|
Plagegeister aller Art und deren Bekämpfung: Ordener auf externe Festplatte als Verknüpfung, lassen sich aber öffnenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
10.10.2014, 11:14 | #1 |
| Ordener auf externe Festplatte als Verknüpfung, lassen sich aber öffnen Hallöchen allerseits. Ich hab hier schon ein ähnliches Thema gelesen, indem sich die Ordner aber nicht öffnen ließen. Nun ist es bei mir aber so, dass ich über die Verknüpfung die Ordner öffnen kann, dann wird ein neues Fenster geöffnet in dem die anderen Datein und Ordner sind, die sich ganz normal nutzen lassen. Außerdem sind auf der Externen noch 2 neue Ordner:
Ich hab keine Ahnung, was genau da passiert ist und wie ich das wieder los werde. Vielen Dank im Voraus! |
10.10.2014, 11:22 | #2 |
/// the machine /// TB-Ausbilder | Ordener auf externe Festplatte als Verknüpfung, lassen sich aber öffnen hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
10.10.2014, 11:38 | #3 |
| Ordener auf externe Festplatte als Verknüpfung, lassen sich aber öffnen Hey, vielen Dank für die schnelle Antwort!
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-10-2014 01 Ran by HP_Besitzer (administrator) on QUEERASFUCK on 10-10-2014 12:33:50 Running from C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\Downloads Loaded Profile: HP_Besitzer (Available profiles: HP_Besitzer) Platform: Microsoft Windows XP Home Edition Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 6 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (Wacom Technology, Corp.) C:\Programme\Tablet\Pen\WTabletServiceCon.exe (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (Hewlett-Packard Co.) C:\Programme\HP\HP Software Update\hpwuSchd2.exe () C:\Programme\Bamboo Dock\BambooCore.exe (Wacom Technology, Corp.) C:\Programme\Tablet\Pen\Pen_TabletUser.exe (Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe (Wacom Technology, Corp.) C:\Programme\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.) C:\Programme\Tablet\Pen\Pen_TouchUser.exe (Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqste08.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Hewlett-Packard Company) C:\hp\KBD\kbd.exe (Realtek Semiconductor Corp.) C:\WINDOWS\ALCXMNTR.EXE (ATI Technologies, Inc.) C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe (Hewlett-Packard Company) C:\WINDOWS\system\hpsysdrv.exe (Malwarebytes Corporation) C:\Programme\ Malwarebytes Anti-Malware \mbam.exe (Mozilla Corporation) C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Programme\Mozilla Firefox\plugin-container.exe (Mozilla Corporation) C:\Programme\Mozilla Thunderbird\thunderbird.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [HPHUPD08] => c:\Programme\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe [49152 2005-06-02] (Hewlett-Packard) HKLM\...\Run: [Recguard] => C:\WINDOWS\SMINST\RECGUARD.EXE [237568 2005-07-22] () HKLM\...\Run: [PCDrProfiler] => [X] HKLM\...\Run: [HPBootOp] => C:\Programme\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe [249856 2005-11-10] (Hewlett-Packard Company) HKLM\...\Run: [HP Software Update] => C:\Programme\HP\HP Software Update\HPwuSchd2.exe [49152 2005-05-12] (Hewlett-Packard Co.) HKLM\...\Run: [Adobe ARM] => C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated) HKLM\...\Run: [BambooCore] => C:\Programme\Bamboo Dock\BambooCore.exe [646744 2014-08-24] () HKLM\...\Run: [IMJPMIG8.1] => C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [208952 2004-08-03] (Microsoft Corporation) HKLM\...\Run: [MSPY2002] => C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [59392 2004-08-03] () HKLM\...\Run: [PHIME2002ASync] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-03] (Microsoft Corporation) HKLM\...\Run: [PHIME2002A] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2004-08-03] (Microsoft Corporation) Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.) HKU\S-1-5-21-7783133-611818083-1653292085-1008\...\Run: [MSMSGS] => C:\Programme\Messenger\msmsgs.exe [1694208 2004-10-14] (Microsoft Corporation) HKU\S-1-5-21-7783133-611818083-1653292085-1008\...\MountPoints2: {35589570-2451-11e4-a2e3-001617588281} - K:\dcdc\gcd.js HKU\S-1-5-21-7783133-611818083-1653292085-1008\...\MountPoints2: {42b89e2c-29eb-11e4-a2ed-001617588281} - E:\dcdc\gcd.js HKU\S-1-5-21-7783133-611818083-1653292085-1008\...\MountPoints2: {52718e05-23c8-11e4-a2df-806d6172696f} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480 Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Dokumente und Einstellungen\HP_Besitzer\Startmenü\Programme\Autostart\Adobe Gamma.lnk ShortcutTarget: Adobe Gamma.lnk -> C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home SearchScopes: HKLM - DefaultScope value is missing. Toolbar: HKCU - &Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\rzcvueyt.default FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @wacom.com/wacom-plugin,version=1.1.0.4 -> C:\Programme\TabletPlugins\npwacom.dll (Wacom, Inc.) FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Programme\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin: Adobe Reader -> C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: wacom.com/WacomTabletPlugin -> C:\Programme\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ghostery - C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\rzcvueyt.default\Extensions\firefox@ghostery.com.xpi [2014-08-15] FF Extension: Tumblr Savior - C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\rzcvueyt.default\Extensions\jid1-W5guVoyeUR0uBg@jetpack.xpi [2014-09-08] FF Extension: Adblock Plus - C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\Mozilla\Firefox\Profiles\rzcvueyt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-09-01] Chrome: ======= ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Adobe LM Service; C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-08-24] (Adobe Systems) [File not signed] S3 aspnet_state; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [32768 2004-07-15] (Microsoft Corporation) [File not signed] S3 IDriverT; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed] S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [114288 2014-09-25] (Mozilla Foundation) S0 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [69632 2004-09-29] (HP) R2 WTabletServiceCon; C:\Programme\Tablet\Pen\WTabletServiceCon.exe [542488 2013-12-17] (Wacom Technology, Corp.