|
Log-Analyse und Auswertung: windows security center windows gesperrtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
04.03.2012, 00:56 | #1 |
| windows security center windows gesperrt hallo habe das problem mit dem windows security center sobald ich windows normal starte kommt ein weisser bildschirm mit einem fenster in dem steht das ich 100€ per paysafe oder ukash bezahlen soll Hier die logfiles von OTL EXTRAS LOGFILE:OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 04/03/2012 00:28:47 - Run 3 OTL by OldTimer - Version 3.2.35.0 Folder = C:\Users\***\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd/MM/yyyy 7,98 Gb Total Physical Memory | 6,99 Gb Available Physical Memory | 87,56% Memory free 15,96 Gb Paging File | 15,02 Gb Available in Paging File | 94,15% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 128,18 Gb Total Space | 43,82 Gb Free Space | 34,19% Space Free | Partition Type: NTFS Drive D: | 144,91 Gb Total Space | 69,06 Gb Free Space | 47,66% Space Free | Partition Type: NTFS Drive F: | 24,98 Gb Total Space | 8,50 Gb Free Space | 34,04% Space Free | Partition Type: FAT32 Computer Name: *** | User Name: *** | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- D:\firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "D:\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "D:\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "D:\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "D:\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC2 "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{11D96381-C349-60F6-6E95-013D80B6B68B}" = AMD Fuel "{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot "{1C4C0E06-5E82-FEF7-7A35-6ED0FBA91307}" = AMD Media Foundation Decoders "{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Atheros Bluetooth Suite (64) "{26A24AE4-039D-4CA4-87B4-2F86417002FF}" = Java(TM) 7 Update 2 (64-bit) "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}" = ASUS Power4Gear Hybrid "{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{E17025A7-39B6-375E-8F1E-20637D19549C}" = AMD Catalyst Install Manager "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FF91D913-0F96-E8B4-7F24-138D64AEE63A}" = ccc-utility64 "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit "CPUID CPU-Z_is1" = CPUID CPU-Z 1.59 "Elantech" = ETDWare PS/2-X64 8.0.5.1_WHQL "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "WinRAR archiver" = WinRAR 4.01 (64-Bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1A10EA04-AF48-AB19-DE2B-0F7ABF174B22}" = CCC Help Finnish "{1AC6E8CB-B022-A7E1-66DA-E063B6CEC373}" = CCC Help Polish "{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3 "{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 24 "{29AFBD5C-71A8-DA79-508C-53E040EE3E71}" = CCC Help Italian "{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012 "{36BFE02C-3247-EC65-5B79-C31CA8A2EA6B}" = CCC Help Chinese Traditional "{375A7FA9-00D6-4BCF-B8B9-682E18CD62B7}_is1" = SleepTimer Ultimate 1.11 "{3993DD42-0739-7DCB-CB1E-512A1D0287B6}" = CCC Help Portuguese "{3D06DD4B-2D97-CB62-1639-66995969E0F7}" = CCC Help Chinese Standard "{40D1F76D-FD54-6FF9-8A83-E2B6849FF755}" = CCC Help Korean "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4C699616-D8EA-9E2F-0246-68E0298A9081}" = CCC Help German "{50B8CA72-98FD-21A1-3448-601998D44C1D}" = CCC Help Swedish "{55C6CD22-E3A4-4937-CFFB-C7E11FA6A5A3}" = CCC Help Dutch "{56050D82-138B-D911-CE56-DC4783CAA22C}" = CCC Help English "{5F6C549F-78DA-4E0E-AE70-0BD981936D99}" = Nuance PDF Reader "{615AA928-1427-735E-C728-55AF614CD3DA}" = Catalyst Control Center Profiles Mobile "{62D16CB8-4DD5-0314-2AD7-C3C2BCADC234}" = CCC Help Thai "{69424C7F-B6CA-8786-E0CA-89D5915C9486}" = CCC Help Turkish "{6E5E0E1B-FADA-9749-80F6-03A0A7967FEC}" = CCC Help Danish "{71296ABE-826A-2D27-9FD0-503F39A4D7ED}" = CCC Help Japanese "{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE}" = ICQ7.7 "{7D916FA5-DAE9-4A25-B089-655C70EAF607}" = Qualcomm Atheros WiFi Driver Installation "{8150221C-8F7E-4997-AD4E-AFDEE7F4B410}" = Wireless Console 3 "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer "{A11EFE0E-A256-C423-223F-4808E88024DB}" = CCC Help Greek "{A9868A83-9D72-2F2D-F549-A5BD46891987}" = CCC Help Norwegian "{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package "{B2A07D8D-71DB-4929-9154-2D8A198F0FDA}" = CCC Help Spanish "{C10C5955-9E14-A895-BF90-29388B133FEA}" = CCC Help Russian "{C9440B47-2604-44EC-DA52-46DB4FA946ED}" = CCC Help French "{CA234488-A4E4-FE20-DEF4-D68C43ACACA2}" = CCC Help Czech "{CE026CFE-73FE-4FED-9D5F-2C8D4DB512B0}" = TuneUp Utilities Language Pack (de-DE) "{DA9FD67B-0AAF-C83D-E2AC-C7D296FA0FE4}" = Catalyst Control Center Localization All "{DE6698C9-53D4-67FB-2A2B-67CB1DEF89E5}" = AMD VISION Engine Control Center "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F8857969-C550-C462-1785-DB5523AE133C}" = CCC Help Hungarian "{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}" = ASUS Live Update "{FDB51A10-A57D-29AB-90D1-3EEE29BD388F}" = Catalyst Control Center InstallProxy "5513-1208-7298-9440" = JDownloader 0.9 "Avira AntiVir Desktop" = Avira Free Antivirus "DealBulldog Toolbar" = DealBulldog Toolbar "Game Booster_is1" = Game Booster 3 "HaaliMkx" = Haali Media Splitter "KLiteCodecPack_is1" = K-Lite Mega Codec Pack 8.1.0 "RocketDock_is1" = RocketDock 1.3.5 "TuneUp Utilities 2012" = TuneUp Utilities 2012 "VLC media player" = VLC media player 1.1.11 "XMedia Recode" = XMedia Recode 3.0.7.0 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dexpot" = Dexpot "Mozilla Firefox 10.0.2 (x86 de)" = Mozilla Firefox 10.0.2 (x86 de) ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 11/02/2012 18:02:00 | Computer Name = Bupgar-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: tsMuxeR.exe, Version: 0.0.0.0, Zeitstempel: 0x4a077b02 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00067479 ID des fehlerhaften Prozesses: 0x145c Startzeit der fehlerhaften Anwendung: 0x01cce908c5dbbd0b Pfad der fehlerhaften Anwendung: C:\Users\Bupgar\Desktop\tsMuxeR_1.10.6\tsMuxeR.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 055de1c4-54fc-11e1-8967-14dae9e68ea3 Error - 19/02/2012 10:18:45 | Computer Name = Bupgar-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: avp.exe, Version: 11.0.2.556, Zeitstempel: 0x4da58980 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec4bb4f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0003331f ID des fehlerhaften Prozesses: 0x1520 Startzeit der fehlerhaften Anwendung: 0x01ccef113275a546 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Suite CBE 11\avp.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: a1872b05-5b04-11e1-81f6-14dae9e68ea3 Error - 19/02/2012 19:04:01 | Computer Name = Bupgar-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: avp.exe, Version: 11.0.2.556, Zeitstempel: 0x4da58980 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec4bb4f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0003331f ID des fehlerhaften Prozesses: 0x1560 Startzeit der fehlerhaften Anwendung: 0x01ccef5a9373b757 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Suite CBE 11\avp.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 026be858-5b4e-11e1-81f6-14dae9e68ea3 Error - 21/02/2012 06:59:40 | Computer Name = Bupgar-PC | Source = Application Hang | ID = 1002 Description = Programm Explorer.EXE, Version 6.1.7601.17567 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: b20 Startzeit: 01ccee96738b4150 Endzeit: 60000 Anwendungspfad: C:\Windows\Explorer.EXE Berichts-ID: e7912d8b-5c7a-11e1-81f6-14dae9e68ea3 Error - 22/02/2012 22:45:55 | Computer Name = Bupgar-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: tsMuxeR.exe, Version: 0.0.0.0, Zeitstempel: 0x4a077b02 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00033e2d ID des fehlerhaften Prozesses: 0x175c Startzeit der fehlerhaften Anwendung: 0x01ccf1d54169bcc0 Pfad der fehlerhaften Anwendung: C:\Users\Bupgar\Desktop\tsMuxeR_1.10.6\tsMuxeR.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 81b994bc-5dc8-11e1-8574-14dae9e68ea3 Error - 22/02/2012 22:46:21 | Computer Name = Bupgar-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: tsMuxeR.exe, Version: 0.0.0.0, Zeitstempel: 0x4a077b02 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00033e2d ID des fehlerhaften Prozesses: 0x1750 Startzeit der fehlerhaften Anwendung: 0x01ccf1d5526202ac Pfad der fehlerhaften Anwendung: C:\Users\Bupgar\Desktop\tsMuxeR_1.10.6\tsMuxeR.