|
Plagegeister aller Art und deren Bekämpfung: blue screen...dauernder neustart...irql_not_less_or_equalWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
19.01.2013, 01:41 | #1 |
| blue screen...dauernder neustart...irql_not_less_or_equal Hi, Ich hoffe mir kann jreand helfen. Mein computer rastet dauernd aus. Es kommt immer wieder der selbe bluescreen und der pc startet neu... Ich wollte mein französisch aufpolieren und habe einen sprachtrainer von 1995 installiert und seitdem hab ich den fehler...deinstallieren konnte ich es leider nicht mehr, da die installation nicht vollständig ausgeführt worden ist... Hab manuell den ordner gelöscht, aber wahrscheinlich nicht die dateien erwichst, die woanders hinterlegt worden sind... Kann mir jemand helfen, ohne den pc neu zu installieren? Sorry, ich muss vom handy aus schreiben, da der pc andauernd neustartet... Den text kennt ihr ja bestimmt Technical information: *** STOP: 0x0000000A (0xC05EC000, 0x00000000, 0x00000000, 0x82AB97AD) Vielen dank hier die fehlermeldung von windows.... Problemsignatur: Problemereignisname: BlueScreen Betriebsystemversion: 6.0.6002.2.2.0.768.3 Gebietsschema-ID: 1031 Zusatzinformationen zum Problem: BCCode: a BCP1: C0645000 BCP2: 00000000 BCP3: 00000000 BCP4: 82AED7AD OS Version: 6_0_6002 Service Pack: 2_0 Product: 768_1 Dateien, die bei der Beschreibung des Problems hilfreich sind: C:\Windows\Minidump\Mini011913-06.dmp C:\Users\Wissem\AppData\Local\Temp\WER-125783-0.sysdata.xml C:\Users\Wissem\AppData\Local\Temp\WER2DB4.tmp.version.txt Lesen Sie unsere Datenschutzrichtlinie: Datenschutzbestimmungen für den Microsoft-Fehlerberichterstattungsdienst |
19.01.2013, 10:32 | #2 |
/// TB-Ausbilder | blue screen...dauernder neustart...irql_not_less_or_equal Also ohne Garantie können wir versuchen, den Fehler zu finden.
__________________Ich werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich. Bitte Lesen: Regeln für die Bereinigung Damit die Bereinigung funktioniert bitte ich dich, die folgenden Punkte aufmerksam zu lesen:
Gelesen und verstanden? Scan mit Farbar's Recovery Scan Tool
__________________ |
19.01.2013, 12:36 | #3 |
| blue screen...dauernder neustart...irql_not_less_or_equal Hi danke das du mir wieder hilfst...
__________________Also ich habe einen sony vaio und daher besitze ich keine recovery cd. Ich habe frst gespeichert...auf dem stick und pc... Ich habe folgendes problem, mein usbstick wird mir im computer reparieren modus nicht angezeigt...meine mobile festplatte erkennt er dagegen... Ich habe es dann über meine mobile festplatte laufen lassen... Dann wird beim starten die mobile festplatte nicht erkannt....und was soll ich nun tun??? Korrektur...hab neu gestartet jetzt erkennt er wieder die mobile festplatte bei mir als h anstatt i: Der scan läuft, ich poste sobald es fertig ist.... |
19.01.2013, 12:58 | #4 |
/// TB-Ausbilder | blue screen...dauernder neustart...irql_not_less_or_equal Der Buchstabe ist immer anders.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
19.01.2013, 13:00 | #5 |
| blue screen...dauernder neustart...irql_not_less_or_equal okay, war meine alternative lösung ohne usb ok? so hier die file...das sagt frst aus: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-01-2013 Ran by SYSTEM at 19-01-2013 12:38:51 Running from H:\ Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: German Standard The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x] HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [835584 2007-03-10] (Synaptics, Inc.) HKLM\...\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup [30192 2010-08-25] (Google) HKLM\...\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [317280 2008-04-03] (Sony Corporation) HKLM\...\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe [24576 2008-11-29] (Sony Corporation) HKLM\...\Run: [Skytel] Skytel.exe [x] HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [61440 2009-05-15] (Advanced Micro Devices, Inc.) HKLM\...\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [599328 2010-03-24] (Sony Corporation) HKLM\...\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [79192 2011-02-18] (Research In Motion Limited) HKLM\...\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\ssmmgr.exe /autorun [618496 2010-06-07] () HKLM\...\Run: [PDFPrint] C:\Program Files\pdf24\pdf24.exe [220744 2012-02-03] (Geek Software GmbH) HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.) HKLM\...\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-03] (Adobe Systems Incorporated) HKU\Default\...\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [x] HKU\Default\...\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" [270336 2008-11-05] (Sony Corporation) HKU\Default User\...\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [x] HKU\Default User\...\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" [270336 2008-11-05] (Sony Corporation) HKU\Gast\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x] HKU\Gast\...\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" [270336 2008-11-05] (Sony Corporation) HKU\Gast\...\Run: [Google Update] "C:\Users\Gast\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-11-09] (Google Inc.) HKU\Gast\...\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung) HKU\Gast\...\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation) HKU\Wissem\...\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" [270336 2008-11-05] (Sony Corporation) HKU\Wissem\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\Wissem\...\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" [247728 2012-01-23] (TomTom) HKU\Wissem\...\Run: [doubleTwist] C:\Program Files\doubleTwist 2.0\DoubleTwist.DeviceHelper.exe [24576 2010-09-18] (doubleTwist Corporation) HKU\Wissem\...\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.) HKU\Wissem\...\Run: [KiesPreload] C:\Program Files\Samsung\Kies\Kies.exe /preload [1476104 2012-12-20] (Samsung) HKU\Wissem\...\Run: [KiesAirMessage] C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup [578560 2012-12-18] (Samsung Electronics) Winlogon\Notify\igfxcui: igfxdev.dll [X] Winlogon\Notify\VESWinlogon: VESWinlogon.dll (Sony Corporation) AppInit_DLLs: c:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll ==================== Services (Whitelisted) =================== 2 AAV UpdateService; "C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe" [128296 2008-10-24] () 3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) 2 dgdersvc; C:\Windows\system32\dgdersvc.exe [95568 2010-09-06] (Devguru Co., Ltd.) 3 GoogleDesktopManager-051210-111108; "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [30192 2010-08-25] (Google) 3 MozillaMaintenance; "C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe" [115168 2012-12-15] (Mozilla Foundation) 3 MSSQL$MSSMLBIZ; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [29293408 2010-12-10] (Microsoft Corporation) 2 NAV; "C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccSvcHst.exe" /s "NAV" /m "C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\diMaster.dll" /prefetch:1 [535416 2012-10-11] (Symantec Corporation) 2 NCO; "C:\Program Files\Norton Identity Safe\Engine\2013.2.1.33\ccSvcHst.exe" /s "NCO" /m "C:\Program Files\Norton Identity Safe\Engine\2013.2.1.33\diMaster.dll" /prefetch:1 [535416 2012-12-05] (Symantec Corporation) 2 NMSAccess; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] () 2 NvcRpcServer; "C:\Program Files\Nortel Networks\NvcRpcSvr.exe" [71176 2007-04-09] (Nortel Networks NA, Inc.) 3 SOHCImp; "C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe" [103712 2008-10-21] (Sony Corporation) 3 SOHDms; "C:\Program Files\Sony\VAIO Media plus\SOHDms.exe" [353568 2008-10-21] (Sony Corporation) 3 SOHDs; "C:\Program Files\Sony\VAIO Media plus\SOHDs.exe" [62752 2008-10-21] (Sony Corporation) 2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) 3 VAIO Entertainment TV Device Arbitration Service; "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe" [69632 2009-03-05] (Sony Corporation) 2 VCFw; "C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe" [5189992 2009-03-05] (Sony Corporation) 3 VcmIAlzMgr; "C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe" [480624 2009-09-16] (Sony Corporation) 3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -RunBySCM [313264 2009-03-05] (Sony Corporation) 3 VUAgent; "C:\Program Files\Sony\VAIO Update Common\VUAgent.exe" [1086568 2011-09-23] (Sony Corporation) 2 VzCdbSvc; "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe" [192512 2009-03-05] (Sony Corporation) 3 MSCSPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe" [x] 3 SPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe" [x] ==================== Drivers (Whitelisted) ==================== 3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.) 