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [3644928 2005-08-30] (Realtek Semiconductor Corp.) R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [43008 2005-03-09] (Advanced Micro Devices) S3 hidkmdf; C:\WINDOWS\System32\DRIVERS\hidkmdf.sys [12088 2013-11-12] (Windows (R) Win 7 DDK provider) S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [51120 2005-03-08] (HP) S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2005-03-08] (HP) S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21744 2005-03-08] (HP) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [110296 2014-10-09] (Malwarebytes Corporation) R1 Ndisprot; C:\WINDOWS\System32\DRIVERS\ndisprot.sys [21504 2009-11-17] (Windows (R) 2000 DDK provider) [File not signed] R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [20640 2005-04-25] (Sonic Solutions) [File not signed] S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation) S3 Secdrv; C:\WINDOWS\System32\DRIVERS\secdrv.sys [27440 2004-08-04] () S3 WacHidRouter; C:\WINDOWS\System32\DRIVERS\wachidrouter.sys [76600 2013-11-12] (Wacom Technology) S3 wacomrouterfilter; C:\WINDOWS\System32\DRIVERS\wacomrouterfilter.sys [13112 2013-11-12] (Wacom Technology) R3 WN5301; C:\WINDOWS\System32\DRIVERS\wn5301.sys [468768 2005-10-05] (Liteon Technology Inc.) S1 intelppm; system32\DRIVERS\intelppm.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 SYMIDSCO; \??\C:\PROGRA~1\GEMEIN~1\SYMANT~1\SymcData\idsdefs\20050901.036\symidsco.sys [X] S3 wacomvhid; system32\DRIVERS\wacomvhid.sys [X] U1 WS2IFSL; No ImagePath S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-10 12:33 - 2014-10-10 12:33 - 00000000 ____D () C:\FRST 2014-10-09 23:34 - 2014-10-09 23:34 - 01280467 _____ () C:\Dokumente und Einstellungen\HP_Besitzer\Desktop\bookmarks.html 2014-10-09 22:45 - 2014-10-09 22:45 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-10-09 22:45 - 2014-05-12 07:26 - 00053208 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-10-09 22:45 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-10-09 22:44 - 2014-10-09 22:45 - 00000000 ____D () C:\Programme\ Malwarebytes Anti-Malware 2014-10-09 01:39 - 2014-10-09 01:39 - 00000829 _____ () C:\Dokumente und Einstellungen\HP_Besitzer\Desktop\iuj.txt 2014-10-07 19:10 - 2014-10-07 19:10 - 00040960 ___SH () C:\Dokumente und Einstellungen\HP_Besitzer\Desktop\Thumbs.db 2014-10-07 12:40 - 2014-10-10 12:11 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-10-07 00:02 - 2014-10-07 00:02 - 00000208 _____ () C:\Dokumente und Einstellungen\HP_Besitzer\Desktop\check.txt 2014-10-02 22:47 - 2014-10-03 17:36 - 00000228 _____ () C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\do.txt 2014-10-02 13:08 - 2014-10-02 13:08 - 00000000 ____D () C:\Dokumente und Einstellungen\HP_Besitzer\Lokale Einstellungen\Anwendungsdaten\WMTools Downloaded Files 2014-10-01 21:05 - 2014-10-02 11:53 - 00000000 ____D () C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\oitnb 2014-09-28 14:03 - 2014-09-28 14:04 - 00000000 ____D () C:\Programme\Mozilla Thunderbird 2014-09-25 11:55 - 2014-09-25 11:55 - 00000274 _____ () C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\speciesism gr.txt 2014-09-25 10:30 - 2014-09-25 10:30 - 00000000 ____D () C:\Programme\Mozilla Firefox 2014-09-23 18:12 - 2014-09-23 18:13 - 00548890 _____ () C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\malinda lo.txt 2014-09-23 18:02 - 2014-09-23 18:02 - 00228774 _____ () C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\malinda lo.odt 2014-09-23 17:45 - 2014-09-23 17:45 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes 2014-09-12 17:03 - 2004-08-03 15:00 - 13463552 _____ () C:\WINDOWS\system32\dllcache\hwxjpn.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 10129408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hwxkor.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 10096640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hwxcht.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 01875968 _____ (Microsoft Corporation) C:\WINDOWS\system32\msir3jp.lex 2014-09-12 17:03 - 2004-08-03 15:00 - 01875968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msir3jp.lex 2014-09-12 17:03 - 2004-08-03 15:00 - 01783864 _____ () C:\WINDOWS\system32\WINPY.MB 2014-09-12 17:03 - 2004-08-03 15:00 - 01677824 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chsbrkr.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 01677824 _____ (Microsoft Corporation) C:\WINDOWS\system32\chsbrkr.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 01564868 _____ () C:\WINDOWS\system32\WINSP.MB 2014-09-12 17:03 - 2004-08-03 15:00 - 01223500 _____ () C:\WINDOWS\system32\WINZM.MB 2014-09-12 17:03 - 2004-08-03 15:00 - 01158818 _____ () C:\WINDOWS\system32\korwbrkr.lex 2014-09-12 17:03 - 2004-08-03 15:00 - 01158818 _____ () C:\WINDOWS\system32\dllcache\korwbrkr.lex 2014-09-12 17:03 - 2004-08-03 15:00 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chtbrkr.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\chtbrkr.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00471102 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imskdic.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00315452 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imskf.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00311359 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imepadsv.exe 2014-09-12 17:03 - 2004-08-03 15:00 - 00229439 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\multibox.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\c_g18030.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_g18030.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00211938 _____ () C:\WINDOWS\system32\lcphrase.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00195618 _____ () C:\WINDOWS\system32\dllcache\c_10002.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00195618 _____ () C:\WINDOWS\system32\c_10002.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00189986 _____ () C:\WINDOWS\system32\dllcache\c_1361.