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 90d74755-5dc8-11e1-8574-14dae9e68ea3 Error - 22/02/2012 22:49:40 | Computer Name = Bupgar-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: tsMuxeR.exe, Version: 0.0.0.0, Zeitstempel: 0x4a077b02 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00033e2d ID des fehlerhaften Prozesses: 0x3bc Startzeit der fehlerhaften Anwendung: 0x01ccf1d5c879d796 Pfad der fehlerhaften Anwendung: C:\Users\Bupgar\Desktop\tsMuxeR_1.10.6\tsMuxeR.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 07a01f57-5dc9-11e1-8574-14dae9e68ea3 Error - 22/02/2012 22:50:39 | Computer Name = Bupgar-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: tsMuxeR.exe, Version: 0.0.0.0, Zeitstempel: 0x4a077b02 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x00033e2d ID des fehlerhaften Prozesses: 0x3bc Startzeit der fehlerhaften Anwendung: 0x01ccf1d5ec459304 Pfad der fehlerhaften Anwendung: C:\Users\Bupgar\Desktop\tsMuxeR_1.10.6\tsMuxeR.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 2ad62844-5dc9-11e1-8574-14dae9e68ea3 Error - 28/02/2012 07:47:51 | Computer Name = Bupgar-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: vlc.exe, Version: 1.1.11.0, Zeitstempel: 0x4e1edf37 Name des fehlerhaften Moduls: vlc.exe, Version: 1.1.11.0, Zeitstempel: 0x4e1edf37 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000174c ID des fehlerhaften Prozesses: 0x1290 Startzeit der fehlerhaften Anwendung: 0x01ccf60e4a7362ab Pfad der fehlerhaften Anwendung: D:\VLC\vlc.exe Pfad des fehlerhaften Moduls: D:\VLC\vlc.exe Berichtskennung: 0a68e121-6202-11e1-86f8-14dae9e68ea3 Error - 29/02/2012 07:27:38 | Computer Name = Bupgar-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: OneClick.exe, Version: 12.0.2160.11, Zeitstempel: 0x4ee886e5 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002dfe4 ID des fehlerhaften Prozesses: 0x1328 Startzeit der fehlerhaften Anwendung: 0x01ccf6d509f3285e Pfad der fehlerhaften Anwendung: D:\Programme\OneClick.exe Pfad des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll Berichtskennung: 62177e42-62c8-11e1-8cf4-14dae9e68ea3 [ System Events ] Error - 03/03/2012 17:15:22 | Computer Name = *** | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 03/03/2012 17:15:22 | Computer Name = *** | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 03/03/2012 17:15:23 | Computer Name = *** | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 03/03/2012 17:15:23 | Computer Name = *** | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 03/03/2012 17:15:23 | Computer Name = *** | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 03/03/2012 17:15:23 | Computer Name = *** | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 03/03/2012 17:15:23 | Computer Name = *** | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 03/03/2012 17:15:23 | Computer Name = *** | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 03/03/2012 18:07:05 | Computer Name = *** | Source = DCOM | ID = 10010 Description = Error - 03/03/2012 18:15:45 | Computer Name = *** | Source = Service Control Manager | ID = 7024 Description = Der Dienst "Superfetch" wurde mit folgendem dienstspezifischem Fehler beendet: %%0. < End of report > UND JETZT DIE OTL.TXT LOGFILE:OTL Logfile: Code:
ATTFilter OTL logfile created on: 04/03/2012 00:28:47 - Run 3 OTL by OldTimer - Version 3.2.35.0 Folder = C:\Users\Bupgar\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd/MM/yyyy 7,98 Gb Total Physical Memory | 6,99 Gb Available Physical Memory | 87,56% Memory free 15,96 Gb Paging File | 15,02 Gb Available in Paging File | 94,15% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 128,18 Gb Total Space | 43,82 Gb Free Space | 34,19% Space Free | Partition Type: NTFS Drive D: | 144,91 Gb Total Space | 69,06 Gb Free Space | 47,66% Space Free | Partition Type: NTFS Drive F: | 24,98 Gb Total Space | 8,50 Gb Free Space | 34,04% Space Free | Partition Type: FAT32 Computer Name: *** | User Name: *** | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\***\Desktop\OTL.exe (OldTimer Tools) PRC - D:\firefox\firefox.exe (Mozilla Corporation) PRC - D:\firefox\plugin-container.exe (Mozilla Corporation) ========== Modules (No Company Name) ========== MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () MOD - D:\firefox\mozjs.dll () ========== Win32 Services (SafeList) ========== SRV:64bit: - (UxTuneUp) -- C:\Windows\SysNative\uxtuneup.dll (TuneUp Software) SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD) SRV:64bit: - (AMD FUEL Service) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.) SRV:64bit: - (AFBAgent) -- C:\Windows\SysNative\FBAgent.exe (ASUSTeK Computer Inc.) