:49 Windows Update
14-08-2013 16:46:50 Windows Update
28-08-2013 17:18:27 Windows Update
12-09-2013 16:48:58 Windows Update
21-09-2013 17:03:11 Removed Java(TM) 6 Update 3
21-09-2013 17:04:13 Removed Java(TM) 6 Update 5
21-09-2013 17:05:11 Removed Java(TM) 6 Update 3
21-09-2013 17:14:34 Removed Java(TM) 6 Update 3
21-09-2013 17:47:47 Removed Java(TM) 6 Update 3
21-09-2013 17:48:25 Removed Java(TM) 6 Update 3
21-09-2013 18:03:31 Wiederherstellungspunkt vor Fehlerhafte Patchregistrierungsschlüssel
21-09-2013 18:05:13 Removed Java(TM) 6 Update 37
01-10-2013 16:43:39 Installed AVG 2014
01-10-2013 16:45:01 Installed AVG 2014
10-10-2013 16:42:20 Windows Update
14-10-2013 14:32:24 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
14-10-2013 14:35:51 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
14-10-2013 14:36:40 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
14-10-2013 17:14:25 DirectX wurde installiert
15-10-2013 07:39:00 Installiert Far Cry 3
31-10-2013 17:28:40 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
31-10-2013 17:32:09 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
31-10-2013 17:33:11 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
13-11-2013 17:13:00 Windows Update
20-11-2013 17:38:53 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
20-11-2013 17:43:27 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
20-11-2013 17:44:33 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
20-11-2013 17:45:57 Windows Update
21-11-2013 14:54:28 Windows Update
13-12-2013 17:19:09 Windows Update
15-01-2014 17:18:41 Windows Update
13-02-2014 17:23:08 Windows Update
13-02-2014 17:56:42 Installed AVG 2014
12-03-2014 17:37:07 Windows Update
09-04-2014 16:21:10 Windows Update
18-04-2014 17:23:25 Geplanter Prüfpunkt
30-04-2014 17:12:36 Installed AVG 2014
02-05-2014 17:19:06 Windows Update
03-05-2014 19:08:49 Geplanter Prüfpunkt
08-05-2014 19:03:11 Geplanter Prüfpunkt
14-05-2014 19:39:12 Geplanter Prüfpunkt
15-05-2014 17:27:36 Windows Update
24-05-2014 17:49:47 Geplanter Prüfpunkt
25-05-2014 17:15:51 Geplanter Prüfpunkt
02-06-2014 12:14:11 Revo Uninstaller's restore point - Mozilla Firefox 29.0.1 (x86 de)
02-06-2014 12:18:19 Revo Uninstaller's restore point - Mozilla Firefox 29.0.1 (x86 de)
02-06-2014 13:02:30 Revo Uninstaller's restore point - Windows Media Player Firefox Plugin
02-06-2014 13:08:30 Revo Uninstaller's restore point - Adobe Shockwave Player
02-06-2014 13:25:31 Revo Uninstaller's restore point - Adobe Flash Player 13 Plugin
02-06-2014 17:52:33 Removed Logitech Webcam Software.
02-06-2014 17:54:13 Logitech Webcam Software v12.10.1110
02-06-2014 18:57:40 Installed eM Client
03-06-2014 12:05:28 Revo Uninstaller's restore point - Mozilla Maintenance Service

==================== Hosts content: ==========================

2006-11-02 14:34 - 2014-05-30 07:36 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {053E07D4-BF57-4777-AB86-2503FFB01905} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10] (Google Inc.)
Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {55BE9422-28E2-4700-A01E-1FCF1D40A620} - System32\Tasks\Opera scheduled Autoupdate 1401625260 => C:\Program Files (x86)\Opera\launcher.exe [2014-05-27] (Opera Software)
Task: {72539E3E-11DA-47CA-A173-02739CA95D54} - System32\Tasks\{DC3C511F-86D5-41EF-B546-2B08E434B6EF} => C:\Program Files (x86)\Skype\Phone\Skype.exe
Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {844584A5-E187-4702-BCCB-906B3C92C738} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {94810335-FB9F-4177-9D98-0DBBE92CD2F6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-02] (Adobe Systems Incorporated)
Task: {D272EFE4-B9B3-4F54-A2AA-0E2618E38D88} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10] (Google Inc.)
Task: {DE93CB4F-5D56-4AF7-8001-27E17F8F0803} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] ()
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe

==================== Loaded Modules (whitelisted) =============

2013-10-15 09:59 - 2013-10-15 09:59 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-06-03 14:04 - 2014-06-03 14:04 - 01396344 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
2009-07-10 15:19 - 2008-12-04 12:57 - 00146432 _____ () C:\Windows\SysWOW64\APOMngr.DLL
2014-06-03 14:04 - 2014-06-03 14:03 - 00957048 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: LogitechQuickCamRibbon => "C:\Programme\Logitech\Logitech WebCam Software\LWS.exe" /hide
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide

==================== Faulty Device Manager Devices =============

Name: NVIDIA High Definition Audio
Description: NVIDIA High Definition Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: NVIDIA
Service: NVHDA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/03/2014 01:54:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 09:01:32 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\eM Client\MailClient.exe . Error code = 0x80131f07

Error: (06/02/2014 09:01:32 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\eM Client\MailClient.exe . Error code = 0x80131f07

Error: (06/02/2014 07:57:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 06:57:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 06:37:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 04:19:54 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 03:36:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 03:11:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 02:26:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (06/03/2014 01:55:51 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/03/2014 01:54:23 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/02/2014 07:59:00 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/02/2014 07:57:15 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/02/2014 06:58:34 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/02/2014 06:57:24 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/02/2014 06:38:20 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/02/2014 06:37:40 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/02/2014 04:21:34 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/02/2014 04:19:55 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt


Microsoft Office Sessions:
=========================
Error: (06/03/2014 01:54:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 09:01:32 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\eM Client\MailClient.exe . Error code = 0x80131f07
C:\Program Files (x86)\eM Client\MailClient.exe

Error: (06/02/2014 09:01:32 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\eM Client\MailClient.exe . Error code = 0x80131f07
C:\Program Files (x86)\eM Client\MailClient.exe

Error: (06/02/2014 07:57:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 06:57:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 06:37:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 04:19:54 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 03:36:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 03:11:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2014 02:26:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
  Date: 2014-06-03 14:13:38.055
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-03 14:13:37.886
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-03 14:13:37.718
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-03 14:13:37.549
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-03 14:13:37.378
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-03 14:13:37.209
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-03 14:13:37.039
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-03 14:13:36.870
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-03 14:13:36.599
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-03 14:13:36.430
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 34%
Total physical RAM: 6134.17 MB
Available physical RAM: 4025 MB
Total Pagefile: 12451.88 MB
Available Pagefile: 10322.26 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:931.51 GB) (Free:610.82 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: 61491321)
Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Was bedeuten denn die vielen Errormeldungen? Schlimm?

Gruß
Gepetto

schrauber 04.06.2014 08:27

Das sind EInträge aus dem Eventviewer, da steht immer ne Menge drin.

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

ProxyServer: localhost:8080

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.




Windows-taste +R drücken, schreibe

CMD und drücke Enter. Nun tippst Du

sfc /scannow und drückst wieder Enter.

Gepetto1 04.06.2014 13:29

Hallo Schrauber,

ich hatte heute ein evtl. aufschlussreiches Gespräch mit der lieben Telek***.
Nach mehrmaligem Bitten habe sie nun doch mal mein Problem an die Diagnose-Abteilung weitergeleitet und einen Langzeittest gemacht.
Also hatte ich heute den Mitarbeiter am Telefon. Erst sagte er mir, dass alles ganz ok aussehen würde. Dann sagte er plötzlich:" Oh je, ach du lieber Himmel! Das sind ja 10stellige (leider konnte ich mir den Namen nicht merken) irgendwas Fehler. Einstellige Fehler wären schon nicht gut, aber zehnstellige Fehler?!? Da muss ein Techniker kommen. Da stimmt definitiv was mit ihrer Leitung nicht."

Ich habe ihn dann auch direkt gefragt, ob das mit meinem Rechner zu tun haben könnte. Er sagte dann:"Nein. Definitiv nicht." Soweit könne er gar nicht "gucken" und diese Fehler würden schon vorher auftreten. Es liege nicht am Rechner.

Sollte das vielleicht die Lösung meines Problems sein???

Nun hätte ich noch 2 Fragen an dich (hoffe es nervt nicht schon)

1. Soll ich mit deinem "fix" und dem Ausführen von sfc /scannow noch mal bis Freitag Nachmittag warten? (Da kommt der Techniker)

2. Was genau macht dein vorgeschlagener "fix" (ProxyServer: localhost:8080)? Siehst du aufgrund der logs noch Fehler auf meinem Rechner?

Vielen Dank nochmal

Gruß
Gepetto

P.S. Soll ich denn nun Combofix etc. wieder deinstallieren??

schrauber 05.06.2014 09:46

Den Fix kannste machen, der Proxy Eintrag gehört da definitiv nicht hin. Melde dich dann wieder wenn der Techniker da war :)

Gepetto1 05.06.2014 12:55

Hi,
fix ist gemacht.
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-06-2014
Ran by Philipp at 2014-06-04 18:45:58 Run:1
Running from C:\Users\Philipp\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
ProxyServer: localhost:8080
*****************

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully.

==== End of Fixlog ====

und ein frisches FRST log


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014
Ran by Philipp (administrator) on PHILIPP-PC on 05-06-2014 13:49:50
Running from C:\Users\Philipp\Desktop
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Creative Technology Ltd) C:\Windows\SysWOW64\CTxfispi.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [123400 2009-01-21] (Logitech Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA3FB10447E45CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  No File
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_37 - C:\Windows\SysWOW64\npdeployJava1.dll No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()

==================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-15] ()

==================== Drivers (Whitelisted) ====================

S4 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [154256 2007-08-10] (Promise Technology, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.)
S1 Beep; No ImagePath
S4 fttxr5_O; C:\Windows\system32\drivers\fttxr5_o.sys [230408 2007-10-25] (Promise Technology, Inc.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15680 2006-11-01] ()
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [160288 2008-04-07] (NVIDIA Corporation)
S3 SaiH0BAC; C:\Windows\System32\DRIVERS\SaiH0BAC.sys [176128 2007-07-13] (Saitek)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz131; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz131\cpuz_x64.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 lvpopf64; system32\DRIVERS\lvpopf64.sys [X]
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
S3 LVRS64; system32\DRIVERS\lvrs64.sys [X]
S3 LVUVC64; system32\DRIVERS\lvuvc64.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-05 13:49 - 2014-06-05 13:49 - 00008365 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-03 14:52 - 2014-06-03 14:52 - 00000884 _____ () C:\Users\Philipp\Desktop\eM Client.lnk
2014-06-03 14:04 - 2014-06-03 14:04 - 00003898 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401625260
2014-06-02 20:59 - 2014-06-04 20:28 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\eM Client
2014-06-02 20:58 - 2014-06-02 20:58 - 00000884 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2014-06-02 20:58 - 2014-06-02 20:58 - 00000000 ____D () C:\Program Files (x86)\eM Client
2014-06-02 20:56 - 2014-06-02 20:57 - 14995456 _____ () C:\Users\Philipp\Downloads\setup.msi
2014-06-02 15:31 - 2014-06-04 21:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-02 15:31 - 2014-06-02 15:31 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-02 15:31 - 2014-06-02 15:31 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-02 15:31 - 2014-06-02 15:31 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\Users\Philipp\Documents\Mail!!!!!
2014-06-02 14:09 - 2014-06-02 14:09 - 00001106 _____ () C:\Users\Philipp\Desktop\Revo Uninstaller.lnk
2014-06-02 14:09 - 2014-06-02 14:09 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-01 20:30 - 2014-06-01 20:30 - 00000000 ____D () C:\Users\Philipp\Documents\Local Folders
2014-06-01 14:21 - 2014-06-03 14:04 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-01 14:21 - 2014-06-01 14:21 - 00000846 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Opera Software
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Opera Software
2014-06-01 10:48 - 2014-06-03 14:12 - 00000000 ____D () C:\Users\Philipp\Desktop\FRST-OlderVersion
2014-06-01 10:47 - 2014-06-01 10:47 - 00000822 _____ () C:\Users\Philipp\Desktop\checkup.txt
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-05-31 21:17 - 2014-05-31 21:17 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-05-31 21:16 - 2014-05-31 21:15 - 00854367 _____ () C:\Users\Philipp\Desktop\SecurityCheck.exe
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-31 07:30 - 2014-05-31 07:30 - 00000636 _____ () C:\Users\Philipp\Desktop\JRT.txt
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-31 07:20 - 2014-05-31 07:20 - 00003200 _____ () C:\Users\Philipp\Desktop\AdwCleaner[S0].txt
2014-05-31 07:16 - 2014-05-31 07:16 - 00001165 _____ () C:\Users\Philipp\Desktop\mbam.txt
2014-05-30 07:40 - 2014-05-30 07:38 - 00010180 _____ () C:\Users\Philipp\Desktop\ComboFix.txt
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-06-05 13:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:17 - 2014-05-30 07:38 - 00000000 ____D () C:\Qoobox
2014-05-30 07:17 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-30 07:17 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-30 07:17 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-30 07:16 - 2014-05-30 07:37 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:16 - 2014-05-30 07:17 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-29 07:08 - 2014-06-05 13:49 - 00000000 ____D () C:\FRST
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 21:02 - 2014-06-03 14:12 - 02068992 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-05-28 21:02 - 2014-05-28 19:36 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 20:38 - 2014-06-01 18:40 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-28 20:38 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-28 20:38 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-28 19:37 - 2014-06-02 16:16 - 00000000 ____D () C:\AdwCleaner
2014-05-28 16:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:02 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 21:55 - 2014-05-27 22:29 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 21:55 - 2014-05-27 22:28 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 19:28 - 2014-05-06 02:46 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 19:28 - 2014-05-06 02:21 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 02:21 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 19:28 - 2014-05-06 01:32 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 19:28 - 2014-05-06 01:14 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 01:14 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 19:01 - 2014-03-25 18:30 - 12900864 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 19:01 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys

==================== One Month Modified Files and Folders =======

2014-06-05 13:50 - 2014-06-05 13:49 - 00008365 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-05 13:50 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-06-05 13:49 - 2014-05-29 07:08 - 00000000 ____D () C:\FRST
2014-06-05 13:47 - 2011-08-10 16:32 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-05 13:47 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-05 13:47 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-05 13:47 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-04 21:43 - 2009-07-10 14:09 - 01384335 _____ () C:\Windows\WindowsUpdate.log
2014-06-04 21:43 - 2006-11-02 17:42 - 00032510 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-04 21:26 - 2014-06-02 15:31 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-04 21:03 - 2012-05-31 17:52 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-04 20:59 - 2011-08-10 16:32 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-04 20:28 - 2014-06-02 20:59 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\eM Client
2014-06-03 19:15 - 2013-12-13 19:33 - 00001080 _____ () C:\Windows\system32\settingsbkup.sfm
2014-06-03 19:15 - 2013-12-13 19:33 - 00001080 _____ () C:\Windows\system32\settings.sfm
2014-06-03 18:43 - 2010-11-05 21:06 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-06-03 18:43 - 2010-11-05 21:03 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-06-03 18:43 - 2009-07-08 21:32 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-03 14:52 - 2014-06-03 14:52 - 00000884 _____ () C:\Users\Philipp\Desktop\eM Client.lnk
2014-06-03 14:12 - 2014-06-01 10:48 - 00000000 ____D () C:\Users\Philipp\Desktop\FRST-OlderVersion
2014-06-03 14:12 - 2014-05-28 21:02 - 02068992 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-06-03 14:04 - 2014-06-03 14:04 - 00003898 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401625260
2014-06-03 14:04 - 2014-06-01 14:21 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-02 20:58 - 2014-06-02 20:58 - 00000884 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2014-06-02 20:58 - 2014-06-02 20:58 - 00000000 ____D () C:\Program Files (x86)\eM Client
2014-06-02 20:57 - 2014-06-02 20:56 - 14995456 _____ () C:\Users\Philipp\Downloads\setup.msi
2014-06-02 19:56 - 2008-01-21 05:26 - 00846494 _____ () C:\Windows\PFRO.log
2014-06-02 19:54 - 2010-04-19 15:57 - 00008843 _____ () C:\Windows\system32\lvcoinst.log
2014-06-02 19:53 - 2010-04-19 15:56 - 00000000 ____D () C:\ProgramData\LogiShrd
2014-06-02 19:53 - 2009-07-22 15:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-06-02 16:16 - 2014-05-28 19:37 - 00000000 ____D () C:\AdwCleaner
2014-06-02 15:32 - 2009-07-10 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Adobe
2014-06-02 15:31 - 2014-06-02 15:31 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-02 15:31 - 2014-06-02 15:31 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-02 15:31 - 2014-06-02 15:31 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-02 15:31 - 2008-05-21 11:53 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\Users\Philipp\Documents\Mail!!!!!
2014-06-02 14:19 - 2009-07-10 20:41 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Mozilla
2014-06-02 14:09 - 2014-06-02 14:09 - 00001106 _____ () C:\Users\Philipp\Desktop\Revo Uninstaller.lnk
2014-06-02 14:09 - 2014-06-02 14:09 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-01 20:30 - 2014-06-01 20:30 - 00000000 ____D () C:\Users\Philipp\Documents\Local Folders
2014-06-01 18:40 - 2014-05-28 20:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-01 14:21 - 2014-06-01 14:21 - 00000846 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Opera Software
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Opera Software
2014-06-01 10:47 - 2014-06-01 10:47 - 00000822 _____ () C:\Users\Philipp\Desktop\checkup.txt
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-05-31 21:17 - 2014-05-31 21:17 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-05-31 21:15 - 2014-05-31 21:16 - 00854367 _____ () C:\Users\Philipp\Desktop\SecurityCheck.exe
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-31 07:30 - 2014-05-31 07:30 - 00000636 _____ () C:\Users\Philipp\Desktop\JRT.txt
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-31 07:20 - 2014-05-31 07:20 - 00003200 _____ () C:\Users\Philipp\Desktop\AdwCleaner[S0].txt
2014-05-31 07:16 - 2014-05-31 07:16 - 00001165 _____ () C:\Users\Philipp\Desktop\mbam.txt
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-05-30 07:40 - 00010180 _____ () C:\Users\Philipp\Desktop\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:17 - 00000000 ____D () C:\Qoobox
2014-05-30 07:37 - 2014-05-30 07:16 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:36 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-30 07:17 - 2014-05-30 07:16 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:14 - 2008-05-21 15:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-30 07:14 - 2008-05-21 15:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat
2014-05-30 07:14 - 2008-05-21 15:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 19:36 - 2014-05-28 21:02 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 14:01 - 2014-05-28 16:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:01 - 2014-05-28 14:02 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-27 23:15 - 2013-10-01 18:40 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Avg2014
2014-05-27 22:29 - 2014-05-27 21:55 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 22:28 - 2014-05-27 21:55 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-19 18:56 - 2014-03-31 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-05-15 19:38 - 2009-07-08 21:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 19:34 - 2013-08-14 18:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 19:33 - 2006-11-02 14:35 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-28 20:38 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-10 18:55 - 2011-08-10 16:32 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-10 18:55 - 2011-08-10 16:32 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-06 02:46 - 2014-05-15 19:28 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 02:21 - 2014-05-15 19:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 02:21 - 2014-05-15 19:28 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 01:32 - 2014-05-15 19:28 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 01:14 - 2014-05-15 19:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 01:14 - 2014-05-15 19:28 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

Some content of TEMP:
====================
C:\Users\Philipp\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-06-04 21:42

==================== End Of Log ============================

--- --- ---


Sieht denn mein Rechner soweit wieder "ok" aus?
Bin irgendwie noch ein bisschen beunruhigt.

Melde mich dann am Freitag wieder, wenn der Techniker da war.

Gruß
Gepetto

schrauber 05.06.2014 19:42

ohne extrem tiefer zu graben sieht das gut aus.

Gepetto1 06.06.2014 18:12

Hallo Schrauber,
also der Techniker war da. Leitung ist ok. So und jetzt steh ich da und bin noch mehr verzweifelt :(

Also ich schreibe dir noch einmal möglichst genau auf, was hier los ist.
Rechner verbindet sich mit dem Internet. Unter Netzwerk- und Freigabecenter steht:
Computer---Netzwerk---Internet.
Wenn ich auf "Satus von LAN-Verbindungen" und dort direkt auf "Diagnose" klicke schreibt er "es wurden keine Probleme mit der Netzwerkverbindung dieses Computers ermittelt".

Wenn ich auf der Taskleiste mit Rechtsklick auf die kleinen Monitorsymbole klicke und dort auf "Diagnose- und Reparatur" klicke schreibt er "Es wurde bestätigt, dass auf diesem Computer ein Netzwerkkonnektivitätsproblem besteht".

Wenn ich im "Netzwerk- und Freigabecenter" auf "Netzwerkverbindung verwalten" klicke, sehe ich dort "LAN Verbindung, Netzwerk, Realtek .... Aber dort taucht nicht der Router auf. Ist das richtig? Überhaupt taucht nirgens der Router auf. Wenn ich bei meinem Smart-TV auf Netzwerverbindung-Satus drücke, steht dort TV--Router--Internet. Aber am PC taucht nie irgendwo der Router auf. Ist da irgendwie was nicht richtig eingerichtet?

Ich habe den Eindruck, dass das alles erst seit dem Windows-Sicherheitsupdate vom 13.5.2014 (MS14-027) besteht. Kann mich aber auch täuschen.

Ich hänge dir jetzt noch mal verschiedene Sachen an. Ich weiß auch nicht mehr weiter.
Besonders der Auszug aus der windowsupdate.txt von heute (unter C:Windows) sieht für meine "keine Ahnung Augen" irgendwie seltsam aus. Aber wenn ich manuell auf Windows updates suchen klicke, scheint er ganz normal zu suchen. Findet halt keine updates. Gibt wahrscheinlich auch keine.

Code:

Microsoft Windows [Version 6.0.6002]
Copyright (c) 2006 Microsoft Corporation. Alle Rechte vorbehalten.

C:\Users\Philipp>ipconfig /all

Windows-IP-Konfiguration

  Hostname  . . . . . . . . . . . . : Philipp-PC
  Primäres DNS-Suffix . . . . . . . :
  Knotentyp . . . . . . . . . . . . : Hybrid
  IP-Routing aktiviert  . . . . . . : Nein
  WINS-Proxy aktiviert  . . . . . . : Nein
  DNS-Suffixsuchliste . . . . . . . : Speedport_W_502V_Typ_A

Ethernet-Adapter LAN-Verbindung:

  Verbindungsspezifisches DNS-Suffix: Speedport_W_502V_Typ_A
  Beschreibung. . . . . . . . . . . : Realtek RTL8168C(P)/8111C(P) Family PCI-E
 Gigabit Ethernet NIC (NDIS 6.0)
  Physikalische Adresse . . . . . . : 00-26-18-24-A4-C7
  DHCP aktiviert. . . . . . . . . . : Ja
  Autokonfiguration aktiviert . . . : Ja
  IPv4-Adresse  . . . . . . . . . . : 192.168.2.104(Bevorzugt)
  Subnetzmaske  . . . . . . . . . . : 255.255.255.0
  Lease erhalten. . . . . . . . . . : Freitag, 6. Juni 2014 18:40:37
  Lease läuft ab. . . . . . . . . . : Dienstag, 10. Juni 2014 18:40:37
  Standardgateway . . . . . . . . . : 192.168.2.1
  DHCP-Server . . . . . . . . . . . : 192.168.2.1
  DNS-Server  . . . . . . . . . . . : 192.168.2.1
  NetBIOS über TCP/IP . . . . . . . : Aktiviert

Tunneladapter LAN-Verbindung* 6:

  Verbindungsspezifisches DNS-Suffix:
  Beschreibung. . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
  Physikalische Adresse . . . . . . : 02-00-54-55-4E-01
  DHCP aktiviert. . . . . . . . . . : Nein
  Autokonfiguration aktiviert . . . : Ja
  IPv6-Adresse. . . . . . . . . . . : 2001:0:5ef5:79fb:2c5f:e9e:3f57:fd97(Bevor
zugt)
  Verbindungslokale IPv6-Adresse  . : fe80::2c5f:e9e:3f57:fd97%11(Bevorzugt)
  Standardgateway . . . . . . . . . : ::
  NetBIOS über TCP/IP . . . . . . . : Deaktiviert

Tunneladapter LAN-Verbindung* 7:

  Medienstatus. . . . . . . . . . . : Medium getrennt
  Verbindungsspezifisches DNS-Suffix: Speedport_W_502V_Typ_A
  Beschreibung. . . . . . . . . . . : isatap.Speedport_W_502V_Typ_A
  Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0
  DHCP aktiviert. . . . . . . . . . : Nein
  Autokonfiguration aktiviert . . . : Ja

C:\Users\Philipp>

ipv6 habe ich deaktiviert. Habe den Eindruck, dass es dadurch stabiler läuft.

Code:

2014-06-06        16:00:36:952        1376        10d8        Misc        ===========  Logging initialized (build: 7.6.7600.256, tz: +0200)  ===========
2014-06-06        16:00:37:404        1376        10d8        Misc          = Process: C:\Windows\system32\svchost.exe
2014-06-06        16:00:37:747        1376        10d8        Misc          = Module: c:\windows\system32\wuaueng.dll
2014-06-06        16:00:36:952        1376        10d8        Service        *************
2014-06-06        16:00:38:184        1376        10d8        Service        ** START **  Service: Service startup
2014-06-06        16:00:38:262        1376        10d8        Service        *********
2014-06-06        16:00:38:434        1376        10d8        Agent          * WU client version 7.6.7600.256
2014-06-06        16:00:38:512        1376        10d8        Agent          * Base directory: C:\Windows\SoftwareDistribution
2014-06-06        16:00:38:590        1376        10d8        Agent          * Access type: No proxy
2014-06-06        16:00:38:668        1376        10d8        Agent          * Network state: Connected
2014-06-06        16:01:25:480        1376        10d8        Report        CWERReporter::Init succeeded
2014-06-06        16:01:25:480        1376        10d8        Agent        ***********  Agent: Initializing Windows Update Agent  ***********
2014-06-06        16:01:25:480        1376        10d8        Agent        ***********  Agent: Initializing global settings cache  ***********
2014-06-06        16:01:25:480        1376        10d8        Agent          * WSUS server: <NULL>
2014-06-06        16:01:25:480        1376        10d8        Agent          * WSUS status server: <NULL>
2014-06-06        16:01:25:480        1376        10d8        Agent          * Target group: (Unassigned Computers)
2014-06-06        16:01:25:480        1376        10d8        Agent          * Windows Update access disabled: No
2014-06-06        16:01:25:496        1376        10d8        DnldMgr        Download manager restoring 0 downloads
2014-06-06        16:01:25:512        1376        10d8        AU        ###########  AU: Initializing Automatic Updates  ###########
2014-06-06        16:01:25:512        1376        10d8        AU        AU setting next detection timeout to 2014-06-06 14:01:25
2014-06-06        16:01:25:512        1376        10d8        AU        AU setting next sqm report timeout to 2014-06-06 14:01:25
2014-06-06        16:01:25:512        1376        10d8        AU          # Approval type: Scheduled (User preference)
2014-06-06        16:01:25:512        1376        10d8        AU          # Scheduled install day/time: Every day at 3:00
2014-06-06        16:01:25:512        1376        10d8        AU          # Auto-install minor updates: Yes (User preference)
2014-06-06        16:01:25:839        1376        10d8        AU        Initializing featured updates
2014-06-06        16:01:25:839        1376        10d8        AU        Found 0 cached featured updates
2014-06-06        16:01:25:839        1376        10d8        AU        AU finished delayed initialization
2014-06-06        16:01:26:182        1376        10d8        Report        ***********  Report: Initializing static reporting data  ***********
2014-06-06        16:01:26:182        1376        10d8        Report          * OS Version = 6.0.6002.2.0.66304
2014-06-06        16:01:26:182        1376        10d8        Report          * OS Product Type = 0x00000003
2014-06-06        16:01:26:245        1376        10d8        Report          * Computer Brand = System manufacturer
2014-06-06        16:01:26:245        1376        10d8        Report          * Computer Model = System Product Name
2014-06-06        16:01:26:245        1376        10d8        Report          * Bios Revision = 0307 
2014-06-06        16:01:26:245        1376        10d8        Report          * Bios Name = BIOS Date: 04/28/09 14:47:25 Ver: 08.00.15
2014-06-06        16:01:26:245        1376        10d8        Report          * Bios Release Date = 2009-04-28T00:00:00
2014-06-06        16:01:26:245        1376        10d8        Report          * Locale ID = 1031
2014-06-06        16:01:26:276        1376        10d8        AU        AU setting next sqm report timeout to 2014-06-07 14:01:26
2014-06-06        16:01:26:276        1376        10d8        AU        #############
2014-06-06        16:01:26:276        1376        10d8        AU        ## START ##  AU: Search for updates
2014-06-06        16:01:26:276        1376        10d8        AU        #########
2014-06-06        16:01:26:276        1376        10d8        AU        <<## SUBMITTED ## AU: Search for updates [CallId = {E9714807-3690-46FF-BA7A-6066C7D45E06}]
2014-06-06        16:01:29:006        1376        129c        Agent        *************
2014-06-06        16:01:29:006        1376        129c        Agent        ** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
2014-06-06        16:01:29:006        1376        129c        Agent        *********
2014-06-06        16:01:29:006        1376        129c        Agent          * Online = Yes; Ignore download priority = No
2014-06-06        16:01:29:006        1376        129c        Agent          * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
2014-06-06        16:01:29:006        1376        129c        Agent          * ServiceID = {7971F918-A847-4430-9279-4A52D1EFE18D} Third party service
2014-06-06        16:01:29:006        1376        129c        Agent          * Search Scope = {Machine}
2014-06-06        16:01:29:022        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:01:29:053        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:29:256        1376        129c        Misc        WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190194
2014-06-06        16:01:29:256        1376        129c        Misc        WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190194
2014-06-06        16:01:29:256        1376        129c        Misc        WARNING: DownloadFileInternal failed for hxxp://download.windowsupdate.com/v9/1/windowsupdate/redir/muv4wuredir.cab: error 0x80190194
2014-06-06        16:01:29:256        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:01:29:271        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:29:474        1376        129c        Misc        WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190194
2014-06-06        16:01:29:474        1376        129c        Misc        WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190194
2014-06-06        16:01:29:474        1376        129c        Misc        WARNING: DownloadFileInternal failed for hxxp://download.microsoft.com/v9/1/windowsupdate/redir/muv4wuredir.cab: error 0x80190194
2014-06-06        16:01:29:474        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:01:29:474        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:29:911        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:01:29:911        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:29:942        1376        129c        Agent        Checking for updated auth cab for service 7971f918-a847-4430-9279-4a52d1efe18d at hxxp://ds.download.windowsupdate.com/v10/1/microsoftupdate/redir/muauth.cab
2014-06-06        16:01:29:942        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\AuthCabs\authcab.cab:
2014-06-06        16:01:29:942        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:30:067        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\AuthCabs\authcab.cab:
2014-06-06        16:01:30:067        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:30:067        1376        129c        Setup        Checking for agent SelfUpdate
2014-06-06        16:01:30:067        1376        129c        Setup        Client version: Core: 7.6.7600.256  Aux: 7.6.7600.256
2014-06-06        16:01:30:082        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:01:30:082        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:30:270        1376        129c        Misc        WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190194
2014-06-06        16:01:30:270        1376        129c        Misc        WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190194
2014-06-06        16:01:30:270        1376        129c        Misc        WARNING: DownloadFileInternal failed for hxxp://download.windowsupdate.com/v9/1/windowsupdate/redir/muv4wuredir.cab: error 0x80190194
2014-06-06        16:01:30:270        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:01:30:270        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:30:441        1376        129c        Misc        WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190194
2014-06-06        16:01:30:441        1376        129c        Misc        WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190194
2014-06-06        16:01:30:441        1376        129c        Misc        WARNING: DownloadFileInternal failed for hxxp://download.microsoft.com/v9/1/windowsupdate/redir/muv4wuredir.cab: error 0x80190194
2014-06-06        16:01:30:441        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:01:30:457        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:30:644        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:01:30:644        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:30:644        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-06-06        16:01:30:675        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:31:081        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-06-06        16:01:31:081        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:31:112        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-06-06        16:01:31:128        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:31:206        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-06-06        16:01:31:221        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:31:268        1376        129c        Setup        Determining whether a new setup handler needs to be downloaded
2014-06-06        16:01:31:268        1376        129c        Setup        SelfUpdate handler is not found.  It will be downloaded
2014-06-06        16:01:31:268        1376        129c        Setup        Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-06        16:01:31:268        1376        129c        Setup        Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-06        16:01:31:268        1376        129c        Setup        Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-06        16:01:31:284        1376        129c        Setup        Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-06        16:01:31:284        1376        129c        Setup        Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-06        16:01:31:315        1376        129c        Setup        Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-06        16:01:31:315        1376        129c        Setup        SelfUpdate check completed.  SelfUpdate is NOT required.
2014-06-06        16:01:47:539        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\muredir.cab:
2014-06-06        16:01:47:554        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:47:586        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\muredir.cab:
2014-06-06        16:01:47:601        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:01:47:601        1376        129c        PT        +++++++++++  PT: Synchronizing server updates  +++++++++++
2014-06-06        16:01:47:601        1376        129c        PT          + ServiceId = {7971F918-A847-4430-9279-4A52D1EFE18D}, Server URL = https://update.microsoft.com/v6/ClientWebService/client.asmx
2014-06-06        16:01:48:444        1376        10d8        AU        Forced install timer expired for scheduled install
2014-06-06        16:01:48:444        1376        10d8        AU        UpdateDownloadProperties: 0 download(s) are still in progress.
2014-06-06        16:01:48:444        1376        10d8        AU        Setting AU scheduled install time to 2014-06-07 01:00:00
2014-06-06        16:01:48:568        1376        129c        Agent        WARNING: Failed to evaluate Installed rule, updateId = {07AEE973-703C-4F27-83F1-3E764D9ED2C7}.202, hr = 80041010
2014-06-06        16:02:49:335        1376        129c        Driver        Matched driver to device PCI\VEN_1102&DEV_0005&SUBSYS_60071102&REV_00
2014-06-06        16:02:49:335        1376        129c        Driver        Status: 0x180200a, ProblemNumber: 00000000
2014-06-06        16:02:49:335        1376        129c        Driver        Matched driver to device PCI\VEN_10EC&DEV_8168&SUBSYS_82C61043&REV_02
2014-06-06        16:02:49:335        1376        129c        Driver        Status: 0x180200a, ProblemNumber: 00000000
2014-06-06        16:03:18:097        1376        129c        Handler        FATAL: UH: 0x80070490: EvaluateApplicability failed in CCbs::EvaluateApplicability
2014-06-06        16:03:25:759        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\muredir.cab:
2014-06-06        16:03:25:766        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:03:25:875        1376        129c        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\muredir.cab:
2014-06-06        16:03:25:879        1376        129c        Misc        Microsoft signed: Yes
2014-06-06        16:03:25:883        1376        129c        PT        +++++++++++  PT: Synchronizing extended update info  +++++++++++
2014-06-06        16:03:25:883        1376        129c        PT          + ServiceId = {7971F918-A847-4430-9279-4A52D1EFE18D}, Server URL = https://update.microsoft.com/v6/ClientWebService/client.asmx
2014-06-06        16:03:40:212        1376        129c        Agent          * Added update {7F7BF126-E759-4D5E-A1FE-8145A56C2436}.100 to search result
2014-06-06        16:03:40:213        1376        129c        Agent          * Added update {087B85DE-3627-4A1F-BF1B-E6D3BCEA03F0}.101 to search result
2014-06-06        16:03:40:213        1376        129c        Agent        Update {FF434E78-8B6A-4860-BD0F-4AC472E29063}.101 is pruned out due to potential supersedence
2014-06-06        16:03:40:213        1376        129c        Agent        Update {566B95D4-66F6-47BA-8953-02CAEA29022C}.101 is pruned out due to potential supersedence
2014-06-06        16:03:40:213        1376        129c        Agent        Update {B932D155-4C7F-4CBC-8527-D5DF17B0A220}.101 is pruned out due to potential supersedence
2014-06-06        16:03:40:213        1376        129c        Agent        Update {B6C0F3C6-C368-4A76-A3BF-BE068C7358F0}.101 is pruned out due to potential supersedence
2014-06-06        16:03:40:213        1376        129c        Agent          * Added update {AAE5E2C7-3498-4F43-AF66-AEC06A59713F}.102 to search result
2014-06-06        16:03:40:213        1376        129c        Agent          * Added update {44D99B03-8E84-4D32-A3A7-74E062CDF914}.103 to search result
2014-06-06        16:03:40:213        1376        129c        Agent          * Added update {400D135F-03E5-45B5-A44B-16EF70722C4F}.201 to search result
2014-06-06        16:03:40:213        1376        129c        Agent          * Found 5 updates and 80 categories in search; evaluated appl. rules of 2591 out of 3944 deployed entities
2014-06-06        16:03:40:793        1376        129c        Agent        *********
2014-06-06        16:03:40:793        1376        129c        Agent        **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
2014-06-06        16:03:40:793        1376        129c        Agent        *************
2014-06-06        16:03:40:809        1376        1230        AU        >>##  RESUMED  ## AU: Search for updates [CallId = {E9714807-3690-46FF-BA7A-6066C7D45E06}]
2014-06-06        16:03:40:809        1376        1230        AU          # 5 updates detected
2014-06-06        16:03:40:810        1376        1230        AU        #########
2014-06-06        16:03:40:810        1376        1230        AU        ##  END  ##  AU: Search for updates [CallId = {E9714807-3690-46FF-BA7A-6066C7D45E06}]
2014-06-06        16:03:40:810        1376        1230        AU        #############
2014-06-06        16:03:40:810        1376        1230        AU        #############
2014-06-06        16:03:40:810        1376        1230        AU        ## START ##  AU: Refresh featured updates info
2014-06-06        16:03:40:810        1376        1230        AU        #########
2014-06-06        16:03:40:810        1376        1230        AU        No featured updates available.
2014-06-06        16:03:40:810        1376        1230        AU        #########
2014-06-06        16:03:40:810        1376        1230        AU        ##  END  ##  AU: Refresh featured updates info
2014-06-06        16:03:40:810        1376        1230        AU        #############
2014-06-06        16:03:40:810        1376        1230        AU        AU setting next detection timeout to 2014-06-07 11:22:33
2014-06-06        16:03:40:811        1376        1230        AU        Setting AU scheduled install time to 2014-06-07 01:00:00
2014-06-06        16:03:40:813        1376        129c        Report        CWERReporter finishing event handling. (00000000)
2014-06-06        16:03:45:836        1376        129c        Report        REPORT EVENT: {B5F79A5D-F53C-4433-A60A-263E2DCF32DA}        2014-06-06 16:03:40:791+0200        1        147        101        {00000000-0000-0000-0000-000000000000}        0        0        AutomaticUpdates        Success        Software Synchronization        Windows Update Client successfully detected 5 updates.
2014-06-06        16:03:45:836        1376        129c        Report        CWERReporter finishing event handling. (00000000)
2014-06-06        16:39:23:842        1376        11dc        AU        Getting featured update notifications.  fIncludeDismissed = true
2014-06-06        16:39:23:843        1376        11dc        AU        No featured updates available.
2014-06-06        16:39:31:037        1376        11dc        AU        Triggering AU detection through DetectNow API
2014-06-06        16:39:31:037        1376        11dc        AU        Triggering Online detection (interactive)
2014-06-06        16:39:31:038        1376        10d8        AU        #############
2014-06-06        16:39:31:038        1376        10d8        AU        ## START ##  AU: Search for updates
2014-06-06        16:39:31:038        1376        10d8        AU        #########
2014-06-06        16:39:31:040        1376        10d8        AU        <<## SUBMITTED ## AU: Search for updates [CallId = {FB5CE1D8-BB8A-405D-96AD-B6DB6979469A}]
2014-06-06        16:39:31:041        1376        ee0        Agent        *************
2014-06-06        16:39:31:041        1376        ee0        Agent        ** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
2014-06-06        16:39:31:041        1376        ee0        Agent        *********
2014-06-06        16:39:31:041        1376        ee0        Agent          * Online = Yes; Ignore download priority = No
2014-06-06        16:39:31:041        1376        ee0        Agent          * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
2014-06-06        16:39:31:041        1376        ee0        Agent          * ServiceID = {7971F918-A847-4430-9279-4A52D1EFE18D} Third party service
2014-06-06        16:39:31:041        1376        ee0        Agent          * Search Scope = {Machine}
2014-06-06        16:39:31:044        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:39:31:052        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:31:243        1376        ee0        Misc        WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190194
2014-06-06        16:39:31:243        1376        ee0        Misc        WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190194
2014-06-06        16:39:31:243        1376        ee0        Misc        WARNING: DownloadFileInternal failed for hxxp://download.windowsupdate.com/v9/1/windowsupdate/redir/muv4wuredir.cab: error 0x80190194
2014-06-06        16:39:31:243        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:39:31:247        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:31:436        1376        ee0        Misc        WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190194
2014-06-06        16:39:31:436        1376        ee0        Misc        WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190194
2014-06-06        16:39:31:436        1376        ee0        Misc        WARNING: DownloadFileInternal failed for hxxp://download.microsoft.com/v9/1/windowsupdate/redir/muv4wuredir.cab: error 0x80190194
2014-06-06        16:39:31:437        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:39:31:441        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:31:855        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:39:31:860        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:31:868        1376        ee0        Agent        Checking for updated auth cab for service 7971f918-a847-4430-9279-4a52d1efe18d at hxxp://ds.download.windowsupdate.com/v10/1/microsoftupdate/redir/muauth.cab
2014-06-06        16:39:31:868        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\AuthCabs\authcab.cab:
2014-06-06        16:39:31:873        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:32:267        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\AuthCabs\authcab.cab:
2014-06-06        16:39:32:271        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:32:271        1376        ee0        Setup        Checking for agent SelfUpdate
2014-06-06        16:39:32:272        1376        ee0        Setup        Client version: Core: 7.6.7600.256  Aux: 7.6.7600.256
2014-06-06        16:39:32:275        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:39:32:279        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:32:423        1376        ee0        Misc        WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190194
2014-06-06        16:39:32:423        1376        ee0        Misc        WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190194
2014-06-06        16:39:32:423        1376        ee0        Misc        WARNING: DownloadFileInternal failed for hxxp://download.windowsupdate.com/v9/1/windowsupdate/redir/muv4wuredir.cab: error 0x80190194
2014-06-06        16:39:32:424        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:39:32:428        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:32:569        1376        ee0        Misc        WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190194
2014-06-06        16:39:32:569        1376        ee0        Misc        WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190194
2014-06-06        16:39:32:570        1376        ee0        Misc        WARNING: DownloadFileInternal failed for hxxp://download.microsoft.com/v9/1/windowsupdate/redir/muv4wuredir.cab: error 0x80190194
2014-06-06        16:39:32:570        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:39:32:574        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:32:765        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2014-06-06        16:39:32:769        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:32:774        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-06-06        16:39:32:778        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:33:279        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-06-06        16:39:33:284        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:33:286        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-06-06        16:39:33:290        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:33:400        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-06-06        16:39:33:405        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:33:422        1376        ee0        Setup        Determining whether a new setup handler needs to be downloaded
2014-06-06        16:39:33:422        1376        ee0        Setup        SelfUpdate handler is not found.  It will be downloaded
2014-06-06        16:39:33:422        1376        ee0        Setup        Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-06        16:39:33:505        1376        ee0        Setup        Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-06        16:39:33:506        1376        ee0        Setup        Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-06        16:39:33:528        1376        ee0        Setup        Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-06        16:39:33:529        1376        ee0        Setup        Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-06        16:39:33:564        1376        ee0        Setup        Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-06        16:39:33:564        1376        ee0        Setup        SelfUpdate check completed.  SelfUpdate is NOT required.
2014-06-06        16:39:49:248        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\muredir.cab:
2014-06-06        16:39:49:253        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:49:301        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\muredir.cab:
2014-06-06        16:39:49:305        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:39:49:310        1376        ee0        PT        +++++++++++  PT: Synchronizing server updates  +++++++++++
2014-06-06        16:39:49:310        1376        ee0        PT          + ServiceId = {7971F918-A847-4430-9279-4A52D1EFE18D}, Server URL = https://update.microsoft.com/v6/ClientWebService/client.asmx
2014-06-06        16:39:50:343        1376        ee0        Agent        WARNING: Failed to evaluate Installed rule, updateId = {07AEE973-703C-4F27-83F1-3E764D9ED2C7}.202, hr = 80041010
2014-06-06        16:40:20:484        1376        ee0        Driver        Matched driver to device PCI\VEN_1102&DEV_0005&SUBSYS_60071102&REV_00
2014-06-06        16:40:20:484        1376        ee0        Driver        Status: 0x180200a, ProblemNumber: 00000000
2014-06-06        16:40:20:484        1376        ee0        Driver        Matched driver to device PCI\VEN_10EC&DEV_8168&SUBSYS_82C61043&REV_02
2014-06-06        16:40:20:484        1376        ee0        Driver        Status: 0x180200a, ProblemNumber: 00000000
2014-06-06        16:40:25:543        1376        ee0        Handler        FATAL: UH: 0x80070490: EvaluateApplicability failed in CCbs::EvaluateApplicability
2014-06-06        16:40:30:484        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\muredir.cab:
2014-06-06        16:40:30:489        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:40:30:534        1376        ee0        Misc        Validating signature for C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\muredir.cab:
2014-06-06        16:40:30:538        1376        ee0        Misc        Microsoft signed: Yes
2014-06-06        16:40:30:543        1376        ee0        PT        +++++++++++  PT: Synchronizing extended update info  +++++++++++
2014-06-06        16:40:30:543        1376        ee0        PT          + ServiceId = {7971F918-A847-4430-9279-4A52D1EFE18D}, Server URL = https://update.microsoft.com/v6/ClientWebService/client.asmx
2014-06-06        16:40:45:246        1376        ee0        Agent          * Added update {7F7BF126-E759-4D5E-A1FE-8145A56C2436}.100 to search result
2014-06-06        16:40:45:246        1376        ee0        Agent          * Added update {087B85DE-3627-4A1F-BF1B-E6D3BCEA03F0}.101 to search result
2014-06-06        16:40:45:246        1376        ee0        Agent        Update {FF434E78-8B6A-4860-BD0F-4AC472E29063}.101 is pruned out due to potential supersedence
2014-06-06        16:40:45:246        1376        ee0        Agent        Update {566B95D4-66F6-47BA-8953-02CAEA29022C}.101 is pruned out due to potential supersedence
2014-06-06        16:40:45:246        1376        ee0        Agent        Update {B932D155-4C7F-4CBC-8527-D5DF17B0A220}.101 is pruned out due to potential supersedence
2014-06-06        16:40:45:246        1376        ee0        Agent        Update {B6C0F3C6-C368-4A76-A3BF-BE068C7358F0}.101 is pruned out due to potential supersedence
2014-06-06        16:40:45:246        1376        ee0        Agent          * Added update {AAE5E2C7-3498-4F43-AF66-AEC06A59713F}.102 to search result
2014-06-06        16:40:45:246        1376        ee0        Agent          * Added update {44D99B03-8E84-4D32-A3A7-74E062CDF914}.103 to search result
2014-06-06        16:40:45:246        1376        ee0        Agent          * Added update {400D135F-03E5-45B5-A44B-16EF70722C4F}.201 to search result
2014-06-06        16:40:45:246        1376        ee0        Agent          * Found 5 updates and 80 categories in search; evaluated appl. rules of 2591 out of 3944 deployed entities
2014-06-06        16:40:45:860        1376        ee0        Agent        *********
2014-06-06        16:40:45:860        1376        ee0        Agent        **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
2014-06-06        16:40:45:860        1376        ee0        Agent        *************
2014-06-06        16:40:45:879        1376        10f4        AU        >>##  RESUMED  ## AU: Search for updates [CallId = {FB5CE1D8-BB8A-405D-96AD-B6DB6979469A}]
2014-06-06        16:40:45:879        1376        10f4        AU          # 5 updates detected
2014-06-06        16:40:45:879        1376        10f4        AU        #########
2014-06-06        16:40:45:879        1376        10f4        AU        ##  END  ##  AU: Search for updates [CallId = {FB5CE1D8-BB8A-405D-96AD-B6DB6979469A}]
2014-06-06        16:40:45:879        1376        10f4        AU        #############
2014-06-06        16:40:45:880        1376        10f4        AU        #############
2014-06-06        16:40:45:880        1376        10f4        AU        ## START ##  AU: Refresh featured updates info
2014-06-06        16:40:45:880        1376        10f4        AU        #########
2014-06-06        16:40:45:880        1376        10f4        AU        No featured updates available.
2014-06-06        16:40:45:880        1376        10f4        AU        #########
2014-06-06        16:40:45:880        1376        10f4        AU        ##  END  ##  AU: Refresh featured updates info
2014-06-06        16:40:45:880        1376        10f4        AU        #############
2014-06-06        16:40:45:880        1376        10f4        AU        No featured updates notifications to show
2014-06-06        16:40:45:880        1376        10f4        AU        AU setting next detection timeout to 2014-06-07 09:54:45
2014-06-06        16:40:45:880        1376        10f4        AU        Setting AU scheduled install time to 2014-06-07 01:00:00
2014-06-06        16:40:45:928        1376        11dc        AU        Getting featured update notifications.  fIncludeDismissed = true
2014-06-06        16:40:45:928        1376        11dc        AU        No featured updates available.
2014-06-06        16:40:50:859        1376        ee0        Report        REPORT EVENT: {5CD1B538-27C7-481B-9744-E0AF5048FC52}        2014-06-06 16:40:45:859+0200        1        147        101        {00000000-0000-0000-0000-000000000000}        0        0        AutomaticUpdates        Success        Software Synchronization        Windows Update Client successfully detected 5 updates.
2014-06-06        16:40:50:859        1376        ee0        Report        CWERReporter finishing event handling. (00000000)

Besonders diese ganzen "Warning" Meldungen finde ich schon seltsam, oder??????
Und diese Meldungen finde ich auch seltsam: 2014-06-06 16:39:33:422 1376 ee0 Setup SelfUpdate handler is not found. It will be downloaded
2014-06-06 16:39:33:422 1376 ee0 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-06 16:39:33:505 1376 ee0 Setup Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-06 16:39:33:506 1376 ee0 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-06 16:39:33:528 1376 ee0 Setup Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-06 16:39:33:529 1376 ee0 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-06 16:39:33:564 1376 ee0 Setup Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-06 16:39:33:564 1376 ee0 Setup SelfUpdate check completed. SelfUpdate is NOT required.

Und diese Meldungen stehen aunfassbar häufig in der PFRO.TXT unter C:Windows. Hier nur ein kleiner Auszug
Code:

6/1/2014 13:48:19 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/1/2014 13:48:19 - 3 Successful PFRO operations

6/1/2014 13:58:51 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/1/2014 13:58:51 - 3 Successful PFRO operations

6/1/2014 15:42:27 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/1/2014 15:42:27 - 3 Successful PFRO operations

6/1/2014 18:35:43 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/1/2014 18:35:43 - 3 Successful PFRO operations

6/2/2014 14:8:5 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/2/2014 14:8:5 - 3 Successful PFRO operations

6/2/2014 14:25:29 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/2/2014 14:25:30 - 5 Successful PFRO operations

6/2/2014 15:11:19 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/2/2014 15:11:19 - 3 Successful PFRO operations

6/2/2014 15:35:53 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/2/2014 15:35:53 - 3 Successful PFRO operations

6/2/2014 16:18:57 - PFRO Error: \??\C:\ProgramData\DataMngr\stats.cfg, |delete operation|, 0xc000003a
6/2/2014 16:18:57 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/2/2014 16:18:57 - 3 Successful PFRO operations

6/2/2014 18:36:24 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/2/2014 18:36:25 - 3 Successful PFRO operations

6/2/2014 18:56:1 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/2/2014 18:56:1 - 3 Successful PFRO operations

6/2/2014 19:56:40 - PFRO Error: \??\C:\Windows\TEMP\logishrd\, |delete operation|, 0xc0000101
6/2/2014 19:56:40 - 3 Successful PFRO operations

Das sieht mir aber sehr sehr seltsam aus!!!!!! Oder??

und diesen Eintrag habe ich im Routermenu heute unter "Systemmeldungen" gefunden
Code:

06.06.2014 16:14:41 **TCP FIN Scan** 192.168.2.104, 57633->>
Was weiß ich, was mit dem Rechner hier los ist....
Oder sollte mich das alles einfach nicht stören? Weil wie gesagt ins Internet komme ich ja eigentlich ganz normal.

Gruß
Gepetto

schrauber 07.06.2014 11:24

Zitat:

Aber dort taucht nicht der Router auf. Ist das richtig?
korrekt.
Zitat:

Überhaupt taucht nirgens der Router auf.
normal.

JEtzt mal ne Frage:
Hast Du irgendwelche richtigen bemerkbaren Probleme oder nur diese Sachen die die stören weil du es nicht besser weißt?

Gepetto1 07.06.2014 12:43

Hallo Schrauber,
also ich habe noch einmal alles ganz genau angeschaut.
Und zwar kurz vor meinem ersten post bei euch hat AVG bei einem kompletten Computerscan folgendes gefunden und gelöscht.

Bedrohung: Beschädigte ausführbare Datei
C:\.....\Temporary Internet Files\Content.IE5\YUMWSO2V\public-update-13586[1]

Ich habe herausgefunden, dass dies mit einem plugin von picasa zu tun haben muss.

Nun habe ich im Ordner "Temporary Internet Files" folgende ASPX Datei gefunden
Code:

hxxp://info.music.metaservices.microsoft.com/cdinfo/GetMDRCDPOSTURL.aspx?locale=407&geoid=5e&version=11.0.6002.18311&userlocale=407&requestID=E2CDB820-A546-43DB-B541-3C84664EA3BE
Wenn ich nun diese Datei z.B. kopieren möchte und sie auf dem Desktop einfügen möchte, steht dort folgendes: Das Element befindet sich nicht mehr in C:\.....\Temporary Internet Files\Content.IE5\YUMWSO2V\public-update-13586[1].
Eben genau dort, welches AVG gelöscht und als Bedrohung erkannt hat.
Kannst Du mir denn sagen, ob diese GetMDRCDPOSTURL.aspx harmlos ist??

Des weiteren habe ich bei euch, glaube ich irgendwo unter FAQ gelesen, dass in den Interneteinstellungen (Eigenschaften von Internet), da Opera diese Einstellungen verwendet, keine Einträge unter "LAN Einstellung--Einstellung für lokales Netzwerk---Proxyserver stehen sollen.
Bei mir ist es nun so, dass dort zwar kein Hacken bei Proxyserver für LAN verwenden gesetzt ist, aber bei Port steht 80. Ist aber alles grau hinterlegt
Wenn ich nun den Hacken setzte und den Port lösche, steht dann sofort wieder 80 drin. Hatte in Erinnerung das bei euch stand, dass das nicht sein darf.
Es ist auch kein Hacken bei "Automatische Suche der Einstellung" gesetzt. Soll ich das vielleicht mal machen? Vielleicht liegt es ja daran, dass bei mir immer Netzwerkkonnektivitätsproblem steht.


Ich habe einfach nur große Sorge, dass mein Rechner (über LAN) sich irgendwie noch etvl. wo anders hin verbindet, ohne das ich es merke und deshalb bei "Diagnose- und Reparatur" steht, dass es ein Netzwerkkonnektivitätsproblem gibt. Da ich ja bei euch gelesen habe, dass ja bei den LAN Einstellungen eigentlich nichts sethen soll. Auch nicht unter Port 80, wie bei mir.

Ich weiß, dass ich deine Nerven arg strapaziere. Vielleicht kannst du mir damit ja noch einmal helfen/zur Klärung beitragen.

Danach würde ich dann alles mal löschen wollen.Vielleicht kannst du mir dann, wenn alles soweit nun doch ok sein sollte noch sagen, in welcher Reihenfolge und ob ich irgendwie mal meine ganzen Temps löschen kann.

Gruß
Gepetto

schrauber 08.06.2014 09:43

Das sind doch nur Temp-Files :)

Setz mal den Haken bei Automatisch, dann das:

Downloade dir bitte Farbar's MiniToolBox auf deinen Desktop und starte das Tool

Setze einen Haken bei folgenden Einträgen
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset IE Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size
  • List Minidump Files
Klicke Go und poste den Inhalt der Result.txt.


Ebenso bitte mal ein frisches FRST log.

Gepetto1 08.06.2014 10:12

Hallo Schrauber,

bevor ich MiniToolbox laufen lassen möchte, würde ich gerne deine Aufmerksamkeit mal auf folgendes legen.

Ich habe noch einmal securitycheck laufen lassen und dort folgende interessante Entdeckung gemacht. Sieh selbst :)

Code:

Results of screen317's Security Check version 0.99.83 
 Windows Vista Service Pack 2 x64 (UAC is enabled) 
 Internet Explorer 9 
 Internet Explorer 8 
``````````````Antivirus/Firewall Check:``````````````
AVG AntiVirus Free Edition 2014 
 Antivirus up to date! 
`````````Anti-malware/Other Utilities Check:`````````
 Adobe Flash Player        13.0.0.214 
 Adobe Reader 9 Adobe Reader out of Date!
 Mozilla Thunderbird (24.5.0)
````````Process Check: objlist.exe by Laurent```````` 
 AVG avgwdsvc.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````

IE8 UND IE9 auf einem Rechner??? Da kann doch was nicht stimmen, oder?

hier mal das brndlog

Code:

03/16/2012 19:12:56 Checking for existence of Branding Active Setup stub...
03/16/2012 19:12:56 InternetExplorerBrandGUID didn't exist: Branding component not installed
03/16/2012 19:12:56 Inf Version is set to "9,00,8112,16421".

03/16/2012 19:12:56    COM initialized with S_OK success code.

03/16/2012 19:12:56 Branding Internet Explorer...
03/16/2012 19:12:56 Command line is "/mode:isp /peruser".

03/16/2012 19:12:56 Global branding settings are:
03/16/2012 19:12:56    Context is (0x01C00008) "Internet Content Providers, running from per-user stub";
03/16/2012 19:12:56    Settings file is        "C:\Program Files (x86)\Internet Explorer\Signup\install.ins";
03/16/2012 19:12:56    Target folder path is  "C:\Program Files (x86)\Internet Explorer\Signup".
03/16/2012 19:12:56 Done.

03/16/2012 19:12:56    About to clear previous branding...
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing migration of old settings...
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing wininet setup...
03/16/2012 19:12:56    There are no connection settings to process!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing deletion of connection settings...
03/16/2012 19:12:56    Existing connection settings weren't specified to be deleted!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing zones HKCU settings...
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing local machine policies and restrictions...
03/16/2012 19:12:56    There are no local machine *.inf files to process!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing current user policies and restrictions...
03/16/2012 19:12:56    There are no current user *.inf files to process!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing legacy policies and restrictions...
03/16/2012 19:12:56        There are no local machine *.inf files to process!
03/16/2012 19:12:56        There are no current user *.inf files to process!
03/16/2012 19:12:56    There are no legacy *.inf files to process!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing general customizations...
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing Help->About customization...
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing browser toolbar buttons...
03/16/2012 19:12:56    There are no toolbar buttons to process!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing root certificates...
03/16/2012 19:12:56    This feature is for ISPs only!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing default favorites and/or quick links...
03/16/2012 19:12:56    Creating separate thread for processing default favorites...

03/16/2012 19:12:56    COM initialized with S_OK success code.
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing deletion of favorites and/or quick links...
03/16/2012 19:12:56    None of the favorites folders were specified to be deleted!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing favorites...
03/16/2012 19:12:56    There are no favorites to add!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing ordering of favorites...
03/16/2012 19:12:56    Favorites will be put into the default position!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing quick links...
03/16/2012 19:12:56    There are no quick links to add!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing ordering of quick links...
03/16/2012 19:12:56    Quick Links will be put into the default position!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing connection settings...
03/16/2012 19:12:56    There are no connection settings to process!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Processing TrustedPublisherLockdown restriction...
03/16/2012 19:12:56    This restriction is not set!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Creating feeds...
03/16/2012 19:12:56 Processing [Feeds] section...

03/16/2012 19:12:56 Processing [FavoritesBar] section for Feeds...

03/16/2012 19:12:56 Processing [FavoritesBar] section for WebSlices...

03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Creating start pages...
03/16/2012 19:12:56    There are no start pages to add!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Creating search providers...
03/16/2012 19:12:56    There are no search providers to add!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Installing Activities...
03/16/2012 19:12:56    There are no Actitivies to Install!
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Installing Unattend Favorite bar items...
03/16/2012 19:12:56 Cannot Open Registry Key HKCU\SOFTWARE\Microsoft\Internet Explorer\AppliedUnattend [error=2]. It probably doesn't exist. Not an error.
03/16/2012 19:12:56 ProcessUnattendFavBarItems processing favbaritems from location: SOFTWARE\Microsoft\Internet Explorer\UnattendBackup\ActiveSetup\FavoriteBarItems
03/16/2012 19:12:56 Successfully opened regkey location: SOFTWARE\Microsoft\Internet Explorer\UnattendBackup\ActiveSetup\FavoriteBarItems
03/16/2012 19:12:56 Number of subkeys found: 0
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Installing Unattend Activites...
03/16/2012 19:12:56 Cannot Open Registry Key HKCU\SOFTWARE\Microsoft\Internet Explorer\AppliedUnattend [error=2]. It probably doesn't exist. Not an error.
03/16/2012 19:12:56 ProcessUnattendActivities processing activities from location: SOFTWARE\Microsoft\Internet Explorer\UnattendBackup\ActiveSetup\Accelerators
03/16/2012 19:12:56 Successfully opened regkey location: SOFTWARE\Microsoft\Internet Explorer\UnattendBackup\ActiveSetup\Accelerators
03/16/2012 19:12:56 Number of subkeys found: 0
03/16/2012 19:12:56    Done.

03/16/2012 19:12:56    Refreshing browser settings...
03/16/2012 19:12:56    Broadcasting "Windows settings change" to all top level windows...
03/16/2012 19:12:56    Done.
03/16/2012 19:12:56 Done.
03/16/2012 19:12:56 Done.

des Weiteren findet sich dort auch noch ne brndlog.bak

So und dann sollte laut microsoft support folgendes unter msinfo32 zu finden sein.

Code:

So stellen Sie unter Windows Vista manuell fest, ob der Winsock2-Schlüssel beschädigt ist

Klicken Sie auf Start und auf Ausführen, geben Sie Msinfo32 ein, und klicken Sie auf OK.
Erweitern Sie Komponenten und Netzwerk, und klicken Sie auf Protokoll.
Unter Protokoll werden zehn Abschnitte angezeigt. Die Abschnittsüberschriften enthalten folgende Namen, wenn der Winsock2-Schlüssel unbeschädigt ist:
MSAFD Tcpip [UDP/IP]
MSAFD Tcpip [UDP/IP]
MSAFD Tcpip [TCP/IPv6]
MSAFD Tcpip [UDP/IPv6]
RSVP UDP Service Provider
RSVP TCP Service Provider
RSVP UDPv6 Service Provider
RSVP TCPv6 Service Provider
MSAFD NetBIOS [\Device\NetBT_Tcpip...
MSAFD NetBIOS [\Device\NetBT_Tcpip...
MSAFD NetBIOS [\Device\NetBT_Tcpip...
MSAFD NetBIOS [\Device\NetBT_Tcpip...
MSAFD NetBIOS [\Device\NetBT_Tcpip...
MSAFD NetBIOS [\Device\NetBT_Tcpip...
Wenn die Namen sich von denen in der vorstehenden Liste unterscheiden, ist entweder der Winsock2-Schlüssel beschädigt, oder auf Ihrem Computer ist ein Add-On eines Drittanbieters, zum Beispiel eine Proxysoftware, installiert.
Wenn auf Ihrem Computer ein Drittanbieter-Add-On installiert ist, werden die Buchstaben "MSAFD" in der Liste durch den Namen des Add-Ons ersetzt.

Wenn die Liste mehr als zehn Abschnitte enthält, sind auf Ihrem Computer Drittanbieter-Add-Ons installiert.

Sind weniger als zehn Abschnitte enthalten, fehlen Informationen.

Bei mir gibt es aber überhaupt keinen einzigen Eintrag, der mit "MSAFD NetBIOS [\Device\NetBT_Tcpip..." anfängt. Komisch....

Also bevor ich MiniToolBox laufen lassen möchte, da dies ja auch meine IP Proxy settings resetet, wäre es toll, wenn wir erst einmal versuchen könnten, diese alte IE8 Version verschwinden zu lassen. Denn sonst kann man vielleicht ja gar nichts richtig einstellen (z.B. Proxy Settings etc.)

Falls Du meinst, ich sollte trotzdem vorher schon Minitoolbox laufen lassen, gib mir kurz Bescheid, dann kann ich das gleich erledigen.

Übrigens habe ich leider immer noch vereinzelt Verbindungsabbrüche.
Und Danke nochmal!!!!!!!!

Gruß
Gepetto

schrauber 08.06.2014 10:30

Zitat:

IE8 UND IE9 auf einem Rechner??? Da kann doch was nicht stimmen, oder?
Securitycheck hat nen Macken, sonst nix :)

Gepetto1 08.06.2014 15:31

Hallo Schrauber,
so...jetzt wirds, glaub ich, ein bisschen länger. Ja,ja...ich seh schon wie du die Hände über dem Kopf zusammen schlägst :)
Also erst einmal das minitoolbox log und ein frisches Frst und Addition log

Code:

MiniToolBox by Farbar  Version: 23-01-2014
Ran by Philipp (administrator) on 08-06-2014 at 13:24:52
Running from "C:\Users\Philipp\Desktop"
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows-IP-Konfiguration

Der DNS-Aufl”sungscache wurde geleert.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================

127.0.0.1      localhost

========================= IP Configuration: ================================

Realtek RTL8168C(P)/8111C(P) Family PCI-E Gigabit Ethernet NIC (NDIS 6.0) = LAN-Verbindung (Connected)


# ----------------------------------
# IPv4-Konfiguration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# Ende der IPv4-Konfiguration



Windows-IP-Konfiguration

  Hostname  . . . . . . . . . . . . : Philipp-PC
  Prim„res DNS-Suffix . . . . . . . :
  Knotentyp . . . . . . . . . . . . : Hybrid
  IP-Routing aktiviert  . . . . . . : Nein
  WINS-Proxy aktiviert  . . . . . . : Nein
  DNS-Suffixsuchliste . . . . . . . : Speedport_W_502V_Typ_A

Ethernet-Adapter LAN-Verbindung:

  Verbindungsspezifisches DNS-Suffix: Speedport_W_502V_Typ_A
  Beschreibung. . . . . . . . . . . : Realtek RTL8168C(P)/8111C(P) Family PCI-E Gigabit Ethernet NIC (NDIS 6.0)
  Physikalische Adresse . . . . . . : 00-26-18-24-A4-C7
  DHCP aktiviert. . . . . . . . . . : Ja
  Autokonfiguration aktiviert . . . : Ja
  IPv4-Adresse  . . . . . . . . . . : 192.168.2.104(Bevorzugt)
  Subnetzmaske  . . . . . . . . . . : 255.255.255.0
  Lease erhalten. . . . . . . . . . : Sonntag, 8. Juni 2014 13:17:42
  Lease l„uft ab. . . . . . . . . . : Donnerstag, 12. Juni 2014 13:17:42
  Standardgateway . . . . . . . . . : 192.168.2.1
  DHCP-Server . . . . . . . . . . . : 192.168.2.1
  DNS-Server  . . . . . . . . . . . : 192.168.2.1
  NetBIOS ber TCP/IP . . . . . . . : Aktiviert

Tunneladapter LAN-Verbindung* 6:

  Verbindungsspezifisches DNS-Suffix:
  Beschreibung. . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
  Physikalische Adresse . . . . . . : 02-00-54-55-4E-01
  DHCP aktiviert. . . . . . . . . . : Nein
  Autokonfiguration aktiviert . . . : Ja
  IPv6-Adresse. . . . . . . . . . . : 2001:0:9d38:6ab8:28ef:121f:3f57:fd97(Bevorzugt)
  Verbindungslokale IPv6-Adresse  . : fe80::28ef:121f:3f57:fd97%11(Bevorzugt)
  Standardgateway . . . . . . . . . : ::
  NetBIOS ber TCP/IP . . . . . . . : Deaktiviert

Tunneladapter LAN-Verbindung* 7:

  Medienstatus. . . . . . . . . . . : Medium getrennt
  Verbindungsspezifisches DNS-Suffix: Speedport_W_502V_Typ_A
  Beschreibung. . . . . . . . . . . : isatap.Speedport_W_502V_Typ_A
  Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0
  DHCP aktiviert. . . . . . . . . . : Nein
  Autokonfiguration aktiviert . . . : Ja
Server:  speedport.ip
Address:  192.168.2.1

Name:    google.com
Addresses:  2a00:1450:4001:c02::66
          173.194.70.113
          173.194.70.101
          173.194.70.102
          173.194.70.138
          173.194.70.139
          173.194.70.100



Ping wird ausgefhrt fr google.com [173.194.70.100] mit 32 Bytes Daten:

Antwort von 173.194.70.100: Bytes=32 Zeit=25ms TTL=50

Antwort von 173.194.70.100: Bytes=32 Zeit=25ms TTL=50



Ping-Statistik fr 173.194.70.100:

    Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust),

Ca. Zeitangaben in Millisek.:

    Minimum = 25ms, Maximum = 25ms, Mittelwert = 25ms

Server:  speedport.ip
Address:  192.168.2.1

Name:    yahoo.com
Addresses:  98.139.183.24
          206.190.36.45
          98.138.253.109



Ping wird ausgefhrt fr yahoo.com [98.138.253.109] mit 32 Bytes Daten:

Antwort von 98.138.253.109: Bytes=32 Zeit=149ms TTL=53

Antwort von 98.138.253.109: Bytes=32 Zeit=143ms TTL=53



Ping-Statistik fr 98.138.253.109:

    Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust),

Ca. Zeitangaben in Millisek.:

    Minimum = 143ms, Maximum = 149ms, Mittelwert = 146ms



Ping wird ausgefhrt fr 127.0.0.1 mit 32 Bytes Daten:

Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128

Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128



Ping-Statistik fr 127.0.0.1:

    Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust),

Ca. Zeitangaben in Millisek.:

    Minimum = 0ms, Maximum = 0ms, Mittelwert = 0ms

===========================================================================
Schnittstellenliste
 10 ...00 26 18 24 a4 c7 ...... Realtek RTL8168C(P)/8111C(P) Family PCI-E Gigabit Ethernet NIC (NDIS 6.0)
  1 ........................... Software Loopback Interface 1
 11 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface
 12 ...00 00 00 00 00 00 00 e0  isatap.Speedport_W_502V_Typ_A
===========================================================================

IPv4-Routentabelle
===========================================================================
Aktive Routen:
    Netzwerkziel    Netzwerkmaske          Gateway    Schnittstelle Metrik
          0.0.0.0          0.0.0.0      192.168.2.1    192.168.2.104    20
        127.0.0.0        255.0.0.0  Auf Verbindung        127.0.0.1    306
        127.0.0.1  255.255.255.255  Auf Verbindung        127.0.0.1    306
  127.255.255.255  255.255.255.255  Auf Verbindung        127.0.0.1    306
      192.168.2.0    255.255.255.0  Auf Verbindung    192.168.2.104    276
    192.168.2.104  255.255.255.255  Auf Verbindung    192.168.2.104    276
    192.168.2.255  255.255.255.255  Auf Verbindung    192.168.2.104    276
        224.0.0.0        240.0.0.0  Auf Verbindung        127.0.0.1    306
        224.0.0.0        240.0.0.0  Auf Verbindung    192.168.2.104    276
  255.255.255.255  255.255.255.255  Auf Verbindung        127.0.0.1    306
  255.255.255.255  255.255.255.255  Auf Verbindung    192.168.2.104    276
===========================================================================
St„ndige Routen:
  Keine

IPv6-Routentabelle
===========================================================================
Aktive Routen:
 If Metrik Netzwerkziel            Gateway
 11    18 ::/0                    Auf Verbindung
  1    306 ::1/128                  Auf Verbindung
 11    18 2001::/32                Auf Verbindung
 11    266 2001:0:9d38:6ab8:28ef:121f:3f57:fd97/128
                                    Auf Verbindung
 11    266 fe80::/64                Auf Verbindung
 11    266 fe80::28ef:121f:3f57:fd97/128
                                    Auf Verbindung
  1    306 ff00::/8                Auf Verbindung
 11    266 ff00::/8                Auf Verbindung
===========================================================================
St„ndige Routen:
  Keine
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [48128] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [50176] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [62464] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [62464] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [19968] (Microsoft Corporation)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [61440] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [62976] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [78848] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [78848] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [27648] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (06/08/2014 01:18:17 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 01:14:53 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 11:02:09 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion.
Die widersprüchlichen Komponenten sind:
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error: (06/08/2014 11:00:28 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 08:16:28 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 08:15:43 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 02:52:05 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion.
Die widersprüchlichen Komponenten sind:
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error: (06/07/2014 01:15:39 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 01:07:32 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 08:43:19 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (06/08/2014 01:19:57 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/08/2014 01:18:17 PM) (Source: Service Control Manager) (User: )
Description: Beep
i8042prt

Error: (06/08/2014 01:16:01 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/08/2014 01:14:54 PM) (Source: Service Control Manager) (User: )
Description: Beep
i8042prt

Error: (06/08/2014 11:02:20 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/08/2014 11:00:29 AM) (Source: Service Control Manager) (User: )
Description: Beep
i8042prt

Error: (06/08/2014 08:18:43 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/08/2014 08:16:29 AM) (Source: Service Control Manager) (User: )
Description: Beep
i8042prt

Error: (06/07/2014 08:17:05 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/07/2014 08:15:44 PM) (Source: Service Control Manager) (User: )
Description: Beep
i8042prt


Microsoft Office Sessions:
=========================
Error: (06/08/2014 01:18:17 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 01:14:53 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 11:02:09 AM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifestC:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe

Error: (06/08/2014 11:00:28 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 08:16:28 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 08:15:43 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 02:52:05 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifestC:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe

Error: (06/07/2014 01:15:39 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 01:07:32 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 08:43:19 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
  Date: 2014-06-07 13:17:12.838
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-07 13:17:12.698
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-07 13:17:12.542
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-07 13:17:12.402
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-07 13:17:12.090
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-07 13:17:11.918
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-07 13:17:11.731
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-07 13:17:11.575
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-07 13:17:11.325
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-07 13:17:11.185
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


=========================== Installed Programs ============================

AVG 2014 (Version: 14.0.3955)
AVG 2014 (Version: 14.0.4592)
AVG 2014 (Version: 2014.0.4592)
CPUID CPU-Z 1.69
Logitech Gaming Software 5.04 (Version: 5.04.110)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938)
Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
NVIDIA 3D Vision Controller-Treiber 331.82 (Version: 331.82)
NVIDIA Grafiktreiber 331.82 (Version: 331.82)
NVIDIA Install Application (Version: 2.1002.140.952)
NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725)
NVIDIA Systemsteuerung 331.82 (Version: 331.82)
Paint.NET v3.5.10 (Version: 3.60.0)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
Visual Studio 2012 x64 Redistributables (Version: 14.0.0.1)
Windows Live ID Sign-in Assistant (Version: 6.500.3165.0)

========================= Memory info: ===================================

Percentage of memory in use: 27%
Total physical RAM: 6134.17 MB
Available physical RAM: 4442.95 MB
Total Pagefile: 12379.88 MB
Available Pagefile: 10679.76 MB
Total Virtual: 4095.88 MB
Available Virtual: 4001.13 MB

========================= Partitions: =====================================

1 Drive c: (Windows) (Fixed) (Total:931.51 GB) (Free:608.52 GB) NTFS

========================= Users: ========================================

Benutzerkonten fr \\PHILIPP-PC

Administrator            Gast                    Philipp                 
Der Befehl wurde erfolgreich ausgefhrt.

========================= Minidump Files ==================================

No minidump file found


**** End of log ****


FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-06-2014
Ran by Philipp (administrator) on PHILIPP-PC on 08-06-2014 15:47:43
Running from C:\Users\Philipp\Desktop
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CTxfispi.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
() C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [123400 2009-01-21] (Logitech Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA3FB10447E45CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  No File
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_37 - C:\Windows\SysWOW64\npdeployJava1.dll No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()

==================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-15] ()

==================== Drivers (Whitelisted) ====================

S4 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [154256 2007-08-10] (Promise Technology, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.)
S1 Beep; No ImagePath
S4 fttxr5_O; C:\Windows\system32\drivers\fttxr5_o.sys [230408 2007-10-25] (Promise Technology, Inc.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15680 2006-11-01] ()
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [160288 2008-04-07] (NVIDIA Corporation)
S3 SaiH0BAC; C:\Windows\System32\DRIVERS\SaiH0BAC.sys [176128 2007-07-13] (Saitek)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz131; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz131\cpuz_x64.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 lvpopf64; system32\DRIVERS\lvpopf64.sys [X]
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
S3 LVRS64; system32\DRIVERS\lvrs64.sys [X]
S3 LVUVC64; system32\DRIVERS\lvuvc64.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-08 15:47 - 2014-06-08 15:47 - 00009108 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-08 13:24 - 2014-06-08 13:25 - 00022917 _____ () C:\Users\Philipp\Desktop\Result.txt
2014-06-08 11:02 - 2014-06-08 11:01 - 00982016 _____ (Farbar) C:\Users\Philipp\Desktop\MiniToolBox.exe
2014-06-03 14:52 - 2014-06-03 14:52 - 00000884 _____ () C:\Users\Philipp\Desktop\eM Client.lnk
2014-06-03 14:04 - 2014-06-03 14:04 - 00003898 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401625260
2014-06-02 20:59 - 2014-06-08 13:24 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\eM Client
2014-06-02 20:58 - 2014-06-05 20:43 - 00000884 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2014-06-02 20:58 - 2014-06-05 20:43 - 00000000 ____D () C:\Program Files (x86)\eM Client
2014-06-02 20:56 - 2014-06-02 20:57 - 14995456 _____ () C:\Users\Philipp\Downloads\setup.msi
2014-06-02 15:31 - 2014-06-08 15:25 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-02 15:31 - 2014-06-02 15:31 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-02 15:31 - 2014-06-02 15:31 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-02 15:31 - 2014-06-02 15:31 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\Users\Philipp\Documents\Mail!!!!!
2014-06-02 14:09 - 2014-06-02 14:09 - 00001106 _____ () C:\Users\Philipp\Desktop\Revo Uninstaller.lnk
2014-06-02 14:09 - 2014-06-02 14:09 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-01 20:30 - 2014-06-01 20:30 - 00000000 ____D () C:\Users\Philipp\Documents\Local Folders
2014-06-01 14:21 - 2014-06-03 14:04 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-01 14:21 - 2014-06-01 14:21 - 00000846 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Opera Software
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Opera Software
2014-06-01 10:48 - 2014-06-07 11:01 - 00000000 ____D () C:\Users\Philipp\Desktop\FRST-OlderVersion
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-05-31 21:17 - 2014-05-31 21:17 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-05-31 21:16 - 2014-05-31 21:15 - 00854367 _____ () C:\Users\Philipp\Desktop\SecurityCheck.exe
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-06-08 15:47 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:17 - 2014-05-30 07:38 - 00000000 ____D () C:\Qoobox
2014-05-30 07:17 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-30 07:17 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-30 07:17 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-30 07:16 - 2014-05-30 07:37 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:16 - 2014-05-30 07:17 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-29 07:08 - 2014-06-08 15:47 - 00000000 ____D () C:\FRST
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 21:02 - 2014-06-07 11:01 - 02072576 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-05-28 21:02 - 2014-05-28 19:36 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 20:38 - 2014-06-05 20:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-28 20:38 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-28 20:38 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-28 19:37 - 2014-06-02 16:16 - 00000000 ____D () C:\AdwCleaner
2014-05-28 16:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:02 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 21:55 - 2014-05-27 22:29 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 21:55 - 2014-05-27 22:28 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 19:28 - 2014-05-06 02:46 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 19:28 - 2014-05-06 02:21 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 02:21 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 19:28 - 2014-05-06 01:32 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 19:28 - 2014-05-06 01:14 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 01:14 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 19:01 - 2014-03-25 18:30 - 12900864 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 19:01 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys

==================== One Month Modified Files and Folders =======

2014-06-08 15:47 - 2014-06-08 15:47 - 00009108 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-08 15:47 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-06-08 15:47 - 2014-05-29 07:08 - 00000000 ____D () C:\FRST
2014-06-08 15:25 - 2014-06-02 15:31 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-08 15:17 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-08 15:17 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-08 14:59 - 2011-08-10 16:32 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-08 14:37 - 2012-05-31 17:52 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-08 13:25 - 2014-06-08 13:24 - 00022917 _____ () C:\Users\Philipp\Desktop\Result.txt
2014-06-08 13:24 - 2014-06-02 20:59 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\eM Client
2014-06-08 13:21 - 2009-07-10 14:09 - 01485671 _____ () C:\Windows\WindowsUpdate.log
2014-06-08 13:17 - 2011-08-10 16:32 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-08 13:17 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-08 13:16 - 2006-11-02 17:42 - 00032510 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-08 11:01 - 2014-06-08 11:02 - 00982016 _____ (Farbar) C:\Users\Philipp\Desktop\MiniToolBox.exe
2014-06-07 11:01 - 2014-06-01 10:48 - 00000000 ____D () C:\Users\Philipp\Desktop\FRST-OlderVersion
2014-06-07 11:01 - 2014-05-28 21:02 - 02072576 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-06-07 09:50 - 2011-12-13 19:22 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Paint.NET
2014-06-05 20:43 - 2014-06-02 20:58 - 00000884 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2014-06-05 20:43 - 2014-06-02 20:58 - 00000000 ____D () C:\Program Files (x86)\eM Client
2014-06-05 20:23 - 2014-05-28 20:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-03 19:15 - 2013-12-13 19:33 - 00001080 _____ () C:\Windows\system32\settingsbkup.sfm
2014-06-03 19:15 - 2013-12-13 19:33 - 00001080 _____ () C:\Windows\system32\settings.sfm
2014-06-03 18:43 - 2010-11-05 21:06 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-06-03 18:43 - 2010-11-05 21:03 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-06-03 18:43 - 2009-07-08 21:32 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-03 14:52 - 2014-06-03 14:52 - 00000884 _____ () C:\Users\Philipp\Desktop\eM Client.lnk
2014-06-03 14:04 - 2014-06-03 14:04 - 00003898 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401625260
2014-06-03 14:04 - 2014-06-01 14:21 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-02 20:57 - 2014-06-02 20:56 - 14995456 _____ () C:\Users\Philipp\Downloads\setup.msi
2014-06-02 19:56 - 2008-01-21 05:26 - 00846494 _____ () C:\Windows\PFRO.log
2014-06-02 19:54 - 2010-04-19 15:57 - 00008843 _____ () C:\Windows\system32\lvcoinst.log
2014-06-02 19:53 - 2010-04-19 15:56 - 00000000 ____D () C:\ProgramData\LogiShrd
2014-06-02 19:53 - 2009-07-22 15:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-06-02 16:16 - 2014-05-28 19:37 - 00000000 ____D () C:\AdwCleaner
2014-06-02 15:32 - 2009-07-10 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Adobe
2014-06-02 15:31 - 2014-06-02 15:31 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-02 15:31 - 2014-06-02 15:31 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-02 15:31 - 2014-06-02 15:31 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-02 15:31 - 2008-05-21 11:53 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\Users\Philipp\Documents\Mail!!!!!
2014-06-02 14:19 - 2009-07-10 20:41 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Mozilla
2014-06-02 14:09 - 2014-06-02 14:09 - 00001106 _____ () C:\Users\Philipp\Desktop\Revo Uninstaller.lnk
2014-06-02 14:09 - 2014-06-02 14:09 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-01 20:30 - 2014-06-01 20:30 - 00000000 ____D () C:\Users\Philipp\Documents\Local Folders
2014-06-01 14:21 - 2014-06-01 14:21 - 00000846 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Opera Software
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Opera Software
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-05-31 21:17 - 2014-05-31 21:17 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-05-31 21:15 - 2014-05-31 21:16 - 00854367 _____ () C:\Users\Philipp\Desktop\SecurityCheck.exe
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:17 - 00000000 ____D () C:\Qoobox
2014-05-30 07:37 - 2014-05-30 07:16 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:36 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-30 07:17 - 2014-05-30 07:16 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:14 - 2008-05-21 15:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-30 07:14 - 2008-05-21 15:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat
2014-05-30 07:14 - 2008-05-21 15:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-28 19:36 - 2014-05-28 21:02 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 14:01 - 2014-05-28 16:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:01 - 2014-05-28 14:02 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-27 23:15 - 2013-10-01 18:40 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Avg2014
2014-05-27 22:29 - 2014-05-27 21:55 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 22:28 - 2014-05-27 21:55 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-19 18:56 - 2014-03-31 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-05-15 19:38 - 2009-07-08 21:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 19:34 - 2013-08-14 18:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 19:33 - 2006-11-02 14:35 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-28 20:38 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-10 18:55 - 2011-08-10 16:32 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-10 18:55 - 2011-08-10 16:32 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

Some content of TEMP:
====================
C:\Users\Philipp\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-06-08 13:24

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-06-2014
Ran by Philipp at 2014-06-08 15:48:04
Running from C:\Users\Philipp\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}

==================== Installed Programs ======================

Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4592 - AVG Technologies)
AVG 2014 (Version: 14.0.3955 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4592 - AVG Technologies) Hidden
Call of Duty: Modern Warfare 3 - Dedicated Server (HKLM-x32\...\Steam App 42750) (Version:  - Infinity Ward - Sledgehammer Games)
Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version:  - Infinity Ward - Sledgehammer Games)
Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version:  - Infinity Ward - Sledgehammer Games)
CPUID CPU-Z 1.69 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version:  - )
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version:  - )
Crysis(R) (HKLM-x32\...\{000E79B7-E725-4F01-870A-C12942B7F8E4}) (Version: 1.20.0000 - Electronic Arts)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{349F73CA-653A-43A6-AE77-970B07D6EDA0}) (Version:  - Microsoft)
Dishonored (HKLM-x32\...\Steam App 205100) (Version: 1.0 - Bethesda Softworks)
eM Client (HKLM-x32\...\{D8EE8B05-41AD-40C3-A18B-E7ECEDAABD26}) (Version: 6.0.20480.0 - eM Client Inc.)
F1 2010 (HKLM-x32\...\GFWL_{434D0831-3E0C-4D03-A5D4-5E1000008400}) (Version: 1.0.0000.132 - Codemasters)
F1 2010 (x32 Version: 1.0.0000.132 - Codemasters) Hidden
F1 2010 (x32 Version: 1.0.0001.132 - Codemasters) Hidden
F1 2011 (HKLM-x32\...\GFWL_{434D0FA1-3E0C-4D03-A5D4-5E1000008100}) (Version: 1.0.0000.129 - Codemasters)
F1 2011 (x32 Version: 1.0.0000.129 - Codemasters) Hidden
F1 2011 (x32 Version: 1.0.0001.129 - Codemasters) Hidden
F1 2011 (x32 Version: 1.0.0002.129 - Codemasters) Hidden
F1 2013 (HKLM-x32\...\Steam App 223670) (Version:  - Codemasters Birmingham)
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
Flight Simulator X (HKLM-x32\...\RTMshadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version:  - )
Flight Simulator X Service Pack 1 (HKLM-x32\...\SP1shadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version:  - )
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Logitech Gaming Software 5.04 (HKLM\...\{8753DF4D-64B0-474E-9A97-0AB5585D9A53}) (Version: 5.04.110 - Logitech)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Flight Simulator X (x32 Version: 10.0.60905 - Microsoft Game Studios) Hidden
Microsoft Flight Simulator X: Acceleration (HKLM-x32\...\FlightSim_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version: 10.0.61637.0 - Microsoft Game Studios)
Microsoft Flight Simulator X: Acceleration (x32 Version: 10.0.61637.0 - Microsoft Game Studios) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla)
MSXML 4.0 SP2 (KB927978) (HKLM-x32\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser und SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
NVIDIA 3D Vision Controller-Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.82 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.82 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.140.952 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Systemsteuerung 331.82 (Version: 331.82 - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Opera Stable 22.0.1471.50 (HKLM-x32\...\Opera 22.0.1471.50) (Version: 22.0.1471.50 - Opera Software ASA)
Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Rapture3D 2.4.9 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5854 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version:  - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}) (Version: 8.0.0.35 - GRISOFT, s.r.o.)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}) (Version: 9.0.0.623 - AVG Technologies CZ, s.r.o.)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)

==================== Restore Points  =========================

10-06-2013 18:33:24 Geplanter Prüfpunkt
12-06-2013 16:45:29 Windows Update
10-07-2013 16:49:49 Windows Update
14-08-2013 16:46:50 Windows Update
28-08-2013 17:18:27 Windows Update
12-09-2013 16:48:58 Windows Update