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00189986 _____ () C:\WINDOWS\system32\c_1361.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00177698 _____ () C:\WINDOWS\system32\dllcache\c_10003.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00177698 _____ () C:\WINDOWS\system32\c_10003.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00173602 _____ () C:\WINDOWS\system32\dllcache\c_10008.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00173602 _____ () C:\WINDOWS\system32\c_10008.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00146126 _____ () C:\WINDOWS\system32\array30.tab 2014-09-12 17:03 - 2004-08-03 15:00 - 00143422 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\softkey.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00134339 _____ () C:\WINDOWS\system32\dllcache\imekr.lex 2014-09-12 17:03 - 2004-08-03 15:00 - 00116285 _____ () C:\WINDOWS\system32\msdayi.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00110566 _____ () C:\WINDOWS\system32\arphr.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00108827 _____ () C:\WINDOWS\system32\dllcache\hanja.lex 2014-09-12 17:03 - 2004-08-03 15:00 - 00102463 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imepadsm.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\msir3jp.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msir3jp.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00083748 _____ () C:\WINDOWS\system32\prcp.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00083748 _____ () C:\WINDOWS\system32\prc.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00083748 _____ () C:\WINDOWS\system32\dllcache\prcp.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00083748 _____ () C:\WINDOWS\system32\dllcache\prc.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00082172 _____ () C:\WINDOWS\system32\dllcache\bopomofo.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00082172 _____ () C:\WINDOWS\system32\bopomofo.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\korwbrkr.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\korwbrkr.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WINGB.IME 2014-09-12 17:03 - 2004-08-03 15:00 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wingb.ime 2014-09-12 17:03 - 2004-08-03 15:00 - 00066728 _____ () C:\WINDOWS\system32\dllcache\big5.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00066728 _____ () C:\WINDOWS\system32\big5.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imkrinst.exe 2014-09-12 17:03 - 2004-08-03 15:00 - 00047066 _____ () C:\WINDOWS\system32\ksc.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00047066 _____ () C:\WINDOWS\system32\dllcache\ksc.nls 2014-09-12 17:03 - 2004-08-03 15:00 - 00044370 _____ () C:\WINDOWS\system32\acode.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00044370 _____ () C:\WINDOWS\system32\a234.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekrmig.exe 2014-09-12 17:03 - 2004-08-03 15:00 - 00043242 _____ () C:\WINDOWS\system32\phoncode.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00036927 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs411.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hanjadic.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00024114 _____ () C:\WINDOWS\system32\lcptr.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0804.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0412.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0411.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0404.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00018600 _____ () C:\WINDOWS\system32\arrayhw.tab 2014-09-12 17:03 - 2004-08-03 15:00 - 00016312 _____ () C:\WINDOWS\system32\arptr.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00016254 _____ () C:\WINDOWS\system32\PINTLPAE.HLP 2014-09-12 17:03 - 2004-08-03 15:00 - 00014821 _____ () C:\WINDOWS\system32\PINTLPAD.HLP 2014-09-12 17:03 - 2004-08-03 15:00 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs412.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdnecAT.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdnecat.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdnecNT.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdnecnt.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdnec95.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdibm02.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\f3ahvoas.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdnec95.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdibm02.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\f3ahvoas.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdlk41a.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdlk41a.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdlk41j.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdax2.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd106n.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd101a.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd101.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdlk41j.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdax2.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd106n.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd101a.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd101.dll 2014-09-12 17:03 - 2004-08-03 15:00 - 00004071 _____ () C:\WINDOWS\system32\phon.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00002714 _____ () C:\WINDOWS\system32\phonptr.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00002060 _____ () C:\WINDOWS\system32\noise.jpn 2014-09-12 17:03 - 2004-08-03 15:00 - 00001486 _____ () C:\WINDOWS\system32\noise.kor 2014-09-12 17:03 - 2004-08-03 15:00 - 00001460 _____ () C:\WINDOWS\system32\a15.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00000700 _____ () C:\WINDOWS\system32\dayiptr.tbl 2014-09-12 17:03 - 2004-08-03 15:00 - 00000520 _____ () C:\WINDOWS\system32\dayiphr.tbl 2014-09-12 17:02 - 2004-08-03 15:00 - 00811064 _____ (Microsoft Corporation) C:\WINDOWS\system32\imjp81k.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00811064 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjp81k.