![]() |
|
Log-Analyse und Auswertung: Problem System Error. Updates funktionieren nichtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #10 |
| ![]() Problem System Error. Updates funktionieren nicht TEIL 2 Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp" Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ "Wallpaper" = "C:\Dokumente und Einstellungen\OpTiKinG\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp" Windows Portable Device AutoPlay Handlers ----------------------------------------- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ BridgeCS3ImportMediaOnArrival\ "Provider" = "Adobe Bridge CS3" "InvokeProgID" = "Adobe.adobebridge" "InvokeVerb" = "launch" HKLM\SOFTWARE\Classes\Adobe.adobebridge\shell\launch\command\(Default) = "C:\Programme\Adobe\Adobe Bridge CS3\bridgeproxy.exe -v %1" ["Adobe Systems, Inc."] dMCAudioCDInput\ "Provider" = "dMC Audio CD Input" "InvokeProgID" = "dMC.AudioCD.Autorun" "InvokeVerb" = "open" HKLM\SOFTWARE\Classes\dMC.AudioCD.Autorun\shell\open\command\(Default) = ""C:\Programme\Illustrate\dBpowerAMP\CDGrab.exe"" ["Illustrate"] DVDneXtCOPYPlayDVDMovieOnArrival\ "Provider" = "DVDneXtCOPY" "InvokeProgID" = "DVDneXtCOPY" "InvokeVerb" = "PlayDVDMovieOnArrival_DVDneXtCOPY" HKLM\SOFTWARE\Classes\DVDneXtCOPY\shell\PlayDVDMovieOnArrival_DVDneXtCOPY\Command\(Default) = ""C:\Programme\DVDneXtCOPY2\DVDneXtCOPY2.exe" /WORK /NEW /SOURCE="%1"" [file not found] IviDVDEventHandler\ "Provider" = "InterVideo WinDVD" "InvokeProgID" = "Ivi.MediaFile" "InvokeVerb" = "play" HKLM\SOFTWARE\Classes\Ivi.MediaFile\shell\play\command\(Default) = "C:\Programme\InterVideo\WinDVD\WinDVD.exe %1" ["InterVideo Inc."] IviVideoCDHandler\ "Provider" = "InterVideo WinDVD" "InvokeProgID" = "Ivi.MediaFile" "InvokeVerb" = "play" HKLM\SOFTWARE\Classes\Ivi.MediaFile\shell\play\command\(Default) = "C:\Programme\InterVideo\WinDVD\WinDVD.exe %1" ["InterVideo Inc."] MSPictureIt10ViewOnArrival\ "Provider" = "Microsoft Foto Designer-Bibliothek - Import-Assistent" "InvokeProgID" = "Microsoft.Picture.It.10.AutoPlay" "InvokeVerb" = "AutoPlay" HKLM\SOFTWARE\Classes\Microsoft.Picture.It.10.AutoPlay\shell\AutoPlay\Command\(Default) = "C:\Programme\Picture It! Premium 10\imprtwiz.exe /invoke={D0551EC1-5A78-11cf-9DBE-00AA00A70BB5}" [MS] MSWPDShellNamespaceHandler\ "Provider" = "@%SystemRoot%\System32\WPDShextRes.dll,-501" "CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}" "InitCmdLine" = " " -> {HKLM...CLSID} = "WPDShextAutoplay" \LocalServer32\(Default) = "C:\WINDOWS\system32\WPDShextAutoplay.exe" [MS] MXCDRBurningCDArrival\ "Provider" = "MAGIX Goya" "InvokeProgID" = "Magix.MXCDR" "InvokeVerb" = "Show" HKLM\SOFTWARE\Classes\Magix.MXCDR\shell\Show\DropTarget\CLSID = "{FF482932-87EF-409E-9C02-48E9FF861CBF}" -> {HKLM...CLSID} = "MXCDR