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (TuneUp.UtilitiesSvc) -- D:\Programme\TuneUpUtilitiesService64.exe (TuneUp Software) SRV - (UxTuneUp) -- C:\Windows\SysWOW64\uxtuneup.dll (TuneUp Software) SRV - (ZAtheros Bt&Wlan Coex Agent) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros) SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Atheros Commnucations) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS) SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) DRV:64bit: - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Atheros) DRV:64bit: - (cpuz135) -- C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID) DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH) DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys (Nokia) DRV:64bit: - (upperdev) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia) DRV:64bit: - (nmwcdc) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia) DRV:64bit: - (nmwcd) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia) DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.) DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.) DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek ) DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.) DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronics Corp.) DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation) DRV:64bit: - (amdiox64) -- C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation) DRV - (TuneUpUtilitiesDrv) -- D:\Programme\TuneUpUtilitiesDriver64.sys (TuneUp Software) DRV - (ATKWMIACPIIO) -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUS) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Ixquick HTTPS - Deutsch" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..network.proxy.type: 0 FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: D:\firefox\components [2012/02/18 15:38:42 | 000,000,000 | ---D | M] [2011/12/29 17:33:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bupgar\AppData\Roaming\mozilla\Extensions [2012/02/28 10:45:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bupgar\AppData\Roaming\mozilla\Firefox\Profiles\mut0tk5f.default\extensions [2012/01/25 16:12:20 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\Bupgar\AppData\Roaming\mozilla\Firefox\Profiles\mut0tk5f.default\extensions\firefox@ghostery.com [2012/03/02 19:25:54 | 000,001,610 | ---- | M] () -- C:\Users\Bupgar\AppData\Roaming\Mozilla\Firefox\Profiles\mut0tk5f.default\searchplugins\ixquick-https---deutsch.xml () (No name found) -- C:\USERS\BUPGAR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MUT0TK5F.DEFAULT\EXTENSIONS\{097D3191-E6FA-4728-9826-B533D755359D}.XPI () (No name found) -- C:\USERS\BUPGAR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MUT0TK5F.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI () (No name found) -- C:\USERS\BUPGAR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MUT0TK5F.DEFAULT\EXTENSIONS\{E968FC70-8F95-4AB9-9E79-304DE2A71EE1}.XPI () (No name found) -- C:\USERS\BUPGAR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MUT0TK5F.DEFAULT\EXTENSIONS\SHAREMENOT@FRANZIROESNER.COM.XPI () (No name found) -- C:\USERS\BUPGAR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MUT0TK5F.DEFAULT\EXTENSIONS\STEALTHYEXTENSION@GMAIL.COM.XPI () (No name found) -- C:\USERS\BUPGAR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MUT0TK5F.DEFAULT\EXTENSIONS\STEFANVANDAMME@STEFANVD.NET.XPI () (No name found) -- C:\USERS\BUPGAR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MUT0TK5F.DEFAULT\EXTENSIONS\TRACKMENOT@MRL.NYU.EDU.XPI () (No name found) -- C:\USERS\BUPGAR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MUT0TK5F.DEFAULT\EXTENSIONS\YOUTUBE2MP3@MONDAYX.DE.XPI O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\DealBulldog Toolbar\tbcore3.dll () O3 - HKLM\..\Toolbar: (DealBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\DealBulldog Toolbar\tbcore3.dll () O3 - HKCU\..