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00716856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpcus.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00571392 _____ (Microsoft Corporation) C:\WINDOWS\system32\TINTLGNT.IME 2014-09-12 17:02 - 2004-08-03 15:00 - 00571392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tintlgnt.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00482304 _____ (Microsoft Corporation) C:\WINDOWS\system32\PINTLGNT.IME 2014-09-12 17:02 - 2004-08-03 15:00 - 00482304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pintlgnt.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cintsetp.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tintsetp.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00426041 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\voicepad.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00368696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpcic.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00340023 _____ (Microsoft Corporation) C:\WINDOWS\system32\imjp81.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00340023 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjp81.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00307257 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdct.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00274489 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjputyc.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00262200 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjputy.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00233527 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjprw.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00208952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpmig.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cintime.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00196665 _____ () C:\WINDOWS\system32\dllcache\imjpinst.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00180770 _____ () C:\WINDOWS\system32\dllcache\c_20932.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00180770 _____ () C:\WINDOWS\system32\c_20932.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00180258 _____ () C:\WINDOWS\system32\dllcache\c_20000.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00180258 _____ () C:\WINDOWS\system32\c_20000.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00177698 _____ () C:\WINDOWS\system32\dllcache\c_20949.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00177698 _____ () C:\WINDOWS\system32\c_20949.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00175104 _____ () C:\WINDOWS\system32\dllcache\pintlcsa.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00173602 _____ () C:\WINDOWS\system32\dllcache\c_20936.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00173602 _____ () C:\WINDOWS\system32\c_20936.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00173568 _____ () C:\WINDOWS\system32\dllcache\chtskf.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00162850 _____ () C:\WINDOWS\system32\dllcache\c_10001.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00162850 _____ () C:\WINDOWS\system32\c_10001.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WINZM.IME 2014-09-12 17:02 - 2004-08-03 15:00 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WINSP.IME 2014-09-12 17:02 - 2004-08-03 15:00 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WINPY.IME 2014-09-12 17:02 - 2004-08-03 15:00 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winzm.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winsp.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winpy.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00155705 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdsvr.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekrcic.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00102456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imlang.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chtmbx.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\imekr61.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekr61.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00086073 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\voicesub.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekrmbx.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00081976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdct.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\winar30.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\phon.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winar30.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\phon.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\dayi.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dayi.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chajei.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\chajei.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\quick.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\quick.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\uniime.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\uniime.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pintlphr.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pmigrate.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00066082 _____ () C:\WINDOWS\system32\dllcache\c_21027.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00066082 _____ () C:\WINDOWS\system32\dllcache\c_20290.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00066082 _____ () C:\WINDOWS\system32\c_21027.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00066082 _____ () C:\WINDOWS\system32\c_20290.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winime.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winime.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\unicdime.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\unicdime.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00059392 _____ () C:\WINDOWS\system32\dllcache\imscinst.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00057399 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cplexe.