Log-Analyse und Auswertung: Rescue Scan hängt in einer Schleife
| ![]() Rescue Scan hängt in einer Schleife Hallo Ich habe die Vermutung, dass mein Rechner infiziert ist. Ich habe mehrere Scan mit Kaspersky Rescue Disk durchgeführt. Bei 15% hängt der Scan in einer Rountineschleife (bei HP) und scannt diese immer wieder, kommt jedoch über diesen Punkt nicht hinaus. Nachfolgend meine Logfiles von OTL: OTL Extras logfile created on: 06.01.2014 04:05:02 - Run 1 Report 1 OTL by OldTimer - Version Folder = C:\Users\XX\Downloads\OTL 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.16428) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 8,00 Gb Total Physical Memory | 5,81 Gb Available Physical Memory | 72,68% Memory free 15,99 Gb Paging File | 13,55 Gb Available in Paging File | 84,70% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 419,82 Gb Total Space | 311,87 Gb Free Space | 74,29% Space Free | Partition Type: NTFS Drive D: | 511,59 Gb Total Space | 146,90 Gb Free Space | 28,72% Space Free | Partition Type: NTFS Drive E: | 318,13 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: XX-PC | User Name: XX | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- Reg Error: Value error. File not found .jse[@ = JSEFile] -- Reg Error: Value error. File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .js [@ = JSFile] -- Reg Error: Value error. File not found .jse [@ = JSEFile] -- Reg Error: Value error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- Reg Error: Value error. jsfile [open] -- Reg Error: Value error. jsfile [print] -- Reg Error: Value error. jsefile [edit] -- Reg Error: Value error. jsefile [open] -- Reg Error: Value error. jsefile [print] -- Reg Error: Value error. piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) jsfile [edit] -- Reg Error: Value error. jsfile [open] -- Reg Error: Value error. jsfile [print] -- Reg Error: Value error. jsefile [edit] -- Reg Error: Value error. jsefile [open] -- Reg Error: Value error. jsefile [print] -- Reg Error: Value error. piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 ========== Firewall Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{005FA5FC-B0D0-425A-97C1-AF8A0139264D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{020C6445-BDF8-4263-AAB5-A995BFAC2801}" = lport=137 | protocol=17 | dir=in | app=system | "{0252BD77-958D-429E-9618-2A2E3BAEC515}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{10F47BFD-CDF0-4480-8C03-7B289CD9477E}" = rport=137 | protocol=17 | dir=out | app=system | "{2521AC9F-720B-46C5-97E9-130EE2593A12}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{336D9124-FD0D-4E57-8D62-E9C185D27A3F}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{34D0DD5F-DCDB-4681-AB99-E2258AA5CD83}" = lport=139 | protocol=6 | dir=in | app=system | "{4A97374D-33AA-4292-BB98-DE86727A7EC6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{4DD8526E-57A8-487B-9C79-7F476484AB5B}" = rport=445 | protocol=6 | dir=out | app=system | "{55AAB4A7-5A38-4C9F-9376-5B3955945A69}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5862F3AB-D9DE-4E2C-8DB3-398D6336F546}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{63BC5A1B-29C6-4308-93FE-60AFF4242C2A}" = lport=2869 | protocol=6 | dir=in | app=system | "{694CCFEF-CDB1-4F40-BDF3-EB657D34B5C8}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6F7F377D-0111-4BC0-8C9A-56E0500BF5B6}" = lport=138 | protocol=17 | dir=in | app=system | "{6FEF5419-6F87-4C5A-9642-64BED0035E29}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{80C286DF-BF73-444C-96F1-9634B6F07523}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe | "{8BF5F1C8-CF0C-465F-8D72-B31AF201AD96}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8C0A9553-DA7A-41D8-B7CC-0F75070B75EA}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{9F8F9B00-31E2-41B1-ABEA-F6283ABE9BD7}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{ACD54C33-1CB0-447B-BD34-D56FE3C01068}" = rport=138 | protocol=17 | dir=out | app=system | "{B98EC04F-3602-4E01-9380-AF2ACCFC5E67}" = rport=139 | protocol=6 | dir=out | app=system | "{BD979A09-BBBE-4F15-A547-D90ACCC335A7}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{C4DF914E-3154-47D2-AA54-9011A908CEAB}" = rport=10243 | protocol=6 | dir=out | app=system | "{CA7FEEF4-1544-41DA-B344-061142B66703}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CE5ECA37-8B47-443C-AEEB-27C9ACFB310D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D2A76227-E497-466F-B380-552B381E5640}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{D7A214EB-4CA1-4830-8D6E-E66EE4196544}" = lport=10243 | protocol=6 | dir=in | app=system | "{E3C1F40F-B240-445B-B403-DB5977D1E1D2}" = lport=445 | protocol=6 | dir=in | app=system | "{FCAA3FC2-C6E1-46A3-A093-FCC3EFEEA2B4}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{03F252D4-59BD-4053-8D8A-C88829FD1481}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{047A8CA2-5DB1-4808-8F5D-DA9991E3283F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{05E5A716-6549-4713-A2E5-3387DC7FBE78}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{091BE56A-F11A-449F-8909-9A3D3199062A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{09E45932-885D-4188-AD32-5EDD131FE426}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{0AE3E65D-F785-4B27-A670-7258888D51E9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{10F1EB98-F96A-4514-819E-6D8F3B08BBD9}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{133A4358-CBB0-48AD-BFB1-D639E6CBBD01}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe | "{16E9E90E-3743-4AA3-BE67-597DB1637C16}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{18143AB5-5B6F-4F08-B9C3-F4C3662D9D79}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe | "{1DAF7642-D9CE-4BD7-8B39-2F03D992F683}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{27E64E33-290E-4C3B-A16B-0F6000D1EA9A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{299CEAF4-73E1-4F83-9A3D-827F14D5770F}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{2C2DAFAA-1351-47CD-A4C7-1E8EEF0CE8F3}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe | "{311DC39A-444F-44A9-A2F4-43F337E310E8}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{35C39063-39BC-401B-89DF-B250F9CE7DDD}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{3E1461EF-49A3-4412-9748-DBD2E9025519}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe | "{42A6DD82-B983-4507-B439-C73EBAD6B56C}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{445BC386-3FB3-4DF0-A669-E38133AAC463}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{4BD2704B-A28E-4B74-AB7A-F20C7408D948}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe | "{54E81EE3-1B00-4225-8B3B-D6CE62F006F2}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{56838CE1-9220-4861-AF88-0B3D5100C8EF}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{56E22073-8D47-4B7C-9270-F278C6664FD4}" = protocol=6 | dir=out | app=system | "{5A9B48A0-375E-4E6D-A7E5-B61F24388783}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{5C990E97-87C7-4EBA-9666-E118A86B6603}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{6317272E-2AC0-4008-84E7-249FBEE85A4F}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqnrs08.exe | "{6D784B99-719C-42E7-9C07-B82C34D77837}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{701BD977-CBE8-4BDB-80F5-D5A7835C6ACE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{7DCE65B5-EB79-4894-A38E-F745933EF056}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{7E8A66C7-0BCF-4E35-9652-386BB39A106B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{827357EF-7BA3-4E59-A696-55578B19A6A0}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{8295E7A7-C2D5-4D60-AA35-A69307FA22D3}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{89AD084F-0F78-475F-AC3B-7350D4B255A1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{8CC7712B-C759-4B4C-AACB-1093BA8F3818}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{93BCCCE0-75B5-4900-BD72-B6B3EC380327}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{9E97345F-A17B-42C7-802B-D57B5A2EC610}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{A2E39E50-42B6-48AF-9E46-164AA787BF5E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpse.exe | "{A6B6016D-9A4F-4792-8AA5-C73D11361637}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\powerdvd.exe | "{BD6B0E96-FF62-4EDA-A0BE-641251A83A23}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{C0EAD1CB-D896-428D-A41D-9C3D8798E603}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{C537C3D6-D6EB-4826-90B0-974DFDBB8130}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{C9BA521F-95FF-46BC-80BF-94F7884C7DA9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{CCE0AA6D-9C62-470B-A796-426558861F1A}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{D44DDF6E-9622-455B-99F2-4C73A7FECF84}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D56B796F-FB85-4960-9ED0-D0280B0EE218}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{D5AB7270-00A5-4089-9CD0-AD51629146EF}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{D64813F4-8E7B-4827-B465-E2AEBF047FC0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe | "{D7268AEA-8B52-44DE-BF73-7E87A37A22A7}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{DB66CA7E-0575-4069-ADE2-2EFD5849441A}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\pdvddxsrv.exe | "{DE6475A6-3C92-411D-B4EA-7323536FA210}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe | "{E1953BDC-2FA8-4A4F-B207-B0584C978C87}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe | "{E1DF1953-AF01-48CC-A033-FC1C77FBB023}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{F50631AF-CE33-466B-A8BA-6DB0A53BEC24}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe | "{FE0F4514-DAC1-46CC-8B86-655DC72178ED}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{FF8C96E1-9D95-488D-9E82-D9C832D0A89F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64 "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support "{427174C0-096E-40D9-9684-9C109BEE2CBF}" = iTunes "{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{704C0303-D20C-45AF-BD2B-556EAF31BE09}" = iCloud "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90140000-0015-0407-1000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0016-0407-1000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0018-0407-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0019-0407-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-001A-0407-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001B-0407-1000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010 "{90140000-0043-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2010 "{90140000-0044-0407-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010 "{90140000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-00A1-0407-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00BA-0407-1000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010 "{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031" = Microsoft .NET Framework 4.5.1 (Deutsch) "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{988329F4-A1A1-4D51-803C-EF2725A97627}" = HP Photosmart All-In-One Driver Software 13.0 Rel. 2 "{9ED333F8-3E6C-4A38-BAFA-728454121CDA}" = PDF-XChange Viewer "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 331.65 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 331.65 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 331.65 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.7.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 331.65 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.13.0725 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 9.3.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamC" = GeForce Experience NvStream Client Components "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 9.3.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.9 "{C513739C-5F16-37B5-9ACF-99925FF1C1F3}" = Microsoft .NET Framework 4.5.1 (DEU) "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "Bitdefender" = Bitdefender Internet Security "CCleaner" = CCleaner "HitmanPro37" = HitmanPro 3.7 "HP Imaging Device Functions" = HP Imaging Device Functions 13.0 "HP Photosmart Essential" = HP Photosmart Essential 3.5 "HP Smart Web Printing" = HP Smart Web Printing 4.51 "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0 "HPExtendedCapabilities" = HP Customer Participation Program 13.0 "HPOCR" = OCR Software by I.R.I.S. 13.0 "Office14.PROPLUSR" = Microsoft Office Professional Plus 2010 "Shop for HP Supplies" = Shop for HP Supplies "sp6" = Logitech SetPoint 6.32 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status "{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch "{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp "{20EFC9AA-BBC1-4DFD-81FF-99654F71CBF8}" = HPPhotoSmartDiscLabel_PrintOnDisc "{26A24AE4-039D-4CA4-87B4-2F83217040FF}" = Java 7 Update 45 "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm "{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery "{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg "{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter "{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport "{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1 "{685B0843-6C8D-4E42-B60D-2B86B45526E0}" = PS_AIO_02_Software_Min "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply "{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox "{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7B5AA67E-FEA0-40BB-BAB5-CA56645A589C}" = NVIDIA PhysX "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert "{94F8D42D-BB31-4858-9705-7D756D8D9655}" = PS_AIO_02_Software "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc "{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.05) - Deutsch "{B28635AB-1DF3-4F07-BFEA-975D911B549B}" = hpphotosmartdisclabelplugin "{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential "{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan "{D9D8F2CF-FE2D-4644-9762-01F916FE90A9}" = HPPhotoSmartDiscLabel_PaperLabel "{DBA8B9E1-C6FF-4624-9598-73D3B41A0903}" = Microsoft Picture It! Foto Premium 9 "{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "3785-6780-1293-3574" = EasyTax 2012 AG 1.03 "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Shockwave Player" = Adobe Shockwave Player 12.0 "AVMWLANCLI" = AVM FRITZ!WLAN "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "PictureIt_v9" = Microsoft Picture It! Foto Premium 9 ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 05.01.2014 23:03:42 | Computer Name =XX-PC | Source = Application Hang | ID = 1002 Description = Programm OTL.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: ff0 Startzeit: 01cf0a8aa70a7618 Endzeit: 0 Anwendungspfad: C:\Users/XX\Downloads\OTL\OTL.exe Berichts-ID: [ System Events ] Error - 05.01.2014 12:38:42 | Computer Name = XX-PC | Source = NETLOGON | ID = 3095 Description = Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser Konfiguration nicht gestartet zu sein. Error - 05.01.2014 16:54:51 | Computer Name = XX-PC | Source = NETLOGON | ID = 3095 Description = Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als Mitglied einer Domäne. Rescue Scan hängt in einer Schleife

hi,
__________________![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