1 BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20130107.001\BHDrvx86.sys [995488 2012-11-30] (Symantec Corporation) 1 ccSet_NAV; C:\Windows\system32\drivers\NAV\1402000.013\ccSetx86.sys [134304 2012-10-03] (Symantec Corporation) 1 ccSet_NST; C:\Windows\system32\drivers\NST\7DD02010.021\ccSetx86.sys [134304 2012-08-20] (Symantec Corporation) 3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [18120 2010-09-06] (Devguru Co., Ltd) 3 Eacfilt; C:\Windows\System32\DRIVERS\eacfilt.sys [31784 2007-04-09] (Nortel Networks) 1 eeCtrl; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2012-12-21] (Symantec Corporation) 3 EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2012-12-21] (Symantec Corporation) 3 FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [36640 2010-09-06] () 1 IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20130111.002\IDSvix86.sys [386720 2012-12-28] (Symantec Corporation) 2 iPodDrv; \??\C:\Windows\system32\drivers\iPodDrv.sys [6656 2010-03-10] (Windows (R) Codename Longhorn DDK provider) 3 IPSECEXT; C:\Windows\System32\DRIVERS\ipsecw2k.sys [148232 2007-04-09] (Nortel Networks NA, Inc.) 3 IPSECSHM; C:\Windows\System32\DRIVERS\ipsecw2k.sys [148232 2007-04-09] (Nortel Networks NA, Inc.) 2 n5lpt.sys; \??\C:\Windows\system32\Drivers\n5lpt.sys [21196 2007-11-30] (Number Five Software) 3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20130118.022\NAVENG.SYS [93296 2013-01-19] (Symantec Corporation) 3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20130118.022\NAVEX15.SYS [1603824 2013-01-19] (Symantec Corporation) 3 SipIMNDI; C:\Windows\System32\DRIVERS\SipIMNDI.sys [24352 2009-10-15] (T-Systems International GmbH) 0 SMR311; C:\Windows\System32\drivers\SMR311.SYS [97440 2012-12-29] (Symantec Corporation) 3 SRTSP; C:\Windows\system32\drivers\NAV\1402000.013\SRTSP.SYS [586400 2012-10-08] (Symantec Corporation) 1 SRTSPX; C:\Windows\system32\drivers\NAV\1402000.013\SRTSPX.SYS [32888 2012-09-06] (Symantec Corporation) 3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [7168 2009-11-12] () 2 Stld; C:\Windows\System32\Drivers\Stld.sys [10240 2009-04-22] (Number Five Software) 0 SymDS; C:\Windows\System32\drivers\NAV\1402000.013\SYMDS.SYS [368288 2012-10-03] (Symantec Corporation) 0 SymEFA; C:\Windows\System32\drivers\NAV\1402000.013\SYMEFA.SYS [927904 2012-10-03] (Symantec Corporation) 3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2012-12-29] (Symantec Corporation) 1 SymIRON; C:\Windows\system32\drivers\NAV\1402000.013\Ironx86.SYS [175264 2012-09-06] (Symantec Corporation) 1 SYMTDIv; C:\Windows\system32\drivers\NAV\1402000.013\SYMTDIV.SYS [350368 2012-09-06] (Symantec Corporation) 3 catchme; \??\C:\Users\Wissem\AppData\Local\Temp\catchme.sys [x] 2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] 3 igfx; C:\Windows\System32\DRIVERS\igdkmd32.sys [x] 3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x] 3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x] 3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x] 4 UIUSys; C:\Windows\System32\DRIVERS\UIUSYS.SYS [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-01-19 12:27 - 2013-01-19 12:27 - 00142520 ____A C:\Windows\Minidump\Mini011913-07.dmp 2013-01-19 11:53 - 2013-01-19 11:53 - 00014452 ____A C:\Users\Wissem\Downloads\CBEB.tmp 2013-01-19 11:52 - 2013-01-19 11:53 - 00909506 ____A (Farbar) C:\Users\Wissem\Downloads\FRST.exe 2013-01-19 04:28 - 2013-01-19 04:28 - 06260632 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NRnR (1).exe 2013-01-19 04:27 - 2013-01-19 04:27 - 06258072 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NRnR.exe 2013-01-19 04:16 - 2013-01-19 04:16 - 00142520 ____A C:\Windows\Minidump\Mini011913-06.dmp 2013-01-19 04:07 - 2013-01-19 04:07 - 00142520 ____A C:\Windows\Minidump\Mini011913-05.dmp 2013-01-19 03:56 - 2013-01-19 03:56 - 00142520 ____A C:\Windows\Minidump\Mini011913-04.dmp 2013-01-19 03:31 - 2013-01-19 03:31 - 00142520 ____A C:\Windows\Minidump\Mini011913-03.dmp 2013-01-19 01:43 - 2013-01-19 01:43 - 00142520 ____A C:\Windows\Minidump\Mini011913-02.dmp 2013-01-19 01:16 - 2013-01-19 01:16 - 00142520 ____A C:\Windows\Minidump\Mini011913-01.dmp 2013-01-17 13:58 - 2013-01-17 13:58 - 00142520 ____A C:\Windows\Minidump\Mini011713-03.dmp 2013-01-17 13:17 - 2013-01-17 13:18 - 00000000 ____D C:\Program Files\Debugging Tools for Windows (x86) 2013-01-17 13:16 - 2013-01-17 13:16 - 17666048 ____A C:\Users\Wissem\Downloads\dbg_x86_6.10.3.233.msi 2013-01-17 13:03 - 2013-01-17 13:04 - 00142520 ____A C:\Windows\Minidump\Mini011713-02.dmp 2013-01-17 12:56 - 2013-01-17 12:56 - 00142520 ____A C:\Windows\Minidump\Mini011713-01.dmp 2013-01-17 11:19 - 2013-01-17 11:19 - 17666048 ____A C:\Users\Wissem\Downloads\Nicht bestätigt 449985.crdownload 2013-01-17 09:47 - 2013-01-17 09:48 - 00004097 ____A C:\Windows\System32\jupdate-1.7.0_11-b21.log 2013-01-12 07:13 - 2013-01-12 07:13 - 00000828 ____A C:\Users\Wissem\Desktop\PhotoScape.lnk 2013-01-12 07:01 - 2013-01-12 07:01 - 21322864 ____A (Mooii) C:\Users\Wissem\Downloads\PhotoScape_V3.6.3.exe 2013-01-12 06:06 - 2013-01-12 06:54 - 00000000 ____D C:\Users\Wissem\Documents\Steuerfälle 2013-01-12 06:05 - 2013-01-12 06:05 - 00000000 ____D C:\Users\Wissem\AppData\Local\AAV 2013-01-12 05:53 - 2013-01-12 06:03 - 00002094 ____A C:\Users\Public\Desktop\Steuer-Spar- Erklärung 2013.lnk 2013-01-12 05:39 - 2013-01-12 05:55 - 00000000 ____D C:\Program Files\Akademische Arbeitsgemeinschaft 2013-01-12 05:37 - 2013-01-12 06:01 - 00000000 ____D C:\Users\All Users\AAV 2013-01-12 04:10 - 2013-01-12 04:11 - 00142520 ____A C:\Windows\Minidump\Mini011213-01.dmp 2013-01-10 04:08 - 2013-01-10 04:08 - 00000000 ____D C:\Program Files\DVDVideoSoft 2013-01-10 04:08 - 2013-01-10 04:08 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-01-10 03:38 - 2013-01-10 03:38 - 25028024 ____A (DVDVideoSoft Ltd. ) C:\Users\Wissem\Downloads\FreeYouTubeToMP3Converter (1).exe 2013-01-09 17:53 - 2012-11-23 02:35 - 02048000 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-01-09 17:52 - 2012-11-20 05:22 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2013-01-09 17:52 - 2012-11-02 11:19 - 01400832 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-12-29 16:48 - 2012-12-29 16:48 - 00000000 ____D C:\Users\Wissem\Desktop\ESET 2012-12-29 16:32 - 2012-12-29 16:32 - 00000000 ____D C:\Users\Wissem\Documents\Symantec 2012-12-29 16:29 - 2013-01-11 19:57 - 00000000 ____D C:\Windows\System32\Drivers\NST 2012-12-29 16:29 - 2012-12-29 16:29 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS 2012-12-29 16:29 - 2012-12-29 16:29 - 00007446 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT 2012-12-29 16:29 - 2012-12-29 16:29 - 00002125 ____A C:\Users\Public\Desktop\Norton AntiVirus.lnk 2012-12-29 16:29 - 2012-12-29 16:29 - 00000000 ____D C:\Program Files\Symantec 2012-12-29 16:29 - 2012-12-29 16:29 - 00000000 ____D C:\Program Files\Norton Identity Safe 2012-12-29 16:28 - 2012-12-29 16:28 - 00000000 ____D C:\Windows\System32\Drivers\NAV 2012-12-29 16:28 - 2012-12-29 16:28 - 00000000 ____D C:\Program Files\Norton AntiVirus 2012-12-29 16:26 - 2012-12-29 16:26 - 00916600 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NAVDownloader (1).exe 2012-12-29 15:44 - 2012-12-29 15:44 - 00000735 ____A C:\DelFix[S2].txt 2012-12-29 15:43 - 2012-12-29 15:43 - 00001456 ____A C:\DelFix[S1].txt 2012-12-29 15:43 - 2012-12-29 15:43 - 00000620 ____A C:\DelFix[R1].txt 2012-12-29 14:30 - 2012-12-29 14:30 - 00000000 ____D C:\Users\All Users\SMR311 2012-12-29 14:28 - 2012-12-29 14:28 - 00097440 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SMR311.SYS 2012-12-29 14:26 - 2012-12-29 14:39 - 00000000 ____D C:\Users\Wissem\AppData\Local\NPE 2012-12-29 14:26 - 2012-12-29 14:26 - 02957840 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NPE.exe 2012-12-29 14:23 - 2012-12-29 14:24 - 00001892 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk 2012-12-29 14:22 - 2012-12-29 14:23 - 00000000 ____D C:\Program Files\Common Files\Adobe 2012-12-29 13:52 - 2012-11-28 10:31 - 00260528 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2012-12-29 13:50 - 2012-11-28 10:35 - 00093640 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll 2012-12-29 13:50 - 2012-11-28 10:31 - 00174000 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2012-12-29 13:50 - 2012-11-28 10:31 - 00173992 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2012-12-29 13:48 - 2012-12-29 13:50 - 00004574 ____A C:\Windows\System32\jupdate-1.7.0_10-b18.log 2012-12-29 13:38 - 2012-12-29 13:38 - 00896016 ____A (Oracle Corporation) C:\Users\Wissem\Downloads\chromeinstall-7u10.exe 2012-12-28 16:35 - 2012-12-28 16:35 - 00000000 ____D C:\Program Files\ESET 