![]() |
|
Log-Analyse und Auswertung: Internet seit kurzem sehr langsam (komische Ip's bei netstat)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #3 |
| ![]() Internet seit kurzem sehr langsam (komische Ip's bei netstat) oh tut mir leid.
__________________Hoffe nun mach ich alles richtig: Defogger hat mir keine Fehlermeldung angezeigt. Und OTL.txt OTL Logfile: Code:
ATTFilter OTL logfile created on: 06.10.2011 09:30:00 - Run 1 OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Eltern_2\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16681) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,20 Gb Available Physical Memory | 60,12% Memory free 4,21 Gb Paging File | 3,43 Gb Available in Paging File | 81,43% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 216,41 Gb Total Space | 129,99 Gb Free Space | 60,07% Space Free | Partition Type: NTFS Drive D: | 107,22 Gb Total Space | 103,20 Gb Free Space | 96,25% Space Free | Partition Type: NTFS Drive E: | 144,12 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive M: | 1,89 Gb Total Space | 1,88 Gb Free Space | 99,95% Space Free | Partition Type: FAT32 Computer Name: ELTERN-PC | User Name: Admin-Eltern | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011.10.05 23:39:24 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Eltern_2\Desktop\OTL.exe PRC - [2011.09.23 06:31:50 | 002,404,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe PRC - [2011.09.21 19:53:12 | 000,973,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe PRC - [2011.09.13 06:32:40 | 001,227,616 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe PRC - [2011.09.08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\PROGRA~1\AVG\AVG2012\avgrsx.exe PRC - [2011.08.15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe PRC - [2011.08.02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe PRC - [2007.11.16 20:50:37 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2007.07.06 11:06:52 | 004,669,440 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2007.05.03 09:04:00 | 000,649,040 | ---- | M] (G DATA Software AG) -- C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe PRC - [2007.04.02 13:49:06 | 001,042,256 | ---- | M] (G DATA Software AG) -- C:\Programme\G DATA AntiVirenKit 2007 Trial\AVKTray\AVKTray.exe PRC - [2007.04.02 13:20:22 | 000,407,376 | ---- | M] (G DATA Software AG) -- C:\Programme\G DATA AntiVirenKit 2007 Trial\AVK\AVKService.exe PRC - [2007.04.02 12:09:00 | 001,103,696 | ---- | M] (G DATA Software AG) -- C:\Programme\G DATA AntiVirenKit 2007 Trial\AVK\AVKWCtl.exe PRC - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe PRC - [2006.11.02 20:40:12 | 000,174,656 | ---- | M] () -- C:\Windows\System32\PSIService.exe ========== Modules (No Company Name) ========== MOD - [2010.03.15 11:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\rarext.dll MOD - [2006.11.02 17:30:43 | 000,385,024 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Deployment.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Deployment.resources.dll MOD - [2006.11.02 17:30:38 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll MOD - [2006.11.02 15:08:54 | 000,015,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\dfsvc\c1e49c5e89ac8bd75d701e7d9f59c1bd\dfsvc.ni.exe MOD - [2006.11.02 14:57:35 | 001,724,416 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\c1bba45a4ec4bf42d3e0b6acdeece8e0\System.Deployment.ni.dll MOD - [2006.11.02 14:57:34 | 013,148,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\35a9f19f21aac42b979be321f1bb5fd4\System.Windows.Forms.ni.dll MOD - [2006.11.02 14:56:59 | 001,617,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\70c145ed25af403aa899ffcb633350b1\System.Drawing.ni.dll MOD - [2006.11.02 14:55:23 | 008,151,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\fcc712bc5da45a672e7f1ad176dbd5a5\System.ni.dll MOD - [2006.11.02 14:55:10 | 011,628,544 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7fe79782947b85d961fd55cb5e02a129\mscorlib.ni.dll MOD - [2004.12.20 20:52:54 | 000,065,536 | ---- | M] () -- C:\Program Files\Astonsoft\DeepBurner Pro\DeepBurnerShellEx.dll ========== Win32 Services (SafeList) ========== SRV - [2011.09.12 06:23:46 | 005,265,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [On_Demand | Stopped] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent) SRV - [2011.08.02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd) SRV - [2007.10.23 00:43:12 | 000,265,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2007.05.03 09:04:00 | 000,649,040 | ---- | M] (G DATA Software AG) [Auto | Running] -- C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe -- (AVKProxy) SRV - [2007.04.02 13:20:22 | 000,407,376 | ---- | M] (G DATA Software AG) [Auto | Running] -- C:\Programme\G DATA AntiVirenKit 2007 Trial\AVK\AVKService.exe -- (AVKService) SRV - [2007.04.02 12:09:00 | 001,103,696 | ---- | M] (G DATA Software AG) [Auto | Running] -- C:\Programme\G DATA AntiVirenKit 2007 Trial\AVK\AVKWCtl.exe -- (AVKWCtl) SRV - [2006.12.14 17:00:00 | 000,544,768 | ---- | M] (Magix AG) [On_Demand | Stopped] -- C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe -- (UPnPService) SRV - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler) SRV - [2006.11.02 20:40:12 | 000,174,656 | ---- | M] () [Auto | Running] -- C:\Windows\System32\PSIService.exe -- (ProtexisLicensing) SRV - [2005.11.17 15:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) ========== Driver Services (SafeList) ========== DRV - [2011.09.13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86) DRV - [2011.08.08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86) DRV - [2011.07.11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix) DRV - [2011.07.11 01:14:02 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter) DRV - [2011.07.11 01:14:02 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim) DRV - [2011.07.11 01:14:00 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH) DRV - [2011.07.11 01:13:58 | 000,134,736 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver) DRV - [2011.07.11 01:13:46 | 000,229,840 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86) DRV - [2010.10.09 17:52:05 | 000,101,248 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\avmaura.sys -- (avmaura) DRV - [2009.03.15 18:40:36 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd) DRV - [2007.10.23 02:44:59 | 000,039,120 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\GDTdiIcpt.sys -- (GDTdiInterceptor) DRV - [2007.10.23 02:44:56 | 000,047,312 | ---- | M] (G DATA Software AG) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MiniIcpt.sys -- (GDMnIcpt) DRV - [2007.10.23 02:44:55 | 000,032,464 | ---- | M] (G DATA Software AG) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HookCentre.sys -- (HookCentre) DRV - [2007.07.02 17:37:10 | 000,131,616 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvrd32.sys -- (nvrd32) DRV - [2007.07.02 17:37:08 | 000,110,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor32.sys -- (nvstor32) DRV - [2007.06.13 23:47:12 | 000,048,256 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\jraid.sys -- (JRAID) DRV - [2007.06.01 17:46:00 | 007,479,008 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2007.03.26 15:26:00 | 000,052,224 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\ViPrt.sys -- (ViPrt) DRV - [2007.03.26 15:26:00 | 000,016,896 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\ViBus.sys -- (ViBus) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.daemon-search.com/startpage IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.daemon-search.com/startpage" FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.0.7.0088 FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011.10.05 21:57:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.01 17:47:18 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.10.05 21:47:23 | 000,000,000 | ---D | M] [2011.07.27 13:39:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eltern\AppData\Roaming\mozilla\Extensions [2007.11.08 20:22:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eltern\AppData\Roaming\mozilla\Firefox\Profiles\6cqsjpr2.default\extensions [2009.03.15 18:43:25 | 000,000,523 | ---- | M] () -- C:\Users\Eltern\AppData\Roaming\Mozilla\Firefox\Profiles\6cqsjpr2.default\searchplugins\daemon-search.xml [2011.10.05 21:47:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2011.10.05 21:47:25 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2009.03.15 18:43:32 | 000,000,000 | ---D | M] (DAEMON Tools Toolbar) -- C:\PROGRAM FILES\DAEMON TOOLS TOOLBAR\FIREFOXDTT [2011.10.05 21:46:50 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2010.03.16 20:28:04 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.03.16 20:28:04 | 000,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2010.03.16 20:28:04 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2010.03.16 20:28:04 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2010.03.16 20:28:04 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2011.10.05 21:27:37 | 000,000,759 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.) O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [AVKTray] C:\Programme\G DATA AntiVirenKit 2007 Trial\AVKTray\AVKTray.exe (G DATA Software AG) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation) O4 - HKLM..\Run: [QuickFinder Scheduler] c:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE (Corel Corporation) O4 - HKLM..\Run: [recinfo694] c:\RecInfo\RecInfo.exe () O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [AVMUSBFernanschluss] C:\Users\Eltern\AppData\Local\Apps\2.0\ZJD78PP4.AO5\3XC5BK4D.OPJ\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\AVMAutoStart.exe (AVM Berlin) O4 - HKCU..\Run: [MBPlayer] C:\Program Files\MB application\MBPlayer.exe (MusicBrigade) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet) O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.6.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AAC86B9-8DC8-43ED-B6BF-0711A666A746}: DhcpNameServer = 192.168.6.1 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\fsc_wallpaper1.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\fsc_wallpaper1.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2006.10.27 14:29:14 | 000,000,106 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{20202a8f-1180-11de-95cc-0019dbf9b4fe}\Shell - "" = AutoRun O33 - MountPoints2\{20202a8f-1180-11de-95cc-0019dbf9b4fe}\Shell\AutoRun\command - "" = L:\autorun.exe de O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2011.10.05 22:54:55 | 000,000,000 | -H-D | C] -- C:\$AVG [2011.10.05 21:58:50 | 000,000,000 | ---D | C] -- C:\Users\Eltern\AppData\Roaming\AVG2012 [2011.10.05 21:57:45 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files [2011.10.05 21:57:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012 [2011.10.05 21:56:08 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012 [2011.10.05 21:56:08 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\AVG [2011.10.05 21:54:37 | 000,000,000 | ---D | C] -- C:\Program Files\AVG [2011.10.05 21:53:48 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData [2011.10.05 21:47:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2011.09.13 06:30:10 | 000,032,592 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys ========== Files - Modified Within 30 Days ========== [2011.10.06 09:26:55 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011.10.06 09:26:54 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011.10.06 09:26:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.10.06 09:26:34 | 2145,902,592 | -HS- | M] () -- C:\hiberfil.sys [2011.10.05 23:48:17 | 000,656,262 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.10.05 23:48:17 | 000,609,944 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.10.05 23:48:17 | 000,121,228 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.10.05 23:48:17 | 000,103,726 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.10.05 23:41:42 | 000,000,176 | ---- | M] () -- C:\Users\Eltern\defogger_reenable [2011.10.05 21:59:55 | 105,854,055 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm [2011.10.05 21:57:28 | 000,000,899 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2011.10.05 21:32:21 | 000,304,704 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011.10.05 21:28:24 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2011.10.05 21:22:02 | 000,005,632 | ---- | M] () -- C:\Users\Eltern\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.10.05 