\Toolbar\WebBrowser: (DealBulldog Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\DealBulldog Toolbar\tbcore3.dll () O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Programme\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.) O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD) O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUS) O4 - HKCU..\Run: [Odcyyzogy] C:\Users\Bupgar\AppData\Roaming\Tezi\afub.exe (Paragon Software Group) O4 - HKCU..\Run: [RocketDock] D:\Programme\RocketDock\RocketDock.exe () O4 - HKCU..\Run: [vasja] C:\Users\Bupgar\AppData\Local\Temp\23894729347.exe (Paragon Software Group) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O9 - Extra Button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - D:\icq\ICQ7.7\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - D:\icq\ICQ7.7\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 10.2.0) O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A527F6CE-8165-4AA2-8552-4B9AE24DE61E}: DhcpNameServer = 192.168.178.1 O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O27:64bit: - HKLM IFEO\liveupdate.exe: Debugger - D:\Programme\TUAutoReactivator64.exe (TuneUp Software) O27:64bit: - HKLM IFEO\p4gxui.exe: Debugger - D:\Programme\TUAutoReactivator64.exe (TuneUp Software) O27 - HKLM IFEO\liveupdate.exe: Debugger - D:\Programme\TUAutoReactivator64.exe (TuneUp Software) O27 - HKLM IFEO\p4gxui.exe: Debugger - D:\Programme\TUAutoReactivator64.exe (TuneUp Software) O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{9f518fe4-3223-11e1-b287-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{9f518fe4-3223-11e1-b287-806e6f6e6963}\Shell\AutoRun\command - "" = G:\Install.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/03/04 00:04:22 | 000,585,216 | ---- | C] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe [2012/03/03 21:36:11 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\ElevatedDiagnostics [2012/03/02 05:07:44 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Tezi [2012/03/02 05:07:44 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Gatiso [2012/03/02 05:07:44 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Curibo [2012/03/02 04:10:39 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Avira [2012/03/02 04:05:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2012/03/02 04:04:58 | 000,132,320 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys [2012/03/02 04:04:58 | 000,097,312 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys [2012/03/02 04:04:58 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys [2012/03/02 04:04:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2012/03/02 04:04:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira [2012/02/26 19:44:42 | 000,000,000 | ---D | C] -- C:\ProgramData\CPA_VA [2012/02/26 19:43:39 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\COMODO [2012/02/25 11:39:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Comodo [2012/02/25 11:39:55 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gdiplus.dll [2012/02/25 11:39:55 | 001,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc71.dll [2012/02/15 02:48:13 | 000,509,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntshrui.dll [2012/02/15 02:48:11 | 000,515,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\timedate.cpl [2012/02/15 02:48:10 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\timedate.cpl [2012/02/15 02:47:58 | 000,634,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcrt.dll [2012/02/15 02:47:38 | 000,702,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2012/02/15 02:47:37 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2012/02/15 02:47:37 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2012/02/15 02:47:36 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2012/02/15 02:47:36 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2012/02/15 02:47:35 | 000,134,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2012/02/15 02:47:34 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2012/02/14 17:52:00 | 000,000,000 | ---D | C] -- C:\Users\***\Documents\ICQ [2012/02/09 04:39:26 | 000,000,000 | ---D | C] -- C:\ImReich der Tiefe [2012/02/09 04:15:46 | 000,000,000 | ---D | C] -- C:\weltall [2012/02/05 21:55:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2012/02/05 21:55:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2012/02/05 