2012-12-28 16:04 - 2012-12-28 16:04 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Malwarebytes 2012-12-28 16:04 - 2012-12-28 16:04 - 00000000 ____D C:\Users\All Users\Malwarebytes 2012-12-28 16:03 - 2012-12-28 16:03 - 10156344 ____A (Malwarebytes Corporation ) C:\Users\Wissem\Downloads\mbam-setup-1.70.0.1100.exe 2012-12-28 13:44 - 2012-12-28 14:09 - 00000000 ____D C:\Windows\erdnt 2012-12-28 00:43 - 2012-12-28 00:43 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2012-12-27 22:59 - 2013-01-11 01:22 - 00000000 ____D C:\Users\Wissem\AppData\Local\CrashDumps 2012-12-27 22:22 - 2012-12-27 22:22 - 00001783 ____A C:\Users\Public\Desktop\Samsung Kies (Lite).lnk 2012-12-27 22:22 - 2012-12-27 22:22 - 00001773 ____A C:\Users\Public\Desktop\Samsung Kies.lnk 2012-12-27 21:59 - 2012-12-27 22:00 - 68037104 ____A (Samsung Electronics Co., Ltd. ) C:\Users\Wissem\Downloads\KiesSetup.exe 2012-12-26 03:05 - 2012-12-26 03:05 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2012-12-26 02:36 - 2012-09-20 05:35 - 00181344 ____A (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudmdm.sys 2012-12-26 02:36 - 2012-09-20 05:35 - 00083168 ____A (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudbus.sys 2012-12-23 03:36 - 2012-12-29 16:28 - 00000829 ____A C:\Users\Wissem\Desktop\Norton-Installationsdateien.lnk 2012-12-23 03:36 - 2012-12-23 03:36 - 00000000 ____D C:\Users\Public\Downloads\Norton 2012-12-23 03:22 - 2012-12-23 03:22 - 00007296 ____A C:\Users\All Users\N360BUOptions.ini 2012-12-23 03:19 - 2012-12-23 03:19 - 00916584 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NAVDownloader.exe 2012-12-21 03:01 - 2012-12-16 14:12 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll 2012-12-21 03:01 - 2012-12-16 11:50 - 00293376 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll ==================== One Month Modified Files and Folders ======== 2013-01-19 12:38 - 2013-01-19 12:38 - 00000000 ____D C:\FRST 2013-01-19 12:33 - 2009-05-13 16:14 - 01320794 ____A C:\Windows\WindowsUpdate.log 2013-01-19 12:33 - 2006-11-02 14:01 - 00032610 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-01-19 12:33 - 2006-11-02 14:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-01-19 12:33 - 2006-11-02 13:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-01-19 12:33 - 2006-11-02 13:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-01-19 12:27 - 2013-01-19 12:27 - 00142520 ____A C:\Windows\Minidump\Mini011913-07.dmp 2013-01-19 12:27 - 2010-02-10 14:50 - 00001094 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-01-19 12:27 - 2009-05-22 05:12 - 00000000 ____D C:\Windows\Minidump 2013-01-19 12:26 - 2009-05-22 05:11 - 341416561 ____A C:\Windows\MEMORY.DMP 2013-01-19 12:09 - 2008-01-21 08:16 - 01606662 ____A C:\Windows\System32\PerfStringBackup.INI 2013-01-19 12:05 - 2011-01-23 01:40 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1190657541-1879476424-4156719937-1003UA.job 2013-01-19 12:04 - 2010-02-10 14:50 - 00001098 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-01-19 11:53 - 2013-01-19 11:53 - 00014452 ____A C:\Users\Wissem\Downloads\CBEB.tmp 2013-01-19 11:53 - 2013-01-19 11:52 - 00909506 ____A (Farbar) C:\Users\Wissem\Downloads\FRST.exe 2013-01-19 04:28 - 2013-01-19 04:28 - 06260632 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NRnR (1).exe 2013-01-19 04:27 - 2013-01-19 04:27 - 06258072 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NRnR.exe 2013-01-19 04:16 - 2013-01-19 04:16 - 00142520 ____A C:\Windows\Minidump\Mini011913-06.dmp 2013-01-19 04:07 - 2013-01-19 04:07 - 00142520 ____A C:\Windows\Minidump\Mini011913-05.dmp 2013-01-19 04:04 - 2010-04-08 09:45 - 00026112 ____A C:\Users\Wissem\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-01-19 03:56 - 2013-01-19 03:56 - 00142520 ____A C:\Windows\Minidump\Mini011913-04.dmp 2013-01-19 03:31 - 2013-01-19 03:31 - 00142520 ____A C:\Windows\Minidump\Mini011913-03.dmp 2013-01-19 01:43 - 2013-01-19 01:43 - 00142520 ____A C:\Windows\Minidump\Mini011913-02.dmp 2013-01-19 01:16 - 2013-01-19 01:16 - 00142520 ____A C:\Windows\Minidump\Mini011913-01.dmp 2013-01-19 01:15 - 2008-01-21 03:47 - 01598020 ____A C:\Windows\PFRO.log 2013-01-17 13:58 - 2013-01-17 13:58 - 00142520 ____A C:\Windows\Minidump\Mini011713-03.dmp 2013-01-17 13:18 - 2013-01-17 13:17 - 00000000 ____D C:\Program Files\Debugging Tools for Windows (x86) 2013-01-17 13:16 - 2013-01-17 13:16 - 17666048 ____A C:\Users\Wissem\Downloads\dbg_x86_6.10.3.233.msi 2013-01-17 13:04 - 2013-01-17 13:03 - 00142520 ____A C:\Windows\Minidump\Mini011713-02.dmp 2013-01-17 12:56 - 2013-01-17 12:56 - 00142520 ____A C:\Windows\Minidump\Mini011713-01.dmp 2013-01-17 12:54 - 2009-05-13 16:18 - 00002032 ____A C:\Users\Wissem\AppData\Local\d3d9caps.dat 2013-01-17 12:43 - 2011-08-12 01:11 - 00000000 ____D C:\users\Gast 2013-01-17 12:43 - 2009-05-13 16:18 - 00000000 ____D C:\users\Wissem 2013-01-17 12:43 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\System32\spool 2013-01-17 12:43 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\System32\Msdtc 2013-01-17 12:43 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\registration 2013-01-17 12:43 - 2006-11-02 11:22 - 62652416 ____A C:\Windows\System32\config\software_previous 2013-01-17 12:43 - 2006-11-02 11:22 - 30670848 ____A C:\Windows\System32\config\system_previous 2013-01-17 12:30 - 2006-11-02 11:22 - 00262144 ____A C:\Windows\System32\config\security_previous 2013-01-17 12:30 - 2006-11-02 11:22 - 00262144 ____A C:\Windows\System32\config\sam_previous 2013-01-17 12:29 - 2006-11-02 11:22 - 37224448 ____A C:\Windows\System32\config\components_previous 2013-01-17 12:29 - 2006-11-02 11:22 - 00786432 ____A C:\Windows\System32\config\default_previous 2013-01-17 11:19 - 2013-01-17 11:19 - 17666048 ____A C:\Users\Wissem\Downloads\Nicht bestätigt 449985.crdownload 2013-01-17 09:48 - 2013-01-17 09:47 - 00004097 ____A C:\Windows\System32\jupdate-1.7.0_11-b21.log 2013-01-17 09:48 - 2008-10-23 13:39 - 00000000 ____D C:\Program Files\Java 2013-01-13 19:12 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-01-12 07:13 - 2013-01-12 07:13 - 00000828 ____A C:\Users\Wissem\Desktop\PhotoScape.lnk 2013-01-12 07:13 - 2012-05-26 14:00 - 00000000 ____D C:\Program Files\PhotoScape 2013-01-12 07:01 - 2013-01-12 07:01 - 21322864 ____A (Mooii) C:\Users\Wissem\Downloads\PhotoScape_V3.6.3.exe 2013-01-12 06:54 - 2013-01-12 06:06 - 00000000 ____D C:\Users\Wissem\Documents\Steuerfälle 2013-01-12 06:05 - 2013-01-12 06:05 - 00000000 ____D C:\Users\Wissem\AppData\Local\AAV 2013-01-12 06:03 - 2013-01-12 05:53 - 00002094 ____A C:\Users\Public\Desktop\Steuer-Spar- Erklärung 2013.lnk 2013-01-12 06:01 - 2013-01-12 05:37 - 00000000 ____D C:\Users\All Users\AAV 2013-01-12 05:55 - 2013-01-12 05:39 - 00000000 ____D C:\Program Files\Akademische Arbeitsgemeinschaft 2013-01-12 04:11 - 2013-01-12 04:10 - 00142520 ____A C:\Windows\Minidump\Mini011213-01.dmp 2013-01-11 21:05 - 2011-01-23 01:40 - 00001072 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1190657541-1879476424-4156719937-1003Core.job 2013-01-11 19:57 - 2012-12-29 16:29 - 00000000 ____D C:\Windows\System32\Drivers\NST 2013-01-11 01:22 - 2012-12-27 22:59 - 00000000 ____D C:\Users\Wissem\AppData\Local\CrashDumps 2013-01-10 04:09 - 2012-11-17 13:26 - 00001191 ____A C:\Users\Wissem\Desktop\Free YouTube to MP3 Converter.lnk 2013-01-10 04:08 - 2013-01-10 04:08 - 00000000 ____D C:\Program Files\DVDVideoSoft 2013-01-10 04:08 - 2013-01-10 04:08 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-01-10 04:08 - 2011-08-19 04:15 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\DVDVideoSoft 2013-01-10 03:38 - 2013-01-10 03:38 - 25028024 ____A (DVDVideoSoft Ltd. ) C:\Users\Wissem\Downloads\FreeYouTubeToMP3Converter (1).exe 2013-01-09 19:47 - 2006-11-02 13:47 - 00404440 ____A C:\Windows\System32\FNTCACHE.DAT 2013-01-09 19:27 - 2008-11-29 10:06 - 00000000 ____D C:\Users\All Users\Microsoft Help 2013-01-09 19:02 - 2006-11-02 11:24 - 65273848 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe 2013-01-08 11:33 - 2012-12-07 23:08 - 00000000 ____D C:\Users\Wissem\Downloads\moni 2013-01-04 00:03 - 2011-05-01 12:28 - 00000000 ____D C:\Users\Wissem\Desktop\Uni 2013-01-01 01:52 - 2010-12-01 20:11 - 00000000 ____D C:\Users\Wissem\Desktop\wiss Hausi 2012-12-30 04:00 - 2008-10-23 13:38 - 00000000 ____D C:\Users\All Users\Adobe 2012-12-30 03:58 - 2009-05-13 22:26 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Adobe 2012-12-29 16:48 - 2012-12-29 16:48 - 00000000 ____D C:\Users\Wissem\Desktop\ESET 2012-12-29 16:36 - 2009-05-13 19:02 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared 2012-12-29 16:32 - 2012-12-29 16:32 - 00000000 ____D C:\Users\Wissem\Documents\Symantec 2012-12-29 16:32 - 2010-04-29 11:40 - 00000000 ____D C:\Users\All Users\Norton 2012-12-29 16:29 - 2012-12-29 16:29 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS 2012-12-29 16:29 - 2012-12-29 16:29 - 00007446 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT 2012-12-29 16:29 - 2012-12-29 16:29 - 00002125 ____A C:\Users\Public\Desktop\Norton AntiVirus.lnk 2012-12-29 16:29 - 2012-12-29 16:29 - 00000000 ____D C:\Program Files\Symantec 2012-12-29 16:29 - 2012-12-29 16:29 - 00000000 ____D C:\Program Files\Norton Identity Safe 2012-12-29 16:28 - 2012-12-29 16:28 - 00000000 ____D C:\Windows\System32\Drivers\NAV 2012-12-29 16:28 - 2012-12-29 16:28 - 00000000 ____D C:\Program Files\Norton AntiVirus 2012-12-29 16:28 - 2012-12-23 03:36 - 00000829 ____A C:\Users\Wissem\Desktop\Norton-Installationsdateien.lnk 2012-12-29 16:26 - 2012-12-29 16:26 - 00916600 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NAVDownloader (1).exe 2012-12-29 15:44 - 2012-12-29 15:44 - 00000735 ____A C:\DelFix[S2].txt 2012-12-29 15:43 - 2012-12-29 15:43 - 00001456 ____A C:\DelFix[S1].txt 2012-12-29 15:43 - 2012-12-29 15:43 - 00000620 ____A C:\DelFix[R1].txt 2012-12-29 14:39 - 2012-12-29 14:26 - 00000000 ____D C:\Users\Wissem\AppData\Local\NPE 2012-12-29 14:30 - 2012-12-29 14:30 - 00000000 ____D C:\Users\All Users\SMR311 2012-12-29 14:28 - 2012-12-29 14:28 - 00097440 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SMR311.SYS 2012-12-29 14:26 - 2012-12-29 14:26 - 02957840 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NPE.exe 2012-12-29 14:24 - 2012-12-29 14:23 - 00001892 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk 2012-12-29 14:23 - 2012-12-29 14:22 - 00000000 ____D C:\Program Files\Common Files\Adobe 2012-12-29 14:22 - 2009-05-13 22:52 - 00000000 ____D C:\Program Files\Adobe 2012-12-29 14:07 - 2009-05-13 16:18 - 00000000 ____D C:\Users\Wissem\AppData\Local\Adobe 2012-12-29 13:50 - 2012-12-29 13:48 - 00004574 ____A C:\Windows\System32\jupdate-1.7.0_10-b18.log 2012-12-29 13:38 - 2012-12-29 13:38 - 00896016 ____A (Oracle Corporation) C:\Users\Wissem\Downloads\chromeinstall-7u10.exe 2012-12-28 16:35 - 2012-12-28 16:35 - 00000000 ____D C:\Program Files\ESET 2012-12-28 16:21 - 2008-10-23 10:25 - 00000000 ____D C:\Windows\InstDrvs 2012-12-28 16:04 - 2012-12-28 16:04 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Malwarebytes 2012-12-28 16:04 - 2012-12-28 16:04 - 00000000 ____D C:\Users\All Users\Malwarebytes 2012-12-28 16:03 - 2012-12-28 16:03 - 10156344 ____A (Malwarebytes Corporation ) C:\Users\Wissem\Downloads\mbam-setup-1.70.0.1100.exe 2012-12-28 15:58 - 2009-05-13 19:00 - 00000000 ____D C:\Users\All Users\T-Online 2012-12-28 15:58 - 2008-10-23 12:25 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2012-12-28 14:24 - 2008-10-23 13:39 - 00000000 ____D C:\Program Files\Google 2012-12-28 14:12 - 2006-11-02 12:18 - 00000000 __RHD C:\users\Default 2012-12-28 14:12 - 2006-11-02 12:18 - 00000000 ___RD C:\users\Public 2012-12-28 14:09 - 2012-12-28 13:44 - 00000000 ____D C:\Windows\erdnt 2012-12-28 14:07 - 2006-11-02 11:23 - 00000215 ____A C:\Windows\system.ini 2012-12-28 13:34 - 2008-10-23 13:39 - 00000000 ____D C:\Program Files\Common Files\Java 2012-12-28 13:30 - 2011-02-13 03:36 - 00000000 ____D C:\Program Files\Biet-O-Matic 2012-12-28 13:29 - 2011-02-13 03:37 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\BOM 2012-12-28 13:21 - 2009-05-13 16:18 - 00000000 ____D C:\Users\Wissem\AppData\Local\Google 2012-12-28 13:21 - 2008-11-29 10:00 - 00000000 ____D C:\Users\All Users\Google 2012-12-28 13:19 - 2011-02-19 12:21 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Gutscheinmieze 2012-12-28 12:21 - 2010-04-15 19:57 - 00000000 ____D C:\Users\All Users\ICQ 2012-12-28 11:49 - 2010-04-15 19:55 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\ICQ 2012-12-28 00:43 - 2012-12-28 00:43 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2012-12-28 00:43 - 2011-03-29 10:28 - 00000000 ____D C:\Users\Wissem\Documents\SelfMV 2012-12-27 22:23 - 2011-04-09 03:22 - 00000000 ____D C:\Users\Wissem\AppData\Local\Samsung 2012-12-27 22:22 - 2012-12-27 22:22 - 00001783 ____A C:\Users\Public\Desktop\Samsung Kies (Lite).lnk 2012-12-27 22:22 - 2012-12-27 22:22 - 00001773 ____A C:\Users\Public\Desktop\Samsung Kies.lnk 2012-12-27 22:18 - 2011-01-25 19:53 - 00000000 ____D C:\Users\All Users\Samsung 2012-12-27 22:05 - 2011-03-29 11:02 - 00000000 ____D C:\Users\Wissem\AppData\Local\Downloaded Installations 2012-12-27 22:00 - 2012-12-27 21:59 - 68037104 ____A (Samsung Electronics Co., Ltd. ) C:\Users\Wissem\Downloads\KiesSetup.exe 2012-12-27 21:48 - 2006-11-02 13:52 - 00135333 ____A C:\Windows\setupact.log 2012-12-26 03:05 - 2012-12-26 03:05 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2012-12-23 03:36 - 2012-12-23 03:36 - 00000000 ____D C:\Users\Public\Downloads\Norton 2012-12-23 03:33 - 2012-11-21 18:44 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2012-12-23 03:27 - 2009-05-13 19:02 - 00000000 ____D C:\Users\All Users\Symantec 2012-12-23 03:22 - 2012-12-23 03:22 - 00007296 ____A C:\Users\All Users\N360BUOptions.ini 2012-12-23 03:19 - 2012-12-23 03:19 - 00916584 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NAVDownloader.exe ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys [2012-12-12 00:13] - [2012-08-21 12:47] - 0224640 ____A (Microsoft Corporation) 786DB5771F05EF300390399F626BF30A ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2012-12-01 16:07:52 Restore point made on: 2012-12-12 01:41:33 Restore point made on: 2012-12-16 23:40:19 Restore point made on: 2012-12-21 03:01:22 Restore point made on: 2012-12-26 02:37:37 Restore point made on: 2012-12-26 02:38:53 Restore point made on: 2012-12-26 02:40:57 Restore point made on: 2012-12-26 02:42:48 Restore point made on: 2012-12-26 02:44:10 Restore point made on: 2012-12-26 02:45:36 Restore point made on: 2012-12-26 02:46:46 Restore point made on: 2012-12-26 02:47:55 Restore point made on: 2012-12-26 02:49:10 Restore point made on: 2012-12-26 02:51:50 Restore point made on: 2012-12-26 02:54:15 Restore point made on: 2012-12-26 02:56:23 Restore point made on: 2012-12-26 02:59:55 Restore point made on: 2012-12-26 03:01:15 Restore point made on: 2012-12-26 04:33:50 Restore point made on: 2012-12-26 17:28:02 Restore point made on: 2012-12-27 22:07:52 Restore point made on: 2012-12-27 22:16:37 Restore point made on: 2012-12-28 13:15:29 Restore point made on: 2012-12-28 13:19:41 Restore point made on: 2012-12-28 13:33:27 Restore point made on: 2012-12-28 13:35:03 Restore point made on: 2012-12-28 14:50:10 Restore point made on: 2012-12-29 13:48:32 Restore point made on: 2012-12-29 13:52:03 Restore point made on: 2012-12-29 14:06:19 Restore point made on: 2012-12-29 14:09:52 Restore point made on: 2012-12-29 14:12:59 Restore point made on: 2012-12-29 14:14:29 Restore point made on: 2012-12-29 17:02:59 Restore point made on: 2013-01-09 19:01:30 Restore point made on: 2013-01-12 05:38:46 Restore point made on: 2013-01-12 05:54:35 Restore point made on: 2013-01-12 18:48:42 Restore point made on: 2013-01-17 09:47:05 Restore point made on: 2013-01-17 13:17:42 ==================== Memory info =========================== Percentage of memory in use: 11% Total physical RAM: 4062.13 MB Available physical RAM: 3587.49 MB Total Pagefile: 3817.3 MB Available Pagefile: 3662.42 MB Total Virtual: 2047.88 MB Available Virtual: 1966.3 MB ==================== Partitions ============================= 1 Drive c: () (Fixed) (Total:288.28 GB) (Free:118.92 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 3 Drive e: (Recovery) (Fixed) (Total:9.81 GB) (Free:0.84 GB) NTFS ==>[System with boot components (obtained from reading drive)] 6 Drive h: (WD MediaCtr) (Fixed) (Total:298.01 GB) (Free:195.74 GB) FAT32 7 Drive i: () (Removable) (Total:0.12 GB) (Free:0.1 GB) FAT 8 Drive x: (Boot) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS Datentr ### Status Gr”áe Frei Dyn GPT -------- ---------- ------- ------- --- --- 0 Online 298 GB 0 B 1 Kein Mediu 0 B 0 B 2 Kein Mediu 0 B 0 B 3 Online 298 GB 8 MB 4 Online 123 MB 0 B Last Boot: 2013-01-19 12:33 ==================== End Of Log ============================ war meine alternative lösung mit mobiler festplatte ok? hier der scan...das frst.txt sagt folgendes: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-01-2013 Ran by SYSTEM at 19-01-2013 12:38:51 Running from H:\ Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: German Standard The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x] HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [835584 2007-03-10] (Synaptics, Inc.) HKLM\...\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup [30192 2010-08-25] (Google) HKLM\...\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [317280 2008-04-03] (Sony Corporation) HKLM\...