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00057398 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdadm.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chtskdic.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pintlcsd.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00045109 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpuex.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tintlphr.exe 2014-09-12 17:02 - 2004-08-03 15:00 - 00028288 _____ () C:\WINDOWS\system32\xjis.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00028288 _____ () C:\WINDOWS\system32\dllcache\xjis.nls 2014-09-12 17:02 - 2004-08-03 15:00 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\romanime.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\romanime.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cintlgnt.ime 2014-09-12 17:02 - 2004-08-03 15:00 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CINTLGNT.IME 2014-09-12 17:02 - 2004-08-03 15:00 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs404.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs804.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\miniime.tpl 2014-09-12 17:02 - 2004-08-03 15:00 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tmigrate.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\c_is2022.dll 2014-09-12 17:02 - 2004-08-03 15:00 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_is2022.dll 2014-09-12 17:02 - 2001-08-18 04:53 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdjpn.dll 2014-09-12 17:02 - 2001-08-18 04:53 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdjpn.dll 2014-09-12 17:02 - 2001-08-18 04:53 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdkor.dll 2014-09-12 17:02 - 2001-08-18 04:53 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdkor.dll 2014-09-12 17:02 - 2001-08-17 14:55 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd106.dll 2014-09-12 17:02 - 2001-08-17 14:55 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd101c.dll 2014-09-12 17:02 - 2001-08-17 14:55 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd101b.dll 2014-09-12 17:02 - 2001-08-17 14:55 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd106.dll 2014-09-12 17:02 - 2001-08-17 14:55 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd101c.dll 2014-09-12 17:02 - 2001-08-17 14:55 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd101b.dll 2014-09-12 17:02 - 2001-08-17 14:55 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd103.dll 2014-09-12 17:02 - 2001-08-17 14:55 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd103.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-10 12:34 - 2014-08-14 17:39 - 00000000 ____D () C:\Dokumente und Einstellungen\HP_Besitzer\Lokale Einstellungen\Temp 2014-10-10 12:28 - 2004-11-02 20:13 - 00497861 _____ () C:\WINDOWS\WindowsUpdate.log 2014-10-10 10:47 - 2014-08-14 17:39 - 00000000 ___RD () C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\Eigene Bilder 2014-10-09 23:26 - 2014-08-16 11:35 - 00055792 _____ () C:\Dokumente und Einstellungen\HP_Besitzer\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT 2014-10-09 22:44 - 2014-08-14 23:13 - 00000000 ___RD () C:\Programme 2014-10-09 22:39 - 2005-10-27 01:34 - 00000000 ____D () C:\Programme\Gemeinsame Dateien\Microsoft Shared 2014-10-09 22:38 - 2014-08-15 13:33 - 00000000 ____D () C:\Dokumente und Einstellungen\HP_Besitzer\Anwendungsdaten\vlc 2014-10-09 22:38 - 2005-10-27 01:31 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme 2014-10-09 13:38 - 2014-08-14 17:39 - 00000000 ___RD () C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\Eigene Musik 2014-10-09 12:23 - 2014-08-14 17:35 - 00000183 _____ () C:\WINDOWS\system\hpsysdrv.DAT 2014-10-09 12:22 - 2004-11-02 20:13 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-10-09 12:22 - 2004-11-02 20:00 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-10-09 12:22 - 2004-11-02 20:00 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-10-09 01:39 - 2014-08-14 17:39 - 00000190 ___SH () C:\Dokumente und Einstellungen\HP_Besitzer\ntuser.ini 2014-10-09 01:39 - 2004-11-02 20:13 - 00032568 _____ () C:\WINDOWS\SchedLgU.Txt 2014-10-07 19:10 - 2014-08-28 18:56 - 00000000 ____D () C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\nano 14 2014-10-07 19:10 - 2014-08-22 15:54 - 00235450 ___SH () C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\Thumbs.db 2014-10-07 19:10 - 2014-08-17 20:08 - 00034816 _____ () C:\Dokumente und Einstellungen\HP_Besitzer\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-10-07 12:40 - 2014-09-01 19:04 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2014-10-07 12:40 - 2014-09-01 19:04 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2014-10-02 13:15 - 2014-08-14 18:14 - 00000000 ____D () C:\WINDOWS\system32\SupportAppCB 2014-10-02 13:10 - 2014-08-14 18:15 - 00062241 _____ () C:\WINDOWS\ZTEInstallInfo.log 2014-10-02 13:10 - 2004-11-02 20:11 - 00729597 _____ () C:\WINDOWS\setupapi.log 2014-10-02 13:05 - 2005-10-27 01:31 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart 2014-10-01 17:15 - 2004-11-02 20:09 - 00001158 _____ () C:\WINDOWS\system32\wpa.dbl 2014-09-28 14:04 - 2014-08-15 10:23 - 00000000 ____D () C:\Programme\Mozilla Maintenance Service 2014-09-23 18:08 - 2006-01-03 02:52 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB885836$ 2014-09-13 23:29 - 2004-11-02 20:08 - 00207304 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-09-12 17:03 - 2005-10-27 01:43 - 00000000 ____D () C:\WINDOWS\Help 2014-09-12 17:02 - 2004-11-02 19:57 - 00004516 _____ () C:\WINDOWS\regopt.log ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- Addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 08-10-2014 01 Ran by HP_Besitzer at 2014-10-10 12:35:31 Running from C:\Dokumente und Einstellungen\HP_Besitzer\Eigene Dateien\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 1500 (Version: 50.0.206.000 - Hewlett-Packard) Hidden 1500_Help (Version: 50.0.206.000 - Hewlett-Packard) Hidden 1500Trb (Version: 50.0.206.000 - Hewlett-Packard) Hidden 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.2.0.2070 - Adobe Systems Incorporated) Adobe AIR (Version: 3.2.0.2070 - Adobe Systems Incorporated) Hidden Adobe Bridge 1.0 (Version: 001.000.001 - Adobe Systems) Hidden Adobe Common File Installer (Version: 1.00.001 - Adobe System Incorporated) Hidden Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Help Center 1.0 (Version: 1.0.1 - Adobe Systems) Hidden Adobe Photoshop CS2 (HKLM\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.) Adobe Photoshop CS2 (Version: 9.0 - Adobe Systems, Inc.) Hidden Adobe Reader XI (11.0.08) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) Adobe Stock Photos 1.0 (Version: 1.0.1 - Adobe Systems) Hidden Agere Systems PCI-SV92PP Soft Modem (HKLM\...