21-09-2013 17:03:11 Removed Java(TM) 6 Update 3
21-09-2013 17:04:13 Removed Java(TM) 6 Update 5
21-09-2013 17:05:11 Removed Java(TM) 6 Update 3
21-09-2013 17:14:34 Removed Java(TM) 6 Update 3
21-09-2013 17:47:47 Removed Java(TM) 6 Update 3
21-09-2013 17:48:25 Removed Java(TM) 6 Update 3
21-09-2013 18:03:31 Wiederherstellungspunkt vor Fehlerhafte Patchregistrierungsschlüssel
21-09-2013 18:05:13 Removed Java(TM) 6 Update 37
01-10-2013 16:43:39 Installed AVG 2014
01-10-2013 16:45:01 Installed AVG 2014
10-10-2013 16:42:20 Windows Update
14-10-2013 14:32:24 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
14-10-2013 14:35:51 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
14-10-2013 14:36:40 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
14-10-2013 17:14:25 DirectX wurde installiert
15-10-2013 07:39:00 Installiert Far Cry 3
31-10-2013 17:28:40 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
31-10-2013 17:32:09 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
31-10-2013 17:33:11 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
13-11-2013 17:13:00 Windows Update
20-11-2013 17:38:53 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
20-11-2013 17:43:27 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
20-11-2013 17:44:33 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
20-11-2013 17:45:57 Windows Update
21-11-2013 14:54:28 Windows Update
13-12-2013 17:19:09 Windows Update
15-01-2014 17:18:41 Windows Update
13-02-2014 17:23:08 Windows Update
13-02-2014 17:56:42 Installed AVG 2014
12-03-2014 17:37:07 Windows Update
09-04-2014 16:21:10 Windows Update
18-04-2014 17:23:25 Geplanter Prüfpunkt
30-04-2014 17:12:36 Installed AVG 2014
02-05-2014 17:19:06 Windows Update
03-05-2014 19:08:49 Geplanter Prüfpunkt
08-05-2014 19:03:11 Geplanter Prüfpunkt
14-05-2014 19:39:12 Geplanter Prüfpunkt
15-05-2014 17:27:36 Windows Update
24-05-2014 17:49:47 Geplanter Prüfpunkt
25-05-2014 17:15:51 Geplanter Prüfpunkt
02-06-2014 12:14:11 Revo Uninstaller's restore point - Mozilla Firefox 29.0.1 (x86 de)
02-06-2014 12:18:19 Revo Uninstaller's restore point - Mozilla Firefox 29.0.1 (x86 de)
02-06-2014 13:02:30 Revo Uninstaller's restore point - Windows Media Player Firefox Plugin
02-06-2014 13:08:30 Revo Uninstaller's restore point - Adobe Shockwave Player
02-06-2014 13:25:31 Revo Uninstaller's restore point - Adobe Flash Player 13 Plugin
02-06-2014 17:52:33 Removed Logitech Webcam Software.
02-06-2014 17:54:13 Logitech Webcam Software v12.10.1110
02-06-2014 18:57:40 Installed eM Client
03-06-2014 12:05:28 Revo Uninstaller's restore point - Mozilla Maintenance Service
05-06-2014 18:42:30 Installed eM Client

==================== Hosts content: ==========================

2006-11-02 14:34 - 2014-05-30 07:36 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {053E07D4-BF57-4777-AB86-2503FFB01905} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10] (Google Inc.)
Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {55BE9422-28E2-4700-A01E-1FCF1D40A620} - System32\Tasks\Opera scheduled Autoupdate 1401625260 => C:\Program Files (x86)\Opera\launcher.exe [2014-05-27] (Opera Software)
Task: {72539E3E-11DA-47CA-A173-02739CA95D54} - System32\Tasks\{DC3C511F-86D5-41EF-B546-2B08E434B6EF} => C:\Program Files (x86)\Skype\Phone\Skype.exe
Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {844584A5-E187-4702-BCCB-906B3C92C738} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {94810335-FB9F-4177-9D98-0DBBE92CD2F6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-02] (Adobe Systems Incorporated)
Task: {D272EFE4-B9B3-4F54-A2AA-0E2618E38D88} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10] (Google Inc.)
Task: {DE93CB4F-5D56-4AF7-8001-27E17F8F0803} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] ()
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe

==================== Loaded Modules (whitelisted) =============

2013-10-15 09:59 - 2013-10-15 09:59 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-06-03 14:04 - 2014-06-03 14:04 - 01396344 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
2009-07-10 15:19 - 2008-12-04 12:57 - 00146432 _____ () C:\Windows\SysWOW64\APOMngr.DLL
2014-06-03 14:04 - 2014-06-03 14:03 - 00957048 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: LogitechQuickCamRibbon => "C:\Programme\Logitech\Logitech WebCam Software\LWS.exe" /hide
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/08/2014 01:18:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 01:14:53 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 11:02:09 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion.
Die widersprüchlichen Komponenten sind:
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error: (06/08/2014 11:00:28 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 08:16:28 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 08:15:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 02:52:05 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen bereits aktiven Komponentenversion.
Die widersprüchlichen Komponenten sind:
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error: (06/07/2014 01:15:39 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 01:07:32 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 08:43:19 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (06/08/2014 01:19:57 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/08/2014 01:18:17 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/08/2014 01:16:01 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/08/2014 01:14:54 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/08/2014 11:02:20 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/08/2014 11:00:29 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/08/2014 08:18:43 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/08/2014 08:16:29 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/07/2014 08:17:05 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/07/2014 08:15:44 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt


Microsoft Office Sessions:
=========================
Error: (06/08/2014 01:18:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 01:14:53 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 11:02:09 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifestC:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe

Error: (06/08/2014 11:00:28 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/08/2014 08:16:28 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 08:15:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 02:52:05 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifestC:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe

Error: (06/07/2014 01:15:39 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 01:07:32 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/07/2014 08:43:19 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
  Date: 2014-06-08 15:48:00.688
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-08 15:48:00.526
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-08 15:48:00.363
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-08 15:48:00.200
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-08 15:48:00.035
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-08 15:47:59.840
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-08 15:47:59.676
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-08 15:47:59.513
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-08 15:47:59.282
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-08 15:47:59.120
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 43%
Total physical RAM: 6134.17 MB
Available physical RAM: 3449.88 MB
Total Pagefile: 12449.88 MB
Available Pagefile: 9560.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:931.51 GB) (Free:608.5 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: 61491321)
Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS)

==================== End Of Log ============================

So und nun komm ich...

Die Fehlerbeschreibung mit dem "//./root/CIMV2"... Dazu habe ich folgendes gefunden:
Code:

Nachdem Sie Windows Vista Service Pack 1 (SP1) oder Windows Server 2008 installiert haben, wird im Anwendungsprotokoll der folgende WMI-Fehler protokolliert:
Protokollname: Anwendung
Quelle: Microsoft-Windows-WMI
Datum: 1/18/2008 2:37:27 PM
Ereigniskennung: 10
Taskkategorie: Keine
Stufe: Fehler
Stichwörter: Klassisch
Beschreibung: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage >
99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist

Zur Lösung dieses Problems führen Sie ein Skript aus, um die Ausgabe von Meldungen mit der Ereignis-ID 10 zu beenden. Gehen Sie folgendermaßen vor, um dieses Skript auszuführen:
Erstellen Sie in einem Texteditor wie Notepad ein neues Textdokument mit dem Namen "Test.vbs".
Fügen Sie den folgenden Code in die Datei "test.vbs" ein:
strComputer = "."
Set objWMIService = GetObject("winmgmts:" _
& "{impersonationLevel=impersonate}!\\" _
& strComputer & "\root\subscription")

Set obj1 = objWMIService.Get("__EventFilter.Name='BVTFilter'")

set obj2set = obj1.Associators_("__FilterToConsumerBinding")

set obj3set = obj1.References_("__FilterToConsumerBinding")



For each obj2 in obj2set
                WScript.echo "Deleting the object"
                WScript.echo obj2.GetObjectText_
                obj2.Delete_
Weiter

For each obj3 in obj3set
                WScript.echo "Deleting the object"
                WScript.echo obj3.GetObjectText_
                obj3.Delete_
Weiter

WScript.echo "Deleting the object"
WScript.echo obj1.GetObjectText_
obj1.Delete_
Nachdem Sie dieses Skript ausgeführt haben, werden keine Meldungen zur Ereignis-ID 10 mehr im Anwendungsprotokoll angezeigt. Sie müssen jedoch alle vorherigen Meldungen mit der Ereignis-ID 10 manuell deaktivieren.

Hinweis Stellen Sie sicher, dass Sie nur die relevanten Meldungen mit der Ereignis-ID 10 löschen. Möglicherweise sind andere Meldungen mit der Ereignis-ID 10 vorhanden, die Sie nicht löschen sollten.
Für Windows 7 und Windows Server 2008 R2 ist eine Fix It-Lösung für Meldungen mit der Ereignis-ID 10 verfügbar, zu der Sie im folgenden Artikel der Microsoft Knowledge Base weitere Informationen finden:
2545227 Nach der Installation von Windows Vista Service Pack 1 oder Windows Server 2008 R2 wird im Anwendungsprotokoll die Ereignis-ID 10 protokolliert

Zum Anfang | Ihr Feedback an uns
Collapse imageWeitere Informationen

Die oben aufgeführte Fehlermeldung mit Ereignis-ID 10 kann getrost ignoriert werden, da sie nicht auf ein Problem mit dem Service Pack oder Betriebssystem hinweist.

Also sollte mich das eigentlich nit stören/beunruhigen. Gell??

Aber... Unter der Computerverwaltung bei windowsprotokolle Sicherheit tauchen sehr häufig (eigntlich immer wenn der Pc an ist) folgende Meldungen auf
Code:

+ System

  - Provider

  [ Name]  Microsoft-Windows-Security-Auditing
  [ Guid]  {54849625-5478-4994-a5ba-3e3b0328c30d}
 
  EventID 4624
 
  Version 0
 
  Level 0
 
  Task 12544
 
  Opcode 0
 
  Keywords 0x8020000000000000
 
  - TimeCreated

  [ SystemTime]  2014-06-08T08:59:48.248Z
 
  EventRecordID 143287
 
  Correlation
 
  - Execution

  [ ProcessID]  1000
  [ ThreadID]  1092
 
  Channel Security
 
  Computer Philipp-PC
 
  Security
 

- EventData

  SubjectUserSid S-1-0-0
  SubjectUserName -
  SubjectDomainName -
  SubjectLogonId 0x0
  TargetUserSid S-1-5-7
  TargetUserName ANONYMOUS-ANMELDUNG
  TargetDomainName NT-AUTORITÄT
  TargetLogonId 0x352ca
  LogonType 3
  LogonProcessName NtLmSsp 
  AuthenticationPackageName NTLM
  WorkstationName 
  LogonGuid {00000000-0000-0000-0000-000000000000}
  TransmittedServices -
  LmPackageName NTLM V1
  KeyLength 0
  ProcessId 0x0
  ProcessName -
  IpAddress -
  IpPort -

Was heißt hier "ANONYMOUS-ANMELDUNG"?????

Unter "Administrative Ereignisse" stehen jeden Tag folgende Fehler:
1. "Fehler bei der Anwendungsinitialisierung [ Name] Microsoft-Windows-
LanguagePackSetup [ Guid] {7237fff9-a08a-4804-9c79-4a8704b70b87}
2. "Das laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: Beep i8042prt
3. "Fehler beim Generieren des Aktivierungskontextes für C:\Windows\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest
C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest

Und der wahrscheinlich wichtigste Fehler, der auch evtl zu den Netzwerkabbrüchen führt:
"Quelle:PlugnPlayManager--Der Dienst "avgwd" (das ist das Antivirenprogramm) war möglicherweise für Geräteereignisbenachrichtigungen nicht deregistriert , bevor er beendet wurde"

Also wie ich den sidebyside Fehler durch esetsmartinstaller unter downloads beheben kann, das kannst du mir ja sicher erklären.

Der Fehler mit //./root/CIMV2 ist ja wohl auch microsoft bekannt und kann ignoriert.

Der Fehler mit dem LanguagePackSetup, da wieß ich auch nicht, wie der zu beheben ist.

Und das nicht laden können von "Beep i8042prt", da wieß ich auch nicht wie man das beheben kann.

Der Fehler von AVG... ja da warte ich mal auf ein Programmupdate. Ansonsten fliegt es runter und AVAST kommt drauf.

So zum Schluss noch. Was sagst du denn zu meiner Beobachtung, dass unter msinfo32--Netzwerke jegliche Eintragungen mit "MSAFD NetBIOS [\Device\NetBT_Tcpip..." fehlen, die ja laut microsoft eigentlich da sein müssten?
und was bedeutet dieser Eintrag im FRST log "BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File"

Viel Spaß beim Antworten ;)

Gruß
Gepetto

schrauber 09.06.2014 07:02

Das ist nur ein Browser Helper Object von Java.

FRST und MInitoolbox sind sauber. In der Ereignisanzeige stehen grundsätlich immer jeder Pups drin. Da kann man sich monatelang dran aufhängen.


Also du hast, neben dem KRam den du in irgendwelchen Logs findest, also wirklich bemerkbare Netzwerkabbrüche?


http://www.trojaner-board.de/126216-...epair-aio.html

Gepetto1 09.06.2014 08:37

Hallo Schrauber,
also du meinst mein Rechner ist sauber? Online banking etc. wieder bedenkenlos möglich?
Das wäre ja perfekt. :-)
Also zu den Netzwerkabbrüchen. Ja, es gibt sie noch. Mit opera aber nicht mehr. Es MUSS mit avg zusammenhängen. Denn wenn ich auf z.B. update bei avg klicke und er fertig mit seinem update ist, trennt sich die Verbindung.

Ich werde avg mal deinstallieren und neu installieren. Wenn das nix hilft, versuche ich Avast.

Kannst du mir noch schreiben, in welcher reihenfolge ich die ganzen programme wie z.b. combofix etc. wieder deinstallieren soll? Das wäre super.

Und nocheinmal vielen vielen vielen Dank für deine Geduld und Mühe!!!

Da mein Rechner ja wohl sauber ist, denke ich, dass ich mich nun hier verabschieden kann.

Gruß
Gepetto

schrauber 09.06.2014 16:05

Fertig :)

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :)

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.

Gepetto1 09.06.2014 18:22

Hi,
super. Danke.

Hab leider noch die letzten Fragen an dich. Dann bist du mich los ;)

Also im FRST log steht ja folgendes:

Code:

S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 lvpopf64; system32\DRIVERS\lvpopf64.sys [X]
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
S3 LVRS64; system32\DRIVERS\lvrs64.sys [X]
S3 LVUVC64; system32\DRIVERS\lvuvc64.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

Ich gehe mal davon aus, dass diese ganzen .sys nicht mehr bei mir vorhanden sind.
Z.B. LVUVC64.sys, LVPr2M64.sys, LVRS64.sys, lvpopf64.sys gehören zur Logitech Webcam. Diese hatte ich aber mit Revo eigentlich deinstalliert. Bei der Deinstallation poppte allerdings ein Fenster mit irgendeinem roten Kreuz auf. Weiß leider nicht mehr was da stand. Jedenfalls gibt es keinen Ordner mehr.
Müssen diese Prozesse noch irgendwie "gekillt" werden??

Des weiteren taucht dort ja folgendes auf
Code:

S1 Beep; No ImagePath
muss ich das beachten?

Dann wollte ich noch fragen, ob ich folgenden Task einfach deaktivieren bzw.löschen kann, da der angegeben Ordner schon bestimmt mindestens 4 Jahre nicht mehr existiert
Code:

Task: {72539E3E-11DA-47CA-A173-02739CA95D54} - System32\Tasks\{DC3C511F-86D5-41EF-B546-2B08E434B6EF} => C:\Program Files (x86)\Skype\Phone\Skype.exe
Und zu guter Letzt hatte ich eigentlich gedacht, dass ich java komplett verbannt habe.
Aber in meinem Autostart (habe es dort aber nicht aktiviert, findet sich noch folgendes
Code:

Disabled items from MSCONFIG
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

Wie kann ich denn den Eintrag komplett aus Autostart entfernen?
Bzw. die einzigen Ordner wo noch irgendwas von java drin ist befinden sich unter
C:\....AppData\LocalLow\Sun und unter ProgramData\Sun.
Kann ich diese Ordner einfach in den Papierkorb schmeißen?

Ich warte noch mit der Deinstallation von Combofix etc. bis zu deiner Rückantwort, falls noch was gebraucht wird.

Vielen Dank!!! Und danach stell ich keine Fragen mehr :)

Gruß
Gepetto

schrauber 10.06.2014 14:12

Die Java Ordner kannste löschen, der Eintrag unter msconfig muss eigenständig nochmal gelöscht werden, der sagt nix aus ob da auch noch wirklich ein ordner vorhanden ist oder nicht. Finger weg von den Services und Diensten ;)

Gepetto1 10.06.2014 17:46

Hilfe!!!
Habe erst Combofix deinstalliert, so wie beschrieben. Hat geklasspt.
Dann habe ich Delfix gestartet. Hat auch fast alles gelöscht. Siehe log.

Code:

# DelFix v10.7 - Datei am 10/06/2014 um 18:34:43 erstellt
# Aktualisiert am 27/04/2014 von Xplode
# Benutzer : Philipp - PHILIPP-PC
# Betriebssystem : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)

~ Aktiviere die Benutzerkontensteuerung ... OK

~ Entferne die Bereinigungsprogramme ...

Gelöscht : C:\32788R22FWJFW
Gelöscht : C:\Combofix
Gelöscht : C:\FRST
Gelöscht : C:\AdwCleaner
Gelöscht : C:\Users\Philipp\Desktop\FRST-OlderVersion
Gelöscht : C:\ComboFix.txt
Gelöscht : C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
Gelöscht : C:\Users\Philipp\Desktop\FRST64.exe
Gelöscht : C:\Users\Philipp\Desktop\JRT.exe
Gelöscht : C:\Users\Philipp\Desktop\MiniToolBox.exe
Gelöscht : C:\Users\Philipp\Desktop\SecurityCheck.exe
Gelöscht : C:\Windows\NIRCMD.exe
Gelöscht : HKLM\SOFTWARE\AdwCleaner
Gelöscht : HKLM\SOFTWARE\Swearware
Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

~ Erstelle ein Backup der Registrierungsdatenbank ... OK

~ Lösche die Wiederherstellungspunkte ...


Ein neuer Wiederherstellungspunkt wurde erstellt !

~ Stelle die Systemeinstellungen wieder her ... OK

########## - EOF - ##########

ABER dann ploppte plötzlich später folgende Meldung auf

Code:

NIRCMD.EXE konnte nicht gefunden werden. Stellen Sie sicher,
dass Sie den Namen richtig eingegeben haben und wiederholen Sie den Vorgang

Habe mehrmals "ok" drücken müssen. Dann verschwand die Meldung.
Und was nu?????

Und noch was völlig seltsames. Ich weiß nicht, wie ich dir das genau beschreiben soll. Aber ich versuche es und hänge mal eine .jpeg Datei an.
Also wenn man im explorer auf "computer" klickt, dann sieht man ja erst "windows (C:) und DVD Laufwerk (D:)
Wenn ich jetzt auf "windows (C:)" klicke, öffnen sich ja alle Ordenr etc., wie z.B auf system32 u.s.w.
Nun steht da plötzlich aber "Combofix". Aber kein Ordner, sondern genau so ein Symbol wie bei "computer" un d wenn ich das anklicke, öffnet sich auch wieder "windows (C:)" und DVD Laufwerk (D) und wenn ich dann auf "windows (C:) klicke, seh ich wieder alle Ordner und WIEDER dieses "Combofix", was genau so aussieht, wie "computer"!!
Ist ja schon wie ne "Endlosschleife".... Was soll denn das?????
Was passiert wenn ich versuchen würde dieses komische Symbol "Combofix" zu löschen, weil es ja auch wieder "windows" und all seine kompletten Ordner enthält, also im Prinzip ja meine komplette Festplatte.
Mist... weiß nicht wie ich hier ne .jpeg Datei anhängen kann, sonst würde ich dir mal den screenshot davon zeigen.

schrauber 11.06.2014 08:55

Lade Combofix neu auf den Desktop und deinstalliere es nochmal mit dem Uninstall Befehl.

Gepetto1 11.06.2014 12:28

Hi,
hab den installer von Combofix auf den desktop geladen. Dann den Uninstall Befehl.
Dann hieß es "Combofix" konnte nicht gefunden werden... :(
Na ganz toll. Und jetzt??? Oder muss ich es erst noch einmal ausführen und dann den Uninstall Befehl?
HILFE!!

schrauber 12.06.2014 07:31

Locker bleiben :)

Sicherstellen das Combofix auf dem Desktop ist, dann anstatt /Uninstall diesen befehl:

"%userprofile%\desktop\Combofix.exe" /Uninstall


Denk an das Leerzeichen.

Gepetto1 12.06.2014 08:02

Hi,
Befehl ausgeführt. Combofix sagt deinstalliert. Verschwindet auch vom desktop.
Aber.... es wird wieder ein "combofix" symbol unter C erstellt (Datum von heute), welches die gleiche Funktion wie "computer" hat und alle Dateien der festplatte enthält.
"zeigt die an diesen Computer angeschlossenen Laufwerke und hardware an"
Also gleiches Problem!
Was soll das denn?

Kommando zurück!!!!! Es ist weg!!!! Wuhuhuhuhu :)
DANKE!

habe aber noch folgendes kleines Problem.
Seit der ersten Ausführung von Combofix rattert meine Festplatte am Anfang wie bekloppt.
Habe nun folgenden Temp Ordner entdeckt. Der jeden Tag dutzende Male folgendes enthält und es immer mehr wird.
Code:

07:43:23:564 : DEBUG: _wsetlocale returns: German_Germany.1252
07:43:24:625 : DEBUG: Cleaning working path in a new thread
07:43:24:828 : DEBUG: Failed to remove directory C:\Windows\TEMP\lpksetup with error 3
07:43:49:086 : PERF: Enumerating installed languages - ENTER
07:43:49:366 : DEBUG: KB937286 is not a language type package
07:43:49:554 : DEBUG: Microsoft-Windows-AutomationAPI-Package-TopLevel is not a language type package
07:43:49:678 : LanguagePack de-DE created.
07:43:49:834 :        type:    MUI
07:43:49:959 :        identity: Microsoft-Windows-Client-LanguagePack-Package~31bf3856ad364e35~amd64~de-DE~6.0.6000.16386
07:43:50:084 :        keyword:  (null)
07:43:50:209 :        cab file: (null)
07:43:50:334 : DEBUG: Microsoft-Windows-DGT-Package-TopLevel is not a language type package
07:43:50:458 : DEBUG: Microsoft-Windows-Foundation-Package is not a language type package
07:43:50:583 : DEBUG: Microsoft-Windows-HomePremiumEdition is not a language type package
07:43:50:708 : DEBUG: Microsoft-Windows-InternetExplorer-8-LanguagePack is not a language type package
07:43:50:833 : DEBUG: Microsoft-Windows-InternetExplorer-8-LanguagePack is not a language type package
07:43:50:958 : DEBUG: Microsoft-Windows-InternetExplorer-8-LanguagePack is not a language type package
07:43:51:082 : DEBUG: Microsoft-Windows-InternetExplorer-8-Package-TopLevel is not a language type package
07:43:51:769 : DEBUG: Microsoft-Windows-InternetExplorer-LanguagePack is not a language type package
07:43:52:018 : DEBUG: Microsoft-Windows-InternetExplorer-Package-TopLevel is not a language type package
07:43:52:143 : DEBUG: Microsoft-Windows-NetFx3-OC-Package is not a language type package
07:43:52:268 : DEBUG: Microsoft-Windows-NetFx3-OC-Package is not a language type package
07:43:52:393 : DEBUG: Microsoft-Windows-NetFx3-OC-Package is not a language type package
07:43:52:518 : DEBUG: Microsoft-Windows-NetFx3-OC-Package is not a language type package
07:43:52:642 : DEBUG: Microsoft-Windows-NetFx3-OC-Package is not a language type package
07:43:52:767 : DEBUG: Microsoft-Windows-Printing-XPSServices-Package is not a language type package
07:43:52:923 : DEBUG: Microsoft-Windows-RecDisc-SDP-Package is not a language type package
07:43:53:079 : DEBUG: Microsoft-Windows-RecDisc-SDP-Package is not a language type package
07:43:53:204 : DEBUG: Microsoft-Windows-Sidebar-Killbits-SDP-Package is not a language type package
07:43:53:360 : DEBUG: Microsoft-Windows-UIRibbon-Package-TopLevel is not a language type package
07:43:53:485 : DEBUG: Microsoft-Windows-VistaServicePack-SysHiper-SP1-Package is not a language type package
07:43:53:610 : DEBUG: Microsoft-Windows-VistaServicePack-UninstallRemoval-Package is not a language type package
07:43:53:734 : DEBUG: Microsoft-Windows-VistaServicePack-UninstallRemoval-Package is not a language type package
07:43:53:906 : DEBUG: Microsoft-Windows-VistaSP1CEIP-Package is not a language type package
07:43:54:031 : DEBUG: Microsoft-Windows-WPD7IP-Package-TopLevel is not a language type package
07:43:54:156 : DEBUG: Microsoft-Windows-WPD7IP-SKU-Package is not a language type package
07:43:54:280 : DEBUG: Microsoft-Windows-WPD7IP-SKU-Package is not a language type package
07:43:54:405 : DEBUG: Package_for_2761494 is not a language type package
07:43:54:530 : DEBUG: Package_for_KB2079403 is not a language type package
07:43:54:655 : DEBUG: Package_for_KB2117917 is not a language type package
07:43:54:780 : DEBUG: Package_for_KB2141007 is not a language type package
07:43:54:904 : DEBUG: Package_for_KB2158563 is not a language type package
07:43:55:029 : DEBUG: Package_for_KB2160329 is not a language type package
07:43:55:154 : DEBUG: Package_for_KB2183461 is not a language type package
07:43:55:310 : DEBUG: Package_for_KB2207566 is not a language type package
07:43:56:574 : DEBUG: Package_for_KB2281679 is not a language type package
07:43:57:822 : DEBUG: Package_for_KB2286198 is not a language type package
07:43:59:070 : DEBUG: Package_for_KB2296011 is not a language type package
07:44:00:333 : DEBUG: Package_for_KB2296199 is not a language type package
07:44:02:221 : DEBUG: Package_for_KB2305420 is not a language type package
07:44:03:531 : DEBUG: Package_for_KB2345886 is not a language type package
07:44:04:218 : DEBUG: Package_for_KB2347290 is not a language type package
07:44:04:342 : DEBUG: Package_for_KB2360131 is not a language type package
07:44:04:467 : DEBUG: Package_for_KB2362765 is not a language type package
07:44:04:592 : DEBUG: Package_for_KB2378111 is not a language type package
07:44:04:717 : DEBUG: Package_for_KB2387149 is not a language type package
07:44:04:842 : DEBUG: Package_for_KB2388210 is not a language type package
07:44:04:966 : DEBUG: Package_for_KB2393802 is not a language type package
07:44:05:091 : DEBUG: Package_for_KB2412687 is not a language type package
07:44:05:216 : DEBUG: Package_for_KB2416400 is not a language type package
07:44:05:341 : DEBUG: Package_for_KB2416470 is not a language type package
07:44:05:466 : DEBUG: Package_for_KB2419640 is not a language type package
07:44:05:590 : DEBUG: Package_for_KB2423089 is not a language type package
07:44:05:715 : DEBUG: Package_for_KB2436673 is not a language type package
07:44:05:840 : DEBUG: Package_for_KB2442962 is not a language type package
07:44:05:965 : DEBUG: Package_for_KB2443685 is not a language type package
07:44:06:090 : DEBUG: Package_for_KB2447568 is not a language type package
07:44:06:277 : DEBUG: Package_for_KB2449742 is not a language type package
07:44:06:402 : DEBUG: Package_for_KB2467659 is not a language type package
07:44:06:526 : DEBUG: Package_for_KB2476490 is not a language type package
07:44:06:651 : DEBUG: Package_for_KB2478660 is not a language type package
07:44:06:776 : DEBUG: Package_for_KB2478935 is not a language type package
07:44:06:901 : DEBUG: Package_for_KB2479628 is not a language type package
07:44:07:057 : DEBUG: Package_for_KB2479943 is not a language type package
07:44:07:182 : DEBUG: Package_for_KB2481109 is not a language type package
07:44:07:306 : DEBUG: Package_for_KB2482017 is not a language type package
07:44:07:431 : DEBUG: Package_for_KB2483185 is not a language type package
07:44:07:556 : DEBUG: Package_for_KB2485376 is not a language type package
07:44:07:681 : DEBUG: Package_for_KB2492386 is not a language type package
07:44:07:806 : DEBUG: Package_for_KB2497640 is not a language type package
07:44:07:930 : DEBUG: Package_for_KB2503658 is not a language type package
07:44:08:086 : DEBUG: Package_for_KB2503665 is not a language type package
07:44:08:211 : DEBUG: Package_for_KB2505189 is not a language type package
07:44:09:412 : DEBUG: Package_for_KB2506014 is not a language type package
07:44:10:208 : DEBUG: Package_for_KB2506212 is not a language type package
07:44:11:503 : DEBUG: Package_for_KB2506223 is not a language type package
07:44:12:766 : DEBUG: Package_for_KB2507618 is not a language type package
07:44:13:578 : DEBUG: Package_for_KB2507938 is not a language type package
07:44:13:765 : DEBUG: Package_for_KB2508272 is not a language type package
07:44:13:890 : DEBUG: Package_for_KB2508429 is not a language type package
07:44:14:014 : DEBUG: Package_for_KB2509553 is not a language type package
07:44:14:233 : DEBUG: Package_for_KB2510531 is not a language type package
07:44:14:358 : DEBUG: Package_for_KB2511455 is not a language type package
07:44:14:482 : DEBUG: Package_for_KB2518866 is not a language type package
07:44:14:607 : DEBUG: Package_for_KB2522422 is not a language type package
07:44:14:732 : DEBUG: Package_for_KB2524375 is not a language type package
07:44:14:857 : DEBUG: Package_for_KB2525694 is not a language type package
07:44:14:982 : DEBUG: Package_for_KB2530548 is not a language type package
07:44:15:106 : DEBUG: Package_for_KB2532531 is not a language type package
07:44:15:231 : DEBUG: Package_for_KB2533623 is not a language type package
07:44:15:356 : DEBUG: Package_for_KB2535512 is not a language type package
07:44:15:481 : DEBUG: Package_for_KB2536275 is not a language type package
07:44:15:606 : DEBUG: Package_for_KB2536276 is not a language type package
07:44:15:730 : DEBUG: Package_for_KB2539633 is not a language type package
07:44:15:855 : DEBUG: Package_for_KB2541763 is not a language type package
07:44:15:980 : DEBUG: Package_for_KB2544521 is not a language type package
07:44:16:136 : DEBUG: Package_for_KB2544893 is not a language type package
07:44:16:261 : DEBUG: Package_for_KB2545698 is not a language type package
07:44:16:386 : DEBUG: Package_for_KB2555917 is not a language type package
07:44:16:510 : DEBUG: Package_for_KB2556532 is not a language type package
07:44:16:635 : DEBUG: Package_for_KB2559049 is not a language type package
07:44:16:760 : DEBUG: Package_for_KB2562937 is not a language type package
07:44:16:885 : DEBUG: Package_for_KB2563227 is not a language type package
07:44:17:010 : DEBUG: Package_for_KB2563894 is not a language type package
07:44:17:134 : DEBUG: Package_for_KB2564958 is not a language type package
07:44:17:259 : DEBUG: Package_for_KB2567053 is not a language type package
07:44:17:384 : DEBUG: Package_for_KB2567680 is not a language type package
07:44:17:509 : DEBUG: Package_for_KB2570791 is not a language type package
07:44:17:634 : DEBUG: Package_for_KB2570947 is not a language type package
07:44:17:758 : DEBUG: Package_for_KB2572075 is not a language type package
07:44:17:883 : DEBUG: Package_for_KB2579686 is not a language type package
07:44:18:008 : DEBUG: Package_for_KB2584146 is not a language type package
07:44:18:133 : DEBUG: Package_for_KB2585542 is not a language type package
07:44:18:289 : DEBUG: Package_for_KB2586448 is not a language type package
07:44:18:414 : DEBUG: Package_for_KB2588516 is not a language type package
07:44:18:601 : DEBUG: Package_for_KB2598479 is not a language type package
07:44:18:726 : DEBUG: Package_for_KB2598845 is not a language type package
07:44:18:850 : DEBUG: Package_for_KB2604094 is not a language type package
07:44:18:975 : DEBUG: Package_for_KB2604105 is not a language type package
07:44:19:100 : DEBUG: Package_for_KB2607712 is not a language type package
07:44:19:225 : DEBUG: Package_for_KB2616676 is not a language type package
07:44:19:350 : DEBUG: Package_for_KB2618444 is not a language type package
07:44:19:474 : DEBUG: Package_for_KB2618451 is not a language type package
07:44:19:599 : DEBUG: Package_for_KB2619339 is not a language type package
07:44:19:724 : DEBUG: Package_for_KB2620704 is not a language type package
07:44:19:849 : DEBUG: Package_for_KB2620712 is not a language type package
07:44:19:974 : DEBUG: Package_for_KB2621440 is not a language type package
07:44:20:098 : DEBUG: Package_for_KB2631813 is not a language type package
07:44:20:254 : DEBUG: Package_for_KB2632503 is not a language type package
07:44:20:379 : DEBUG: Package_for_KB2633874 is not a language type package
07:44:20:504 : DEBUG: Package_for_KB2633952 is not a language type package
07:44:20:629 : DEBUG: Package_for_KB2639417 is not a language type package
07:44:20:754 : DEBUG: Package_for_KB2641653 is not a language type package
07:44:20:878 : DEBUG: Package_for_KB2641690 is not a language type package
07:44:21:003 : DEBUG: Package_for_KB2644615 is not a language type package
07:44:21:128 : DEBUG: Package_for_KB2645640 is not a language type package
07:44:21:253 : DEBUG: Package_for_KB2646524 is not a language type package
07:44:21:378 : DEBUG: Package_for_KB2647516 is not a language type package
07:44:21:502 : DEBUG: Package_for_KB2647518 is not a language type package
07:44:21:627 : DEBUG: Package_for_KB2653956 is not a language type package
07:44:21:752 : DEBUG: Package_for_KB2654428 is not a language type package
07:44:21:877 : DEBUG: Package_for_KB2655992 is not a language type package
07:44:22:002 : DEBUG: Package_for_KB2656362 is not a language type package
07:44:22:126 : DEBUG: Package_for_KB2656374 is not a language type package
07:44:22:282 : DEBUG: Package_for_KB2656409 is not a language type package
07:44:22:407 : DEBUG: Package_for_KB2658846 is not a language type package
07:44:22:532 : DEBUG: Package_for_KB2659262 is not a language type package
07:44:22:813 : DEBUG: Package_for_KB2660465 is not a language type package
07:44:23:156 : DEBUG: Package_for_KB2660649 is not a language type package
07:44:23:343 : DEBUG: Package_for_KB2661254 is not a language type package
07:44:23:468 : DEBUG: Package_for_KB2665364 is not a language type package
07:44:23:593 : DEBUG: Package_for_KB2675157 is not a language type package
07:44:23:718 : DEBUG: Package_for_KB2676562 is not a language type package
07:44:23:842 : DEBUG: Package_for_KB2677070 is not a language type package
07:44:23:967 : DEBUG: Package_for_KB2679255 is not a language type package
07:44:24:092 : DEBUG: Package_for_KB2685939 is not a language type package
07:44:24:217 : DEBUG: Package_for_KB2686833 is not a language type package
07:44:24:373 : DEBUG: Package_for_KB2688338 is not a language type package
07:44:24:498 : DEBUG: Package_for_KB2690533 is not a language type package
07:44:24:700 : DEBUG: Package_for_KB2691442 is not a language type package
07:44:24:841 : DEBUG: Package_for_KB2695962 is not a language type package
07:44:24:966 : DEBUG: Package_for_KB2698365 is not a language type package
07:44:25:090 : DEBUG: Package_for_KB2699988 is not a language type package
07:44:25:215 : DEBUG: Package_for_KB2705219 is not a language type package
07:44:25:371 : DEBUG: Package_for_KB2709162 is not a language type package
07:44:25:496 : DEBUG: Package_for_KB2712808 is not a language type package
07:44:25:621 : DEBUG: Package_for_KB2718523 is not a language type package
07:44:25:746 : DEBUG: Package_for_KB2718704 is not a language type package
07:44:25:886 : DEBUG: Package_for_KB2719177 is not a language type package
07:44:26:900 : DEBUG: Package_for_KB2719985 is not a language type package
07:44:27:025 : DEBUG: Package_for_KB2722913 is not a language type package
07:44:27:150 : DEBUG: Package_for_KB2724197 is not a language type package
07:44:27:274 : DEBUG: Package_for_KB2727528 is not a language type package
07:44:27:399 : DEBUG: Package_for_KB2729453 is not a language type package
07:44:27:524 : DEBUG: Package_for_KB2731847 is not a language type package
07:44:27:649 : DEBUG: Package_for_KB2736233 is not a language type package
07:44:27:774 : DEBUG: Package_for_KB2742601 is not a language type package
07:44:27:898 : DEBUG: Package_for_KB2744842 is not a language type package
07:44:28:023 : DEBUG: Package_for_KB2748349 is not a language type package
07:44:28:164 : DEBUG: Package_for_KB2749655 is not a language type package
07:44:28:273 : DEBUG: Package_for_KB2753842 is not a language type package
07:44:28:429 : DEBUG: Package_for_KB2756822 is not a language type package
07:44:28:616 : DEBUG: Package_for_KB2756919 is not a language type package
07:44:28:741 : DEBUG: Package_for_KB2757638 is not a language type package
07:44:28:866 : DEBUG: Package_for_KB2758857 is not a language type package
07:44:29:037 : DEBUG: Package_for_KB2761226 is not a language type package
07:44:29:146 : DEBUG: Package_for_KB2761451 is not a language type package
07:44:29:287 : DEBUG: Package_for_KB2761465 is not a language type package
07:44:29:396 : DEBUG: Package_for_KB2763674 is not a language type package
07:44:29:536 : DEBUG: Package_for_KB2770660 is not a language type package
07:44:29:646 : DEBUG: Package_for_KB2778344 is not a language type package
07:44:29:770 : DEBUG: Package_for_KB2778930 is not a language type package
07:44:29:911 : DEBUG: Package_for_KB2779030 is not a language type package
07:44:30:036 : DEBUG: Package_for_KB2779562 is not a language type package
07:44:30:176 : DEBUG: Package_for_KB2780091 is not a language type package
07:44:30:301 : DEBUG: Package_for_KB2785220 is not a language type package
07:44:30:426 : DEBUG: Package_for_KB2789646 is not a language type package
07:44:30:550 : DEBUG: Package_for_KB2790655 is not a language type package