\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe [24576 2008-11-29] (Sony Corporation) HKLM\...\Run: [Skytel] Skytel.exe [x] HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [61440 2009-05-15] (Advanced Micro Devices, Inc.) HKLM\...\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [599328 2010-03-24] (Sony Corporation) HKLM\...\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [79192 2011-02-18] (Research In Motion Limited) HKLM\...\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\ssmmgr.exe /autorun [618496 2010-06-07] () HKLM\...\Run: [PDFPrint] C:\Program Files\pdf24\pdf24.exe [220744 2012-02-03] (Geek Software GmbH) HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.) HKLM\...\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-03] (Adobe Systems Incorporated) HKU\Default\...\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [x] HKU\Default\...\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" [270336 2008-11-05] (Sony Corporation) HKU\Default User\...\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [x] HKU\Default User\...\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" [270336 2008-11-05] (Sony Corporation) HKU\Gast\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x] HKU\Gast\...\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" [270336 2008-11-05] (Sony Corporation) HKU\Gast\...\Run: [Google Update] "C:\Users\Gast\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-11-09] (Google Inc.) HKU\Gast\...\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844296 2012-12-20] (Samsung) HKU\Gast\...\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation) HKU\Wissem\...\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" [270336 2008-11-05] (Sony Corporation) HKU\Wissem\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\Wissem\...\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" [247728 2012-01-23] (TomTom) HKU\Wissem\...\Run: [doubleTwist] C:\Program Files\doubleTwist 2.0\DoubleTwist.DeviceHelper.exe [24576 2010-09-18] (doubleTwist Corporation) HKU\Wissem\...\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [310280 2012-12-20] (Samsung Electronics Co., Ltd.) HKU\Wissem\...\Run: [KiesPreload] C:\Program Files\Samsung\Kies\Kies.exe /preload [1476104 2012-12-20] (Samsung) HKU\Wissem\...\Run: [KiesAirMessage] C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup [578560 2012-12-18] (Samsung Electronics) Winlogon\Notify\igfxcui: igfxdev.dll [X] Winlogon\Notify\VESWinlogon: VESWinlogon.dll (Sony Corporation) AppInit_DLLs: c:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll ==================== Services (Whitelisted) =================== 2 AAV UpdateService; "C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe" [128296 2008-10-24] () 3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) 2 dgdersvc; C:\Windows\system32\dgdersvc.exe [95568 2010-09-06] (Devguru Co., Ltd.) 3 GoogleDesktopManager-051210-111108; "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [30192 2010-08-25] (Google) 3 MozillaMaintenance; "C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe" [115168 2012-12-15] (Mozilla Foundation) 3 MSSQL$MSSMLBIZ; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [29293408 2010-12-10] (Microsoft Corporation) 2 NAV; "C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccSvcHst.exe" /s "NAV" /m "C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\diMaster.dll" /prefetch:1 [535416 2012-10-11] (Symantec Corporation) 2 NCO; "C:\Program Files\Norton Identity Safe\Engine\2013.2.1.33\ccSvcHst.exe" /s "NCO" /m "C:\Program Files\Norton Identity Safe\Engine\2013.2.1.33\diMaster.dll" /prefetch:1 [535416 2012-12-05] (Symantec Corporation) 2 NMSAccess; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] () 2 NvcRpcServer; "C:\Program Files\Nortel Networks\NvcRpcSvr.exe" [71176 2007-04-09] (Nortel Networks NA, Inc.) 3 SOHCImp; "C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe" [103712 2008-10-21] (Sony Corporation) 3 SOHDms; "C:\Program Files\Sony\VAIO Media plus\SOHDms.exe" [353568 2008-10-21] (Sony Corporation) 3 SOHDs; "C:\Program Files\Sony\VAIO Media plus\SOHDs.exe" [62752 2008-10-21] (Sony Corporation) 2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) 3 VAIO Entertainment TV Device Arbitration Service; "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe" [69632 2009-03-05] (Sony Corporation) 2 VCFw; "C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe" [5189992 2009-03-05] (Sony Corporation) 3 VcmIAlzMgr; "C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe" [480624 2009-09-16] (Sony Corporation) 3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -RunBySCM [313264 2009-03-05] (Sony Corporation) 3 VUAgent; "C:\Program Files\Sony\VAIO Update Common\VUAgent.exe" [1086568 2011-09-23] (Sony Corporation) 2 VzCdbSvc; "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe" [192512 2009-03-05] (Sony Corporation) 3 MSCSPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe" [x] 3 SPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe" [x] ==================== Drivers (Whitelisted) ==================== 3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.) 1 BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20130107.001\BHDrvx86.sys [995488 2012-11-30] (Symantec Corporation) 1 ccSet_NAV; C:\Windows\system32\drivers\NAV\1402000.013\ccSetx86.sys [134304 2012-10-03] (Symantec Corporation) 1 ccSet_NST; C:\Windows\system32\drivers\NST\7DD02010.021\ccSetx86.sys [134304 2012-08-20] (Symantec Corporation) 3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [18120 2010-09-06] (Devguru Co., Ltd) 3 Eacfilt; C:\Windows\System32\DRIVERS\eacfilt.sys [31784 2007-04-09] (Nortel Networks) 1 eeCtrl; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376480 2012-12-21] (Symantec Corporation) 3 EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106656 2012-12-21] (Symantec Corporation) 3 FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [36640 2010-09-06] () 1 IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20130111.002\IDSvix86.sys [386720 2012-12-28] (Symantec Corporation) 2 iPodDrv; \??\C:\Windows\system32\drivers\iPodDrv.sys [6656 2010-03-10] (Windows (R) Codename Longhorn DDK provider) 3 IPSECEXT; C:\Windows\System32\DRIVERS\ipsecw2k.sys [148232 2007-04-09] (Nortel Networks NA, Inc.) 3 IPSECSHM; C:\Windows\System32\DRIVERS\ipsecw2k.sys [148232 2007-04-09] (Nortel Networks NA, Inc.) 2 n5lpt.sys; \??\C:\Windows\system32\Drivers\n5lpt.sys [21196 2007-11-30] (Number Five Software) 3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20130118.022\NAVENG.SYS [93296 2013-01-19] (Symantec Corporation) 3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20130118.022\NAVEX15.SYS [1603824 2013-01-19] (Symantec Corporation) 3 SipIMNDI; C:\Windows\System32\DRIVERS\SipIMNDI.sys [24352 2009-10-15] (T-Systems International GmbH) 0 SMR311; C:\Windows\System32\drivers\SMR311.SYS [97440 2012-12-29] (Symantec Corporation) 3 SRTSP; C:\Windows\system32\drivers\NAV\1402000.013\SRTSP.SYS [586400 2012-10-08] (Symantec Corporation) 1 SRTSPX; C:\Windows\system32\drivers\NAV\1402000.013\SRTSPX.SYS [32888 2012-09-06] (Symantec Corporation) 3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [7168 2009-11-12] () 2 Stld; C:\Windows\System32\Drivers\Stld.sys [10240 2009-04-22] (Number Five Software) 0 SymDS; C:\Windows\System32\drivers\NAV\1402000.013\SYMDS.SYS [368288 2012-10-03] (Symantec Corporation) 0 SymEFA; C:\Windows\System32\drivers\NAV\1402000.013\SYMEFA.SYS [927904 2012-10-03] (Symantec Corporation) 3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [142496 2012-12-29] (Symantec Corporation) 1 SymIRON; C:\Windows\system32\drivers\NAV\1402000.013\Ironx86.SYS [175264 2012-09-06] (Symantec Corporation) 1 SYMTDIv; C:\Windows\system32\drivers\NAV\1402000.013\SYMTDIV.SYS [350368 2012-09-06] (Symantec Corporation) 3 catchme; \??