\Agere Systems Soft Modem) (Version: - ) AiO_Scan (Version: 50.0.206.000 - Hewlett-Packard) Hidden AiO_Scan_CDA (Version: 50.0.214.000 - Hewlett-Packard) Hidden AiOSoftware (Version: 50.0.206.000 - Hewlett-Packard) Hidden AiOSoftwareNPI (Version: 50.0.214.000 - Hewlett-Packard) Hidden ATI Display Driver (HKLM\...\ATI Display Driver) (Version: 8.17-050813a1-025991C-HP - ) ATI Systemsteuerung (HKLM\...\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}) (Version: 6.14.10.5166 - ) Bamboo Dock (Version: 3.3.0 - Wacom Europe GmH) Hidden Bamboo Dock 3.3 (HKLM\...\Bamboo Dock) (Version: 3.3 - Wacom Co., Ltd.) BufferChm (Version: 60.0.155.000 - Hewlett-Packard) Hidden CameraDrivers (Version: 5.0.0.290 - Ihr Firmenname) Hidden CameraDrivers (Version: 5.0.0.328 - Ihr Firmenname) Hidden CP_AtenaShokunin1Config (Version: 60.0.155.000 - Hewlett-Packard) Hidden CP_CalendarTemplates1 (Version: 60.0.155.000 - Hewlett-Packard) Hidden cp_LightScribeConfig (Version: 60.0.155.000 - Hewlett-Packard) Hidden cp_OnlineProjectsConfig (Version: 60.0.155.000 - Hewlett-Packard) Hidden CP_Package_Basic1 (Version: 60.0.155.000 - Hewlett-Packard) Hidden CP_Package_Variety1 (Version: 60.0.155.000 - Hewlett-Packard) Hidden CP_Package_Variety2 (Version: 60.0.155.000 - Hewlett-Packard) Hidden CP_Package_Variety3 (Version: 60.0.155.000 - Hewlett-Packard) Hidden CP_Panorama1Config (Version: 60.0.155.000 - Hewlett-Packard) Hidden cp_PosterPrintConfig (Version: 60.0.155.000 - Hewlett-Packard) Hidden cp_UpdateProjectsConfig (Version: 60.0.155.000 - Hewlett-Packard) Hidden CueTour (Version: 60.0.155.000 - Hewlett-Packard) Hidden Destinations (Version: 60.0.155.000 - Hewlett-Packard) Hidden DocProc (Version: 5.2.0.0 - Hewlett-Packard) Hidden DocumentViewer (Version: 53.0.13.000 - Hewlett-Packard) Hidden DocumentViewerQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden Fax (Version: 50.0.206.000 - Hewlett-Packard) Hidden Fax_CDA (Version: 50.0.214.000 - Hewlett-Packard) Hidden Free M4a to MP3 Converter 5.9 (HKLM\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com) FullDPAppQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden High Definition Audio - KB888111 (HKLM\...\KB888111WXPSP2) (Version: 20040219.000000 - Microsoft Corporation) Hotfix für Windows XP (KB893357) (HKLM\...\KB893357) (Version: 2 - Microsoft Corporation) Hotfix für Windows XP (KB906569) (HKLM\...\KB906569) (Version: 2 - Microsoft Corporation) HP Boot Optimizer (HKLM\...\{3BA95526-6AE0-4B87-A62D-17187EF565FC}) (Version: 2.0.5.1 - Hewlett-Packard Company) HP Deskjet Printer Preload (HKLM\...\{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}) (Version: 10.1.0 - Hewlett-Packard Company) HP Document Viewer 5.3 (HKLM\...\HP Document Viewer) (Version: 5.3 - HP) HP DVD Play 1.0 (HKLM\...\{45D707E9-F3C4-11D9-A373-0050BAE317E1}) (Version: - ) HP Imaging Device Functions 6.0 (HKLM\...\HP Imaging Device Functions) (Version: 6.0 - HP) HP Multimedia Keyboard Software (HKLM\...\KBD) (Version: - ) HP Photosmart 330,380,420,470,7800,8000,8200 Series (HKLM\...\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}) (Version: 8.1 - HP) HP Photosmart Kameras 5.0 (HKLM\...\{C83A12B9-B31B-461A-BBD4-CE9B988094F1}) (Version: 5.0 - HP) HP Photosmart Premier Software 6.0 (HKLM\...\HP Photo & Imaging) (Version: 6.0 - HP) HP PSC & OfficeJet 5.3.A (HKLM\...\{3E386744-10FA-44b2-98C9-DF7A270DECB3}) (Version: - HP) HP PSC & OfficeJet 5.3.B (HKLM\...\{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}) (Version: - HP) HP Software Update (HKLM\...\{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}) (Version: 3.0.6.002 - HEWLET~1|Hewlett-Packard) HP Solution Center & Imaging Support Tools 5.3 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 5.3 - HP) HPProductAssistant (Version: 53.0.13.000 - Hewlett-Packard) Hidden HpSdpAppCoreApp (Version: 3.00.0000 - Hewlett-Packard) Hidden InstantShareDevices (Version: 60.0.155.000 - Hewlett-Packard) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 1.1 German Language Pack (HKLM\...\{E78BFA60-5393-4C38-82AB-E8019E464EB4}) (Version: 1.1.4322 - Microsoft) Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 (Version: - Microsoft Corporation) Hidden Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 32.0.3 (x86 de) (HKLM\...\Mozilla Firefox 32.0.3 (x86 de)) (Version: 32.0.3 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) Mozilla Thunderbird 31.1.2 (x86 de) (HKLM\...\Mozilla Thunderbird 31.1.2 (x86 de)) (Version: 31.1.2 - Mozilla) NewCopy (Version: 50.0.206.000 - Hewlett-Packard) Hidden NewCopy_CDA (Version: 50.0.214.000 - Hewlett-Packard) Hidden OpenOffice 4.1.1 (HKLM\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) OptionalContentQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden PanoStandAlone (Version: 53.0.13.000 - Hewlett-Packard) Hidden PhotoGallery (Version: 60.0.155.000 - Hewlett-Packard) Hidden ProductContext (Version: 50.0.206.000 - Hewlett-Packard) Hidden PS2 (HKLM\...\PS2) (Version: - ) PSPrinters08 (Version: 8.01.0000 - Hewlett-Packard) Hidden PSTAPlugin (Version: 8.01.0000 - Hewlett-Packard) Hidden RandMap (Version: 60.0.155.000 - Hewlett-Packard) Hidden Readme (Version: 50.0.214.000 - Hewlett-Packard) Hidden Scan (Version: 5.2.0.0 - Hewlett-Packard) Hidden ScannerCopy (Version: 5.2.0.0 - Hewlett-Packard) Hidden Sicherheitsupdate für Windows XP (KB896358) (HKLM\...\KB896358) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB896422) (HKLM\...\KB896422) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB896424) (HKLM\...