07:44:30:675 : DEBUG: Package_for_KB2792100 is not a language type package
07:44:30:816 : DEBUG: Package_for_KB2797052 is not a language type package
07:44:30:925 : DEBUG: Package_for_KB2799494 is not a language type package
07:44:31:050 : DEBUG: Package_for_KB2803821 is not a language type package
07:44:31:190 : DEBUG: Package_for_KB2804580 is not a language type package
07:44:31:299 : DEBUG: Package_for_KB2807986 is not a language type package
07:44:31:424 : DEBUG: Package_for_KB2808679 is not a language type package
07:44:31:549 : DEBUG: Package_for_KB2808735 is not a language type package
07:44:31:674 : DEBUG: Package_for_KB2809289 is not a language type package
07:44:31:830 : DEBUG: Package_for_KB2813170 is not a language type package
07:44:32:079 : DEBUG: Package_for_KB2813345 is not a language type package
07:44:32:204 : DEBUG: Package_for_KB2813430 is not a language type package
07:44:32:329 : DEBUG: Package_for_KB2817183 is not a language type package
07:44:32:454 : DEBUG: Package_for_KB2820197 is not a language type package
07:44:33:202 : DEBUG: Package_for_KB2820917 is not a language type package
07:44:33:624 : DEBUG: Package_for_KB2829361 is not a language type package
07:44:35:215 : DEBUG: Package_for_KB2829530 is not a language type package
07:44:35:948 : DEBUG: Package_for_KB2830290 is not a language type package
07:44:39:208 : DEBUG: Package_for_KB2832412 is not a language type package
07:44:39:380 : DEBUG: Package_for_KB2833947 is not a language type package
07:44:41:112 : DEBUG: Package_for_KB2834886 is not a language type package
07:44:41:767 : DEBUG: Package_for_KB2835361 is not a language type package
07:44:41:845 : DEBUG: Package_for_KB2835364 is not a language type package
07:44:41:985 : DEBUG: Package_for_KB2838727 is not a language type package
07:44:42:110 : DEBUG: Package_for_KB2839894 is not a language type package
07:44:42:235 : DEBUG: Package_for_KB2840149 is not a language type package
07:44:42:360 : DEBUG: Package_for_KB2844287 is not a language type package
07:44:42:921 : DEBUG: Package_for_KB2845187 is not a language type package
07:44:43:046 : DEBUG: Package_for_KB2845690 is not a language type package
07:44:43:186 : DEBUG: Package_for_KB2846071 is not a language type package
07:44:43:296 : DEBUG: Package_for_KB2847204 is not a language type package
07:44:43:436 : DEBUG: Package_for_KB2847311 is not a language type package
07:44:43:608 : DEBUG: Package_for_KB2849470 is not a language type package
07:44:43:764 : DEBUG: Package_for_KB2850851 is not a language type package
07:44:43:888 : DEBUG: Package_for_KB2855844 is not a language type package
07:44:44:013 : DEBUG: Package_for_KB2859537 is not a language type package
07:44:44:154 : DEBUG: Package_for_KB2861190 is not a language type package
07:44:44:294 : DEBUG: Package_for_KB2861855 is not a language type package
07:44:44:403 : DEBUG: Package_for_KB2862152 is not a language type package
07:44:44:528 : DEBUG: Package_for_KB2862330 is not a language type package
07:44:44:668 : DEBUG: Package_for_KB2862335 is not a language type package
07:44:44:809 : DEBUG: Package_for_KB2862772 is not a language type package
07:44:44:949 : DEBUG: Package_for_KB2862966 is not a language type package
07:44:45:074 : DEBUG: Package_for_KB2862973 is not a language type package
07:44:45:199 : DEBUG: Package_for_KB2863058 is not a language type package
07:44:45:370 : DEBUG: Package_for_KB2863253 is not a language type package
07:44:45:495 : DEBUG: Package_for_KB2864058 is not a language type package
07:44:45:604 : DEBUG: Package_for_KB2864063 is not a language type package
07:44:45:870 : DEBUG: Package_for_KB2864202 is not a language type package
07:44:46:026 : DEBUG: Package_for_KB2868038 is not a language type package
07:44:46:166 : DEBUG: Package_for_KB2868623 is not a language type package
07:44:46:291 : DEBUG: Package_for_KB2868626 is not a language type package
07:44:46:431 : DEBUG: Package_for_KB2870699 is not a language type package
07:44:46:556 : DEBUG: Package_for_KB2875783 is not a language type package
07:44:46:728 : DEBUG: Package_for_KB2876284 is not a language type package
07:44:46:868 : DEBUG: Package_for_KB2876315 is not a language type package
07:44:47:008 : DEBUG: Package_for_KB2876331 is not a language type package
07:44:47:164 : DEBUG: Package_for_KB2879017 is not a language type package
07:44:47:305 : DEBUG: Package_for_KB2883150 is not a language type package
07:44:47:430 : DEBUG: Package_for_KB2884256 is not a language type package
07:44:47:539 : DEBUG: Package_for_KB2887069 is not a language type package
07:44:47:710 : DEBUG: Package_for_KB2888505 is not a language type package
07:44:47:835 : DEBUG: Package_for_KB2892075 is not a language type package
07:44:48:225 : DEBUG: Package_for_KB2893294 is not a language type package
07:44:48:334 : DEBUG: Package_for_KB2893984 is not a language type package
07:44:48:459 : DEBUG: Package_for_KB2898785 is not a language type package
07:44:48:646 : DEBUG: Package_for_KB2898858 is not a language type package
07:44:48:834 : DEBUG: Package_for_KB2900986 is not a language type package
07:44:48:990 : DEBUG: Package_for_KB2901113 is not a language type package
07:44:49:161 : DEBUG: Package_for_KB2901674 is not a language type package
07:44:49:302 : DEBUG: Package_for_KB2904266 is not a language type package
07:44:49:473 : DEBUG: Package_for_KB2909921 is not a language type package
07:44:49:660 : DEBUG: Package_for_KB2911502 is not a language type package
07:44:49:785 : DEBUG: Package_for_KB2916036 is not a language type package
07:44:49:957 : DEBUG: Package_for_KB2922229 is not a language type package
07:44:50:097 : DEBUG: Package_for_KB2925418 is not a language type package
07:44:50:269 : DEBUG: Package_for_KB2926765 is not a language type package
07:44:50:409 : DEBUG: Package_for_KB2929733 is not a language type package
07:44:50:565 : DEBUG: Package_for_KB2929961 is not a language type package
07:44:50:784 : DEBUG: Package_for_KB2930275 is not a language type package
07:44:50:924 : DEBUG: Package_for_KB2931354 is not a language type package
07:44:51:080 : DEBUG: Package_for_KB2936068 is not a language type package
07:44:51:174 : DEBUG: Package_for_KB2953522 is not a language type package
07:44:51:361 : DEBUG: Package_for_KB2964358 is not a language type package
07:44:51:517 : DEBUG: Package_for_KB905866 is not a language type package
07:44:51:673 : DEBUG: Package_for_KB935509 is not a language type package
07:44:51:798 : DEBUG: Package_for_KB937287 is not a language type package
07:44:51:985 : DEBUG: Package_for_KB938371 is not a language type package
07:44:52:125 : DEBUG: Package_for_KB938464 is not a language type package
07:44:52:266 : DEBUG: Package_for_KB941693 is not a language type package
07:44:52:375 : DEBUG: Package_for_KB947864 is not a language type package
07:44:52:515 : DEBUG: Package_for_KB948590 is not a language type package
07:44:52:765 : DEBUG: Package_for_KB948609 is not a language type package
07:44:52:874 : DEBUG: Package_for_KB948610 is not a language type package
07:44:53:014 : DEBUG: Package_for_KB948881 is not a language type package
07:44:53:139 : DEBUG: Package_for_KB949246 is not a language type package
07:44:53:373 : DEBUG: Package_for_KB949247 is not a language type package
07:44:53:545 : DEBUG: Package_for_KB950124 is not a language type package
07:44:53:763 : DEBUG: Package_for_KB950125 is not a language type package
07:44:53:888 : DEBUG: Package_for_KB950760 is not a language type package
07:44:54:013 : DEBUG: Package_for_KB950762 is not a language type package
07:44:54:138 : DEBUG: Package_for_KB950974 is not a language type package
07:44:54:262 : DEBUG: Package_for_KB951066 is not a language type package
07:44:54:387 : DEBUG: Package_for_KB951376 is not a language type package
07:44:54:512 : DEBUG: Package_for_KB951698 is not a language type package
07:44:54:652 : DEBUG: Package_for_KB951978 is not a language type package
07:44:54:824 : DEBUG: Package_for_KB952004 is not a language type package
07:44:54:949 : DEBUG: Package_for_KB952069 is not a language type package
07:44:55:058 : DEBUG: Package_for_KB952287 is not a language type package
07:44:55:214 : DEBUG: Package_for_KB952709 is not a language type package
07:44:55:323 : DEBUG: Package_for_KB953155 is not a language type package
07:44:55:448 : DEBUG: Package_for_KB953733 is not a language type package
07:44:55:573 : DEBUG: Package_for_KB954154 is not a language type package
07:44:55:729 : DEBUG: Package_for_KB954155 is not a language type package
07:44:55:978 : DEBUG: Package_for_KB954459 is not a language type package
07:44:56:088 : DEBUG: Package_for_KB955020 is not a language type package
07:44:56:212 : DEBUG: Package_for_KB955069 is not a language type package
07:44:56:384 : DEBUG: Package_for_KB955302 is not a language type package
07:44:56:493 : DEBUG: Package_for_KB955430 is not a language type package
07:44:56:618 : DEBUG: Package_for_KB955839 is not a language type package
07:44:56:805 : DEBUG: Package_for_KB956250 is not a language type package
07:44:56:961 : DEBUG: Package_for_KB956572 is not a language type package
07:44:57:086 : DEBUG: Package_for_KB956744 is not a language type package
07:44:57:211 : DEBUG: Package_for_KB956802 is not a language type package
07:44:57:382 : DEBUG: Package_for_KB957097 is not a language type package
07:44:57:492 : DEBUG: Package_for_KB957200 is not a language type package
07:44:57:679 : DEBUG: Package_for_KB957321 is not a language type package
07:44:57:850 : DEBUG: Package_for_KB957388 is not a language type package
07:44:57:975 : DEBUG: Package_for_KB958481 is not a language type package
07:44:58:116 : DEBUG: Package_for_KB958483 is not a language type package
07:44:58:272 : DEBUG: Package_for_KB958623 is not a language type package
07:44:58:521 : DEBUG: Package_for_KB958624 is not a language type package
07:44:58:708 : DEBUG: Package_for_KB958644 is not a language type package
07:44:58:880 : DEBUG: Package_for_KB958687 is not a language type package
07:44:59:020 : DEBUG: Package_for_KB959108 is not a language type package
07:44:59:161 : DEBUG: Package_for_KB959130 is not a language type package
07:44:59:286 : DEBUG: Package_for_KB959426 is not a language type package
07:44:59:395 : DEBUG: Package_for_KB960225 is not a language type package
07:44:59:520 : DEBUG: Package_for_KB960803 is not a language type package
07:44:59:660 : DEBUG: Package_for_KB961371 is not a language type package
07:44:59:816 : DEBUG: Package_for_KB961501 is not a language type package
07:44:59:925 : DEBUG: Package_for_KB967190 is not a language type package
07:45:00:066 : DEBUG: Package_for_KB967632 is not a language type package
07:45:00:222 : DEBUG: Package_for_KB967723 is not a language type package
07:45:00:534 : DEBUG: Package_for_KB968389 is not a language type package
07:45:00:674 : DEBUG: Package_for_KB968537 is not a language type package
07:45:00:799 : DEBUG: Package_for_KB968816 is not a language type package
07:45:00:939 : DEBUG: Package_for_KB969058 is not a language type package
07:45:01:080 : DEBUG: Package_for_KB969897 is not a language type package
07:45:01:189 : DEBUG: Package_for_KB969897 is not a language type package
07:45:01:314 : DEBUG: Package_for_KB969898 is not a language type package
07:45:01:454 : DEBUG: Package_for_KB969947 is not a language type package
07:45:01:579 : DEBUG: Package_for_KB970238 is not a language type package
07:45:01:719 : DEBUG: Package_for_KB970430 is not a language type package
07:45:01:828 : DEBUG: Package_for_KB970653 is not a language type package
07:45:01:969 : DEBUG: Package_for_KB970710 is not a language type package
07:45:02:203 : DEBUG: Package_for_KB971029 is not a language type package
07:45:02:328 : DEBUG: Package_for_KB971468 is not a language type package
07:45:02:452 : DEBUG: Package_for_KB971486 is not a language type package
07:45:02:577 : DEBUG: Package_for_KB971557 is not a language type package
07:45:02:686 : DEBUG: Package_for_KB971657 is not a language type package
07:45:02:842 : DEBUG: Package_for_KB971737 is not a language type package
07:45:02:983 : DEBUG: Package_for_KB971930 is not a language type package
07:45:03:108 : DEBUG: Package_for_KB971961 is not a language type package
07:45:03:232 : DEBUG: Package_for_KB972036 is not a language type package
07:45:03:357 : DEBUG: Package_for_KB972145 is not a language type package
07:45:03:482 : DEBUG: Package_for_KB972260 is not a language type package
07:45:03:716 : DEBUG: Package_for_KB972270 is not a language type package
07:45:03:888 : DEBUG: Package_for_KB972636 is not a language type package
07:45:04:012 : DEBUG: Package_for_KB973346 is not a language type package
07:45:04:137 : DEBUG: Package_for_KB973507 is not a language type package
07:45:04:278 : DEBUG: Package_for_KB973525 is not a language type package
07:45:04:418 : DEBUG: Package_for_KB973540 is not a language type package
07:45:04:558 : DEBUG: Package_for_KB973565 is not a language type package
07:45:04:683 : DEBUG: Package_for_KB973687 is not a language type package
07:45:04:824 : DEBUG: Package_for_KB973768 is not a language type package
07:45:04:933 : DEBUG: Package_for_KB973874 is not a language type package
07:45:05:136 : DEBUG: Package_for_KB973917 is not a language type package
07:45:05:260 : DEBUG: Package_for_KB974145 is not a language type package
07:45:05:370 : DEBUG: Package_for_KB974306 is not a language type package
07:45:05:526 : DEBUG: Package_for_KB974318 is not a language type package
07:45:05:666 : DEBUG: Package_for_KB974455 is not a language type package
07:45:05:791 : DEBUG: Package_for_KB974470 is not a language type package
07:45:05:978 : DEBUG: Package_for_KB974571 is not a language type package
07:45:06:103 : DEBUG: Package_for_KB975364 is not a language type package
07:45:06:228 : DEBUG: Package_for_KB975467 is not a language type package
07:45:06:384 : DEBUG: Package_for_KB975517 is not a language type package
07:45:06:508 : DEBUG: Package_for_KB975558 is not a language type package
07:45:06:633 : DEBUG: Package_for_KB975560 is not a language type package
07:45:06:758 : DEBUG: Package_for_KB975561 is not a language type package
07:45:06:945 : DEBUG: Package_for_KB975929 is not a language type package
07:45:07:101 : DEBUG: Package_for_KB976002 is not a language type package
07:45:07:273 : DEBUG: Package_for_KB976098 is not a language type package
07:45:07:398 : DEBUG: Package_for_KB976264 is not a language type package
07:45:07:554 : DEBUG: Package_for_KB976325 is not a language type package
07:45:07:694 : DEBUG: Package_for_KB976470 is not a language type package
07:45:07:803 : DEBUG: Package_for_KB976662 is not a language type package
07:45:07:990 : DEBUG: Package_for_KB976749 is not a language type package
07:45:08:131 : DEBUG: Package_for_KB976768 is not a language type package
07:45:08:318 : DEBUG: Package_for_KB976772 is not a language type package
07:45:08:474 : DEBUG: Package_for_KB977165 is not a language type package
07:45:08:786 : DEBUG: Package_for_KB977816 is not a language type package
07:45:08:942 : DEBUG: Package_for_KB978207 is not a language type package
07:45:09:192 : DEBUG: Package_for_KB978251 is not a language type package
07:45:09:441 : DEBUG: Package_for_KB978262 is not a language type package
07:45:09:660 : DEBUG: Package_for_KB978338 is not a language type package
07:45:09:878 : DEBUG: Package_for_KB978506 is not a language type package
07:45:11:688 : DEBUG: Package_for_KB978542 is not a language type package
07:45:11:812 : DEBUG: Package_for_KB978601 is not a language type package
07:45:11:968 : DEBUG: Package_for_KB978886 is not a language type package
07:45:12:093 : DEBUG: Package_for_KB979099 is not a language type package
07:45:12:249 : DEBUG: Package_for_KB979306 is not a language type package
07:45:12:390 : DEBUG: Package_for_KB979309 is not a language type package
07:45:12:561 : DEBUG: Package_for_KB979482 is not a language type package
07:45:12:702 : DEBUG: Package_for_KB979559 is not a language type package
07:45:12:873 : DEBUG: Package_for_KB979683 is not a language type package
07:45:13:045 : DEBUG: Package_for_KB979687 is not a language type package
07:45:13:201 : DEBUG: Package_for_KB979688 is not a language type package
07:45:13:341 : DEBUG: Package_for_KB979899 is not a language type package
07:45:13:482 : DEBUG: Package_for_KB979910 is not a language type package
07:45:13:669 : DEBUG: Package_for_KB980182 is not a language type package
07:45:13:950 : DEBUG: Package_for_KB980195 is not a language type package
07:45:14:230 : DEBUG: Package_for_KB980218 is not a language type package
07:45:14:355 : DEBUG: Package_for_KB980232 is not a language type package
07:45:14:496 : DEBUG: Package_for_KB980248 is not a language type package
07:45:14:652 : DEBUG: Package_for_KB980302 is not a language type package
07:45:14:792 : DEBUG: Package_for_KB980436 is not a language type package
07:45:14:948 : DEBUG: Package_for_KB980842 is not a language type package
07:45:15:073 : DEBUG: Package_for_KB981322 is not a language type package
07:45:15:198 : DEBUG: Package_for_KB981332 is not a language type package
07:45:15:338 : DEBUG: Package_for_KB981793 is not a language type package
07:45:15:478 : DEBUG: Package_for_KB981852 is not a language type package
07:45:15:603 : DEBUG: Package_for_KB981957 is not a language type package
07:45:15:728 : DEBUG: Package_for_KB981997 is not a language type package
07:45:15:868 : DEBUG: Package_for_KB982132 is not a language type package
07:45:16:009 : DEBUG: Package_for_KB982214 is not a language type package
07:45:16:149 : DEBUG: Package_for_KB982381 is not a language type package
07:45:16:258 : DEBUG: Package_for_KB982480 is not a language type package
07:45:16:383 : DEBUG: Package_for_KB982519 is not a language type package
07:45:16:524 : DEBUG: Package_for_KB982632 is not a language type package
07:45:16:664 : DEBUG: Package_for_KB982664 is not a language type package
07:45:16:789 : DEBUG: Package_for_KB982665 is not a language type package
07:45:16:914 : DEBUG: Package_for_KB982799 is not a language type package
07:45:17:054 : DEBUG: Package_for_KB983589 is not a language type package
07:45:17:194 : DEBUG: VistaSP2-KB948465 is not a language type package
07:45:17:319 : DEBUG: Windows-Management-Framework-Core-TopLevel is not a language type package
07:45:17:460 : DEBUG: ws4-update-TopLevel is not a language type package
07:45:17:600 : DEBUG: WUClient-SelfUpdate-ActiveX is not a language type package
07:45:17:740 : DEBUG: WUClient-SelfUpdate-ActiveX is not a language type package
07:45:17:896 : DEBUG: WUClient-SelfUpdate-ActiveX is not a language type package
07:45:18:037 : DEBUG: WUClient-SelfUpdate-ActiveX is not a language type package
07:45:18:162 : DEBUG: WUClient-SelfUpdate-Aux-TopLevel is not a language type package
07:45:18:286 : DEBUG: WUClient-SelfUpdate-Aux-TopLevel is not a language type package
07:45:18:427 : DEBUG: WUClient-SelfUpdate-Aux-TopLevel is not a language type package
07:45:18:567 : DEBUG: WUClient-SelfUpdate-Aux-TopLevel is not a language type package
07:45:18:723 : DEBUG: WUClient-SelfUpdate-Core-TopLevel is not a language type package
07:45:18:864 : DEBUG: WUClient-SelfUpdate-Core-TopLevel is not a language type package
07:45:19:098 : DEBUG: WUClient-SelfUpdate-Core-TopLevel is not a language type package
07:45:19:456 : DEBUG: WUClient-SelfUpdate-Core-TopLevel is not a language type package
07:45:19:644 : PERF: Enumerating installed languages - LEAVE
07:45:19:846 : Error found in call to ProcessUnattendedArguments: 0x80070032
07:45:19:971 : ExitProcess: There was an internal error: 0x80070032
07:45:20:127 : PERF: RestorePointEnd - ENTER
07:45:20:268 : PERF: RestorePointEnd - LEAVE
07:45:22:358 : DEBUG: Cleaning working path in a new process

Tante google sagt, dass dies ist ein bekanntes Vista Problem sein soll und sollte eigentlich nicht stören. Hat es bisher auch nicht, weil es diesen Temp Ordner mit den ganzen Meldungen nicht gab.
Könnte ich denn einfach irgendwie den Task "lpremove" deaktivieren? Hatte das im Netz gelesen und soll angeblich helfen....
Weißt du was genaueres, warum seit "combofix" diese ganzen Einträge, die immer mehr werden plötzlich den Temp Ordner füllen und auch wahrscheinlich die Festplatte zum durchdrehen bringen?



Ach und ich habe noch die Ordner "FRST" und "AdwCleaner" und "ERUNT" unter C: gefunden die noch einiges enthalten. Sind beide "schreibgeschützt" Soll ich die einfach in den Papierkorb schmeißen?



Des Weiteren hat sich am 5.6.2014 unter "AppData"---"roaming" folgender Ordner unter "Adobe" gebildet. Ordner nennt sich "Flash Player" mit dem Unterordner "AssetCache" und diversen Einträgen wie z.b.
Code:

B26751D6A80EB1FCB651912469AE18819AB.heu
oder
Code:

381814F6F5270FFBB27E244D6138BC023AF911D5.swz
Wenn man google danach fragt, erscheinen sehr oft irgendwelche Geschichte, die mit virus, backdoor etc. zu tun haben. Muss ich mir jetzt doch noch Sorgen machen?????


Und zu guter Letzt, möchtest du noch ein letztes frisches frst log zur Endkontrolle?

Vielen Dank!!

schrauber 12.06.2014 09:03

Deinstalliere den Flashplayer, lösch den kompletten Ordner, und installiere ihn neu.

Hast Du Delfix schon laufen lassen?

Gepetto1 12.06.2014 09:45

Hi,
flash player deinstalliert und neu installiert. Hat wieder deisen Ordner erstellt. Ist ja dann wohl normal oder?

Delfix hatte ich schon laufen lassen siehe weiter oben oder auch hier
Code:

# DelFix v10.7 - Datei am 10/06/2014 um 18:34:43 erstellt
# Aktualisiert am 27/04/2014 von Xplode
# Benutzer : Philipp - PHILIPP-PC
# Betriebssystem : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)

~ Aktiviere die Benutzerkontensteuerung ... OK

~ Entferne die Bereinigungsprogramme ...

Gelöscht : C:\32788R22FWJFW
Gelöscht : C:\Combofix
Gelöscht : C:\FRST
Gelöscht : C:\AdwCleaner
Gelöscht : C:\Users\Philipp\Desktop\FRST-OlderVersion
Gelöscht : C:\ComboFix.txt
Gelöscht : C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
Gelöscht : C:\Users\Philipp\Desktop\FRST64.exe
Gelöscht : C:\Users\Philipp\Desktop\JRT.exe
Gelöscht : C:\Users\Philipp\Desktop\MiniToolBox.exe
Gelöscht : C:\Users\Philipp\Desktop\SecurityCheck.exe
Gelöscht : C:\Windows\NIRCMD.exe
Gelöscht : HKLM\SOFTWARE\AdwCleaner
Gelöscht : HKLM\SOFTWARE\Swearware
Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

~ Erstelle ein Backup der Registrierungsdatenbank ... OK

~ Lösche die Wiederherstellungspunkte ...


Ein neuer Wiederherstellungspunkt wurde erstellt !

~ Stelle die Systemeinstellungen wieder her ... OK

########## - EOF - ##########

Aber ich habe den Eindruck, dass es nicht wirklich das alles gelöscht hat. Sonst wären die ganzen Ordner ja nicht noch da, oder?
Den Ordner C:\32788R22FWJFW gibt es auch noch. Inhalt leer. Aber schreibgeschüzt. Hat delfix also auch nicht gelöscht. Auch ist noch die txt Datei con Combofix unter C:. Also auch nicht gelöscht.
Keine Ahnung ob dann überhaupt auch diese Einträge
Code:

HKLM\SOFTWARE\AdwCleaner
Gelöscht : HKLM\SOFTWARE\Swearware
Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

überhaupt auch gelöscht wurden, wie angeblich von Delfix gemeldet.
Soll ich die nun einfach alle in den Papierkorb schmeißen?
Und seit dem Lauf mit Combofix am 30.5. habe ich eine unter "windows" eine system.ini mit folgendem Inhalt
Code:

; for 16-bit app support
[386Enh]
woafont=dosapp.fon
EGA80WOA.FON=EGA80WOA.FON
EGA40WOA.FON=EGA40WOA.FON
CGA80WOA.FON=CGA80WOA.FON
CGA40WOA.FON=CGA40WOA.FON
[drivers]
wave=mmdrv.dll
timer=timer.drv
[mci]

Was soll das denn nun?

Und leider ist mir noch was aufgefallen.
1 Tag bevor ich mich hier gemeldet habe, hatte ich ja mal spybot laufen lassen, aber habe nichts machen lassen. Sondern es nach dem ersten Suchlauf gleich wieder deinstalliert.
Nun habe ich aber folgende wininit.inf unter "windows", die an dem Tag erstellt worden ist, als ich spybot laufen hab lassen.
Code:

[rename]
NUL=C:\Program Files (x86)\Spybot - Search & Destroy 2\av\smartdb-ntfs.db

und auch noch den folgenden Ordner unter "programData"---- "spybot searchh&destroy"
mit einigen Unterordnern.Ich dachte ich hätte es komplett deinstalliert???
Es taucht auch nicht mehr unter "programme installieren/deinstallieren auf.

Und wieso wurde unter "windows"--"system32" die Datei tcpip.sys am 5.4.2014 geändert??? Hat das vielleicht mit meinem eigentlichen Problem Netzwerkkonektivitätsproblem zu tun?
Wer oder was hat diese Datei denn geändert? Und warum?
EDIT: google hat ergeben, dass dies mit dem Sicherheitsupdate MS14-031 zu tun haben muss. Bzw. sollte. Hoffe damit ist diese Frage schon erledigt...

Und was sagst du dazu, dass seit combofix dieser Temp Ordner immer weiter mit diesen ganzen lpksetup.txt Dateien gefüllt wird?

schrauber 12.06.2014 11:44

Ich glaube nicht dass das mit Combofix zusammenhängt, auch wenn CF viele Standards wiederherstellt.

Die Reste der Tools kannste manuell löschen, ebenso die Reste von Spybot.

Gepetto1 12.06.2014 12:56

Hi,
habe alle Reste entfernt.
Dann hoffe ich mal, obwohl unter "Diagnose und Reparatur" immer noch steht, dass auf diesem Computer ein Netzwerkkonnektivitätsproblem besteht, dass mein Rechner soweit sauber ist!!

Wenn du magst, kannst du ja noch einmal kurz auf das letzte FRST log von vor 2 Tagen schauen und dein OK geben.


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-06-2014
Ran by Philipp (administrator) on PHILIPP-PC on 08-06-2014 15:47:43
Running from C:\Users\Philipp\Desktop
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CTxfispi.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
() C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [123400 2009-01-21] (Logitech Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA3FB10447E45CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  No File
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_37 - C:\Windows\SysWOW64\npdeployJava1.dll No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()

==================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-15] ()

==================== Drivers (Whitelisted) ====================

S4 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [154256 2007-08-10] (Promise Technology, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.)
S1 Beep; No ImagePath
S4 fttxr5_O; C:\Windows\system32\drivers\fttxr5_o.sys [230408 2007-10-25] (Promise Technology, Inc.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15680 2006-11-01] ()
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [160288 2008-04-07] (NVIDIA Corporation)
S3 SaiH0BAC; C:\Windows\System32\DRIVERS\SaiH0BAC.sys [176128 2007-07-13] (Saitek)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz131; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz131\cpuz_x64.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 lvpopf64; system32\DRIVERS\lvpopf64.sys [X]
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
S3 LVRS64; system32\DRIVERS\lvrs64.sys [X]
S3 LVUVC64; system32\DRIVERS\lvuvc64.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-08 15:47 - 2014-06-08 15:47 - 00009108 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-08 13:24 - 2014-06-08 13:25 - 00022917 _____ () C:\Users\Philipp\Desktop\Result.txt
2014-06-08 11:02 - 2014-06-08 11:01 - 00982016 _____ (Farbar) C:\Users\Philipp\Desktop\MiniToolBox.exe
2014-06-03 14:52 - 2014-06-03 14:52 - 00000884 _____ () C:\Users\Philipp\Desktop\eM Client.lnk
2014-06-03 14:04 - 2014-06-03 14:04 - 00003898 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401625260
2014-06-02 20:59 - 2014-06-08 13:24 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\eM Client
2014-06-02 20:58 - 2014-06-05 20:43 - 00000884 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2014-06-02 20:58 - 2014-06-05 20:43 - 00000000 ____D () C:\Program Files (x86)\eM Client
2014-06-02 20:56 - 2014-06-02 20:57 - 14995456 _____ () C:\Users\Philipp\Downloads\setup.msi
2014-06-02 15:31 - 2014-06-08 15:25 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-02 15:31 - 2014-06-02 15:31 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-02 15:31 - 2014-06-02 15:31 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-02 15:31 - 2014-06-02 15:31 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\Users\Philipp\Documents\Mail!!!!!
2014-06-02 14:09 - 2014-06-02 14:09 - 00001106 _____ () C:\Users\Philipp\Desktop\Revo Uninstaller.lnk
2014-06-02 14:09 - 2014-06-02 14:09 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-01 20:30 - 2014-06-01 20:30 - 00000000 ____D () C:\Users\Philipp\Documents\Local Folders
2014-06-01 14:21 - 2014-06-03 14:04 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-01 14:21 - 2014-06-01 14:21 - 00000846 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Opera Software
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Opera Software
2014-06-01 10:48 - 2014-06-07 11:01 - 00000000 ____D () C:\Users\Philipp\Desktop\FRST-OlderVersion
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-05-31 21:17 - 2014-05-31 21:17 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-05-31 21:16 - 2014-05-31 21:15 - 00854367 _____ () C:\Users\Philipp\Desktop\SecurityCheck.exe
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-06-08 15:47 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:17 - 2014-05-30 07:38 - 00000000 ____D () C:\Qoobox
2014-05-30 07:17 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-30 07:17 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-30 07:17 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-30 07:17 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-30 07:16 - 2014-05-30 07:37 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:16 - 2014-05-30 07:17 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-29 07:08 - 2014-06-08 15:47 - 00000000 ____D () C:\FRST
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 21:02 - 2014-06-07 11:01 - 02072576 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-05-28 21:02 - 2014-05-28 19:36 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 20:38 - 2014-06-05 20:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-28 20:38 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-28 20:38 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-28 19:37 - 2014-06-02 16:16 - 00000000 ____D () C:\AdwCleaner
2014-05-28 16:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:02 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 21:55 - 2014-05-27 22:29 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 21:55 - 2014-05-27 22:28 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 19:28 - 2014-05-06 02:46 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 19:28 - 2014-05-06 02:21 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 02:21 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 19:28 - 2014-05-06 01:32 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 19:28 - 2014-05-06 01:14 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 19:28 - 2014-05-06 01:14 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 19:01 - 2014-03-25 18:30 - 12900864 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 19:01 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys

==================== One Month Modified Files and Folders =======

2014-06-08 15:47 - 2014-06-08 15:47 - 00009108 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-08 15:47 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-06-08 15:47 - 2014-05-29 07:08 - 00000000 ____D () C:\FRST
2014-06-08 15:25 - 2014-06-02 15:31 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-08 15:17 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-08 15:17 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-08 14:59 - 2011-08-10 16:32 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-08 14:37 - 2012-05-31 17:52 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-08 13:25 - 2014-06-08 13:24 - 00022917 _____ () C:\Users\Philipp\Desktop\Result.txt
2014-06-08 13:24 - 2014-06-02 20:59 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\eM Client
2014-06-08 13:21 - 2009-07-10 14:09 - 01485671 _____ () C:\Windows\WindowsUpdate.log
2014-06-08 13:17 - 2011-08-10 16:32 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-08 13:17 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-08 13:16 - 2006-11-02 17:42 - 00032510 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-08 11:01 - 2014-06-08 11:02 - 00982016 _____ (Farbar) C:\Users\Philipp\Desktop\MiniToolBox.exe
2014-06-07 11:01 - 2014-06-01 10:48 - 00000000 ____D () C:\Users\Philipp\Desktop\FRST-OlderVersion
2014-06-07 11:01 - 2014-05-28 21:02 - 02072576 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-06-07 09:50 - 2011-12-13 19:22 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Paint.NET
2014-06-05 20:43 - 2014-06-02 20:58 - 00000884 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2014-06-05 20:43 - 2014-06-02 20:58 - 00000000 ____D () C:\Program Files (x86)\eM Client
2014-06-05 20:23 - 2014-05-28 20:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-03 19:15 - 2013-12-13 19:33 - 00001080 _____ () C:\Windows\system32\settingsbkup.sfm
2014-06-03 19:15 - 2013-12-13 19:33 - 00001080 _____ () C:\Windows\system32\settings.sfm
2014-06-03 18:43 - 2010-11-05 21:06 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-06-03 18:43 - 2010-11-05 21:03 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-06-03 18:43 - 2009-07-08 21:32 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-03 14:52 - 2014-06-03 14:52 - 00000884 _____ () C:\Users\Philipp\Desktop\eM Client.lnk
2014-06-03 14:04 - 2014-06-03 14:04 - 00003898 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401625260
2014-06-03 14:04 - 2014-06-01 14:21 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-02 20:57 - 2014-06-02 20:56 - 14995456 _____ () C:\Users\Philipp\Downloads\setup.msi
2014-06-02 19:56 - 2008-01-21 05:26 - 00846494 _____ () C:\Windows\PFRO.log
2014-06-02 19:54 - 2010-04-19 15:57 - 00008843 _____ () C:\Windows\system32\lvcoinst.log
2014-06-02 19:53 - 2010-04-19 15:56 - 00000000 ____D () C:\ProgramData\LogiShrd
2014-06-02 19:53 - 2009-07-22 15:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-06-02 16:16 - 2014-05-28 19:37 - 00000000 ____D () C:\AdwCleaner
2014-06-02 15:32 - 2009-07-10 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Adobe
2014-06-02 15:31 - 2014-06-02 15:31 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-02 15:31 - 2014-06-02 15:31 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-02 15:31 - 2014-06-02 15:31 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-02 15:31 - 2008-05-21 11:53 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\Users\Philipp\Documents\Mail!!!!!
2014-06-02 14:19 - 2009-07-10 20:41 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Mozilla
2014-06-02 14:09 - 2014-06-02 14:09 - 00001106 _____ () C:\Users\Philipp\Desktop\Revo Uninstaller.lnk
2014-06-02 14:09 - 2014-06-02 14:09 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-01 20:30 - 2014-06-01 20:30 - 00000000 ____D () C:\Users\Philipp\Documents\Local Folders
2014-06-01 14:21 - 2014-06-01 14:21 - 00000846 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Opera Software
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Opera Software
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-05-31 21:17 - 2014-05-31 21:17 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-05-31 21:15 - 2014-05-31 21:16 - 00854367 _____ () C:\Users\Philipp\Desktop\SecurityCheck.exe
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-31 07:23 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-05-30 07:39 - 2014-05-30 07:39 - 00010180 _____ () C:\cmb.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00010180 _____ () C:\ComboFix.txt
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:17 - 00000000 ____D () C:\Qoobox
2014-05-30 07:37 - 2014-05-30 07:16 - 00000000 ____D () C:\Windows\erdnt
2014-05-30 07:36 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-30 07:17 - 2014-05-30 07:16 - 00000000 ____D () C:\32788R22FWJFW
2014-05-30 07:14 - 2008-05-21 15:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-30 07:14 - 2008-05-21 15:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat
2014-05-30 07:14 - 2008-05-21 15:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat
2014-05-30 07:13 - 2014-05-30 07:13 - 05203398 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2014-05-28 21:13 - 2014-05-28 21:13 - 01016261 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 20:38 - 2014-05-28 20:38 - 00000948 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-05-28 20:38 - 2014-05-28 20:38 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-05-28 19:36 - 2014-05-28 21:02 - 01327971 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.211.exe
2014-05-28 14:01 - 2014-05-28 16:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:01 - 2014-05-28 14:02 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-27 23:15 - 2013-10-01 18:40 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Avg2014
2014-05-27 22:29 - 2014-05-27 21:55 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini
2014-05-27 22:28 - 2014-05-27 21:55 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-27 20:26 - 2014-05-27 20:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-19 18:56 - 2014-03-31 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-05-15 19:38 - 2009-07-08 21:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 19:34 - 2013-08-14 18:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 19:33 - 2006-11-02 14:35 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-28 20:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-28 20:38 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-10 18:55 - 2011-08-10 16:32 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-10 18:55 - 2011-08-10 16:32 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

Some content of TEMP:
====================
C:\Users\Philipp\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-06-08 13:24

==================== End Of Log ============================

--- --- ---
[/CODE]

Damit ich wieder endlich online-banking etc., ohne große Sorgen zu haben, durchführen kann.

Sag mal, kann ich eigentlich den "temp" Ordner unter AppData--Local löschen?
Da ist ne ganze Menge drin.
Oder sollte ich mal TFC downloaden? Ist das auch "idiotensicher"?? :)

Also ein abschließendes "go" deiner Seits würde mich sehr beruhigen!!

schrauber 13.06.2014 11:59

Die Ordner nicht löschen, nimm dazu TFC oder Ccleaner.

Passwörter ändern.

Zitat:

Dann hoffe ich mal, obwohl unter "Diagnose und Reparatur" immer noch steht, dass auf diesem Computer ein Netzwerkkonnektivitätsproblem besteht, dass mein Rechner soweit sauber ist!!
Hast Du denn auch Probleme mit der Konnektivität? Also merkst DU was?

Virentechnisch hast du das go :)

Gepetto1 13.06.2014 14:03

Hallo Schrauber,
Verbindungsabbrüche habe ich, seit ich Opera benutze, nicht mehr.

Aber folgende Eintragungen im Ereignisprotokoll habe ich gefunden.

Code:

Das Diagnosemodul {c8544339-5be9-4f25-862e-485f1b1a6935} (%SystemRoot%\system32\diagperf.dll) hat ein Problem für Szenario {86432a0b-3c7d-4ddf-a89c-172faa90485d},
Instanz {fd5bd75d-be01-49fe-a5ed-103e3c8e05a8}, ursprüngliche Aktivitäts-ID {86432a0b-3c7d-4ddf-a89c-172faa90485d} erkannt.

Code:

Das Diagnosemodul {c8544339-5be9-4f25-862e-485f1b1a6935} (%SystemRoot%\system32\diagperf.dll) hat die Problembehandlung für Szenario
{86432a0b-3c7d-4ddf-a89c-172faa90485d}, Instanz {fd5bd75d-be01-49fe-a5ed-103e3c8e05a8}, ursprüngliche Aktivitäts-ID {86432a0b-3c7d-4ddf-a89c-172faa90485d} abgeschlossen.
Das Diagnosemodul hat keine Lösung festgelegt.

Code:

Das Diagnosemodul {15fba3b8-a37a-4f91-bdba-fbb98fe804bf} (%SystemRoot%\system32\diagperf.dll) hat ein Problem für Szenario {2698178d-fdad-40ae-9d3c-1371703adc5b}, Instanz {37441c17-a547-4899-8889-6ee0c46c75a0},
ursprüngliche Aktivitäts-ID {2698178d-fdad-40ae-9d3c-1371703adc5b} erkannt.

Code:

Das Diagnosemodul {15fba3b8-a37a-4f91-bdba-fbb98fe804bf} (%SystemRoot%\system32\diagperf.dll) hat die Problembehandlung für Szenario {2698178d-fdad-40ae-9d3c-1371703adc5b}, Instanz {37441c17-a547-4899-8889-6ee0c46c75a0}, ursprüngliche Aktivitäts-ID {2698178d-fdad-40ae-9d3c-1371703adc5b} abgeschlossen.
Das Diagnosemodul hat keine Lösung festgelegt.

Code:

Das Diagnosemodul {bf2de437-b736-48fb-84a0-5f0c389a068e} (%windir%\system32\netdiagfx.dll) hat die Problembehandlung für Szenario
{c99981ee-27c3-4b63-9fca-c34f5cce580c}, Instanz {e7bcafa5-fde8-4458-a4b7-fdcbe4e439dd}, ursprüngliche Aktivitäts-ID {00000000-0000-0000-0000-000000000000} abgeschlossen.
Es hat die Lösung {bf2de437-b736-48fb-84a0-5f0c389a068e} für Benutzer NULL SID in Sitzung 1 mit Ablaufdatum 01.01.1601 00:00:00 festgelegt. Die Lösung wird sofort gestartet.

Code:

Der \SystemRoot\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\LVPr2M64.cat-Katalog konnte nicht geladen werden.
Diese Eintragungen mit diagpref.dll haben wohl alle mit
Code:

Subkey of registry key HKLM\SYSTEM\ControlSet001\Control\WDI\Scenarios
Subkey of registry key HKLM\SYSTEM\ControlSet003\Control\WDI\Scenarios
Subkey of registry key HKLM\SYSTEM\CurrentControlSet\Control\WDI\Scenarios

zu tun.

Was mich beunruhigt ist, wenn man bei google "wdi {86432a0b-3c7d-4ddf-a89c-172faa90485d}" eingibt, kommt haufenweise irgendwas von wegen backdoor, trojaner etc.!!!!

"root technisch" ist doch aber alles sauber bei mir, oder??

schrauber 14.06.2014 15:04

das kommt weil in antimalware-foren logfiles gepostet werden, un du diese Einträge dauernd in Logfles findest ;)

Gepetto1 14.06.2014 15:24

Hi,
Ok. Also dann würde ich sagen, ich werde damit leben, dass eben da immer "netzwerkkonnektivitätsproblem" steht und mich einfach nicht aufregen. Falls dir zu meinen geposteten Einträgen bzgl. diagpref.dll und catroot noch was erhellendes einfällt, dann immer her damit.

Ansonsten denke ich, da ich ja dein "go" bekommen habe, dass du mich aus deinem Abo rausnehmen kannst.
Werde mir dann noch tcl downloaden und ausführen und dann ist's gut.

Ich möchte mich nochmals ganz ganz herzlich bei dir bedanken!!!!

Gruß
Gepetto

schrauber 15.06.2014 06:17

Ich verstehe das Problem nicht, in der Regel bemerkt man auch Konnektivitätsprobleme wenn Se angezeigt werden. HAst du mal über ein Upgrade auf Win 7 nachgedacht?

Gepetto1 15.06.2014 17:06

Hi,
Ich versteh es ja selber nicht wirklich. Mit opera hab ich keinerlei
Probleme mehr. Ich kann nur mutmaßen, da es irgendwie mit dem firefox zu tun hatte. Opera nutzt ja die
Interneteinstellungen des ie soweit ich das verstanden habe. Firefox ja nicht. Glaub ich. Vielleicht liegt es ja irgendwie daran.
Solange ich virentechnisch auf der sicheren Seite bin, ist mir das momentan egal. Mir geht es hauptsächlich darum, dass ich wieder sich online banking machen kann.
Evtl. werde ich in der nächsten Zeit eh einen kompletten neuen pc kaufen.
Bis dahin muss dieser halt zumindest für sicheres online banking herhalten.
Es kann auch an avg liegen, da es wohl mit dem 2014 update bei vielen anderen auch
Probleme gibt, die sogar gar nicht mehr ins Netz kommen. Avg hat wohl diverse Filter installiert, die zu Problemen führen können.
Aber nix genaues weiß man.
Wie gesagt, solange der Rechner sauber in Bezug auf online banking ist, ist das ok für mich.

Kurzes update:
Also jetzt hab ich doch schiss.
Habe gerade diesen temp file cleaner benutzt.
Dort stand: user GAST firefox cache emptied 17644898 bytes!!!!
1. Ich habe mich noch nie als Gast angemeldet!
2. Hatte ich doch vor ca 1 Woche firefox mit revo deinstalliert. Hätte da nicht alles gelöscht werden müssen?
3. Ist mein GastKonto gar nicht aktiviert!!

Sag mal du bist aber schon sehr sicher, dass sich hier niemand in meinen Rechner gehackt hat?!? Ich sag nur Netzwerkkonektivitätsproblem...
Woher kommen dann diese bytes unter user GAST von firefox????

Ich hoffe so sehr,dass du mir das erklären kannst und ich mir doch keine Sorgen machen muss.
Das einzige was ich nämlich wirklich dringend muss, ist online banking.

Gruß
Gepetto

schrauber 16.06.2014 09:31

Firefox wird nie sauber deinstalliert. Temp-Files bleiben grundsätzlich stehen.
Woher der Cache im Gastkonto kommt kann ich aber jetzt auf die Schnelle auch nicht erklären.

Ich kann Dir nur sagen dass dein Rechner laut Logfiles sauber ist.

Gepetto1 16.06.2014 21:54

Hi,

Code:

Ich kann Dir nur sagen dass dein Rechner laut Logfiles sauber ist.
YES!! Genau diesen Satz wollte ich lesen.

Also dann kannst du mich aus deinen Abos rausnehmen.
Wie gesagt, mir ist es jetzt erstmal Worscht, ob da Netzwerkkonnektivitätsproblem steht.
Internet läuft wie es soll. Fertig. Aus. Und so bleibts jetzt auch erstmal.

Gruß
Gepetto

stopp:
Folgende Frage hätte ich dann schon noch.
Hatte doch mal geschrieben, dass in den Interneteinstellungen, zwar ausgegraut aber trotzdem, unter port immer 80 steht und wenn ich es lösche, es trotzdem gleich wieder drin steht.
Überall lese ich aber, dass da nix drin stehen darf und es auch nicht von selbst wieder rein geschrieben werden darf.
Jetzt hab ich gelesen, habs aber nicht kapiert, dass man irgendwelche scripts erstellen kann, irgendwas mit wpad oder dchp 252 und so weiter. Das das dann alles doch über irgendeinen proxy läuft u.s.w.
Irgendwie hab ich noch echt ein ungutes Gefühl, Bei mir stand ja auch bei dem log von frst mal dieser seltsame eintrag mit proxyserver localhost 8080 drin. Und dann lässt sich dieser port 80 Eintrag auch nicht löschen. Der sollte doch aber auf jeden Fall zu löschen sein, oder? Da stimmt doch was nicht.
Ich habe KEIN Hacken bei automatische Suche der Einstellung. Soll denn da einer sein?????? Gibt es irgendein Programm mit dem du meine registry in Bezug auf inernet Settings unter windows currentVersion mal ansehen kannst?? Ich bin nicht sicher, ob da alles so stimmt. Hab ein sehr mulmiges Gefühl.
Kann es denn sein, dass ich auch irgendwie so ein script auf mein Rechner geschmuggelt bekommen habe?
Und wie kann ich das rausfinden, ob da so ein script besteht?

schrauber 17.06.2014 10:01

im letzten Log ist der Eintrag nicht drin. Poste mal ein frisches FRST log. Und ja, der Haken muss auf automatisch stehen.

Gepetto1 17.06.2014 14:31

Hi,
und danke nochmal für deine Mühen :)

Also den Haken habe ich jetzt auf automatisch gesetzt.

Hier das frische log. In der großen Hoffnung, dass die sauber sind!!!!!!


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-06-2014
Ran by Philipp (administrator) on PHILIPP-PC on 17-06-2014 14:59:03
Running from C:\Users\Philipp\Desktop
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3890208 2014-06-16] (AVAST Software)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA3FB10447E45CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  No File
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_37 - C:\Windows\SysWOW64\npdeployJava1.dll No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-16] (AVAST Software)
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2009-07-10] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [307200 2008-11-18] (Creative Technology Ltd) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-15] ()

==================== Drivers (Whitelisted) ====================

S4 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [154256 2007-08-10] (Promise Technology, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-16] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-16] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [64752 2014-06-16] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-16] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-06-16] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-06-16] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2014-06-16] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-06-16] ()
S1 Beep; No ImagePath
S4 fttxr5_O; C:\Windows\system32\drivers\fttxr5_o.sys [230408 2007-10-25] (Promise Technology, Inc.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15680 2006-11-01] ()
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [160288 2008-04-07] (NVIDIA Corporation)
S3 SaiH0BAC; C:\Windows\System32\DRIVERS\SaiH0BAC.sys [176128 2007-07-13] (Saitek)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz131; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz131\cpuz_x64.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 lvpopf64; system32\DRIVERS\lvpopf64.sys [X]
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
S3 LVRS64; system32\DRIVERS\lvrs64.sys [X]
S3 LVUVC64; system32\DRIVERS\lvuvc64.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-17 14:59 - 2014-06-17 14:59 - 00008060 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-17 14:58 - 2014-06-17 14:59 - 00000000 ____D () C:\FRST
2014-06-17 14:58 - 2014-06-17 14:57 - 02081280 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-06-17 14:46 - 2014-06-17 14:46 - 00000671 _____ () C:\Users\Philipp\Desktop\internetregistry.txt
2014-06-17 13:48 - 2014-06-17 14:57 - 00000308 _____ () C:\Users\Philipp\Desktop\migrate.txt
2014-06-16 16:18 - 2014-06-16 16:18 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\AVAST Software
2014-06-16 16:18 - 2014-06-16 16:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-16 16:17 - 2014-06-16 16:18 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-16 16:17 - 2014-06-16 16:17 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1402928274789
2014-06-16 16:17 - 2014-06-16 16:17 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-16 16:17 - 2014-06-16 16:17 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswrdr.sys.1402928274789
2014-06-16 16:17 - 2014-06-16 16:17 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswrdr.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-16 16:17 - 2014-06-16 16:17 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-16 16:16 - 2014-06-16 16:16 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-16 16:15 - 2014-06-16 16:15 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-16 16:07 - 2014-06-16 16:10 - 00585462 _____ () C:\Users\Philipp\Downloads\avgremover.log
2014-06-16 16:04 - 2014-06-16 16:04 - 03386520 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Philipp\Downloads\avg_remover_stf_x64_2014_4116.exe
2014-06-16 16:02 - 2014-06-16 16:04 - 94714880 _____ (AVAST Software) C:\Users\Philipp\Downloads\avast_free_antivirus_setup_21514.exe
2014-06-15 16:14 - 2014-06-15 16:14 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-15 16:14 - 2014-06-15 16:14 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-15 16:14 - 2014-06-15 16:14 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Macromedia
2014-06-15 16:14 - 2014-06-15 16:14 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Adobe
2014-06-12 18:54 - 2014-06-12 19:05 - 00003917 _____ () C:\Users\Philipp\Documents\netstat.txt
2014-06-11 13:32 - 2014-04-26 20:21 - 00622592 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 13:32 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-11 13:32 - 2014-04-05 11:10 - 01422784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 13:32 - 2014-03-10 08:26 - 01869824 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 13:32 - 2014-03-10 08:26 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 13:32 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-11 13:32 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-11 13:31 - 2014-05-28 20:53 - 17857536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 13:31 - 2014-05-28 20:37 - 02338816 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 13:31 - 2014-05-28 20:35 - 10890240 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 13:31 - 2014-05-28 20:31 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 13:31 - 2014-05-28 20:31 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 13:31 - 2014-05-28 20:30 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 13:31 - 2014-05-28 20:30 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-06-11 13:31 - 2014-05-28 20:29 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 13:31 - 2014-05-28 20:29 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-11 13:31 - 2014-05-28 20:29 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 13:31 - 2014-05-28 20:29 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 13:31 - 2014-05-28 20:29 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 13:31 - 2014-05-28 20:29 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 13:31 - 2014-05-28 20:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 13:31 - 2014-05-28 20:28 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 13:31 - 2014-05-28 20:28 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 13:31 - 2014-05-28 20:28 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 13:31 - 2014-05-28 20:28 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-06-11 13:31 - 2014-05-28 20:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-06-11 13:31 - 2014-05-28 20:28 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-06-11 13:31 - 2014-05-28 20:27 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 13:31 - 2014-05-28 18:48 - 12356608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-11 13:31 - 2014-05-28 18:39 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-11 13:31 - 2014-05-28 18:38 - 09711104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-11 13:31 - 2014-05-28 18:33 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-11 13:31 - 2014-05-28 18:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-11 13:31 - 2014-05-28 18:32 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-11 13:31 - 2014-05-28 18:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-06-11 13:31 - 2014-05-28 18:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-11 13:31 - 2014-05-28 18:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-11 13:31 - 2014-05-28 18:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-11 13:31 - 2014-05-28 18:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-11 13:31 - 2014-05-28 18:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-11 13:31 - 2014-05-28 18:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-11 13:31 - 2014-05-28 18:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-11 13:31 - 2014-05-28 18:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-06-11 13:31 - 2014-05-28 18:29 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-11 13:31 - 2014-05-28 18:29 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-11 13:31 - 2014-05-28 18:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-11 13:31 - 2014-05-28 18:29 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-06-11 13:31 - 2014-05-28 18:29 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-06-11 13:31 - 2014-05-28 18:28 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-10 18:43 - 2014-06-10 18:43 - 00000136 _____ () C:\Users\Philipp\Documents\Del.txt
2014-06-10 18:35 - 2014-06-10 18:35 - 00001186 _____ () C:\Users\Philipp\Documents\DelFix.txt
2014-06-10 18:34 - 2014-06-10 18:34 - 00001186 _____ () C:\DelFix.txt
2014-06-03 14:52 - 2014-06-03 14:52 - 00000884 _____ () C:\Users\Philipp\Desktop\eM Client.lnk
2014-06-03 14:04 - 2014-06-03 14:04 - 00003898 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401625260
2014-06-02 20:59 - 2014-06-16 20:25 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\eM Client
2014-06-02 20:58 - 2014-06-12 08:50 - 00000884 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2014-06-02 20:58 - 2014-06-12 08:50 - 00000000 ____D () C:\Program Files (x86)\eM Client
2014-06-02 20:56 - 2014-06-02 20:57 - 14995456 _____ () C:\Users\Philipp\Downloads\setup.msi
2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\Users\Philipp\Documents\Mail!!!!!
2014-06-01 20:30 - 2014-06-01 20:30 - 00000000 ____D () C:\Users\Philipp\Documents\Local Folders
2014-06-01 14:21 - 2014-06-03 14:04 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-01 14:21 - 2014-06-01 14:21 - 00000846 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Opera Software
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Opera Software
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-31 07:23 - 2014-06-10 18:34 - 00000000 ____D () C:\Windows\ERUNT
2014-05-30 07:38 - 2014-06-17 14:59 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:16 - 2014-06-12 08:58 - 00000000 ____D () C:\Windows\erdnt
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 16:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:02 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini

==================== One Month Modified Files and Folders =======

2014-06-17 14:59 - 2014-06-17 14:59 - 00008060 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-06-17 14:59 - 2014-06-17 14:58 - 00000000 ____D () C:\FRST
2014-06-17 14:59 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Philipp\AppData\Local\temp
2014-06-17 14:57 - 2014-06-17 14:58 - 02081280 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-06-17 14:57 - 2014-06-17 13:48 - 00000308 _____ () C:\Users\Philipp\Desktop\migrate.txt
2014-06-17 14:46 - 2014-06-17 14:46 - 00000671 _____ () C:\Users\Philipp\Desktop\internetregistry.txt
2014-06-17 14:01 - 2011-08-10 16:32 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-17 13:48 - 2009-07-10 14:09 - 01812631 _____ () C:\Windows\WindowsUpdate.log
2014-06-17 13:43 - 2011-08-10 16:32 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-17 13:43 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-17 13:43 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-17 13:43 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-17 13:42 - 2006-11-02 17:42 - 00032510 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-16 20:25 - 2014-06-02 20:59 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\eM Client
2014-06-16 19:23 - 2008-01-21 05:26 - 00868984 _____ () C:\Windows\PFRO.log
2014-06-16 16:18 - 2014-06-16 16:18 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\AVAST Software
2014-06-16 16:18 - 2014-06-16 16:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-16 16:18 - 2014-06-16 16:17 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-16 16:17 - 2014-06-16 16:17 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1402928274789
2014-06-16 16:17 - 2014-06-16 16:17 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-16 16:17 - 2014-06-16 16:17 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswrdr.sys.1402928274789
2014-06-16 16:17 - 2014-06-16 16:17 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswrdr.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-16 16:17 - 2014-06-16 16:17 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-16 16:16 - 2014-06-16 16:16 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-16 16:15 - 2014-06-16 16:15 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-16 16:10 - 2014-06-16 16:07 - 00585462 _____ () C:\Users\Philipp\Downloads\avgremover.log
2014-06-16 16:04 - 2014-06-16 16:04 - 03386520 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Philipp\Downloads\avg_remover_stf_x64_2014_4116.exe
2014-06-16 16:04 - 2014-06-16 16:02 - 94714880 _____ (AVAST Software) C:\Users\Philipp\Downloads\avast_free_antivirus_setup_21514.exe
2014-06-15 16:14 - 2014-06-15 16:14 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-15 16:14 - 2014-06-15 16:14 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-15 16:14 - 2014-06-15 16:14 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Macromedia
2014-06-15 16:14 - 2014-06-15 16:14 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Adobe
2014-06-12 19:05 - 2014-06-12 18:54 - 00003917 _____ () C:\Users\Philipp\Documents\netstat.txt
2014-06-12 08:58 - 2014-05-30 07:16 - 00000000 ____D () C:\Windows\erdnt
2014-06-12 08:50 - 2014-06-02 20:58 - 00000884 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2014-06-12 08:50 - 2014-06-02 20:58 - 00000000 ____D () C:\Program Files (x86)\eM Client
2014-06-11 13:37 - 2013-08-14 18:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-11 13:36 - 2006-11-02 14:35 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-06-11 13:35 - 2009-07-08 21:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-10 19:31 - 2011-12-13 19:22 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Paint.NET
2014-06-10 18:43 - 2014-06-10 18:43 - 00000136 _____ () C:\Users\Philipp\Documents\Del.txt
2014-06-10 18:35 - 2014-06-10 18:35 - 00001186 _____ () C:\Users\Philipp\Documents\DelFix.txt
2014-06-10 18:34 - 2014-06-10 18:34 - 00001186 _____ () C:\DelFix.txt
2014-06-10 18:34 - 2014-05-31 07:23 - 00000000 ____D () C:\Windows\ERUNT
2014-06-09 18:32 - 2006-11-02 17:27 - 00138928 _____ () C:\Windows\setupact.log
2014-06-03 19:15 - 2013-12-13 19:33 - 00001080 _____ () C:\Windows\system32\settingsbkup.sfm
2014-06-03 19:15 - 2013-12-13 19:33 - 00001080 _____ () C:\Windows\system32\settings.sfm
2014-06-03 18:43 - 2010-11-05 21:06 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-06-03 18:43 - 2010-11-05 21:03 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-06-03 18:43 - 2009-07-08 21:32 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-03 14:52 - 2014-06-03 14:52 - 00000884 _____ () C:\Users\Philipp\Desktop\eM Client.lnk
2014-06-03 14:04 - 2014-06-03 14:04 - 00003898 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401625260
2014-06-03 14:04 - 2014-06-01 14:21 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-02 20:57 - 2014-06-02 20:56 - 14995456 _____ () C:\Users\Philipp\Downloads\setup.msi
2014-06-02 19:54 - 2010-04-19 15:57 - 00008843 _____ () C:\Windows\system32\lvcoinst.log
2014-06-02 19:53 - 2010-04-19 15:56 - 00000000 ____D () C:\ProgramData\LogiShrd
2014-06-02 19:53 - 2009-07-22 15:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-06-02 15:31 - 2008-05-21 11:53 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-06-02 14:43 - 2014-06-02 14:43 - 00000000 ____D () C:\Users\Philipp\Documents\Mail!!!!!
2014-06-02 14:19 - 2009-07-10 20:41 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Mozilla
2014-06-01 20:30 - 2014-06-01 20:30 - 00000000 ____D () C:\Users\Philipp\Documents\Local Folders
2014-06-01 14:21 - 2014-06-01 14:21 - 00000846 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Opera Software
2014-06-01 14:21 - 2014-06-01 14:21 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Opera Software
2014-06-01 06:46 - 2014-06-01 06:46 - 00003072 _____ () C:\Windows\System32\Tasks\{A86BF584-E974-4761-B199-EFC4BDE010C0}
2014-05-31 15:44 - 2014-05-31 15:44 - 28041256 _____ (Opera Software ASA) C:\Users\Philipp\Downloads\Opera_21.0.1432.67_Setup.exe
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-05-30 07:38 - 2014-05-30 07:38 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-05-30 07:36 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-30 07:14 - 2008-05-21 15:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-30 07:14 - 2008-05-21 15:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat
2014-05-30 07:14 - 2008-05-21 15:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat
2014-05-28 21:06 - 2014-05-28 21:06 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Philipp\Downloads\revosetup95.exe
2014-05-28 20:53 - 2014-06-11 13:31 - 17857536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-28 20:37 - 2014-06-11 13:31 - 02338816 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-28 20:35 - 2014-06-11 13:31 - 10890240 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-28 20:31 - 2014-06-11 13:31 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-28 20:31 - 2014-06-11 13:31 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-28 20:30 - 2014-06-11 13:31 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-28 20:30 - 2014-06-11 13:31 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-05-28 20:29 - 2014-06-11 13:31 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-28 20:29 - 2014-06-11 13:31 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-05-28 20:29 - 2014-06-11 13:31 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-28 20:29 - 2014-06-11 13:31 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-28 20:29 - 2014-06-11 13:31 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-28 20:29 - 2014-06-11 13:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-28 20:28 - 2014-06-11 13:31 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-28 20:28 - 2014-06-11 13:31 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-28 20:28 - 2014-06-11 13:31 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-28 20:28 - 2014-06-11 13:31 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-28 20:28 - 2014-06-11 13:31 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-05-28 20:28 - 2014-06-11 13:31 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-05-28 20:28 - 2014-06-11 13:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-05-28 20:27 - 2014-06-11 13:31 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-28 18:48 - 2014-06-11 13:31 - 12356608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-28 18:39 - 2014-06-11 13:31 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-28 18:38 - 2014-06-11 13:31 - 09711104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-28 18:33 - 2014-06-11 13:31 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-28 18:32 - 2014-06-11 13:31 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-28 18:32 - 2014-06-11 13:31 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-28 18:31 - 2014-06-11 13:31 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-05-28 18:31 - 2014-06-11 13:31 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-28 18:30 - 2014-06-11 13:31 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-28 18:30 - 2014-06-11 13:31 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-05-28 18:30 - 2014-06-11 13:31 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-28 18:30 - 2014-06-11 13:31 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-28 18:30 - 2014-06-11 13:31 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-28 18:30 - 2014-06-11 13:31 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-28 18:30 - 2014-06-11 13:31 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-05-28 18:29 - 2014-06-11 13:31 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-28 18:29 - 2014-06-11 13:31 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-28 18:29 - 2014-06-11 13:31 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-28 18:29 - 2014-06-11 13:31 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-05-28 18:29 - 2014-06-11 13:31 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-05-28 18:28 - 2014-06-11 13:31 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-28 14:01 - 2014-05-28 16:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000 (2).bin
2014-05-28 14:01 - 2014-05-28 14:02 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(2).bin
2014-05-28 14:01 - 2014-05-28 14:01 - 02031626 _____ () C:\Users\Philipp\Downloads\FW_Speedportw502v_v1.24.000(1).bin
2014-05-27 22:28 - 2014-05-27 22:28 - 00000085 _____ () C:\Windows\wininit.ini

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-17 13:50

==================== End Of Log ============================

--- --- ---


Diesen Eintrag hatte ich, glaub ich in den älteren logs nicht.
Code:

BootExecute: autocheck autochk * sdnclean64.exe

hier noch Addition
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-06-2014
Ran by Philipp at 2014-06-17 14:59:27
Running from C:\Users\Philipp\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.125 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2018 - Avast Software)
Call of Duty: Modern Warfare 3 - Dedicated Server (HKLM-x32\...\Steam App 42750) (Version:  - Infinity Ward - Sledgehammer Games)
Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version:  - Infinity Ward - Sledgehammer Games)
Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version:  - Infinity Ward - Sledgehammer Games)
CPUID CPU-Z 1.69 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version:  - )
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version:  - )
Crysis(R) (HKLM-x32\...\{000E79B7-E725-4F01-870A-C12942B7F8E4}) (Version: 1.20.0000 - Electronic Arts)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{CA75CBF9-B078-47CB-ABA3-74EFD4FC9A43}) (Version:  - Microsoft)
Dishonored (HKLM-x32\...\Steam App 205100) (Version: 1.0 - Bethesda Softworks)
eM Client (HKLM-x32\...\{7C89BB82-4231-4004-B275-C859880D4948}) (Version: 6.0.20498.0 - eM Client Inc.)
F1 2010 (HKLM-x32\...\GFWL_{434D0831-3E0C-4D03-A5D4-5E1000008400}) (Version: 1.0.0000.132 - Codemasters)
F1 2010 (x32 Version: 1.0.0000.132 - Codemasters) Hidden
F1 2010 (x32 Version: 1.0.0001.132 - Codemasters) Hidden
F1 2011 (HKLM-x32\...\GFWL_{434D0FA1-3E0C-4D03-A5D4-5E1000008100}) (Version: 1.0.0000.129 - Codemasters)
F1 2011 (x32 Version: 1.0.0000.129 - Codemasters) Hidden
F1 2011 (x32 Version: 1.0.0001.129 - Codemasters) Hidden
F1 2011 (x32 Version: 1.0.0002.129 - Codemasters) Hidden
F1 2013 (HKLM-x32\...\Steam App 223670) (Version:  - Codemasters Birmingham)
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
Flight Simulator X (HKLM-x32\...\RTMshadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version:  - )
Flight Simulator X Service Pack 1 (HKLM-x32\...\SP1shadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version:  - )
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Logitech Gaming Software 5.04 (HKLM\...\{8753DF4D-64B0-474E-9A97-0AB5585D9A53}) (Version: 5.04.110 - Logitech)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Flight Simulator X (x32 Version: 10.0.60905 - Microsoft Game Studios) Hidden
Microsoft Flight Simulator X: Acceleration (HKLM-x32\...\FlightSim_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version: 10.0.61637.0 - Microsoft Game Studios)
Microsoft Flight Simulator X: Acceleration (x32 Version: 10.0.61637.0 - Microsoft Game Studios) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla)
MSXML 4.0 SP2 (KB927978) (HKLM-x32\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser und SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
NVIDIA 3D Vision Controller-Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.82 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.82 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.140.952 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Systemsteuerung 331.82 (Version: 331.82 - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Opera Stable 22.0.1471.50 (HKLM-x32\...\Opera 22.0.1471.50) (Version: 22.0.1471.50 - Opera Software ASA)
Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Rapture3D 2.4.9 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5854 - Realtek Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version:  - Microsoft)
Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version:  - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}) (Version: 8.0.0.35 - GRISOFT, s.r.o.)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}) (Version: 9.0.0.623 - AVG Technologies CZ, s.r.o.)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)

==================== Restore Points  =========================

14-08-2013 16:46:50 Windows Update
28-08-2013 17:18:27 Windows Update
12-09-2013 16:48:58 Windows Update
21-09-2013 17:03:11 Removed Java(TM) 6 Update 3
21-09-2013 17:04:13 Removed Java(TM) 6 Update 5
21-09-2013 17:05:11 Removed Java(TM) 6 Update 3
21-09-2013 17:14:34 Removed Java(TM) 6 Update 3
21-09-2013 17:47:47 Removed Java(TM) 6 Update 3
21-09-2013 17:48:25 Removed Java(TM) 6 Update 3
21-09-2013 18:03:31 Wiederherstellungspunkt vor Fehlerhafte Patchregistrierungsschlüssel
21-09-2013 18:05:13 Removed Java(TM) 6 Update 37
01-10-2013 16:43:39 Installed AVG 2014
01-10-2013 16:45:01 Installed AVG 2014
10-10-2013 16:42:20 Windows Update
14-10-2013 14:32:24 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
14-10-2013 14:35:51 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
14-10-2013 14:36:40 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
14-10-2013 17:14:25 DirectX wurde installiert
15-10-2013 07:39:00 Installiert Far Cry 3
31-10-2013 17:28:40 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
31-10-2013 17:32:09 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
31-10-2013 17:33:11 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
13-11-2013 17:13:00 Windows Update
20-11-2013 17:38:53 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
20-11-2013 17:43:27 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
20-11-2013 17:44:33 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
20-11-2013 17:45:57 Windows Update
21-11-2013 14:54:28 Windows Update
13-12-2013 17:19:09 Windows Update
15-01-2014 17:18:41 Windows Update
13-02-2014 17:23:08 Windows Update
13-02-2014 17:56:42 Installed AVG 2014
12-03-2014 17:37:07 Windows Update
09-04-2014 16:21:10 Windows Update
18-04-2014 17:23:25 Geplanter Prüfpunkt
30-04-2014 17:12:36 Installed AVG 2014
02-05-2014 17:19:06 Windows Update
03-05-2014 19:08:49 Geplanter Prüfpunkt
08-05-2014 19:03:11 Geplanter Prüfpunkt
14-05-2014 19:39:12 Geplanter Prüfpunkt
15-05-2014 17:27:36 Windows Update
24-05-2014 17:49:47 Geplanter Prüfpunkt
25-05-2014 17:15:51 Geplanter Prüfpunkt
02-06-2014 12:14:11 Revo Uninstaller's restore point - Mozilla Firefox 29.0.1 (x86 de)
02-06-2014 12:18:19 Revo Uninstaller's restore point - Mozilla Firefox 29.0.1 (x86 de)
02-06-2014 13:02:30 Revo Uninstaller's restore point - Windows Media Player Firefox Plugin
02-06-2014 13:08:30 Revo Uninstaller's restore point - Adobe Shockwave Player
02-06-2014 13:25:31 Revo Uninstaller's restore point - Adobe Flash Player 13 Plugin
02-06-2014 17:52:33 Removed Logitech Webcam Software.
02-06-2014 17:54:13 Logitech Webcam Software v12.10.1110
02-06-2014 18:57:40 Installed eM Client
03-06-2014 12:05:28 Revo Uninstaller's restore point - Mozilla Maintenance Service
05-06-2014 18:42:30 Installed eM Client
09-06-2014 19:35:57 Installed eM Client
11-06-2014 11:32:14 Windows Update
12-06-2014 06:49:24 Installed eM Client
16-06-2014 14:15:51 avast! antivirus system restore point

==================== Hosts content: ==========================

2006-11-02 14:34 - 2014-05-30 07:36 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {053E07D4-BF57-4777-AB86-2503FFB01905} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10] (Google Inc.)
Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {1C919D3A-550F-4455-BAEB-1B11CF4AF57E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-06-16] (AVAST Software)
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {55BE9422-28E2-4700-A01E-1FCF1D40A620} - System32\Tasks\Opera scheduled Autoupdate 1401625260 => C:\Program Files (x86)\Opera\launcher.exe [2014-05-27] (Opera Software)
Task: {72539E3E-11DA-47CA-A173-02739CA95D54} - System32\Tasks\{DC3C511F-86D5-41EF-B546-2B08E434B6EF} => C:\Program Files (x86)\Skype\Phone\Skype.exe
Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {844584A5-E187-4702-BCCB-906B3C92C738} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {D272EFE4-B9B3-4F54-A2AA-0E2618E38D88} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10] (Google Inc.)
Task: {DE93CB4F-5D56-4AF7-8001-27E17F8F0803} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe

==================== Loaded Modules (whitelisted) =============

2013-10-15 09:59 - 2013-10-15 09:59 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-06-17 13:38 - 2014-06-17 13:38 - 02776064 _____ () C:\Program Files\AVAST Software\Avast\defs\14061700\algo.dll
2014-06-16 16:17 - 2014-06-16 16:17 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: CTxfiHlp => CTXFIHLP.EXE
MSCONFIG\startupreg: LogitechQuickCamRibbon => "C:\Programme\Logitech\Logitech WebCam Software\LWS.exe" /hide
MSCONFIG\startupreg: Start WingMan Profiler => C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/17/2014 01:44:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/17/2014 01:38:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2014 11:18:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2014 08:35:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2014 07:24:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2014 04:10:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2014 03:34:39 PM) (Source: Windows Search Service Profile Notification) (EventID: 2) (User: )
Description: Die indizierten Daten des Windows-Suchdiensts für den Benutzer 'Philipp-PC\Gast' können im Zuge der Löschung des Benutzerprofils nicht entfernt werden. Fehlercode 0x80070422.

Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden.
.

Error: (06/16/2014 01:36:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/15/2014 08:43:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/15/2014 06:56:48 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (06/17/2014 01:46:30 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/17/2014 01:44:07 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/17/2014 01:42:30 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Windows Update

Error: (06/17/2014 01:40:15 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/17/2014 01:38:26 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/16/2014 11:21:23 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/16/2014 11:18:19 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/16/2014 08:37:25 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (06/16/2014 08:35:40 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (06/16/2014 07:27:57 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032


Microsoft Office Sessions:
=========================
Error: (06/17/2014 01:44:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/17/2014 01:38:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2014 11:18:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2014 08:35:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2014 07:24:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2014 04:10:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2014 03:34:39 PM) (Source: Windows Search Service Profile Notification) (EventID: 2) (User: )
Description: Philipp-PC\Gast0x80070422Der angegebene Dienst kann nicht gestartet werden. Er ist deaktiviert oder nicht mit aktivierten Geräten verbunden.

Error: (06/16/2014 01:36:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/15/2014 08:43:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/15/2014 06:56:48 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
  Date: 2014-06-15 20:39:28.760
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.620
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.480
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.324
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.058
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:27.934
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:27.778
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:27.637
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:38:37.842
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\AVG\AVG2014\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:38:37.717
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\AVG\AVG2014\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 26%
Total physical RAM: 6134.17 MB
Available physical RAM: 4500.54 MB
Total Pagefile: 12455.88 MB
Available Pagefile: 10815.27 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:931.51 GB) (Free:611.11 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: 61491321)
Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS)

==================== End Of Log ============================


So und dann habe ich unter "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" unter anderem folgendes stehen.
Code:

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,> "MigrateProxy"=dword:00000001 (1)
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,> "ProxyHttp1.1"=dword:00000001 (1)
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,> "EnableNegotiable"=dword:00000001 (1)

ist das ok so?


Und unter "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER"

sind so viele seltsame "user". Ist das normal??

Code:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3910817694-2664832902-3065649910-1636
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3910817694-2664832902-3065649910-1640
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3910817694-2664832902-3065649910-1651
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3628605695-4247540781-2636836620-1002
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-692924467-1411480276-1425026954-1000

Danke und Gruß
Gepetto

schrauber 18.06.2014 09:16

ja passt alles :)

Gepetto1 18.06.2014 17:29

Echt?? Alles ok? Frst log etc. sauber? Rechner clean?!?
Olé olé olé. Schalala lalala.....

Super! Vielen vielen vielen Dank!!!

Dann sind wir fertig? Kann ich frst eigentlich auf dem Rechner lassen oder muss ich es zwingend deinstallieren? Und wenn ja, muss das unbedingt mit delfix gemacht werden oder geht das auch anders?

schrauber 19.06.2014 13:25

Delfix macht das alles. Oder einfach FRST löschen, Logs löschen, Ordner C:\FRST löschen :)

Gepetto1 19.06.2014 17:09

Super!!!
Danke schön! Dann kannst du mich also aus deinen abos rausnehmen.
Nochmals vielen Dank für alles!!!!!

Sorry. Ich nochmal.

Also in der registry unter Current User--Software--Microsoft--Windows--CurrentVersion--
Internetsettings-Connections steht folgendes
Code:

DefaultConnectionSettings  REG_BINARY 46 00 00 00 0e 00.....
SavedLegacySettings REG_BINARY 46 00 00 00 a6 14 00.....

weiter konnte ich die Zahlen nicht sehen.

Ist denn das normal, dass da so was steht???

Und dann war unter "InternetSettings" ein Ordner mit dem Namen "WPAD".
Dieser war aber immer leer.

Jetzt steht da auf einmal so einiges drin!!!!!!!!! Ich weiß nicht, wie ich dir das zeigen kann, was da jetzt plötzlich drin steht...

Kann das sein, dass da jetzt was drin steht, weil ich den Haken bei "automatische Suche der Einstellungen" gesetzt hatte???


Übrigens steht bei t-online, dass man den Haken NICHT setzen soll. Ich hab den jetzt wieder raus genommen. Oder soll der doch rein? Und wieso sagt t-online der muss raus??

schrauber 20.06.2014 18:08

Zeig mir mal nen Screenshot von dem Fenster wo du den Haken setzt.

Und hatten wir das Thema nicht schon dass du aufhören sollst in irgendwelchen Einstellungen und Registry rum zu suchen wenn Du keine Ahnung hast wofür das gut is? :)

Gepetto1 21.06.2014 14:27

Liste der Anhänge anzeigen (Anzahl: 1)
Hi,
Code:

Und hatten wir das Thema nicht schon dass du aufhören sollst in irgendwelchen Einstellungen und Registry rum zu suchen wenn Du keine Ahnung hast wofür das gut is?
ja.... da hast du Recht :-)

Also hier mal das, was bei t-online zu diesem "Haken" steht:
Code:

Proxy und automatisches Konfigurationsskript ausschalten:
Im Browser darf kein Proxy konfiguriert sein und es darf kein automatisches Konfigurationsskript verwendet werden. Bleiben Sie zunächst im Reiter "Verbindungen" der Internetoptionen (vgl. Punkt a). Klicken Sie dort unter "LAN-Einstellungen" auf <Einstellungen> und entfernen Sie alle Haken.

Im Anhang findest du mein Bild.
Dort habe ich also jetzt, weil es so bei t-online steht, alle Haken raus gemacht.
Auch den bei "automatische Suche der Einstellung".

Bei euch unter FAQ steht, dass der Haken rein soll?? Oder hab ich das falsch verstanden...
Außerdem steht bei euch, dass unter "Port" nix stehen soll.
Wie du in meinem Anhang sehen kannst, steht da, zwar grau, unter Port "80".
Wenn ich versuche das zu löschen, schreibt sich aber sofort wieder unter Port die 80 rein.

schrauber 22.06.2014 06:54

Haken 1 ist, wenn Du ne dynamische IP bekommst und Windows sich den Kremel selbst suchen soll =>99% aller User

Haken 2 ist für Firmen, wenn ein NEtzwerk Proxy benutzt wird
Haken 3,wenn Du einen Proxy mit IP benutzt.

Der obere Haken muss rein.

Gepetto1 22.06.2014 07:27

Dann werd ich den wohl wieder rein machen bei automatische Suche der Einstellung. Auch wenn es bei tonline anders steht. Frag mich nur halt, warum die das so schreiben und sogar auf Bildern zeigen. Nun ja, vielleicht muss man auch nicht alles verstehen. Also Haken wieder rein. Komisch nur, dass es auch funktioniert, wenn der Haken nicht gesetzt ist.

schrauber 22.06.2014 07:39

Ich würde die ja mal eiskalt fragen :D

vielleicht hat das damit zu tun wenn du deren voll unötige Software zum verbinden benutzt.

Gepetto1 22.06.2014 09:31

Ja, da hast du wahrscheinlich Recht :-)
Also da du ja geschrieben hast, dass mein Rechner sauber ist, kannst du mich dann aus deinen Abos rausnehmen.
Diese Nachricht, dass ein Netzwerkkonnektivitätsproblem besteht ist zwar immer noch vorhanden, aber da es keine Verbindungsabbrüche mehr mit opera gibt, ist mir das egal. Was weiß ich, welche Einstellungen dazu geführt haben.
Ich habe hier noch ne upgrade Dvd auf win7 liegen, die ich damals dazubekommen habe bzw. bestellen konnte.
Wenn ich nun dann doch mal ein upgrade von vista auf win7 durchführen sollte über die upgrade Funktion, werden dann auch die evtl. Fehler, die zu dieser Nachricht "Netzwerkkonnektivitätsproblem" geführt haben, mit übernommen?

Und die Einträge in der registry unter Wpad sind also normal, wenn man den Haken setzt. Richtig?

schrauber 23.06.2014 07:40

Die Einträge passen, kann sein dass die meldung sogar weg ist nach Upgrade :)

Gepetto1 13.07.2014 09:43

Hallo Schrauber,

melde mich noch einmal nach langer Zeit. Also bis vor 2 Tagen war alles soweit ok mit den seltsamen Verbindungsabbrüchen. Dann gab es das monatliche Windowsupdate, habe einen neuen Drucker installiert und den alten flash player deinstalliert und den neuen installiert. Und ich hab einen USB Stick einer Kollegin angeschlossen. Auf diesem waren nur 2 Sachen. Eine open office Datei (diese habe ich kopiert und bei mir gespeichert) und eine "seltsame" Verknüpfung die irgendwas wie "Netzwerkeinstellungen" hieß. Habe aber nichts angeklickt.

Jedenfalls habe ich seit dem, ich glaube aber seit den windows-updates wieder immer wieder den Wechsel zwischen "nur lokal" und "lokal und internet".

Im Log des Routers ist aber nichts zu sehen, dass er die Verbindung trennt.

Jedenfalls meinte ein Kollege, ob ich sicher bin nicht "zeroaccess" zu haben...

Würdest du das in einem frischen Frst log sehen?

Ich hänge mal eins an.


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-07-2014
Ran by Philipp (administrator) on PHILIPP-PC on 13-07-2014 10:27:34
Running from C:\Users\Philipp\Desktop
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-06-29] (AVAST Software)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA3FB10447E45CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  No File
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_37 - C:\Windows\SysWOW64\npdeployJava1.dll No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-06-16]

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-29] (AVAST Software)
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2009-07-10] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [307200 2008-11-18] (Creative Technology Ltd) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-15] ()

==================== Drivers (Whitelisted) ====================

S4 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [154256 2007-08-10] (Promise Technology, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-21] (Microsoft Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-29] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-29] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [64752 2014-06-29] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-29] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-06-29] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-05] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2014-06-29] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-06-29] ()
S1 Beep; No ImagePath
S4 fttxr5_O; C:\Windows\system32\drivers\fttxr5_o.sys [230408 2007-10-25] (Promise Technology, Inc.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15680 2006-11-01] ()
S4 nvrd64; C:\Windows\system32\drivers\nvrd64.sys [160288 2008-04-07] (NVIDIA Corporation)
S3 SaiH0BAC; C:\Windows\System32\DRIVERS\SaiH0BAC.sys [176128 2007-07-13] (Saitek)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz131; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz131\cpuz_x64.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 lvpopf64; system32\DRIVERS\lvpopf64.sys [X]
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
S3 LVRS64; system32\DRIVERS\lvrs64.sys [X]
S3 LVUVC64; system32\DRIVERS\lvuvc64.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-13 10:27 - 2014-07-13 10:27 - 00008246 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-07-12 20:08 - 2014-07-12 20:08 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Adobe
2014-07-12 19:29 - 2014-07-12 19:29 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-12 19:29 - 2014-07-12 19:29 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-10 11:02 - 2014-07-10 11:02 - 00000000 ___RD () C:\Users\Philipp\AppData\Roaming\Brother
2014-07-10 10:59 - 2014-07-10 10:59 - 00000000 ____D () C:\ProgramData\Brother
2014-07-10 10:14 - 2014-06-07 06:02 - 17854464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-10 10:14 - 2014-06-07 05:13 - 10890752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-10 10:14 - 2014-06-07 04:59 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-10 10:14 - 2014-06-07 04:52 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-10 10:14 - 2014-06-07 04:51 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-10 10:14 - 2014-06-07 04:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-10 10:14 - 2014-06-07 04:50 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-07-10 10:14 - 2014-06-07 04:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-10 10:14 - 2014-06-07 04:45 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-07-10 10:14 - 2014-06-07 04:45 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-10 10:14 - 2014-06-07 04:45 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-10 10:14 - 2014-06-07 04:42 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-10 10:14 - 2014-06-07 04:42 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-10 10:14 - 2014-06-07 04:42 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-10 10:14 - 2014-06-07 04:42 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-10 10:14 - 2014-06-07 04:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-10 10:14 - 2014-06-07 04:41 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-07-10 10:14 - 2014-06-07 04:41 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-07-10 10:14 - 2014-06-07 04:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-10 10:14 - 2014-06-07 04:39 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-07-10 10:14 - 2014-06-07 04:35 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-10 10:14 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-10 10:14 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-10 10:14 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-10 10:14 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-10 10:14 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-10 10:14 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-10 10:14 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-07-10 10:14 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-10 10:14 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-10 10:14 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-07-10 10:14 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-10 10:14 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-10 10:14 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-10 10:14 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-10 10:14 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-07-10 10:14 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-10 10:14 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-10 10:14 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-07-10 10:14 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-10 10:14 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-07-10 10:14 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-10 10:13 - 2014-06-07 02:33 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-10 10:13 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-10 10:13 - 2014-06-06 09:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-10 10:13 - 2014-05-30 09:10 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-10 10:10 - 2014-07-10 10:10 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-07-10 10:10 - 2014-07-10 10:10 - 00000000 ____D () C:\Windows\system32\Macromed
2014-07-08 14:11 - 2014-07-07 18:54 - 00008564 _____ () C:\Users\Philipp\Documents\zeugnisse 2014 (2).odt
2014-07-06 16:33 - 2014-07-04 12:43 - 00024592 _____ () C:\Users\Philipp\Documents\zeugnisse 2014.odt
2014-06-29 10:45 - 2014-06-29 10:45 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-17 14:58 - 2014-07-13 10:27 - 00000000 ____D () C:\FRST
2014-06-17 14:58 - 2014-07-11 15:36 - 02084864 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-06-16 16:18 - 2014-06-16 16:18 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\AVAST Software
2014-06-16 16:18 - 2014-06-16 16:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-16 16:17 - 2014-07-11 18:23 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-16 16:17 - 2014-07-05 14:39 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-06-16 16:17 - 2014-06-29 10:45 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-06-16 16:17 - 2014-06-29 10:45 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-16 16:17 - 2014-06-29 10:45 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-16 16:17 - 2014-06-29 10:45 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-16 16:17 - 2014-06-29 10:45 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-16 16:17 - 2014-06-29 10:45 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2014-06-16 16:17 - 2014-06-29 10:45 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswrdr.sys
2014-06-16 16:17 - 2014-06-29 10:45 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-16 16:17 - 2014-06-16 16:17 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1402928274789
2014-06-16 16:17 - 2014-06-16 16:17 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswrdr.sys.1402928274789
2014-06-16 16:16 - 2014-06-16 16:16 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-16 16:15 - 2014-06-16 16:15 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-16 16:07 - 2014-06-16 16:10 - 00585462 _____ () C:\Users\Philipp\Downloads\avgremover.log
2014-06-16 16:04 - 2014-06-16 16:04 - 03386520 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Philipp\Downloads\avg_remover_stf_x64_2014_4116.exe
2014-06-16 16:02 - 2014-06-16 16:04 - 94714880 _____ (AVAST Software) C:\Users\Philipp\Downloads\avast_free_antivirus_setup_21514.exe
2014-06-15 16:14 - 2014-06-15 16:14 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Macromedia

==================== One Month Modified Files and Folders =======

2014-07-13 10:27 - 2014-07-13 10:27 - 00008246 _____ () C:\Users\Philipp\Desktop\FRST.txt
2014-07-13 10:27 - 2014-06-17 14:58 - 00000000 ____D () C:\FRST
2014-07-13 10:25 - 2009-07-10 14:09 - 01166806 _____ () C:\Windows\WindowsUpdate.log
2014-07-13 10:22 - 2011-08-10 16:32 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-13 10:22 - 2006-11-02 17:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-13 10:22 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-13 10:22 - 2006-11-02 17:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-13 09:20 - 2006-11-02 17:42 - 00032510 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-13 09:06 - 2011-08-10 16:32 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-13 08:31 - 2008-05-21 15:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-13 08:31 - 2008-05-21 15:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat
2014-07-13 08:31 - 2008-05-21 15:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat
2014-07-13 08:27 - 2006-11-02 17:27 - 00139724 _____ () C:\Windows\setupact.log
2014-07-12 20:08 - 2014-07-12 20:08 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Adobe
2014-07-12 19:29 - 2014-07-12 19:29 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-12 19:29 - 2014-07-12 19:29 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-12 19:22 - 2009-07-10 21:33 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Google
2014-07-12 19:22 - 2009-07-10 21:33 - 00000000 ____D () C:\Program Files (x86)\Google
2014-07-12 19:17 - 2014-06-02 20:59 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\eM Client
2014-07-11 18:23 - 2014-06-16 16:17 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-07-11 15:36 - 2014-06-17 14:58 - 02084864 _____ (Farbar) C:\Users\Philipp\Desktop\FRST64.exe
2014-07-10 11:02 - 2014-07-10 11:02 - 00000000 ___RD () C:\Users\Philipp\AppData\Roaming\Brother
2014-07-10 10:59 - 2014-07-10 10:59 - 00000000 ____D () C:\ProgramData\Brother
2014-07-10 10:59 - 2009-07-10 14:16 - 00000000 ____D () C:\Users\Philipp
2014-07-10 10:33 - 2006-11-02 17:21 - 00383744 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-10 10:31 - 2006-11-02 17:07 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-10 10:24 - 2009-07-08 21:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-07-10 10:23 - 2013-08-14 18:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-10 10:22 - 2006-11-02 14:35 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-07-10 10:10 - 2014-07-10 10:10 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-07-10 10:10 - 2014-07-10 10:10 - 00000000 ____D () C:\Windows\system32\Macromed
2014-07-07 18:54 - 2014-07-08 14:11 - 00008564 _____ () C:\Users\Philipp\Documents\zeugnisse 2014 (2).odt
2014-07-05 14:39 - 2014-06-16 16:17 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-07-04 12:43 - 2014-07-06 16:33 - 00024592 _____ () C:\Users\Philipp\Documents\zeugnisse 2014.odt
2014-06-29 11:01 - 2011-08-10 16:32 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-29 11:01 - 2011-08-10 16:32 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-29 10:54 - 2008-01-21 05:26 - 00870094 _____ () C:\Windows\PFRO.log
2014-06-29 10:45 - 2014-06-29 10:45 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-29 10:45 - 2014-06-16 16:17 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-06-29 10:45 - 2014-06-16 16:17 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-29 10:45 - 2014-06-16 16:17 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-29 10:45 - 2014-06-16 16:17 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-29 10:45 - 2014-06-16 16:17 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-29 10:45 - 2014-06-16 16:17 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2014-06-29 10:45 - 2014-06-16 16:17 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswrdr.sys
2014-06-29 10:45 - 2014-06-16 16:17 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-21 15:08 - 2011-12-13 19:22 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Paint.NET
2014-06-19 16:09 - 2014-06-03 14:04 - 00003904 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401625260
2014-06-19 16:09 - 2014-06-01 14:21 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-16 16:18 - 2014-06-16 16:18 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\AVAST Software
2014-06-16 16:18 - 2014-06-16 16:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-16 16:17 - 2014-06-16 16:17 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1402928274789
2014-06-16 16:17 - 2014-06-16 16:17 - 00064752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswrdr.sys.1402928274789
2014-06-16 16:16 - 2014-06-16 16:16 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-16 16:15 - 2014-06-16 16:15 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-16 16:10 - 2014-06-16 16:07 - 00585462 _____ () C:\Users\Philipp\Downloads\avgremover.log
2014-06-16 16:04 - 2014-06-16 16:04 - 03386520 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Philipp\Downloads\avg_remover_stf_x64_2014_4116.exe
2014-06-16 16:04 - 2014-06-16 16:02 - 94714880 _____ (AVAST Software) C:\Users\Philipp\Downloads\avast_free_antivirus_setup_21514.exe
2014-06-15 16:14 - 2014-06-15 16:14 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Macromedia

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-13 10:28

==================== End Of Log ============================

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-07-2014
Ran by Philipp at 2014-07-13 10:28:01
Running from C:\Users\Philipp\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
Call of Duty: Modern Warfare 3 - Dedicated Server (HKLM-x32\...\Steam App 42750) (Version:  - Infinity Ward - Sledgehammer Games)
Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version:  - Infinity Ward - Sledgehammer Games)
Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version:  - Infinity Ward - Sledgehammer Games)
CPUID CPU-Z 1.69 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version:  - )
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version:  - )
Crysis(R) (HKLM-x32\...\{000E79B7-E725-4F01-870A-C12942B7F8E4}) (Version: 1.20.0000 - Electronic Arts)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5C78021E-3C8E-4EDF-97EA-E9B8D808FD6D}) (Version:  - Microsoft)
Dishonored (HKLM-x32\...\Steam App 205100) (Version: 1.0 - Bethesda Softworks)
eM Client (HKLM-x32\...\{7C89BB82-4231-4004-B275-C859880D4948}) (Version: 6.0.20498.0 - eM Client Inc.)
F1 2010 (HKLM-x32\...\GFWL_{434D0831-3E0C-4D03-A5D4-5E1000008400}) (Version: 1.0.0000.132 - Codemasters)
F1 2010 (x32 Version: 1.0.0000.132 - Codemasters) Hidden
F1 2010 (x32 Version: 1.0.0001.132 - Codemasters) Hidden
F1 2011 (HKLM-x32\...\GFWL_{434D0FA1-3E0C-4D03-A5D4-5E1000008100}) (Version: 1.0.0000.129 - Codemasters)
F1 2011 (x32 Version: 1.0.0000.129 - Codemasters) Hidden
F1 2011 (x32 Version: 1.0.0001.129 - Codemasters) Hidden
F1 2011 (x32 Version: 1.0.0002.129 - Codemasters) Hidden
F1 2013 (HKLM-x32\...\Steam App 223670) (Version:  - Codemasters Birmingham)
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
Flight Simulator X (HKLM-x32\...\RTMshadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version:  - )
Flight Simulator X Service Pack 1 (HKLM-x32\...\SP1shadow_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version:  - )
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Logitech Gaming Software 5.04 (HKLM\...\{8753DF4D-64B0-474E-9A97-0AB5585D9A53}) (Version: 5.04.110 - Logitech)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Flight Simulator X (x32 Version: 10.0.60905 - Microsoft Game Studios) Hidden
Microsoft Flight Simulator X: Acceleration (HKLM-x32\...\FlightSim_{7D606567-5047-451A-B49E-29FCB6012B4E}) (Version: 10.0.61637.0 - Microsoft Game Studios)
Microsoft Flight Simulator X: Acceleration (x32 Version: 10.0.61637.0 - Microsoft Game Studios) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla)
MSXML 4.0 SP2 (KB927978) (HKLM-x32\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser und SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
NVIDIA 3D Vision Controller-Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.82 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.82 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.140.952 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Systemsteuerung 331.82 (Version: 331.82 - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Opera Stable 22.0.1471.70 (HKLM-x32\...\Opera 22.0.1471.70) (Version: 22.0.1471.70 - Opera Software ASA)
Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Rapture3D 2.4.9 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5854 - Realtek Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version:  - Microsoft)
Update for Microsoft Excel 2010 (KB2837600) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4ACD847E-547D-493F-9A86-F73EAE1B5174}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0D672F7-883E-4279-8E75-D97A5445AB46}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{C0BDC1DE-C35E-422B-8CBD-C1D555468720}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version:  - Microsoft)
Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version:  - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}) (Version: 8.0.0.35 - GRISOFT, s.r.o.)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}) (Version: 9.0.0.623 - AVG Technologies CZ, s.r.o.)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)

==================== Restore Points  =========================

28-08-2013 17:18:27 Windows Update
12-09-2013 16:48:58 Windows Update
21-09-2013 17:03:11 Removed Java(TM) 6 Update 3
21-09-2013 17:04:13 Removed Java(TM) 6 Update 5
21-09-2013 17:05:11 Removed Java(TM) 6 Update 3
21-09-2013 17:14:34 Removed Java(TM) 6 Update 3
21-09-2013 17:47:47 Removed Java(TM) 6 Update 3
21-09-2013 17:48:25 Removed Java(TM) 6 Update 3
21-09-2013 18:03:31 Wiederherstellungspunkt vor Fehlerhafte Patchregistrierungsschlüssel
21-09-2013 18:05:13 Removed Java(TM) 6 Update 37
01-10-2013 16:43:39 Installed AVG 2014
01-10-2013 16:45:01 Installed AVG 2014
10-10-2013 16:42:20 Windows Update
14-10-2013 14:32:24 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
14-10-2013 14:35:51 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
14-10-2013 14:36:40 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
14-10-2013 17:14:25 DirectX wurde installiert
15-10-2013 07:39:00 Installiert Far Cry 3
31-10-2013 17:28:40 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
31-10-2013 17:32:09 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
31-10-2013 17:33:11 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
13-11-2013 17:13:00 Windows Update
20-11-2013 17:38:53 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte
20-11-2013 17:43:27 Gerätetreiber-Paketinstallation: NVIDIA Corporation Audio-, Video- und Gamecontroller
20-11-2013 17:44:33 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller
20-11-2013 17:45:57 Windows Update
21-11-2013 14:54:28 Windows Update
13-12-2013 17:19:09 Windows Update
15-01-2014 17:18:41 Windows Update
13-02-2014 17:23:08 Windows Update
13-02-2014 17:56:42 Installed AVG 2014
12-03-2014 17:37:07 Windows Update
09-04-2014 16:21:10 Windows Update
18-04-2014 17:23:25 Geplanter Prüfpunkt
30-04-2014 17:12:36 Installed AVG 2014
02-05-2014 17:19:06 Windows Update
03-05-2014 19:08:49 Geplanter Prüfpunkt
08-05-2014 19:03:11 Geplanter Prüfpunkt
14-05-2014 19:39:12 Geplanter Prüfpunkt
15-05-2014 17:27:36 Windows Update
24-05-2014 17:49:47 Geplanter Prüfpunkt
25-05-2014 17:15:51 Geplanter Prüfpunkt
02-06-2014 12:14:11 Revo Uninstaller's restore point - Mozilla Firefox 29.0.1 (x86 de)
02-06-2014 12:18:19 Revo Uninstaller's restore point - Mozilla Firefox 29.0.1 (x86 de)
02-06-2014 13:02:30 Revo Uninstaller's restore point - Windows Media Player Firefox Plugin
02-06-2014 13:08:30 Revo Uninstaller's restore point - Adobe Shockwave Player
02-06-2014 13:25:31 Revo Uninstaller's restore point - Adobe Flash Player 13 Plugin
02-06-2014 17:52:33 Removed Logitech Webcam Software.
02-06-2014 17:54:13 Logitech Webcam Software v12.10.1110
02-06-2014 18:57:40 Installed eM Client
03-06-2014 12:05:28 Revo Uninstaller's restore point - Mozilla Maintenance Service
05-06-2014 18:42:30 Installed eM Client
09-06-2014 19:35:57 Installed eM Client
11-06-2014 11:32:14 Windows Update
12-06-2014 06:49:24 Installed eM Client
16-06-2014 14:15:51 avast! antivirus system restore point
29-06-2014 08:42:23 avast! antivirus system restore point
10-07-2014 08:20:08 Windows Update
10-07-2014 08:57:46 Gerätetreiber-Paketinstallation: Brother Drucker

==================== Hosts content: ==========================

2006-11-02 14:34 - 2014-05-30 07:36 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {053E07D4-BF57-4777-AB86-2503FFB01905} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10] (Google Inc.)
Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {72539E3E-11DA-47CA-A173-02739CA95D54} - System32\Tasks\{DC3C511F-86D5-41EF-B546-2B08E434B6EF} => C:\Program Files (x86)\Skype\Phone\Skype.exe
Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {844584A5-E187-4702-BCCB-906B3C92C738} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {A1497C70-8B77-4716-BD12-F38BC8B39BBD} - System32\Tasks\Opera scheduled Autoupdate 1401625260 => C:\Program Files (x86)\Opera\launcher.exe [2014-06-16] (Opera Software)
Task: {D272EFE4-B9B3-4F54-A2AA-0E2618E38D88} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10] (Google Inc.)
Task: {D5F2D815-0C3E-43EF-A366-8A4F8CFD8EB5} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-06-29] (AVAST Software)
Task: {DE93CB4F-5D56-4AF7-8001-27E17F8F0803} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe

==================== Loaded Modules (whitelisted) =============

2013-10-15 09:59 - 2013-10-15 09:59 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-06-16 16:17 - 2014-06-29 10:45 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-07-13 08:26 - 2014-07-13 08:26 - 02792960 _____ () C:\Program Files\AVAST Software\Avast\defs\14071201\algo.dll
2014-07-13 10:23 - 2014-07-13 10:23 - 02792960 _____ () C:\Program Files\AVAST Software\Avast\defs\14071300\algo.dll
2014-06-16 16:17 - 2014-06-29 10:45 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: CTxfiHlp => CTXFIHLP.EXE
MSCONFIG\startupreg: LogitechQuickCamRibbon => "C:\Programme\Logitech\Logitech WebCam Software\LWS.exe" /hide
MSCONFIG\startupreg: Start WingMan Profiler => C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/13/2014 10:23:47 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/13/2014 08:26:18 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/12/2014 07:15:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/12/2014 03:27:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 06:24:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 04:24:05 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 04:06:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 02:12:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/10/2014 10:52:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/10/2014 10:34:04 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (07/13/2014 10:24:39 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (07/13/2014 10:23:48 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (07/13/2014 08:29:14 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (07/13/2014 08:26:18 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (07/12/2014 07:17:00 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (07/12/2014 07:15:02 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (07/12/2014 03:29:34 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (07/12/2014 03:27:44 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt

Error: (07/11/2014 06:25:30 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (07/11/2014 06:24:08 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Beep
i8042prt


Microsoft Office Sessions:
=========================
Error: (07/13/2014 10:23:47 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/13/2014 08:26:18 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/12/2014 07:15:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/12/2014 03:27:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 06:24:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 04:24:05 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 04:06:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 02:12:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/10/2014 10:52:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/10/2014 10:34:04 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