21:15:42 | 2421,307,391 | ---- | M] () -- C:\Videoband 2011_10_05_20_39_43.avi [2011.10.05 20:23:26 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{CEFF007C-5C08-47B0-93AB-594193834339}.job [2011.09.13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys ========== Files Created - No Company Name ========== [2011.10.05 23:41:27 | 000,000,176 | ---- | C] () -- C:\Users\Eltern\defogger_reenable [2011.10.05 21:59:55 | 105,854,055 | ---- | C] () -- C:\Windows\System32\drivers\AVG\incavi.avm [2011.10.05 21:57:28 | 000,000,899 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2011.10.05 21:28:24 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2011.10.05 21:17:42 | 2421,307,391 | ---- | C] () -- C:\Videoband 2011_10_05_20_39_43.avi [2011.10.05 21:15:47 | 000,005,632 | ---- | C] () -- C:\Users\Eltern\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.10.22 20:17:22 | 000,010,296 | ---- | C] () -- C:\Windows\System32\drivers\ASUSHWIO.SYS [2010.07.22 12:10:16 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini [2007.11.08 20:22:12 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2007.10.23 02:50:12 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll [2007.10.23 02:50:11 | 000,006,768 | ---- | C] () -- C:\Windows\mgxoschk.ini [2007.10.23 02:44:59 | 000,039,120 | ---- | C] () -- C:\Windows\System32\drivers\GDTdiIcpt.sys [2007.10.23 02:40:27 | 000,069,632 | ---- | C] () -- C:\Windows\System32\vuins32.dll [2006.11.02 20:40:12 | 000,174,656 | ---- | C] () -- C:\Windows\System32\PSIService.exe [2006.11.02 17:33:31 | 000,656,262 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2006.11.02 17:33:31 | 000,121,228 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006.11.02 14:47:37 | 000,304,704 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 12:33:01 | 000,609,944 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006.11.02 12:33:01 | 000,103,726 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2006.11.02 09:22:43 | 000,099,999 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2006.11.02 09:22:43 | 000,018,271 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2006.08.11 09:52:02 | 000,012,288 | ---- | C] () -- C:\Windows\System32\EvOnlDiag.dll [2005.02.03 02:50:28 | 000,004,224 | ---- | C] () -- C:\Windows\System32\StarOpen.sys ========== LOP Check ========== [2011.10.05 21:58:50 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\AVG2012 [2010.10.09 17:55:07 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\Canon [2009.03.15 18:44:20 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\DAEMON Tools [2009.03.15 18:44:39 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\DAEMON Tools Lite [2009.03.15 18:44:20 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\DAEMON Tools Pro [2009.10.28 21:58:10 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\DeepBurner Pro [2008.03.20 12:44:11 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\ImgBurn [2008.10.22 17:34:33 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\Leadertech [2010.07.22 12:07:25 | 000,000,000 | ---D | M] -- C:\Users\Eltern\AppData\Roaming\MAGIX [2011.10.05 23:51:33 | 000,032,620 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2011.10.05 20:23:26 | 000,000,420 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{CEFF007C-5C08-47B0-93AB-594193834339}.job ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2011.10.05 22:54:55 | 000,000,000 | -H-D | M] -- C:\$AVG [2007.11.08 08:09:41 | 000,000,000 | ---D | M] -- C:\$fsctmp [2007.11.08 20:46:47 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2007.10.23 02:43:45 | 000,000,000 | ---D | M] -- C:\Big Fish Games [2007.10.22 18:11:18 | 000,000,000 | -HSD | M] -- C:\Boot [2006.11.02 15:02:03 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2007.11.07 21:48:07 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2007.10.23 02:41:41 | 000,000,000 | R--D | M] -- C:\DRIVER [2007.11.07 21:55:56 | 000,000,000 | ---D | M] -- C:\FirstSteps [2007.10.23 02:45:07 | 000,000,000 | ---D | M] -- C:\GDATA [2010.05.11 18:12:06 | 000,000,000 | ---D | M] -- C:\IrfanView [2007.10.23 02:52:49 | 000,000,000 | ---D | M] -- C:\Magix-Media-Suite [2007.10.23 02:41:41 | 000,000,000 | R--D | M] -- C:\MANUAL [2007.11.09 16:33:16 | 000,000,000 | RH-D | M] -- C:\MSOCache [2007.10.23 02:54:35 | 000,000,000 | ---D | M] -- C:\nero [2007.10.23 02:56:03 | 000,000,000 | ---D | M] -- C:\OfficeX3 [2011.10.05 21:54:37 | 000,000,000 | R--D | M] -- C:\Program Files [2011.10.05 21:57:45 | 000,000,000 | -H-D | M] -- C:\ProgramData [2007.10.23 02:44:18 | 000,000,000 | ---D | M] -- C:\Programme [2007.10.23 02:56:04 | 000,000,000 | ---D | M] -- C:\RecInfo [2011.10.06 09:33:08 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2010.10.22 20:16:11 | 000,000,000 | ---D | M] -- C:\TempEI4 [2007.10.23 14:10:07 | 000,000,000 | ---D | M] -- C:\TMP [2007.11.08 20:46:11 | 000,000,000 | R--D | M] -- C:\Users [2011.10.06 09:36:19 | 000,000,000 | ---D | M] -- C:\Windows [2007.10.23 00:33:05 | 000,000,000 | ---D | M] -- C:\x86 < %PROGRAMFILES%\*.exe > < %LOCALAPPDATA%\*.exe > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.manifest /3 > < MD5 for: EXPLORER.EXE > [2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\SoftwareDistribution\Download\7061d8bdfc6a60f6588941d7a2c304c7\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe [2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\SoftwareDistribution\Download\7061d8bdfc6a60f6588941d7a2c304c7\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe [2008.10.30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\SoftwareDistribution\Download\7061d8bdfc6a60f6588941d7a2c304c7\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe [2007.11.16 20:50:37 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\explorer.exe [2007.11.16 20:50:37 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe [2007.11.16 20:50:36 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe [2008.10.28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\SoftwareDistribution\Download\7061d8bdfc6a60f6588941d7a2c304c7\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe [2006.11.02 11:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe < MD5 for: REGEDIT.EXE > [2006.11.02 11:45:35 | 000,134,656 | ---- | M] (Microsoft Corporation) MD5=F13123E76FDA33E55F11E0EB832E832A -- C:\Windows\regedit.exe [2006.11.02 11:45:35 | 000,134,656 | ---- | M] (Microsoft Corporation) MD5=F13123E76FDA33E55F11E0EB832E832A -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.0.6000.16386_none_f1f7f368deed95c3\regedit.exe < MD5 for: USERINIT.EXE > [2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\System32\userinit.exe [2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe < MD5 for: WININIT.EXE > [2007.10.23 01:14:36 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=39D959CD9F3BC44F78DB3C6588AAC3FE -- C:\Windows\System32\wininit.exe [2007.10.23 01:14:36 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=39D959CD9F3BC44F78DB3C6588AAC3FE -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.20593_none_2f37c4ba208e02ab\wininit.exe [2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe < MD5 for: WINLOGON.EXE > [2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe [2007.10.23 01:14:36 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=A3FEA6ED9FD3CF07219A632E4A716226 -- C:\Windows\System32\winlogon.exe [2007.10.23 01:14:36 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=A3FEA6ED9FD3CF07219A632E4A716226 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.20593_none_6e080d01f12ed7fe\winlogon.exe < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2008-07-20 15:53:58 ========== Alternate Data Streams ========== @Alternate Data Stream - 537278 bytes -> C:\Videoband 2011_10_05_20_39_43.avi:TOC.WMV < End of report > Die Extra.txt OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 06.10.2011 09:30:00 - Run 1 OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Eltern_2\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16681) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,20 Gb Available Physical Memory | 60,12% Memory free 4,21 Gb Paging File | 3,43 Gb Available in Paging File | 81,43% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 216,41 Gb Total Space | 129,99 Gb Free Space | 60,07% Space Free | Partition Type: NTFS Drive D: | 107,22 Gb Total Space | 103,20 Gb Free Space | 96,25% Space Free | Partition Type: NTFS Drive E: | 144,12 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive M: | 1,89 Gb Total Space | 1,88 Gb Free Space | 99,95% Space Free | Partition Type: FAT32 Computer Name: ELTERN-PC | User Name: Admin-Eltern | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07ABB4BC-18A3-4A1A-9404-7DC24EFCE1D1}" = lport=138 | protocol=17 | dir=in | app=system | "{08240853-D043-482E-8EC1-7F9855C0C953}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{2D5CC778-EEDC-4100-8644-77318E948A79}" = rport=445 | protocol=6 | dir=out | app=system | "{52308EB7-9AF8-48A6-9F91-1BC2F0543624}" = lport=139 | protocol=6 | dir=in | app=system | "{6059875F-A6FE-4CB3-BB88-9E3C745E1811}" = rport=137 | protocol=17 | dir=out | app=system | "{72551129-2748-4359-B886-0F6F3652A87B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{7C17BE22-F4FA-43E5-BBAF-49FFBA228B50}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{7D546227-012A-4B9D-B011-15D4D15D91FC}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{7DB04099-6A25-4532-90F0-40E7EC86BF78}" = rport=139 | protocol=6 | dir=out | app=system | "{926D58FD-50A2-4185-B322-D3F82FABCACA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{BC696B03-9FB4-4962-BAC3-C1FAAE92FD91}" = lport=137 | protocol=17 | dir=in | app=system | "{BE1D59B7-7F65-4F3A-B7CD-2A67B808707E}" = lport=445 | protocol=6 | dir=in | app=system | "{D90E3495-374B-4304-B8A6-C63EF21C2700}" = rport=138 | protocol=17 | dir=out | app=system | "{F4AEC372-58BA-4DC3-8AF6-3DA9E6D100F9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0896583C-E4F6-416C-9C3F-5430F24D4CE8}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{090A0E94-0E4D-43BA-8FEA-F09FEB7EEAD5}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe | "{1CF3936F-A03F-40FF-A1F1-AF15F89B9992}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{23377FC1-9F61-4BBE-80A6-A6DCCAAB049B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe | "{5018DCAF-BBED-484E-A0CB-3C61B1477936}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe | "{6AE177BB-DF0C-44F9-A772-3AD40360ED85}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{76B868A7-E27B-4EF5-BF9C-DB05C97EC715}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{8D0E5E72-E95F-41AE-9BA9-4F3AEAE22D75}" = protocol=17 | dir=in | app=c:\users\eltern\appdata\local\apps\2.0\zjd78pp4.ao5\3xc5bk4d.opj\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe | "{9745B194-C63D-4A42-A91C-A4F8EC547BBB}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe | "{97AB14A0-9301-46FF-8040-73C898526979}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe | "{A5E7D772-AFF7-4BA7-8F6B-53DB2CED4D58}" = protocol=6 | dir=in | app=c:\users\eltern\appdata\local\apps\2.0\zjd78pp4.ao5\3xc5bk4d.opj\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe | "{A917F295-2211-4E92-A8EA-8CC0F8604CD2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{B200DDB0-830B-4C0C-A666-7D47F6EF0A28}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{C55AB439-7AF3-48E8-BC4D-368BD3E38381}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{D383D906-C622-4D0B-8FBE-0399E60BBE89}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe | "{D4420C3F-85E2-4A77-9CEC-BC9CBFADB1DC}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe | "{D444BE6C-1D1B-417D-9264-B62EBCE7217D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{DEEF850E-A129-4BFC-818A-EA8EF97A079E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{E7DDBAB4-D190-4A54-90EE-F8B902230CAE}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe | "{F608ECF8-7B22-45EC-BC2C-F98ACC08624B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{FE5771C2-DE2A-41DE-9F04-0F8AEBEBCC62}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "TCP Query User{19BDA44D-30B8-40D8-B6E8-C724189867F6}D:\program files\sixteen tons entertainment\emergency 4 deluxe\em4deluxe.exe" = protocol=6 | dir=in | app=d:\program files\sixteen tons entertainment\emergency 4 deluxe\em4deluxe.exe | "TCP Query User{56FF793B-5AC4-4764-B67D-9DF1AC91FD6F}C:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe" = protocol=6 | dir=in | app=c:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe | "TCP Query User{ACDBDCA4-8CF6-480C-90E3-6B2ED617BAE6}C:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe" = protocol=6 | dir=in | app=c:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe | "UDP Query User{5C6EAAD9-1929-42FA-9412-207661B1F5CE}D:\program files\sixteen tons entertainment\emergency 4 deluxe\em4deluxe.exe" = protocol=17 | dir=in | app=d:\program files\sixteen tons entertainment\emergency 4 deluxe\em4deluxe.exe | "UDP Query User{DC30D536-BAE4-46CA-AB0F-9F9A863AF3B9}C:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe" = protocol=17 | dir=in | app=c:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0001_383382c5c60b72bd\fritzbox-usb-fernanschluss.exe | "UDP Query User{ED48EAD5-2F0A-4AA3-A924-D954982FCD29}C:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe" = protocol=17 | dir=in | app=c:\users\eltern_2\appdata\local\apps\2.0\jo57157x.5xx\99c19jg1.cmk\frit..tion_8488884cfbcefd60_0002.0002_8541bf1f4a1c673d\fritzbox-usb-fernanschluss.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "_{54DB13F1-0CE0-4BAB-BD5F-7DE150C043C8}" = WordPerfect Office X3 "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP270_series" = Canon MP270 series MP Drivers "{1AD22277-7A1E-71EC-B27D-EB7A22BED143}" = DeepBurner Pro v1.9.0.228 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{2315B23D-3E21-4920-837D-AE6460934ECB}" = FIFA 09 "{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 26 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4D0FEAB4-5D81-4461-A9CA-766B530FC6EA}" = G DATA AntiVirenKit "{54DB13F1-0CE0-4BAB-BD5F-7DE150C043C8}" = WordPerfect Office X3 "{56839333-0802-40D6-9A50-EBB9EB2BF541}" = AVG 2012 "{6DA0B8BE-3735-4287-AF4D-B8DE088D0AA7}" = AVG 2012 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{81CD6232-10F5-4832-B3DA-1B88B1571031}" = Nero 7 Essentials "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{94D66D71-12F0-48A5-B46A-D4B835A0F1B7}" = FirstSteps Diagnostics "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{AC76BA86-7AD7-1031-7B44-A81000000003}" = Adobe Reader 8.1.0 - Deutsch "{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser "{EDA12670-56B5-4459-BA21-D010F0E3EBA1}" = Emergency 4 Deluxe "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "AVG" = AVG 2012 "AVMFBox" = AVM FRITZ!Box Dokumentation "AVMFBoxPrinter" = AVM FRITZ!Box Druckeranschluss "Big Fish Games Center" = Big Fish Games Center (remove only) "Big Fish Games Sudoku" = Big Fish Games Sudoku (remove only) "Cradle of Rome" = Cradle of Rome (remove only) "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition 2.0.0.1 (D) "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "ImgBurn" = ImgBurn "Luxor Amun Rising" = Luxor Amun Rising (remove only) "MAGIX Foto Manager 2007 D" = MAGIX Foto Manager 2007 4.2.0.79 (D) "MAGIX Media Suite D" = MAGIX Media Suite 1.12.0.89 (D) "MAGIX Music Manager 2007 D" = MAGIX Music Manager 2007 8.2.0.144 (D) "MAGIX Online Druck Service D" = MAGIX Online Druck Service 2.3.2.0 (D) "MAGIX Ringtone Maker SE D" = MAGIX Ringtone Maker SE 3.1.0.4 (D) "Mahjong Towers Eternity EU" = Mahjong Towers Eternity EU (remove only) "Mozilla Firefox (3.6.2pre)" = Mozilla Firefox (3.6.2pre) "Mystery Case Files - Prime Suspects" = Mystery Case Files - Prime Suspects (remove only) "NVIDIA Drivers" = NVIDIA Drivers "Poker Superstars II" = Poker Superstars II (remove only) "Virtual Villagers" = Virtual Villagers (remove only) "VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter "WinRAR archiver" = WinRAR ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "f018cf21c0452c64" = AVM FRITZ!Box USB-Fernanschluss ========== Last 10 Event Log Errors ========== Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt! < End of report > |
Themen zu Internet seit kurzem sehr langsam (komische Ip's bei netstat) |
adresse, adressen, aufrufe, aufrufen, avg, einiger, fehler, fritzbox, gefunde, heute, inter, interne, internet, internet sehr langsam, komisch, komische, kurzem, langsam, netstat, neustarts, plug-in, programm, rechner, sehr langsam, stand, stehe, webseite, webseiten, windows |