\KB896424) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB901214) (HKLM\...\KB901214) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB902400) (HKLM\...\KB902400) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB904706) (HKLM\...\KB904706) (Version: 2 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB905915) (HKLM\...\KB905915) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB908519) (HKLM\...\KB908519) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB912919) (HKLM\...\KB912919) (Version: 1 - Microsoft Corporation) SkinsHP1 (Version: 60.0.155.000 - Hewlett-Packard) Hidden SolutionCenter (Version: 50.0.152.000 - Hewlett-Packard) Hidden Sonic RecordNow Audio (HKLM\...\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}) (Version: 2.0.4 - Sonic Solutions) Sonic RecordNow Copy (HKLM\...\{B12665F4-4E93-4AB4-B7FC-37053B524629}) (Version: 2.0.4 - Sonic Solutions) Sonic RecordNow Data (HKLM\...\{075473F5-846A-448B-BCB3-104AA1760205}) (Version: 2.0.4 - Sonic Solutions) Sonic Update Manager (HKLM\...\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}) (Version: 3.0.0 - Sonic Solutions) Sonic_PrimoSDK (Version: 60.0.155.000 - Hewlett-Packard) Hidden Status (Version: 53.0.13.000 - Hewlett-Packard) Hidden TrayApp (Version: 53.0.13.000 - Hewlett-Packard) Hidden Unload (Version: 6.0.0 - Hewlett-Packard) Hidden VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) Wacom (HKLM\...\Pen Tablet Driver) (Version: 5.3.3-2 - Wacom Technology Corp.) WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden WebReg (Version: 53.0.13.000 - Hewlett-Packard) Hidden WebTablet FB Plugin 32 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.3 - Wacom Technology Corp.) WebTablet IE Plugin (HKLM\...\Wacom WebTabletPlugin for IE) (Version: 1.1.0.5 - Wacom Technology Corp.) WebTablet Netscape Plugin (HKLM\...\Wacom WebTabletPlugin for Netscape) (Version: 1.1.0.4 - Wacom Technology Corp.) Windows Installer 3.1 (KB893803) (HKLM\...\KB893803v2) (Version: - Microsoft Corporation) Windows Media Format Runtime (HKLM\...\Windows Media Format Runtime) (Version: - ) Windows Media Player 10 (HKLM\...\Windows Media Player) (Version: - ) Windows XP-Hotfix - KB873339 (HKLM\...\KB873339) (Version: 20041117.092459 - Microsoft Corporation) Windows XP-Hotfix - KB883667 (HKLM\...\KB883667) (Version: 20040812.104354 - Microsoft Corporation) Windows XP-Hotfix - KB885250 (HKLM\...\KB885250) (Version: 20050118.202711 - Microsoft Corporation) Windows XP-Hotfix - KB885835 (HKLM\...\KB885835) (Version: 20041027.181713 - Microsoft Corporation) Windows XP-Hotfix - KB885836 (HKLM\...\KB885836) (Version: 20041028.173203 - Microsoft Corporation) Windows XP-Hotfix - KB887472 (HKLM\...\KB887472) (Version: 20041014.162858 - Microsoft Corporation) Windows XP-Hotfix - KB887742 (HKLM\...\KB887742) (Version: 20041103.095002 - Microsoft Corporation) Windows XP-Hotfix - KB888113 (HKLM\...\KB888113) (Version: 20041116.131036 - Microsoft Corporation) Windows XP-Hotfix - KB890175 (HKLM\...\KB890175) (Version: 20041201.233338 - Microsoft Corporation) Windows XP-Hotfix - KB891781 (HKLM\...\KB891781) (Version: 20050110.165439 - Microsoft Corporation) Windows XP-Hotfix - KB892050 (HKLM\...\KB892050) (Version: 3 - Microsoft Corporation) Windows XP-Hotfix - KB893066 (HKLM\...\KB893066) (Version: 1 - Microsoft Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-7783133-611818083-1653292085-1008_Classes\CLSID\{092dfa86-5807-5a94-bf3b-5a53ba9e5308}\InprocServer32 -> C:\Programme\TabletPlugins\npWacomTabletPlugin.dll (Wacom) ==================== Restore Points ========================= 14-08-2014 16:14:53 Installiert Mobile Partner Manager 15-08-2014 07:53:50 Windows XP KB893357 wurde installiert. 15-08-2014 08:18:41 Konfiguriert easy Internet sign-up 15-08-2014 08:19:59 Konfiguriert Internet Services 15-08-2014 08:21:52 J2SE Runtime Environment 5.0 Update 5 wird entfernt 15-08-2014 09:51:28 Konfiguriert Customer Experience Enhancement 15-08-2014 09:55:09 Sonic Express Labeler wird entfernt 15-08-2014 11:20:46 Sonic MyDVD Plus wird entfernt 16-08-2014 11:30:23 Systemprüfpunkt 17-08-2014 12:21:05 Systemprüfpunkt 19-08-2014 07:59:14 Systemprüfpunkt 20-08-2014 08:22:24 Systemprüfpunkt 21-08-2014 09:37:19 Systemprüfpunkt 21-08-2014 14:44:08 Adobe Reader 7.0 - Deutsch wird entfernt 22-08-2014 15:01:55 Systemprüfpunkt 23-08-2014 15:49:54 Systemprüfpunkt 24-08-2014 13:33:56 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 24-08-2014 13:34:33 OpenOffice 4.1.1 wird installiert 24-08-2014 15:18:09 Installed Adobe Photoshop CS2 25-08-2014 11:59:44 Installed Windows XP Wdf01009. 26-08-2014 18:24:59 Systemprüfpunkt 27-08-2014 18:46:56 Systemprüfpunkt 29-08-2014 07:04:28 Systemprüfpunkt 30-08-2014 09:45:18 Systemprüfpunkt 31-08-2014 10:22:08 Systemprüfpunkt 01-09-2014 13:59:18 Systemprüfpunkt 02-09-2014 16:39:38 Systemprüfpunkt 03-09-2014 19:28:00 Systemprüfpunkt 04-09-2014 19:41:18 Systemprüfpunkt 06-09-2014 10:54:56 Systemprüfpunkt 07-09-2014 11:08:37 Systemprüfpunkt 08-09-2014 15:19:51 Systemprüfpunkt 09-09-2014 15:39:27 Systemprüfpunkt 11-09-2014 12:13:23 Systemprüfpunkt 12-09-2014 12:18:20 Systemprüfpunkt 14-09-2014 09:46:26 Systemprüfpunkt 15-09-2014 16:06:23 Systemprüfpunkt 16-09-2014 16:11:37 Systemprüfpunkt 17-09-2014 18:50:07 Systemprüfpunkt 19-09-2014 11:20:33 Systemprüfpunkt 20-09-2014 13:36:34 Systemprüfpunkt 21-09-2014 16:10:47 Systemprüfpunkt 22-10-2014 14:26:00 Systemprüfpunkt 22-09-2014 16:37:21 Systemprüfpunkt 24-09-2014 08:16:22 Systemprüfpunkt 25-09-2014 09:05:48 Systemprüfpunkt 26-09-2014 16:46:46 Systemprüfpunkt 28-09-2014 09:22:41 Systemprüfpunkt 29-09-2014 09:23:26 Systemprüfpunkt 01-10-2014 19:32:57 Systemprüfpunkt 02-10-2014 11:10:53 Entfernt Mobile Partner Manager 05-10-2014 09:11:21 Systemprüfpunkt 06-10-2014 11:15:40 Systemprüfpunkt 07-10-2014 11:49:21 Systemprüfpunkt 09-10-2014 14:39:47 Systemprüfpunkt 09-10-2014 20:37:55 Microsoft Works wird entfernt ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2004-08-04 13:00 - 2004-08-04 13:00 - 00000820 ____N C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2010-07-28 23:58 - 2014-08-24 18:30 - 00646744 _____ () C:\Programme\Bamboo Dock\BambooCore.exe 2005-09-16 08:33 - 2005-09-16 08:33 - 00204800 _____ () c:\Programme\HP\Digital Imaging\bin\HpqUtil.dll 2014-08-25 13:59 - 2013-12-17 03:17 - 01019672 _____ () C:\Programme\Tablet\Pen\libxml2.dll 2014-09-25 10:30 - 2014-09-25 10:30 - 03715184 _____ () C:\Programme\Mozilla Firefox\mozjs.dll 2014-10-07 12:40 - 2014-10-07 12:40 - 16825520 _____ () C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll 2014-09-28 14:03 - 2014-09-28 14:03 - 03339376 _____ () C:\Programme\Mozilla Thunderbird\mozjs.dll 2014-09-28 14:03 - 2014-09-28 14:03 - 00158832 _____ () C:\Programme\Mozilla Thunderbird\NSLDAP32V60.dll 2014-09-28 14:03 - 2014-09-28 14:03 - 00023152 _____ () C:\Programme\Mozilla Thunderbird\NSLDAPPR32V60.