21:54:59 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll [2012/02/05 21:54:59 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2012/02/05 21:54:59 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2012/02/05 21:54:59 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2012/02/05 21:54:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java [2012/02/05 20:31:45 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\cintia ========== Files - Modified Within 30 Days ========== [2012/03/04 00:04:26 | 000,585,216 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe [2012/03/03 23:31:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/03/03 23:31:44 | 2131,529,727 | -HS- | M] () -- C:\hiberfil.sys [2012/03/03 23:04:14 | 000,003,536 | ---- | M] () -- C:\bootsqm.dat [2012/03/03 21:30:45 | 000,001,820 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini [2012/03/03 21:19:03 | 000,015,472 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/03/03 21:19:03 | 000,015,472 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/03/03 21:11:31 | 000,001,189 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini [2012/03/03 20:02:34 | 000,043,093 | ---- | M] () -- C:\Users\***\Desktop\laura-maggi-08.jpg [2012/03/03 05:51:32 | 001,468,593 | ---- | M] () -- C:\Users\***\Desktop\artleo.com-18603.jpg [2012/03/03 05:49:52 | 000,079,656 | ---- | M] () -- C:\Users\***\Desktop\cintia_dicker_sports_illustrated12.jpg [2012/03/02 04:01:55 | 001,095,728 | ---- | M] () -- C:\Windows\SysNative\drivers\sfi.dat [2012/03/01 01:34:06 | 000,000,069 | ---- | M] () -- C:\Users\***\Desktop\Filmhochschule – Wikipedia.URL [2012/02/25 11:39:55 | 001,700,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\gdiplus.dll [2012/02/25 11:39:55 | 001,060,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc71.dll [2012/02/25 11:05:54 | 000,017,408 | ---- | M] () -- C:\Users\***\AppData\Local\WebpageIcons.db [2012/02/25 10:42:51 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2012/02/20 06:07:57 | 000,000,083 | ---- | M] () -- C:\Users\***\Desktop\Betten-ABC.URL [2012/02/19 02:49:42 | 000,654,166 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2012/02/19 02:49:42 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012/02/19 02:49:42 | 000,130,006 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2012/02/19 02:49:42 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012/02/19 02:49:41 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012/02/17 05:52:29 | 000,000,066 | ---- | M] () -- C:\Users\***\Desktop\wurfzelt von decathlon.de, Ihr DECATHLON-Geschäft im Internet..URL [2012/02/17 04:44:18 | 000,000,083 | ---- | M] () -- C:\Users\***\Desktop\The Walking Dead Torn Apart - Family Matters (AMC Webisodes - Part 2) - YouTube.URL [2012/02/17 02:52:59 | 000,000,424 | ---- | M] () -- C:\Users\***\Desktop\JOBBÖRSE - Stellenangebot.URL [2012/02/15 05:42:22 | 000,274,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012/02/12 05:41:12 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ccdcmbx64_01009.Wdf [2012/02/08 21:13:02 | 000,000,066 | ---- | M] () -- C:\Users\***\Desktop\Kontakt Fachbetrieb für Isolierglas, Bleiverglasung und Wintergartenverglasung Ihr Meisterbetrieb Jaap - Glasversand24.de.URL [2012/02/08 21:12:47 | 000,000,059 | ---- | M] () -- C:\Users\***\Desktop\Wandspiegel, Badspiegel, Spiegelglas, Spiegel nach Maß Spiegelschrank - Wandspiegel, Badspiegel, Spiegelglas, Spiegel nach M.URL [2012/02/08 21:00:41 | 000,000,062 | ---- | M] () -- C:\Users\***\Desktop\Share-Links.biz - Der.Herr.der.Ringe.-.Die.Zwei....luray.NEUFASSUNG.AVC.REMUX-HDS.URL [2012/02/08 20:59:53 | 000,000,062 | ---- | M] () -- C:\Users\***\Desktop\Share-Links.biz - Der.Herr.der.Ringe.