\C:\Users\Wissem\AppData\Local\Temp\catchme.sys [x] 2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] 3 igfx; C:\Windows\System32\DRIVERS\igdkmd32.sys [x] 3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x] 3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x] 3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x] 4 UIUSys; C:\Windows\System32\DRIVERS\UIUSYS.SYS [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-01-19 12:27 - 2013-01-19 12:27 - 00142520 ____A C:\Windows\Minidump\Mini011913-07.dmp 2013-01-19 11:53 - 2013-01-19 11:53 - 00014452 ____A C:\Users\Wissem\Downloads\CBEB.tmp 2013-01-19 11:52 - 2013-01-19 11:53 - 00909506 ____A (Farbar) C:\Users\Wissem\Downloads\FRST.exe 2013-01-19 04:28 - 2013-01-19 04:28 - 06260632 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NRnR (1).exe 2013-01-19 04:27 - 2013-01-19 04:27 - 06258072 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NRnR.exe 2013-01-19 04:16 - 2013-01-19 04:16 - 00142520 ____A C:\Windows\Minidump\Mini011913-06.dmp 2013-01-19 04:07 - 2013-01-19 04:07 - 00142520 ____A C:\Windows\Minidump\Mini011913-05.dmp 2013-01-19 03:56 - 2013-01-19 03:56 - 00142520 ____A C:\Windows\Minidump\Mini011913-04.dmp 2013-01-19 03:31 - 2013-01-19 03:31 - 00142520 ____A C:\Windows\Minidump\Mini011913-03.dmp 2013-01-19 01:43 - 2013-01-19 01:43 - 00142520 ____A C:\Windows\Minidump\Mini011913-02.dmp 2013-01-19 01:16 - 2013-01-19 01:16 - 00142520 ____A C:\Windows\Minidump\Mini011913-01.dmp 2013-01-17 13:58 - 2013-01-17 13:58 - 00142520 ____A C:\Windows\Minidump\Mini011713-03.dmp 2013-01-17 13:17 - 2013-01-17 13:18 - 00000000 ____D C:\Program Files\Debugging Tools for Windows (x86) 2013-01-17 13:16 - 2013-01-17 13:16 - 17666048 ____A C:\Users\Wissem\Downloads\dbg_x86_6.10.3.233.msi 2013-01-17 13:03 - 2013-01-17 13:04 - 00142520 ____A C:\Windows\Minidump\Mini011713-02.dmp 2013-01-17 12:56 - 2013-01-17 12:56 - 00142520 ____A C:\Windows\Minidump\Mini011713-01.dmp 2013-01-17 11:19 - 2013-01-17 11:19 - 17666048 ____A C:\Users\Wissem\Downloads\Nicht bestätigt 449985.crdownload 2013-01-17 09:47 - 2013-01-17 09:48 - 00004097 ____A C:\Windows\System32\jupdate-1.7.0_11-b21.log 2013-01-12 07:13 - 2013-01-12 07:13 - 00000828 ____A C:\Users\Wissem\Desktop\PhotoScape.lnk 2013-01-12 07:01 - 2013-01-12 07:01 - 21322864 ____A (Mooii) C:\Users\Wissem\Downloads\PhotoScape_V3.6.3.exe 2013-01-12 06:06 - 2013-01-12 06:54 - 00000000 ____D C:\Users\Wissem\Documents\Steuerfälle 2013-01-12 06:05 - 2013-01-12 06:05 - 00000000 ____D C:\Users\Wissem\AppData\Local\AAV 2013-01-12 05:53 - 2013-01-12 06:03 - 00002094 ____A C:\Users\Public\Desktop\Steuer-Spar- Erklärung 2013.lnk 2013-01-12 05:39 - 2013-01-12 05:55 - 00000000 ____D C:\Program Files\Akademische Arbeitsgemeinschaft 2013-01-12 05:37 - 2013-01-12 06:01 - 00000000 ____D C:\Users\All Users\AAV 2013-01-12 04:10 - 2013-01-12 04:11 - 00142520 ____A C:\Windows\Minidump\Mini011213-01.dmp 2013-01-10 04:08 - 2013-01-10 04:08 - 00000000 ____D C:\Program Files\DVDVideoSoft 2013-01-10 04:08 - 2013-01-10 04:08 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-01-10 03:38 - 2013-01-10 03:38 - 25028024 ____A (DVDVideoSoft Ltd. ) C:\Users\Wissem\Downloads\FreeYouTubeToMP3Converter (1).exe 2013-01-09 17:53 - 2012-11-23 02:35 - 02048000 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-01-09 17:52 - 2012-11-20 05:22 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2013-01-09 17:52 - 2012-11-02 11:19 - 01400832 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-12-29 16:48 - 2012-12-29 16:48 - 00000000 ____D C:\Users\Wissem\Desktop\ESET 2012-12-29 16:32 - 2012-12-29 16:32 - 00000000 ____D C:\Users\Wissem\Documents\Symantec 2012-12-29 16:29 - 2013-01-11 19:57 - 00000000 ____D C:\Windows\System32\Drivers\NST 2012-12-29 16:29 - 2012-12-29 16:29 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS 2012-12-29 16:29 - 2012-12-29 16:29 - 00007446 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT 2012-12-29 16:29 - 2012-12-29 16:29 - 00002125 ____A C:\Users\Public\Desktop\Norton AntiVirus.lnk 2012-12-29 16:29 - 2012-12-29 16:29 - 00000000 ____D C:\Program Files\Symantec 2012-12-29 16:29 - 2012-12-29 16:29 - 00000000 ____D C:\Program Files\Norton Identity Safe 2012-12-29 16:28 - 2012-12-29 16:28 - 00000000 ____D C:\Windows\System32\Drivers\NAV 2012-12-29 16:28 - 2012-12-29 16:28 - 00000000 ____D C:\Program Files\Norton AntiVirus 2012-12-29 16:26 - 2012-12-29 16:26 - 00916600 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NAVDownloader (1).exe 2012-12-29 15:44 - 2012-12-29 15:44 - 00000735 ____A C:\DelFix[S2].txt 2012-12-29 15:43 - 2012-12-29 15:43 - 00001456 ____A C:\DelFix[S1].txt 2012-12-29 15:43 - 2012-12-29 15:43 - 00000620 ____A C:\DelFix[R1].txt 2012-12-29 14:30 - 2012-12-29 14:30 - 00000000 ____D C:\Users\All Users\SMR311 2012-12-29 14:28 - 2012-12-29 14:28 - 00097440 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SMR311.SYS 2012-12-29 14:26 - 2012-12-29 14:39 - 00000000 ____D C:\Users\Wissem\AppData\Local\NPE 2012-12-29 14:26 - 2012-12-29 14:26 - 02957840 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NPE.exe 2012-12-29 14:23 - 2012-12-29 14:24 - 00001892 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk 2012-12-29 14:22 - 2012-12-29 14:23 - 00000000 ____D C:\Program Files\Common Files\Adobe 2012-12-29 13:52 - 2012-11-28 10:31 - 00260528 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2012-12-29 13:50 - 2012-11-28 10:35 - 00093640 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll 2012-12-29 13:50 - 2012-11-28 10:31 - 00174000 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2012-12-29 13:50 - 2012-11-28 10:31 - 00173992 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2012-12-29 13:48 - 2012-12-29 13:50 - 00004574 ____A C:\Windows\System32\jupdate-1.7.0_10-b18.log 2012-12-29 13:38 - 2012-12-29 13:38 - 00896016 ____A (Oracle Corporation) C:\Users\Wissem\Downloads\chromeinstall-7u10.exe 2012-12-28 16:35 - 2012-12-28 16:35 - 00000000 ____D C:\Program Files\ESET 2012-12-28 16:04 - 2012-12-28 16:04 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Malwarebytes 2012-12-28 16:04 - 2012-12-28 16:04 - 00000000 ____D C:\Users\All Users\Malwarebytes 2012-12-28 16:03 - 2012-12-28 16:03 - 10156344 ____A (Malwarebytes Corporation ) C:\Users\Wissem\Downloads\mbam-setup-1.70.0.1100.exe 2012-12-28 13:44 - 2012-12-28 14:09 - 00000000 ____D C:\Windows\erdnt 2012-12-28 00:43 - 2012-12-28 00:43 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2012-12-27 22:59 - 2013-01-11 01:22 - 00000000 ____D C:\Users\Wissem\AppData\Local\CrashDumps 2012-12-27 22:22 - 2012-12-27 22:22 - 00001783 ____A C:\Users\Public\Desktop\Samsung Kies (Lite).lnk 2012-12-27 22:22 - 2012-12-27 22:22 - 00001773 ____A C:\Users\Public\Desktop\Samsung Kies.lnk 2012-12-27 21:59 - 2012-12-27 22:00 - 68037104 ____A (Samsung Electronics Co., Ltd. ) C:\Users\Wissem\Downloads\KiesSetup.exe 2012-12-26 03:05 - 2012-12-26 03:05 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2012-12-26 02:36 - 2012-09-20 05:35 - 00181344 ____A (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudmdm.sys 2012-12-26 02:36 - 2012-09-20 05:35 - 00083168 ____A (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudbus.sys 2012-12-23 03:36 - 2012-12-29 16:28 - 00000829 ____A C:\Users\Wissem\Desktop\Norton-Installationsdateien.lnk 2012-12-23 03:36 - 2012-12-23 03:36 - 00000000 ____D C:\Users\Public\Downloads\Norton 2012-12-23 03:22 - 2012-12-23 03:22 - 00007296 ____A C:\Users\All Users\N360BUOptions.ini 2012-12-23 03:19 - 2012-12-23 03:19 - 00916584 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NAVDownloader.exe 2012-12-21 03:01 - 2012-12-16 14:12 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll 2012-12-21 03:01 - 2012-12-16 11:50 - 00293376 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll ==================== One Month Modified Files and Folders ======== 2013-01-19 12:38 - 2013-01-19 12:38 - 00000000 ____D C:\FRST 2013-01-19 12:33 - 2009-05-13 16:14 - 01320794 ____A C:\Windows\WindowsUpdate.log 2013-01-19 12:33 - 2006-11-02 14:01 - 00032610 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-01-19 12:33 - 2006-11-02 14:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-01-19 12:33 - 2006-11-02 13:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-01-19 12:33 - 2006-11-02 13:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-01-19 12:27 - 2013-01-19 12:27 - 00142520 ____A C:\Windows\Minidump\Mini011913-07.dmp 2013-01-19 12:27 - 2010-02-10 14:50 - 00001094 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-01-19 12:27 - 2009-05-22 05:12 - 00000000 ____D C:\Windows\Minidump 2013-01-19 12:26 - 2009-05-22 05:11 - 341416561 ____A C:\Windows\MEMORY.DMP 2013-01-19 12:09 - 2008-01-21 08:16 - 01606662 ____A C:\Windows\System32\PerfStringBackup.INI 2013-01-19 12:05 - 2011-01-23 01:40 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1190657541-1879476424-4156719937-1003UA.job 2013-01-19 12:04 - 2010-02-10 14:50 - 00001098 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-01-19 11:53 - 2013-01-19 11:53 - 00014452 ____A C:\Users\Wissem\Downloads\CBEB.tmp 2013-01-19 11:53 - 2013-01-19 11:52 - 00909506 ____A (Farbar) C:\Users\Wissem\Downloads\FRST.exe 2013-01-19 04:28 - 2013-01-19 04:28 - 06260632 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NRnR (1).exe 2013-01-19 04:27 - 2013-01-19 04:27 - 06258072 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NRnR.exe 2013-01-19 04:16 - 2013-01-19 04:16 - 00142520 ____A C:\Windows\Minidump\Mini011913-06.dmp 2013-01-19 04:07 - 2013-01-19 04:07 - 00142520 ____A