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-7783133-611818083-1653292085-500 - Administrator - Enabled) Gast (S-1-5-21-7783133-611818083-1653292085-501 - Limited - Disabled) Hilfeassistent (S-1-5-21-7783133-611818083-1653292085-1007 - Limited - Disabled) HP_Besitzer (S-1-5-21-7783133-611818083-1653292085-1008 - Administrator - Enabled) => %SystemDrive%\Dokumente und Einstellungen\HP_Besitzer SUPPORT_388945a0 (S-1-5-21-7783133-611818083-1653292085-1002 - Limited - Disabled) SUPPORT_fddfa904 (S-1-5-21-7783133-611818083-1653292085-1006 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/09/2014 09:21:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlgeschlagene Anwendung plugin-container.exe, Version 32.0.3.5379, fehlgeschlagenes Modul mozalloc.dll, Version 32.0.3.5379, Fehleradresse 0x0000141b. Das medienspezifische Ereignis für [plugin-container.exe!ws!] wird verarbeitet. Error: (10/09/2014 05:44:54 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlgeschlagene Anwendung plugin-container.exe, Version 32.0.3.5379, fehlgeschlagenes Modul mozalloc.dll, Version 32.0.3.5379, Fehleradresse 0x0000141b. Das medienspezifische Ereignis für [plugin-container.exe!ws!] wird verarbeitet. Error: (09/22/2014 08:30:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlgeschlagene Anwendung plugin-container.exe, Version 32.0.2.5373, fehlgeschlagenes Modul mozalloc.dll, Version 32.0.2.5373, Fehleradresse 0x0000141b. Das medienspezifische Ereignis für [plugin-container.exe!ws!] wird verarbeitet. Error: (09/10/2014 06:15:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlgeschlagene Anwendung plugin-container.exe, Version 31.0.0.5310, fehlgeschlagenes Modul mozalloc.dll, Version 31.0.0.5310, Fehleradresse 0x0000141b. Das medienspezifische Ereignis für [plugin-container.exe!ws!] wird verarbeitet. Error: (08/15/2014 09:52:03 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlgeschlagene Anwendung iexplore.exe, Version 6.0.2900.2180, fehlgeschlagenes Modul mshtml.dll, Version 6.0.2900.2802, Fehleradresse 0x0006907d. Das medienspezifische Ereignis für [iexplore.exe!ws!] wird verarbeitet. System errors: ============= Error: (10/09/2014 10:39:28 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: %%126 Error: (10/09/2014 10:39:28 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: %%126 Error: (10/09/2014 10:39:27 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: %%126 Error: (10/09/2014 10:39:27 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: %%126 Error: (10/09/2014 10:39:27 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: %%126 Error: (10/09/2014 10:39:27 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: %%126 Error: (10/09/2014 10:39:27 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: %%126 Error: (10/09/2014 10:39:27 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: %%126 Error: (10/09/2014 10:39:27 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: %%126 Error: (10/09/2014 10:39:27 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: %%126 Microsoft Office Sessions: ========================= Error: (10/09/2014 09:21:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe32.0.3.5379mozalloc.dll32.0.3.53790000141b Error: (10/09/2014 05:44:54 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe32.0.3.5379mozalloc.dll32.0.3.53790000141b Error: (09/22/2014 08:30:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe32.0.2.5373mozalloc.dll32.0.2.53730000141b Error: (09/10/2014 06:15:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe31.0.0.5310mozalloc.dll31.0.0.53100000141b Error: (08/15/2014 09:52:03 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: iexplore.exe6.0.2900.2180mshtml.dll6.0.2900.28020006907d ==================== Memory info =========================== Processor: AMD Sempron(tm) Processor 3400+ Percentage of memory in use: 88% Total physical RAM: 958.48 MB Available physical RAM: 110.77 MB Total Pagefile: 2313.82 MB Available Pagefile: 1302.11 MB Total Virtual: 2047.88 MB Available Virtual: 1950.21 MB ==================== Drives ================================ Drive c: (HP_PAVILION) (Fixed) (Total:181.01 GB) (Free:157.9 GB) NTFS ==>[Drive with boot components (Windows XP)] Drive d: (HP_RECOVERY) (Fixed) (Total:5.29 GB) (Free:0.51 GB) FAT32 ==>[Drive with boot components (Windows XP)] Drive f: (The Front Runner) (Fixed) (Total:931.51 GB) (Free:173.98 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 186.3 GB) (Disk ID: CAB10BEE) Partition 1: (Active) - (Size=181 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=5.3 GB) - (Type=0C) ======================================================== Disk: 5 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 7DD73DA0) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
11.10.2014, 10:54 | #4 |
/// the machine /// TB-Ausbilder | Ordener auf externe Festplatte als Verknüpfung, lassen sich aber öffnen Daten sichern , Rechner formatieren, neu aufsetzen. Externe Platten dann versteckte Dateien sichtbar machen, dann sollten die Originalordner zu sehen sein.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Ordener auf externe Festplatte als Verknüpfung, lassen sich aber öffnen |
ahnung, andere, anderen, datei, datein, ebenfalls, externe, externe festplatte, externen, fenster, festplatte, keine ahnung, neues, neues fenster, nicht öffnen, nutze, nutzen, ordner, platte, system, thema, verknüpfung, viren, volume, ähnliches, öffnen |