-.Die.Rueck...luray.NEUFASSUNG.AVC.REMUX-HDS.URL [2012/02/05 21:54:33 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll [2012/02/05 21:54:33 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2012/02/05 21:54:33 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2012/02/05 21:54:33 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe ========== Files Created - No Company Name ========== [2012/03/03 23:04:14 | 000,003,536 | ---- | C] () -- C:\bootsqm.dat [2012/03/03 20:02:33 | 000,043,093 | ---- | C] () -- C:\Users\***\Desktop\laura-maggi-08.jpg [2012/03/03 05:51:30 | 001,468,593 | ---- | C] () -- C:\Users\***\Desktop\artleo.com-18603.jpg [2012/03/03 05:49:51 | 000,079,656 | ---- | C] () -- C:\Users\***\Desktop\cintia_dicker_sports_illustrated12.jpg [2012/03/01 01:34:06 | 000,000,069 | ---- | C] () -- C:\Users\***\Desktop\Filmhochschule – Wikipedia.URL [2012/02/25 11:42:06 | 001,095,728 | ---- | C] () -- C:\Windows\SysNative\drivers\sfi.dat [2012/02/25 11:05:51 | 000,017,408 | ---- | C] () -- C:\Users\***\AppData\Local\WebpageIcons.db [2012/02/20 06:07:57 | 000,000,083 | ---- | C] () -- C:\Users\***\Desktop\Betten-ABC.URL [2012/02/17 05:52:29 | 000,000,066 | ---- | C] () -- C:\Users\***\Desktop\wurfzelt von decathlon.de, Ihr DECATHLON-Geschäft im Internet..URL [2012/02/17 04:44:18 | 000,000,083 | ---- | C] () -- C:\Users\***\Desktop\The Walking Dead Torn Apart - Family Matters (AMC Webisodes - Part 2) - YouTube.URL [2012/02/17 02:52:59 | 000,000,424 | ---- | C] () -- C:\Users\***\Desktop\JOBBÖRSE - Stellenangebot.URL [2012/02/12 05:41:12 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ccdcmbx64_01009.Wdf [2012/02/08 21:13:02 | 000,000,066 | ---- | C] () -- C:\Users\***\Desktop\Kontakt Fachbetrieb für Isolierglas, Bleiverglasung und Wintergartenverglasung Ihr Meisterbetrieb Jaap - Glasversand24.de.URL [2012/02/08 21:12:47 | 000,000,059 | ---- | C] () -- C:\Users\***\Desktop\Wandspiegel, Badspiegel, Spiegelglas, Spiegel nach Maß Spiegelschrank - Wandspiegel, Badspiegel, Spiegelglas, Spiegel nach M.URL [2012/02/08 21:00:41 | 000,000,062 | ---- | C] () -- C:\Users\***\Desktop\Share-Links.biz - Der.Herr.der.Ringe.-.Die.Zwei....luray.NEUFASSUNG.AVC.REMUX-HDS.URL [2012/02/08 20:59:53 | 000,000,062 | ---- | C] () -- C:\Users\***\Desktop\Share-Links.biz - Der.Herr.der.Ringe.-.Die.Rueck...luray.NEUFASSUNG.AVC.REMUX-HDS.URL [2012/01/20 00:40:41 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2012/01/20 00:40:41 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2012/01/20 00:40:41 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2012/01/19 23:55:46 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2012/01/14 12:18:55 | 000,007,609 | ---- | C] () -- C:\Users\***\AppData\Local\resmon.resmoncfg [2012/01/09 02:49:24 | 000,065,536 | ---- | C] () -- C:\Windows\IFinst27.exe [2012/01/08 20:48:58 | 039,371,232 | ---- | C] () -- C:\Users\***\AppData\Roaming\Pflanzen_gegen_Zombies_GOTY_Setup-de.exe [2011/12/29 19:42:36 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2011/12/29 19:36:31 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2011/07/13 18:55:06 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll < End of report > ich hoffe ihr könnt mir helfen auf jeden fall danke schonmal |
04.03.2012, 16:24 | #2 |
/// Malware-holic | windows security center windows gesperrt hi
__________________dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user. wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts. • Starte bitte die OTL.exe • Kopiere nun das Folgende in die Textbox. Code:
ATTFilter :OTL O4 - HKCU..\Run: [vasja] C:\Users\Bupgar\AppData\Local\Temp\23894729347.exe (Paragon Software Group) O4 - HKCU..\Run: [Odcyyzogy] C:\Users\Bupgar\AppData\Roaming\Tezi\afub.exe (Paragon Software Group) [2012/03/02 05:07:44 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Gatiso [2012/03/02 05:07:44 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Curibo :Files C:\Users\Bupgar\AppData\Local\Temp\23894729347.exe C:\Users\Bupgar\AppData\Roaming\Tezi :Commands [purity] [EMPTYFLASH] [emptytemp] [Reboot] • Schliesse bitte nun alle Programme. • Klicke nun bitte auf den Fix Button. • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen. • Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren. starte in den normalen modus. falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang in den Thread posten! Drücke bitte die + E Taste.
__________________ |
Themen zu windows security center windows gesperrt |
64-bit, autorun, avira, avp.exe, bho, bildschirm, cpu-z, error, flash player, format, gesperrt, gfnexsrv.exe, helper, home, install.exe, jdownloader, kaspersky, mozilla, mp3, ntdll.dll, object, plug-in, problem, programm, realtek, registry, rundll, scan, searchscopes, security, software, usb, usb 2.0, version=2.0, windows, wlan, zeon/pdf |