C:\Windows\Minidump\Mini011913-05.dmp 2013-01-19 04:04 - 2010-04-08 09:45 - 00026112 ____A C:\Users\Wissem\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-01-19 03:56 - 2013-01-19 03:56 - 00142520 ____A C:\Windows\Minidump\Mini011913-04.dmp 2013-01-19 03:31 - 2013-01-19 03:31 - 00142520 ____A C:\Windows\Minidump\Mini011913-03.dmp 2013-01-19 01:43 - 2013-01-19 01:43 - 00142520 ____A C:\Windows\Minidump\Mini011913-02.dmp 2013-01-19 01:16 - 2013-01-19 01:16 - 00142520 ____A C:\Windows\Minidump\Mini011913-01.dmp 2013-01-19 01:15 - 2008-01-21 03:47 - 01598020 ____A C:\Windows\PFRO.log 2013-01-17 13:58 - 2013-01-17 13:58 - 00142520 ____A C:\Windows\Minidump\Mini011713-03.dmp 2013-01-17 13:18 - 2013-01-17 13:17 - 00000000 ____D C:\Program Files\Debugging Tools for Windows (x86) 2013-01-17 13:16 - 2013-01-17 13:16 - 17666048 ____A C:\Users\Wissem\Downloads\dbg_x86_6.10.3.233.msi 2013-01-17 13:04 - 2013-01-17 13:03 - 00142520 ____A C:\Windows\Minidump\Mini011713-02.dmp 2013-01-17 12:56 - 2013-01-17 12:56 - 00142520 ____A C:\Windows\Minidump\Mini011713-01.dmp 2013-01-17 12:54 - 2009-05-13 16:18 - 00002032 ____A C:\Users\Wissem\AppData\Local\d3d9caps.dat 2013-01-17 12:43 - 2011-08-12 01:11 - 00000000 ____D C:\users\Gast 2013-01-17 12:43 - 2009-05-13 16:18 - 00000000 ____D C:\users\Wissem 2013-01-17 12:43 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\System32\spool 2013-01-17 12:43 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\System32\Msdtc 2013-01-17 12:43 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\registration 2013-01-17 12:43 - 2006-11-02 11:22 - 62652416 ____A C:\Windows\System32\config\software_previous 2013-01-17 12:43 - 2006-11-02 11:22 - 30670848 ____A C:\Windows\System32\config\system_previous 2013-01-17 12:30 - 2006-11-02 11:22 - 00262144 ____A C:\Windows\System32\config\security_previous 2013-01-17 12:30 - 2006-11-02 11:22 - 00262144 ____A C:\Windows\System32\config\sam_previous 2013-01-17 12:29 - 2006-11-02 11:22 - 37224448 ____A C:\Windows\System32\config\components_previous 2013-01-17 12:29 - 2006-11-02 11:22 - 00786432 ____A C:\Windows\System32\config\default_previous 2013-01-17 11:19 - 2013-01-17 11:19 - 17666048 ____A C:\Users\Wissem\Downloads\Nicht bestätigt 449985.crdownload 2013-01-17 09:48 - 2013-01-17 09:47 - 00004097 ____A C:\Windows\System32\jupdate-1.7.0_11-b21.log 2013-01-17 09:48 - 2008-10-23 13:39 - 00000000 ____D C:\Program Files\Java 2013-01-13 19:12 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-01-12 07:13 - 2013-01-12 07:13 - 00000828 ____A C:\Users\Wissem\Desktop\PhotoScape.lnk 2013-01-12 07:13 - 2012-05-26 14:00 - 00000000 ____D C:\Program Files\PhotoScape 2013-01-12 07:01 - 2013-01-12 07:01 - 21322864 ____A (Mooii) C:\Users\Wissem\Downloads\PhotoScape_V3.6.3.exe 2013-01-12 06:54 - 2013-01-12 06:06 - 00000000 ____D C:\Users\Wissem\Documents\Steuerfälle 2013-01-12 06:05 - 2013-01-12 06:05 - 00000000 ____D C:\Users\Wissem\AppData\Local\AAV 2013-01-12 06:03 - 2013-01-12 05:53 - 00002094 ____A C:\Users\Public\Desktop\Steuer-Spar- Erklärung 2013.lnk 2013-01-12 06:01 - 2013-01-12 05:37 - 00000000 ____D C:\Users\All Users\AAV 2013-01-12 05:55 - 2013-01-12 05:39 - 00000000 ____D C:\Program Files\Akademische Arbeitsgemeinschaft 2013-01-12 04:11 - 2013-01-12 04:10 - 00142520 ____A C:\Windows\Minidump\Mini011213-01.dmp 2013-01-11 21:05 - 2011-01-23 01:40 - 00001072 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1190657541-1879476424-4156719937-1003Core.job 2013-01-11 19:57 - 2012-12-29 16:29 - 00000000 ____D C:\Windows\System32\Drivers\NST 2013-01-11 01:22 - 2012-12-27 22:59 - 00000000 ____D C:\Users\Wissem\AppData\Local\CrashDumps 2013-01-10 04:09 - 2012-11-17 13:26 - 00001191 ____A C:\Users\Wissem\Desktop\Free YouTube to MP3 Converter.lnk 2013-01-10 04:08 - 2013-01-10 04:08 - 00000000 ____D C:\Program Files\DVDVideoSoft 2013-01-10 04:08 - 2013-01-10 04:08 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-01-10 04:08 - 2011-08-19 04:15 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\DVDVideoSoft 2013-01-10 03:38 - 2013-01-10 03:38 - 25028024 ____A (DVDVideoSoft Ltd. ) C:\Users\Wissem\Downloads\FreeYouTubeToMP3Converter (1).exe 2013-01-09 19:47 - 2006-11-02 13:47 - 00404440 ____A C:\Windows\System32\FNTCACHE.DAT 2013-01-09 19:27 - 2008-11-29 10:06 - 00000000 ____D C:\Users\All Users\Microsoft Help 2013-01-09 19:02 - 2006-11-02 11:24 - 65273848 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe 2013-01-08 11:33 - 2012-12-07 23:08 - 00000000 ____D C:\Users\Wissem\Downloads\moni 2013-01-04 00:03 - 2011-05-01 12:28 - 00000000 ____D C:\Users\Wissem\Desktop\Uni 2013-01-01 01:52 - 2010-12-01 20:11 - 00000000 ____D C:\Users\Wissem\Desktop\wiss Hausi 2012-12-30 04:00 - 2008-10-23 13:38 - 00000000 ____D C:\Users\All Users\Adobe 2012-12-30 03:58 - 2009-05-13 22:26 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Adobe 2012-12-29 16:48 - 2012-12-29 16:48 - 00000000 ____D C:\Users\Wissem\Desktop\ESET 2012-12-29 16:36 - 2009-05-13 19:02 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared 2012-12-29 16:32 - 2012-12-29 16:32 - 00000000 ____D C:\Users\Wissem\Documents\Symantec 2012-12-29 16:32 - 2010-04-29 11:40 - 00000000 ____D C:\Users\All Users\Norton 2012-12-29 16:29 - 2012-12-29 16:29 - 00142496 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS 2012-12-29 16:29 - 2012-12-29 16:29 - 00007446 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT 2012-12-29 16:29 - 2012-12-29 16:29 - 00002125 ____A C:\Users\Public\Desktop\Norton AntiVirus.lnk 2012-12-29 16:29 - 2012-12-29 16:29 - 00000000 ____D C:\Program Files\Symantec 2012-12-29 16:29 - 2012-12-29 16:29 - 00000000 ____D C:\Program Files\Norton Identity Safe 2012-12-29 16:28 - 2012-12-29 16:28 - 00000000 ____D C:\Windows\System32\Drivers\NAV 2012-12-29 16:28 - 2012-12-29 16:28 - 00000000 ____D C:\Program Files\Norton AntiVirus 2012-12-29 16:28 - 2012-12-23 03:36 - 00000829 ____A C:\Users\Wissem\Desktop\Norton-Installationsdateien.lnk 2012-12-29 16:26 - 2012-12-29 16:26 - 00916600 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NAVDownloader (1).exe 2012-12-29 15:44 - 2012-12-29 15:44 - 00000735 ____A C:\DelFix[S2].txt 2012-12-29 15:43 - 2012-12-29 15:43 - 00001456 ____A C:\DelFix[S1].txt 2012-12-29 15:43 - 2012-12-29 15:43 - 00000620 ____A C:\DelFix[R1].txt 2012-12-29 14:39 - 2012-12-29 14:26 - 00000000 ____D C:\Users\Wissem\AppData\Local\NPE 2012-12-29 14:30 - 2012-12-29 14:30 - 00000000 ____D C:\Users\All Users\SMR311 2012-12-29 14:28 - 2012-12-29 14:28 - 00097440 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SMR311.SYS 2012-12-29 14:26 - 2012-12-29 14:26 - 02957840 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NPE.exe 2012-12-29 14:24 - 2012-12-29 14:23 - 00001892 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk 2012-12-29 14:23 - 2012-12-29 14:22 - 00000000 ____D C:\Program Files\Common Files\Adobe 2012-12-29 14:22 - 2009-05-13 22:52 - 00000000 ____D C:\Program Files\Adobe 2012-12-29 14:07 - 2009-05-13 16:18 - 00000000 ____D C:\Users\Wissem\AppData\Local\Adobe 2012-12-29 13:50 - 2012-12-29 13:48 - 00004574 ____A C:\Windows\System32\jupdate-1.7.0_10-b18.log 2012-12-29 13:38 - 2012-12-29 13:38 - 00896016 ____A (Oracle Corporation) C:\Users\Wissem\Downloads\chromeinstall-7u10.exe 2012-12-28 16:35 - 2012-12-28 16:35 - 00000000 ____D C:\Program Files\ESET 2012-12-28 16:21 - 2008-10-23 10:25 - 00000000 ____D C:\Windows\InstDrvs 2012-12-28 16:04 - 2012-12-28 16:04 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Malwarebytes 2012-12-28 16:04 - 2012-12-28 16:04 - 00000000 ____D C:\Users\All Users\Malwarebytes 2012-12-28 16:03 - 2012-12-28 16:03 - 10156344 ____A (Malwarebytes Corporation ) C:\Users\Wissem\Downloads\mbam-setup-1.70.0.1100.exe 2012-12-28 15:58 - 2009-05-13 19:00 - 00000000 ____D C:\Users\All Users\T-Online 2012-12-28 15:58 - 2008-10-23 12:25 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2012-12-28 14:24 - 2008-10-23 13:39 - 00000000 ____D C:\Program Files\Google 2012-12-28 14:12 - 2006-11-02 12:18 - 00000000 __RHD C:\users\Default 2012-12-28 14:12 - 2006-11-02 12:18 - 00000000 ___RD C:\users\Public 2012-12-28 14:09 - 2012-12-28 13:44 - 00000000 ____D C:\Windows\erdnt 2012-12-28 14:07 - 2006-11-02 11:23 - 00000215 ____A C:\Windows\system.ini 2012-12-28 13:34 - 2008-10-23 13:39 - 00000000 ____D C:\Program Files\Common Files\Java 2012-12-28 13:30 - 2011-02-13 03:36 - 00000000 ____D C:\Program Files\Biet-O-Matic 2012-12-28 13:29 - 2011-02-13 03:37 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\BOM 2012-12-28 13:21 - 2009-05-13 16:18 - 00000000 ____D C:\Users\Wissem\AppData\Local\Google 2012-12-28 13:21 - 2008-11-29 10:00 - 00000000 ____D C:\Users\All Users\Google 2012-12-28 13:19 - 2011-02-19 12:21 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\Gutscheinmieze 