  Date: 2014-06-15 20:39:28.760
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.620
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.480
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.324
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.058
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:27.934
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:27.778
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:27.637
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:38:37.842
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\AVG\AVG2014\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:38:37.717
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\AVG\AVG2014\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 25%
Total physical RAM: 6134.17 MB
Available physical RAM: 4540.39 MB
Total Pagefile: 12379.88 MB
Available Pagefile: 10884.98 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:931.51 GB) (Free:610.27 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: 61491321)
Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Danke schon mal!!

schrauber 13.07.2014 15:19

ich seh nichts :)

Gepetto1 13.07.2014 17:24

Ok. Dann bin ich beruhigt! Dann sch... ich auf diese Abbrüche. Brauche den Rechner vorerst hauptsächlich zum online banking. Deshalb sollte der schon sauber sein. Aber das ist er ja anscheinend :-) Weitere scanns sind also nicht nötig, oder?

Was ich nur nicht verstehe, wenn ich bei virustotal oder jotti den system32 ordner öffnen will, öffnet sich immer nur der Inhalt des SysWow64?!? Warum ist das so? Wer oder was macht das?

Und dann, falls du das weißt, würde ich gerne wissen wie ich rausfinden kann, welches
Programm den Dienst Rasman startet. Der steht bei mir auf manuell und wird ausgeführt. Aber so wie ich das verstanden habe, soll der gar nicht laufen, wenn man über den Router ins Netz geht. Oder check ich da was nicht? Habe in dem Zusammenhang nämlich was von conficker oder so ähnlich gelesen.
Oder hättest du das in den frst logs gesehen?

Ich hab irgendwie einfach den Eindruck, dass da die firewall, entweder router oder windows, was blockiert und deshalb sich die Verbindung immer wieder ohne ersichtlichen Grund kappt und anschließend wieder neu einwählt.

Gruß
Gepetto

Werde evtl in 2 wochen dann mal das upgrade von vista auf win7 versuchen. Wobei ich glaube, dass das mit den Daten und
Programme behalten beim upgrade eh in die Hose geht...

schrauber 14.07.2014 14:48

hast du denn den Dienst und auch den Ordner Syswow64 mal bei Google eingegeben? ;)

Gepetto1 14.07.2014 15:30

Ja, den Dienst habe ich mir bei google angeschaut. Aber ganz ehrlich, kapiert habe ich das nicht wirklich :confused:
Dachte, wenn ich über den Router ins Netz gehe, muss der Dienst nicht laufen...

Was mich halt echt ärgert, ich hatte den Eindruck, dass dieses ganze sch... Problem mit dem letzten windows update vor 4 oder 6 Wochen angefangen hat. Dann, nachdem wir hier alles mögliche durchgegangen sind und ich von firefox auf opera gewechselt bin, war ja auch alles ok. Mit firefox war es ja unmöglich, da ja ständig Abbrüche entstanden.

Bis auf diese Meldung, dass ein Netzwerkkonnektivitätsproblem besteht. Diese Meldung habe ich ja immer noch. Hatte aber keine Abbrüche mehr. Und jetzt, nach dem letzten windows update, ging der ganze Mist schon wieder los. Gibt es denn ne .dll die für updates verantwortlich ist und vielleicht nicht ok ist?

Es passiert auch einfach mal 1 oder 2 Stunden nix. Dann kann es aber auch kurz nach hochfahren des Rechners sein, ohne das ich irgendein einziges Programm gestartet habe, das die Verbindung raus fliegt und es wird wieder neu aufgebaut wird.

Als ob sich da irgendwas in oder zwischen meine Internetverbindung setzt.

Oder aber irgendwas mit den Einstellungen meiner firewall stimmen nicht??

Kannst ganz ehrlich sein, wenn du darauf keine Lust hast könnte ich das verstehen, aber könnte ich dir vielleicht mal nen screenshot von meinen firewalleinstellungen anhängen und du würdest mal nen Blick drauf werfen?

Und echt vielen Dank für deine Geduld!!! Ich kann mir vorstellen, dass es ganz schön nervig für dich ist...

schrauber 14.07.2014 18:12

Was hat der Dienst mit nem Router zu tun?
Remote Access Connection Manager (System Services for the Windows Server 2003 Family and Windows XP Operating Systems)

Kannst du nen Screenshot machen wenn die Verbindung weg geht? Und dann vielleicht ganz schnell Minitoolbox laufen lassen?


Downloade dir bitte Farbar's MiniToolBox auf deinen Desktop und starte das Tool

Setze einen Haken bei folgenden Einträgen
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset IE Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size
  • List Minidump Files
Klicke Go und poste den Inhalt der Result.txt.

Gepetto1 14.07.2014 20:56

Liste der Anhänge anzeigen (Anzahl: 1)
Hi,
also im screenshot siehst du wie es normal aussieht bei mir. Wenn die Verbindung weg geht, steht dann nicht mehr lokal und internet, sondern nur noch lokal.
Die Verbindung besteht aber trotzdem!!
Kann weiter surfen und auch am Router sind alle Lampen an, die an sein sollen.Nach ner gewissen Zeit wechselt es auch wieder auf lokal und internet.

Kommen wir nun zu minitoolbox
Habe es laufen lassen, als wieder nur lokal da stand.
Hat ziemlich lange bei "getting ip config" gestanden, dann als es weiter ging, stand auch nicht mehr nur noch "lokal", sonder es wechselte wieder auf "lokal und internet" und minitoolbox lief weiter bis zum Ende.

Code:

MiniToolBox by Farbar  Version: 06-07-2014
Ran by Philipp (administrator) on 14-07-2014 at 20:45:05
Running from "C:\Users\Philipp\Desktop"
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows-IP-Konfiguration

Der DNS-Aufl�sungscache wurde geleert.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================

127.0.0.1      localhost

========================= IP Configuration: ================================

Realtek RTL8168C(P)/8111C(P) Family PCI-E Gigabit Ethernet NIC (NDIS 6.0) = LAN-Verbindung (Connected)


# ----------------------------------
# IPv4-Konfiguration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# Ende der IPv4-Konfiguration



Windows-IP-Konfiguration

  Hostname  . . . . . . . . . . . . : Philipp-PC
  Prim�res DNS-Suffix . . . . . . . :
  Knotentyp . . . . . . . . . . . . : Hybrid
  IP-Routing aktiviert  . . . . . . : Nein
  WINS-Proxy aktiviert  . . . . . . : Nein
  DNS-Suffixsuchliste . . . . . . . : Speedport_W_502V_Typ_A

Ethernet-Adapter LAN-Verbindung:

  Verbindungsspezifisches DNS-Suffix: Speedport_W_502V_Typ_A
  Beschreibung. . . . . . . . . . . : Realtek RTL8168C(P)/8111C(P) Family PCI-E Gigabit Ethernet NIC (NDIS 6.0)
  Physikalische Adresse . . . . . . : 00-26-18-24-A4-C7
  DHCP aktiviert. . . . . . . . . . : Ja
  Autokonfiguration aktiviert . . . : Ja
  IPv4-Adresse  . . . . . . . . . . : 192.168.2.104(Bevorzugt)
  Subnetzmaske  . . . . . . . . . . : 255.255.255.0
  Lease erhalten. . . . . . . . . . : Montag, 14. Juli 2014 20:04:46
  Lease l�uft ab. . . . . . . . . . : Freitag, 18. Juli 2014 20:04:46
  Standardgateway . . . . . . . . . : 192.168.2.1
  DHCP-Server . . . . . . . . . . . : 192.168.2.1
  DNS-Server  . . . . . . . . . . . : 192.168.2.1
  NetBIOS �ber TCP/IP . . . . . . . : Aktiviert

Tunneladapter LAN-Verbindung* 6:

  Verbindungsspezifisches DNS-Suffix:
  Beschreibung. . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
  Physikalische Adresse . . . . . . : 02-00-54-55-4E-01
  DHCP aktiviert. . . . . . . . . . : Nein
  Autokonfiguration aktiviert . . . : Ja
  IPv6-Adresse. . . . . . . . . . . : 2001:0:9d38:90d7:10d8:1565:3f57:fd97(Bevorzugt)
  Verbindungslokale IPv6-Adresse  . : fe80::10d8:1565:3f57:fd97%11(Bevorzugt)
  Standardgateway . . . . . . . . . : ::
  NetBIOS �ber TCP/IP . . . . . . . : Deaktiviert

Tunneladapter LAN-Verbindung* 7:

  Medienstatus. . . . . . . . . . . : Medium getrennt
  Verbindungsspezifisches DNS-Suffix: Speedport_W_502V_Typ_A
  Beschreibung. . . . . . . . . . . : isatap.Speedport_W_502V_Typ_A
  Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0
  DHCP aktiviert. . . . . . . . . . : Nein
  Autokonfiguration aktiviert . . . : Ja
Server:  speedport.ip
Address:  192.168.2.1

Name:    google.com
Addresses:  2a00:1450:4001:804::1009
          173.194.112.135
          173.194.112.132
          173.194.112.134
          173.194.112.133
          173.194.112.137
          173.194.112.130
          173.194.112.142
          173.194.112.128
          173.194.112.129
          173.194.112.131
          173.194.112.136



Ping wird ausgef�hrt f�r google.com [173.194.112.136] mit 32 Bytes Daten:

Antwort von 173.194.112.136: Bytes=32 Zeit=24ms TTL=57

Antwort von 173.194.112.136: Bytes=32 Zeit=25ms TTL=57



Ping-Statistik f�r 173.194.112.136:

    Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust),

Ca. Zeitangaben in Millisek.:

    Minimum = 24ms, Maximum = 25ms, Mittelwert = 24ms

Server:  speedport.ip
Address:  192.168.2.1

Name:    yahoo.com
Addresses:  98.138.253.109
          98.139.183.24
          206.190.36.45



Ping wird ausgef�hrt f�r yahoo.com [206.190.36.45] mit 32 Bytes Daten:

Antwort von 206.190.36.45: Bytes=32 Zeit=194ms TTL=49

Antwort von 206.190.36.45: Bytes=32 Zeit=193ms TTL=49



Ping-Statistik f�r 206.190.36.45:

    Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust),

Ca. Zeitangaben in Millisek.:

    Minimum = 193ms, Maximum = 194ms, Mittelwert = 193ms



Ping wird ausgef�hrt f�r 127.0.0.1 mit 32 Bytes Daten:

Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128

Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128



Ping-Statistik f�r 127.0.0.1:

    Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust),

Ca. Zeitangaben in Millisek.:

    Minimum = 0ms, Maximum = 0ms, Mittelwert = 0ms

===========================================================================
Schnittstellenliste
 10 ...00 26 18 24 a4 c7 ...... Realtek RTL8168C(P)/8111C(P) Family PCI-E Gigabit Ethernet NIC (NDIS 6.0)
  1 ........................... Software Loopback Interface 1
 11 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface
 12 ...00 00 00 00 00 00 00 e0  isatap.Speedport_W_502V_Typ_A
===========================================================================

IPv4-Routentabelle
===========================================================================
Aktive Routen:
    Netzwerkziel    Netzwerkmaske          Gateway    Schnittstelle Metrik
          0.0.0.0          0.0.0.0      192.168.2.1    192.168.2.104    20
        127.0.0.0        255.0.0.0  Auf Verbindung        127.0.0.1    306
        127.0.0.1  255.255.255.255  Auf Verbindung        127.0.0.1    306
  127.255.255.255  255.255.255.255  Auf Verbindung        127.0.0.1    306
      192.168.2.0    255.255.255.0  Auf Verbindung    192.168.2.104    276
    192.168.2.104  255.255.255.255  Auf Verbindung    192.168.2.104    276
    192.168.2.255  255.255.255.255  Auf Verbindung    192.168.2.104    276
        224.0.0.0        240.0.0.0  Auf Verbindung        127.0.0.1    306
        224.0.0.0        240.0.0.0  Auf Verbindung    192.168.2.104    276
  255.255.255.255  255.255.255.255  Auf Verbindung        127.0.0.1    306
  255.255.255.255  255.255.255.255  Auf Verbindung    192.168.2.104    276
===========================================================================
St�ndige Routen:
  Keine

IPv6-Routentabelle
===========================================================================
Aktive Routen:
 If Metrik Netzwerkziel            Gateway
 11    18 ::/0                    Auf Verbindung
  1    306 ::1/128                  Auf Verbindung
 11    18 2001::/32                Auf Verbindung
 11    266 2001:0:9d38:90d7:10d8:1565:3f57:fd97/128
                                    Auf Verbindung
 11    266 fe80::/64                Auf Verbindung
 11    266 fe80::10d8:1565:3f57:fd97/128
                                    Auf Verbindung
  1    306 ff00::/8                Auf Verbindung
 11    266 ff00::/8                Auf Verbindung
===========================================================================
St�ndige Routen:
  Keine
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [48128] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [50176] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [62464] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [62464] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [19968] (Microsoft Corporation)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [61440] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [62976] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [78848] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [78848] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [27648] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (07/14/2014 08:05:04 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/14/2014 04:13:12 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/13/2014 10:23:47 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/13/2014 08:26:18 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/12/2014 07:15:01 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/12/2014 03:27:44 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 06:24:07 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 04:24:05 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 04:06:09 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 02:12:02 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (07/14/2014 08:06:11 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (07/14/2014 08:05:07 PM) (Source: Service Control Manager) (User: )
Description: Beep
i8042prt

Error: (07/14/2014 04:14:37 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (07/14/2014 04:13:12 PM) (Source: Service Control Manager) (User: )
Description: Beep
i8042prt

Error: (07/13/2014 10:24:39 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (07/13/2014 10:23:48 AM) (Source: Service Control Manager) (User: )
Description: Beep
i8042prt

Error: (07/13/2014 08:29:14 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (07/13/2014 08:26:18 AM) (Source: Service Control Manager) (User: )
Description: Beep
i8042prt

Error: (07/12/2014 07:17:00 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: 0x80070032

Error: (07/12/2014 07:15:02 PM) (Source: Service Control Manager) (User: )
Description: Beep
i8042prt


Microsoft Office Sessions:
=========================
Error: (07/14/2014 08:05:04 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/14/2014 04:13:12 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/13/2014 10:23:47 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/13/2014 08:26:18 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/12/2014 07:15:01 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/12/2014 03:27:44 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 06:24:07 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 04:24:05 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 04:06:09 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/11/2014 02:12:02 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
  Date: 2014-06-15 20:39:28.760
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.620
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.480
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.324
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3E85.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:28.058
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:27.934
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:27.778
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:39:27.637
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\SET3BD4.tmp" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:38:37.842
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\AVG\AVG2014\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-15 20:38:37.717
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\AVG\AVG2014\Drivers\avgidsdriverx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.



=========================== Installed Programs ============================
CPUID CPU-Z 1.69 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
CPUID CPU-Z 1.69 (HKLM-x32\...\CPUID CPU-Z_is1) (Version:  - )
Logitech Gaming Software 5.04 (HKLM\...\{8753DF4D-64B0-474E-9A97-0AB5585D9A53}) (Version: 5.04.110 - Logitech)
Logitech Gaming Software 5.04 (HKLM-x32\...\{8753DF4D-64B0-474E-9A97-0AB5585D9A53}) (Version: 5.04.110 - Logitech)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM-x32\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (x32 Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM-x32\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (x32 Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (x32 Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM-x32\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (x32 Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM-x32\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM-x32\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM-x32\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM-x32\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM-x32\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM-x32\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
NVIDIA 3D Vision Controller-Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.82 - NVIDIA Corporation)
NVIDIA 3D Vision Controller-Treiber 331.82 (HKLM-x32\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.82 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.82 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.82 (HKLM-x32\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.82 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.140.952 - NVIDIA Corporation) Hidden
NVIDIA Install Application (x32 Version: 2.1002.140.952 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM-x32\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Systemsteuerung 331.82 (Version: 331.82 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 331.82 (x32 Version: 331.82 - NVIDIA Corporation) Hidden
Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
Paint.NET v3.5.10 (HKLM-x32\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM-x32\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM-x32\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Live ID Sign-in Assistant (HKLM-x32\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)

========================= Memory info: ===================================

Percentage of memory in use: 26%
Total physical RAM: 6134.17 MB
Available physical RAM: 4535.84 MB
Total Pagefile: 12453.88 MB
Available Pagefile: 10783.75 MB
Total Virtual: 4095.88 MB
Available Virtual: 3994.8 MB

========================= Partitions: =====================================

1 Drive c: (Windows) (Fixed) (Total:931.51 GB) (Free:610.34 GB) NTFS

========================= Users: ========================================

Benutzerkonten fr \\PHILIPP-PC

Administrator            Gast                    Philipp                 
Der Befehl wurde erfolgreich ausgefhrt.

========================= Minidump Files ==================================

No minidump file found


**** End of log ****



Hier mal mein log vom Router. Wobei die Einträge "smurf" und "tcp fin scan" nicht in der Zeit aufgezeichnet wurden, in der dieses wechseln auf nur noch "lokal" passiert.
Habe meine ip durch **** unkenntlich gemacht.


Code:

14.07.2014 21:28:53 192.168.2.104 Anmeldung erfolgreich.
14.07.2014 20:51:46 **TCP FIN Scan** 192.168.2.104, 50765->> 193.46.63.61, 80 (von PPPoE - Ausgang)
14.07.2014 20:51:46 **TCP FIN Scan** 192.168.2.104, 50825->> 37.187.131.169, 80 (von PPPoE - Ausgang)
14.07.2014 20:51:46 **TCP FIN Scan** 192.168.2.104, 50768->> 91.215.100.38, 80 (von PPPoE - Ausgang)
14.07.2014 20:51:46 **TCP FIN Scan** 192.168.2.104, 50776->> 81.169.224.223, 80 (von PPPoE - Ausgang)
14.07.2014 20:51:46 **TCP FIN Scan** 192.168.2.104, 50823->> 46.105.73.158, 80 (von PPPoE - Ausgang)
14.07.2014 20:51:46 **TCP FIN Scan** 192.168.2.104, 50743->> 212.19.62.76, 80 (von PPPoE - Ausgang)
14.07.2014 20:51:46 **TCP FIN Scan** 192.168.2.104, 50786->> 108.61.217.56, 80 (von PPPoE - Ausgang)
14.07.2014 20:51:46 **TCP FIN Scan** 192.168.2.104, 50780->> 188.40.16.134, 80 (von PPPoE - Ausgang)
14.07.2014 20:51:31 192.168.2.104 Abmeldung.
14.07.2014 20:49:15 192.168.2.104 Anmeldung erfolgreich.
14.07.2014 20:36:29 192.168.2.104 Anmeldung erfolgreich.
14.07.2014 20:10:13 DHCP ist aktiv: WLAN MAC Adresse <5C:FF:35:24:F0:4C> IP-Adresse <192.168.2.100> Subnetzmaske <255.255.255.0> DNS-Server <192.168.2.1> Gateway <192.168.2.1> Lease Time <345600> (H001)
14.07.2014 20:10:13 sende ACK an 192.168.2.100
14.07.2014 20:07:17 DHCP ist aktiv: LAN MAC Adresse <00:26:18:24:A4:C7> IP-Adresse <192.168.2.104> Subnetzmaske <255.255.255.0> DNS-Server <192.168.2.1> Gateway <192.168.2.1> Lease Time <345600> (H001)
14.07.2014 20:07:17 sende ACK an 192.168.2.104
14.07.2014 20:05:12 DHCP ist aktiv: LAN MAC Adresse <00:26:18:24:A4:C7> IP-Adresse <192.168.2.104> Subnetzmaske <255.255.255.0> DNS-Server <192.168.2.1> Gateway <192.168.2.1> Lease Time <345600> (H001)
14.07.2014 20:05:12 sende ACK an 192.168.2.104
14.07.2014 20:04:52 DHCP ist aktiv: LAN MAC Adresse <00:26:18:24:A4:C7> IP-Adresse <192.168.2.104> Subnetzmaske <255.255.255.0> DNS-Server <192.168.2.1> Gateway <192.168.2.1> Lease Time <345600> (H001)
14.07.2014 20:04:52 sende ACK an 192.168.2.104
14.07.2014 20:04:34 **Smurf** 222.216.65.255, 36266->> ************, 8080 (von PPPoE - Eingang)
14.07.2014 20:04:16 **Smurf** 222.216.65.255, 7287->> *************, 80 (von PPPoE - Eingang)
14.07.2014 20:03:59 **Smurf** 222.216.65.255, 48155->> **************, 23 (von PPPoE - Eingang)


So und dann habe ich gesehen, dass 13 mal svchost läuft.
Hier mal die Einträge, die ausgeführt werden, von denen ich das Gefühl habe, dass sie gar nicht ausgeführt werden sollen???

Code:

Imhosts
Dhcp
LanmanServer
Rasman
iphlpsvc
Browser
IKEEXT
Netman
PluPlay
DcomLaunch
gpsvc
WebClient
upnphost
SstpSvc
SSDPSRV
LanmanWorkstation
fdpHost
TermService
TapiSrv
NlaSvc
PolicyAgent


und zu "rasman" habe ich noch folgendes gefunden

Code:

Der Dienst "RasMan" wird benötigt wenn Sie eine Verbindung über: Modem, VPN, ISDN-Verbindungen herstellen wollen.
Bei DSL-Verbindungen wird der Dienst nur benötigt, wenn eine direkte PPPoP-Verbindung hergestellt werden soll
für normal DSL-Verbindungen über einen Router ist der Dienst nicht notwendig.

Nur weiß ich nicht, ob ich über eine direkte PPPoP-Verbindung gehe oder nicht. Wenn ja, dann wäre es ja ok, wenn dieser Dienst läuft.

Übrigens passiert dieser sch... Wechsel zwischen "lokal" und "lokal und internet" momentan sehr häufig. Auch eben, jetzt beim schreiben. Wie gesagt die Verbindung steht ja trotzdem weiterhin.

Gruß
Gepetto

schrauber 15.07.2014 19:33

Der Dienst läuft auch wenn DU in irgend einer Weise Remote machen willst.

Die svchost sind alle normal.

Das die IP bei Smurf aber ne China-IP is haste bemerkt?

Gepetto1 15.07.2014 21:28

Hmmm... also ich weiß ehrlich gesagt nicht, was du meinst mit "Remote machen".
Soweit ich weiß, mache ich sowas nicht. Warum der Dienst dann ausgeführt wird? Naja, ist wahrscheinlich eh nicht so wichtig und hat mit diesem Netzwerkkonnektivitätsproblem nix zu tun-

Und was wollen die Chinesen denn von mir?? Ist das bedenklich?????

Also ich hab nochmal ins router log geschaut. Die ip bleibt bei diesen mini Verbindungsabbrüchen weiter die Selbe und wird nicht geändert.

Ich weiß nun nicht mehr weiter- Solange ich nen, fürs banking sauberen Rechner habe, muss ich wohl erstmal damit leben.
Werde die Tage mal ein neues lan Kabel kaufen und nochmal bei der telekom anrufen.

Wenn das nix bringt, werde ich auf win7 upgraden- Wenn das auch nix bringt, nen neuen router kaufen und als letztes Mittel dann doch nen neuen Pc.

Sag mal wo kommt dieser Eintrag im frst log unter Registry mit sdnclean64.exe eigentlich her?
Der war in den früheren logs nicht da...

schrauber 16.07.2014 18:46

What is sdnclean64.exe?
Der kommt von Spybot.

Die IP Sieht nach IP Spoofing aus. Sprich die scnüffeln enfach IP Bereiche ab und schauen wer antwortet, Router sollte das aber blocken.

Gepetto1 16.07.2014 21:45

Hmm... das mit der sdnclean64.exe finde ich seltsam.
Ich hatte vor ca. 6 oder 7 Wochen spybot installiert, kurz laufen lassen aber nix beheben lassen und gleich wieder deinstalliert. Das war bevor ich hier das erste Mal gepostet habe.
Und bei allen frst logs, die alle samt danach gemacht und hier gepostet worden, stand bis zum log auf Seite 5 glaube ich hier diese sdnclean nicht drin. Und bei den letzten logs plötzlich.
Das einzige was ich zwischen den logs, von Seite 1 bis 5 und den letzten logs gemacht habe war. avg zu deinstallieren und avast zu installieren.
Warum erscheint den sdnclean jetzt erst in den letzten logs?

Ich werde morgen nochmal bei der telekom anrufen und nochmal um ne Langzeitdiagnose bitten.
Mal sehen ob das noch was ergibt.

schrauber 17.07.2014 15:45

warscheinlich hat der scanner es erst jetzt gecheckt :)

Gepetto1 17.07.2014 20:23

Liste der Anhänge anzeigen (Anzahl: 1)
Hi,
ich habe folgende Entdeckung gemacht, die mich beunruhigt. Hoffe Du kannst mich beruhigen!!!!!!!

Wenn ich den taskmanager öffne und dann auf "prozesse aller Benutzer anzeigen" klicke, sehe ich für ca. 1 Sekunde das dort 2mal dllhost.exe steht.
Das verschwindet aber sofort wieder. Auch bei jeden neuen öffnen und nachschauen, steht das wieder immer nur ca. 1 Sekunde 2mal drin und verschwindet dann sofort.
Vor allem ändert sich jedes mal wenn man das kurz sieht die PID. Die ist jedes mal ne andere bei jedem Aufruf des taskmanagers.
Hab mal ein Screenshot gemacht, als es ganz kurz zu sehen war.
Kann das an diesen Netzwerkabbrüchen liegen?
Ist das was schlimmes?????

Des weiteren läuft auch ständig im resourcenmonitor "WmiprvSE.exe".
Ich habe mal google bemüht und bin unter system 32 auf einen Ordner wbem gestoßen. Dieser ist 86 MB groß und enthält viele Ordner und Dateien.
Unter anderem auch den Ordner "logs" Dort habe ich ich folgendes unter "wmiprov" gefunden. Ist nur ein Ausschnitt. Beginnen tun die Einträge am 13.4.2013.
Code:

(Wed May 28 13:55:27 2014.87422) : ***************************************
(Wed May 28 13:55:27 2014.87438) : Could not get pointer to binary resource for file:
(Wed May 28 13:55:27 2014.87438) : C:\Windows\system32\drivers\ndis.sys[MofResourceName](Wed May 28 13:55:27 2014.87438) :
(Wed May 28 13:55:27 2014.87438) : ***************************************
(Wed May 28 13:55:27 2014.87469) : ***************************************
(Wed May 28 13:55:27 2014.87469) : Could not get pointer to binary resource for file:
(Wed May 28 13:55:27 2014.87469) : C:\Windows\system32\DRIVERS\monitor.sys[MonitorWMI](Wed May 28 13:55:27 2014.87469) :
(Wed May 28 13:55:27 2014.87469) : ***************************************
(Wed May 28 15:35:58 2014.126033) : ***************************************
(Wed May 28 15:35:58 2014.126033) : Could not get pointer to binary resource for file:
(Wed May 28 15:35:58 2014.126033) : C:\Windows\system32\drivers\ndis.sys[MofResourceName](Wed May 28 15:35:58 2014.126033) :
(Wed May 28 15:35:58 2014.126033) : ***************************************
(Wed May 28 15:35:58 2014.126048) : ***************************************
(Wed May 28 15:35:58 2014.126048) : Could not get pointer to binary resource for file:
(Wed May 28 15:35:58 2014.126048) : C:\Windows\system32\DRIVERS\monitor.sys[MonitorWMI](Wed May 28 15:35:58 2014.126048) :
(Wed May 28 15:35:58 2014.126048) : ***************************************
(Wed May 28 16:12:26 2014.140463) : ***************************************
(Wed May 28 16:12:26 2014.140478) : Could not get pointer to binary resource for file:
(Wed May 28 16:12:26 2014.140478) : C:\Windows\system32\drivers\ndis.sys[MofResourceName](Wed May 28 16:12:26 2014.140478) :
(Wed May 28 16:12:26 2014.140478) : ***************************************
(Wed May 28 16:12:26 2014.140510) : ***************************************
(Wed May 28 16:12:26 2014.140510) : Could not get pointer to binary resource for file:
(Wed May 28 16:12:26 2014.140510) : C:\Windows\system32\DRIVERS\monitor.sys[MonitorWMI](Wed May 28 16:12:26 2014.140510) :
(Wed May 28 16:12:26 2014.140510) : ***************************************
(Wed May 28 18:20:10 2014.104957) : ***************************************
(Wed May 28 18:20:10 2014.104957) : Could not get pointer to binary resource for file:
(Wed May 28 18:20:10 2014.104957) : C:\Windows\system32\DRIVERS\monitor.sys[MonitorWMI](Wed May 28 18:20:10 2014.104957) :
(Wed May 28 18:20:10 2014.104957) : ***************************************
(Thu May 29 07:05:38 2014.86564) : ***************************************
(Thu May 29 07:05:38 2014.86580) : Could not get pointer to binary resource for file:
(Thu May 29 07:05:38 2014.86580) : C:\Windows\system32\DRIVERS\monitor.sys[MonitorWMI](Thu May 29 07:05:38 2014.86580) :
(Thu May 29 07:05:38 2014.86580) : ***************************************
(Thu May 29 08:42:29 2014.115986) : ***************************************
(Thu May 29 08:42:29 2014.116002) : Could not get pointer to binary resource for file:
(Thu May 29 08:42:29 2014.116002) : C:\Windows\system32\DRIVERS\monitor.sys[MonitorWMI](Thu May 29 08:42:29 2014.116002) :
(Thu May 29 08:42:29 2014.116002) : ***************************************
(Thu May 29 08:54:09 2014.71432) : ***************************************
(Thu May 29 08:54:09 2014.71448) : Could not get pointer to binary resource for file:
(Thu May 29 08:54:09 2014.71448) : C:\Windows\system32\DRIVERS\monitor.sys[MonitorWMI](Thu May 29 08:54:09 2014.71448) :
(Thu May 29 08:54:09 2014.71448) : ***************************************
(Thu May 29 10:22:59 2014.62400) : ***************************************
(Thu May 29 10:22:59 2014.62431) : Could not get pointer to binary resource for file:
(Thu May 29 10:22:59 2014.62431) : C:\Windows\system32\DRIVERS\monitor.sys[MonitorWMI](Thu May 29 10:22:59 2014.62431) :
(Thu May 29 10:22:59 2014.62431) : ***************************************
(Thu May 29 14:40:37 2014.121930) : ***************************************
(Thu May 29 14:40:37 2014.121945) : Could not get pointer to binary resource for file:
(Thu May 29 14:40:37 2014.121945) : C:\Windows\system32\DRIVERS\monitor.sys[MonitorWMI](Thu May 29 14:40:37 2014.121945) :
(Thu May 29 14:40:37 2014.121945) : ***************************************
(Fri May 30 07:09:46 2014.113194) : ***************************************
(Fri May 30 07:09:46 2014.113241) : Could not get pointer to binary resource for file:
(Fri May 30 07:09:46 2014.113241) : C:\Windows\system32\DRIVERS\monitor.sys[MonitorWMI](Fri May 30 07:09:46 2014.113241) :
(Fri May 30 07:09:46 2014.113241) : ***************************************
(Sun Jul 06 16:33:04 2014.177872) : Received Event
(Sun Jul 06 16:34:04 2014.238556) : Received Event
(Tue Jul 08 14:10:54 2014.116454) : Received Event
(Tue Jul 08 14:11:38 2014.160400) : Received Event
(Sun Jul 13 08:27:32 2014.165641) : Received Event
(Sun Jul 13 08:29:03 2014.255935) : Received Event
(Sun Jul 13 08:29:24 2014.277182) : Received Event
(Sun Jul 13 08:29:57 2014.310644) : Received Event
(Wed Jul 16 15:46:28 2014.2161206) : Received Event
(Wed Jul 16 15:47:43 2014.2236570) : Received Event

Was mich aber wundert ist, dass ab dem 6.7. nun "Received Event" steht und vorher immer nur Fehler.
Kann das damit zu tun haben, dass ich ja jetzt Avast! nutze?? Ich hoffe doch sehr!
Sagt dir das was??

Unter logs --- framework steht u.a folgendes
Code:

Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        10/30/2013 18:24:38.896        thread:3132        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        10/30/2013 18:24:38.906        thread:3132        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        11/04/2013 19:45:51.385        thread:1224        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        11/04/2013 19:45:51.432        thread:1224        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
ERROR CInstance(Win32_Processor)::SetDWORD(LoadPercentage)        FAILED! error# 80041005        11/06/2013 18:40:47.736        thread:4316        [d:\rtm\admin\wmi\wbem\sdk\framedyn\instance.cpp.2441]
ERROR CInstance(Win32_Processor)::SetDWORD(LoadPercentage)        FAILED! error# 80041005        11/09/2013 18:22:19.954        thread:6032        [d:\rtm\admin\wmi\wbem\sdk\framedyn\instance.cpp.2441]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        11/11/2013 19:43:21.247        thread:4460        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        11/11/2013 19:43:21.247        thread:4460        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        11/21/2013 15:41:49.123        thread:4460        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        11/21/2013 15:41:49.138        thread:4460        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        11/21/2013 15:42:14.769        thread:4460        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        11/21/2013 15:42:14.769        thread:4460        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        11/21/2013 15:46:23.181        thread:1324        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        11/21/2013 15:46:23.181        thread:1324        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        11/21/2013 15:52:58.454        thread:3608        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        11/21/2013 15:52:58.454        thread:3608        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        11/30/2013 18:36:42.978        thread:1688        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        11/30/2013 18:36:42.989        thread:1688        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        12/07/2013 13:42:56.419        thread:5596        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        12/07/2013 13:42:56.435        thread:5596        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        12/14/2013 18:15:53.778        thread:4172        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        12/14/2013 18:15:53.789        thread:4172        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        12/14/2013 18:16:19.635        thread:4724        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        12/14/2013 18:16:19.635        thread:4724        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        01/03/2014 18:12:27.182        thread:5108        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        01/03/2014 18:12:27.195        thread:5108        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
Failed to open device in loop \\.\PHYSICALDRIVE0 (5)        02/06/2014 18:25:45.470        thread:3100        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.892]
Failed to open device \\.\PHYSICALDRIVE0 (0) for read        02/06/2014 18:25:45.483        thread:3100        [d:\longhorn\admin\wmi\wbem\providers\win32provider\providers\diskpartition.cpp.1098]
ERROR CInstance(Win32_Processor)::SetDWORD(LoadPercentage)        FAILED! error# 80041005        04/22/2014 20:08:58.704        thread:4492        [d:\rtm\admin\wmi\wbem\sdk\framedyn\instance.cpp.2441]


schrauber 18.07.2014 05:27

sagt mir alles gar nix, sorry :)

Gepetto1 20.07.2014 17:58

Hallo,
mit der Antwort habe ich jetzt aber nicht gerechnet :-) Mist...
Sag mal was hälst du davon, wenn ich folgendes mal probiere:
netsh int ip reset c:\resetlog.txt
Wollte dich nur vorher fragen, bevor ich damit noch mehr kaputt mache.
Dieses ständige rausfliegen aus dem Netz geht mir sowas von auf die Nerven.
Vielleicht würde der cmd Befehl ja was helfen? Was meinst du?

schrauber 20.07.2014 21:11

kannste machen, kaput geht da nix :)

Gepetto1 04.08.2014 13:44

Hallo Schrauber,
wollte mich nochmals kurz melden.
Ich habe mir einen neuen PC gegönnt und somit sind alle Probleme gelöst :lach:
Ich möchte mich auch noch einmal ganz ganz herzlich bei dir bedanken.
Du machst wirklich einen super Job!!

Habe jetzt win7 und benutze opera und em client. Als Av habe ich momentan Avast free.
Denke das sollte ok soweit sein. Finde opera wirklich nicht schlecht. Wie schneidet der denn im Vergleich zu firefox in Bezug auf "sicheres surfen" ab? Oder gibts da keine relevanten Unterschiede?
Hab natürlich adblock installiert. Java habe ich gar nicht erst installiert.

Gruß
Gepetto

schrauber 05.08.2014 06:27

Ich kenn Opera nicht genau, sollte sich aber nix zu andren geben :)


Alle Zeitangaben in WEZ +1. Es ist jetzt 21:21 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131