2012-12-28 12:21 - 2010-04-15 19:57 - 00000000 ____D C:\Users\All Users\ICQ 2012-12-28 11:49 - 2010-04-15 19:55 - 00000000 ____D C:\Users\Wissem\AppData\Roaming\ICQ 2012-12-28 00:43 - 2012-12-28 00:43 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2012-12-28 00:43 - 2011-03-29 10:28 - 00000000 ____D C:\Users\Wissem\Documents\SelfMV 2012-12-27 22:23 - 2011-04-09 03:22 - 00000000 ____D C:\Users\Wissem\AppData\Local\Samsung 2012-12-27 22:22 - 2012-12-27 22:22 - 00001783 ____A C:\Users\Public\Desktop\Samsung Kies (Lite).lnk 2012-12-27 22:22 - 2012-12-27 22:22 - 00001773 ____A C:\Users\Public\Desktop\Samsung Kies.lnk 2012-12-27 22:18 - 2011-01-25 19:53 - 00000000 ____D C:\Users\All Users\Samsung 2012-12-27 22:05 - 2011-03-29 11:02 - 00000000 ____D C:\Users\Wissem\AppData\Local\Downloaded Installations 2012-12-27 22:00 - 2012-12-27 21:59 - 68037104 ____A (Samsung Electronics Co., Ltd. ) C:\Users\Wissem\Downloads\KiesSetup.exe 2012-12-27 21:48 - 2006-11-02 13:52 - 00135333 ____A C:\Windows\setupact.log 2012-12-26 03:05 - 2012-12-26 03:05 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2012-12-23 03:36 - 2012-12-23 03:36 - 00000000 ____D C:\Users\Public\Downloads\Norton 2012-12-23 03:33 - 2012-11-21 18:44 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2012-12-23 03:27 - 2009-05-13 19:02 - 00000000 ____D C:\Users\All Users\Symantec 2012-12-23 03:22 - 2012-12-23 03:22 - 00007296 ____A C:\Users\All Users\N360BUOptions.ini 2012-12-23 03:19 - 2012-12-23 03:19 - 00916584 ____A (Symantec Corporation) C:\Users\Wissem\Downloads\NAVDownloader.exe ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys [2012-12-12 00:13] - [2012-08-21 12:47] - 0224640 ____A (Microsoft Corporation) 786DB5771F05EF300390399F626BF30A ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2012-12-01 16:07:52 Restore point made on: 2012-12-12 01:41:33 Restore point made on: 2012-12-16 23:40:19 Restore point made on: 2012-12-21 03:01:22 Restore point made on: 2012-12-26 02:37:37 Restore point made on: 2012-12-26 02:38:53 Restore point made on: 2012-12-26 02:40:57 Restore point made on: 2012-12-26 02:42:48 Restore point made on: 2012-12-26 02:44:10 Restore point made on: 2012-12-26 02:45:36 Restore point made on: 2012-12-26 02:46:46 Restore point made on: 2012-12-26 02:47:55 Restore point made on: 2012-12-26 02:49:10 Restore point made on: 2012-12-26 02:51:50 Restore point made on: 2012-12-26 02:54:15 Restore point made on: 2012-12-26 02:56:23 Restore point made on: 2012-12-26 02:59:55 Restore point made on: 2012-12-26 03:01:15 Restore point made on: 2012-12-26 04:33:50 Restore point made on: 2012-12-26 17:28:02 Restore point made on: 2012-12-27 22:07:52 Restore point made on: 2012-12-27 22:16:37 Restore point made on: 2012-12-28 13:15:29 Restore point made on: 2012-12-28 13:19:41 Restore point made on: 2012-12-28 13:33:27 Restore point made on: 2012-12-28 13:35:03 Restore point made on: 2012-12-28 14:50:10 Restore point made on: 2012-12-29 13:48:32 Restore point made on: 2012-12-29 13:52:03 Restore point made on: 2012-12-29 14:06:19 Restore point made on: 2012-12-29 14:09:52 Restore point made on: 2012-12-29 14:12:59 Restore point made on: 2012-12-29 14:14:29 Restore point made on: 2012-12-29 17:02:59 Restore point made on: 2013-01-09 19:01:30 Restore point made on: 2013-01-12 05:38:46 Restore point made on: 2013-01-12 05:54:35 Restore point made on: 2013-01-12 18:48:42 Restore point made on: 2013-01-17 09:47:05 Restore point made on: 2013-01-17 13:17:42 ==================== Memory info =========================== Percentage of memory in use: 11% Total physical RAM: 4062.13 MB Available physical RAM: 3587.49 MB Total Pagefile: 3817.3 MB Available Pagefile: 3662.42 MB Total Virtual: 2047.88 MB Available Virtual: 1966.3 MB ==================== Partitions ============================= 1 Drive c: () (Fixed) (Total:288.28 GB) (Free:118.92 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 3 Drive e: (Recovery) (Fixed) (Total:9.81 GB) (Free:0.84 GB) NTFS ==>[System with boot components (obtained from reading drive)] 6 Drive h: (WD MediaCtr) (Fixed) (Total:298.01 GB) (Free:195.74 GB) FAT32 7 Drive i: () (Removable) (Total:0.12 GB) (Free:0.1 GB) FAT 8 Drive x: (Boot) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS Datentr ### Status Gr”áe Frei Dyn GPT -------- ---------- ------- ------- --- --- 0 Online 298 GB 0 B 1 Kein Mediu 0 B 0 B 2 Kein Mediu 0 B 0 B 3 Online 298 GB 8 MB 4 Online 123 MB 0 B Last Boot: 2013-01-19 12:33 ==================== End Of Log ============================ |
19.01.2013, 13:07 | #6 |
/// TB-Ausbilder | blue screen...dauernder neustart...irql_not_less_or_equal Ja, prima unübersichtlich. Und was genau bitte hast du gemacht bevor es zum Bluescreen kam? Und wie heisst das Programm?
__________________ --> blue screen...dauernder neustart...irql_not_less_or_equal |
19.01.2013, 13:16 | #7 |
| blue screen...dauernder neustart...irql_not_less_or_equal hehe...sorry dafür also ich hab software gefunden gehabt...einen sprachtrainer französisch von dr. lothar rossipaul...diese software ist alt und ich hab diese installiert... die installation startete und ist ab versionen ms windows 3.1 ausgelegt...die installation würde aber nicht beendet und dann von mir abgebrochen, da hatte es aber schon unzählige daten eingespeist. dann kam dieser bluescreen nach dem nächsten neustart. ich hab dann versucht die dateien zu löschen von dem system...hab den entsprechenden ordner gefunden und gelöscht...allerdings speichert das system ja nicht nur im programmordner sondern doch auch an anderen stellen oder? nunja...hab dann versucht einen wiederherstellungspunkt vor der installation zu setzen. das hat nichts gebracht, ausser das mein norton antivirus seitdem gecrasht ist...dieses repariert sich aber grade wieder selbst. nunja ich will diesen fehler einfach loswerden... würde ja auch das system plattmachen nachdem ich alles auf die mobile festplatte gezogen habe an dateien die notwendig sind, aber ich habe keine wiederherstellungscd, da diese net bei vaios mitgeliefert wird. mir wäre es auch lieber das system ohne wiederherstellung hinzukriegen, ist das machbar? |
19.01.2013, 13:23 | #8 |
/// TB-Ausbilder | blue screen...dauernder neustart...irql_not_less_or_equal und wie HEISST dieser programmordner?
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
19.01.2013, 13:24 | #9 |
| blue screen...dauernder neustart...irql_not_less_or_equal der hieß rosp den hab ich allerdings manuell mit rechtsklick gelöscht, da er auch in der softwareanzeige nicht angezeigt worden ist... |
19.01.2013, 13:27 | #10 |
/// TB-Ausbilder | blue screen...dauernder neustart...irql_not_less_or_equal In Ordnung. Dann versuche mal beim Booten: F8 drücken wie gehabt und dann "letzte als funktionierend bekannte konfig."
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
19.01.2013, 13:37 | #11 |
| blue screen...dauernder neustart...irql_not_less_or_equal ok erledigt und nun? Also jetzt kommt der fehler in kürzeren abständen... Hast du eine andere idee? Oder weisst du wo ich eine wincd für meinen vaio zum recovery herbekomme??! |
19.01.2013, 17:55 | #12 |
/// TB-Ausbilder | blue screen...dauernder neustart...irql_not_less_or_equal Normalerweise müßte beim Booten so eine Meldung kommen wie: Press F11 for Recovery Wenn das der Fall ist brauchst du keine CD.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
21.01.2013, 18:57 | #13 |
/// TB-Ausbilder | blue screen...dauernder neustart...irql_not_less_or_equal Hallo, benötigst Du noch weiterhin Hilfe ? Sollte ich innerhalb der nächsten 24 Stunden keine Antwort von dir erhalten, werde ich dein Thema aus meinen Abos nehmen und bekomme dadurch keine Nachricht über neue Antworten. Das Verschwinden der Symptome bedeutet nicht, dass dein System schon sauber ist
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
23.01.2013, 14:48 | #14 |
/// TB-Ausbilder | blue screen...dauernder neustart...irql_not_less_or_equal Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomm ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Keine Logfiles einsenden, nur kurzer Hinweis. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
24.01.2013, 09:36 | #15 |
/// TB-Ausbilder | blue screen...dauernder neustart...irql_not_less_or_equal Hast du das Recovery geschafft?
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
Themen zu blue screen...dauernder neustart...irql_not_less_or_equal |
0x0000000a, andauernd, ausgeführt, blue, bluescreen, computer, dateien, dauernd, formation, französisch, gelöscht, hilfreich, information, installation, installiert, kommt immer wieder, konnte, manuell, minidump, nicht mehr, ordner, starte, startet, stop: 0x0000000a, vollständig, wahrscheinlich, woanders |