AutoplayClass" \LocalServer32\(Default) = "C:\Programme\MAGIX\Goya_burnR_mxcdr\Goya.exe" ["MAGIX AG"] MXFotomakerBrowseOnArrival\ "Provider" = "MAGIX Digital Foto Maker 2007" "InvokeProgID" = "Magix.Fotomaker" "InvokeVerb" = "Brws" HKLM\SOFTWARE\Classes\Magix.Fotomaker\shell\Brws\DropTarget\CLSID = "{51BD566E-A02D-4387-9A82-D929EA8C20B0}" -> {HKLM...CLSID} = "MXFotomaker Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Foto_Manager_2007\FotoMaker.exe" ["MAGIX"] MXFotomakerBurningCDArrival\ "Provider" = "MAGIX Digital Foto Maker 2007" "InvokeProgID" = "Magix.Fotomaker" "InvokeVerb" = "Burn" HKLM\SOFTWARE\Classes\Magix.Fotomaker\shell\Burn\DropTarget\CLSID = "{51BD566E-A02D-4387-9A82-D929EA8C20B0}" -> {HKLM...CLSID} = "MXFotomaker Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Foto_Manager_2007\FotoMaker.exe" ["MAGIX"] MXFotomakerPlayAudioOnArrival\ "Provider" = "MAGIX Digital Foto Maker 2007" "InvokeProgID" = "Magix.Fotomaker" "InvokeVerb" = "PlayA" HKLM\SOFTWARE\Classes\Magix.Fotomaker\shell\PlayA\DropTarget\CLSID = "{51BD566E-A02D-4387-9A82-D929EA8C20B0}" -> {HKLM...CLSID} = "MXFotomaker Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Foto_Manager_2007\FotoMaker.exe" ["MAGIX"] MXFotomakerPlayCDOnArrival\ "Provider" = "MAGIX Digital Foto Maker 2007" "InvokeProgID" = "Magix.Fotomaker" "InvokeVerb" = "PlayCD" HKLM\SOFTWARE\Classes\Magix.Fotomaker\shell\PlayCD\DropTarget\CLSID = "{51BD566E-A02D-4387-9A82-D929EA8C20B0}" -> {HKLM...CLSID} = "MXFotomaker Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Foto_Manager_2007\FotoMaker.exe" ["MAGIX"] MXFotomakerShowPicturesOnArrival\ "Provider" = "MAGIX Digital Foto Maker 2007" "InvokeProgID" = "Magix.Fotomaker" "InvokeVerb" = "ShwPic" HKLM\SOFTWARE\Classes\Magix.Fotomaker\shell\ShwPic\DropTarget\CLSID = "{51BD566E-A02D-4387-9A82-D929EA8C20B0}" -> {HKLM...CLSID} = "MXFotomaker Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Foto_Manager_2007\FotoMaker.exe" ["MAGIX"] MXMP3MakerBrowseOnArrival\ "Provider" = "MAGIX MP3 Maker 12" "InvokeProgID" = "Magix.MP3Maker" "InvokeVerb" = "Brws" HKLM\SOFTWARE\Classes\Magix.MP3Maker\shell\Brws\DropTarget\CLSID = "{C783A282-958A-4684-9093-AB409B3834E0}" -> {HKLM...CLSID} = "MXMP3Maker Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Music_Manager_2007\MP3Maker.exe" ["MAGIX"] MXMP3MakerBurningCDArrival\ "Provider" = "MAGIX MP3 Maker 12" "InvokeProgID" = "Magix.MP3Maker" "InvokeVerb" = "Burn" HKLM\SOFTWARE\Classes\Magix.MP3Maker\shell\Burn\DropTarget\CLSID = "{C783A282-958A-4684-9093-AB409B3834E0}" -> {HKLM...CLSID} = "MXMP3Maker Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Music_Manager_2007\MP3Maker.exe" ["MAGIX"] MXMP3MakerPlayAudioOnArrival\ "Provider" = "MAGIX MP3 Maker 12" "InvokeProgID" = "Magix.MP3Maker" "InvokeVerb" = "PlayA" HKLM\SOFTWARE\Classes\Magix.MP3Maker\shell\PlayA\DropTarget\CLSID = "{C783A282-958A-4684-9093-AB409B3834E0}" -> {HKLM...CLSID} = "MXMP3Maker Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Music_Manager_2007\MP3Maker.exe" ["MAGIX"] MXMP3MakerPlayCDOnArrival\ "Provider" = "MAGIX MP3 Maker 12" "InvokeProgID" = "Magix.MP3Maker" "InvokeVerb" = "PlayCD" HKLM\SOFTWARE\Classes\Magix.MP3Maker\shell\PlayCD\DropTarget\CLSID = "{C783A282-958A-4684-9093-AB409B3834E0}" -> {HKLM...CLSID} = "MXMP3Maker Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Music_Manager_2007\MP3Maker.exe" ["MAGIX"] MXMP3MakerPlayVideoOnArrival\ "Provider" = "MAGIX MP3 Maker 12" "InvokeProgID" = "Magix.MP3Maker" "InvokeVerb" = "PlayV" HKLM\SOFTWARE\Classes\Magix.MP3Maker\shell\PlayV\DropTarget\CLSID = "{C783A282-958A-4684-9093-AB409B3834E0}" -> {HKLM...CLSID} = "MXMP3Maker Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Music_Manager_2007\MP3Maker.exe" ["MAGIX"] MXMP3MakerShowPicturesOnArrival\ "Provider" = "MAGIX MP3 Maker 12" "InvokeProgID" = "Magix.MP3Maker" "InvokeVerb" = "ShwPic" HKLM\SOFTWARE\Classes\Magix.MP3Maker\shell\ShwPic\DropTarget\CLSID = "{C783A282-958A-4684-9093-AB409B3834E0}" -> {HKLM...CLSID} = "MXMP3Maker Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Music_Manager_2007\MP3Maker.exe" ["MAGIX"] MXSuiteBurningCDArrival\ "Provider" = "MAGIX Goya burnR" "InvokeProgID" = "Magix.MXSuite" "InvokeVerb" = "Show" HKLM\SOFTWARE\Classes\Magix.MXSuite\shell\Show\DropTarget\CLSID = "{F9AD4E4F-B992-4B84-AC51-9F990D5F4738}" -> {HKLM...CLSID} = "MAGIXSuite Autoplay Class" \LocalServer32\(Default) = "C:\Programme\MAGIX\Goya_burnR\Goya.exe" ["MAGIX AG"] MxVideoDeLuxeBurningCDArrival\ "Provider" = "MAGIX Video deLuxe 2005/2006 PLUS" "InvokeProgID" = "Magix.videodeLuxe" "InvokeVerb" = "Show" HKLM\SOFTWARE\Classes\Magix.videodeLuxe\shell\Show\DropTarget\CLSID = "{1810360D-0FC7-474B-ABC1-84E96BF51D2F}" -> {HKLM...CLSID} = "videodeLuxe AutoplayClass" \LocalServer32\(Default) = "K:\ProgramZ 'n GameZ\VideoDeluxe\videodeLuxe.exe" [file not found] MxVideoDeLuxeVideoCameraArrival\ "Provider" = "MAGIX Video deLuxe 2005/2006 PLUS" "ProgID" = "Magix.videodeLuxe" HKLM\SOFTWARE\Classes\Magix.videodeLuxe\CLSID\(Default) = "{1810360D-0FC7-474B-ABC1-84E96BF51D2F}" -> {HKLM...CLSID} = "videodeLuxe AutoplayClass" \LocalServer32\(Default) = "K:\ProgramZ 'n GameZ\VideoDeluxe\videodeLuxe.exe" [file not found] NeroAutoPlay8AudioToNeroDigital\ "Provider" = "Nero Burning ROM" "InvokeProgID" = "Nero.AutoPlay8" "InvokeVerb" = "AudioToNeroDigital_PlayCDAudioOnArrival" HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\AudioToNeroDigital_PlayCDAudioOnArrival\command\(Default) = "C:\Programme\Nero\Nero8\Nero Burning Rom\nero.exe /Dialog:SaveTracks %L" ["Nero AG"] NeroAutoPlay8CDAudio\ "Provider" = "Nero Express" "InvokeProgID" = "Nero.AutoPlay8" "InvokeVerb" = "CDAudio_HandleCDBurningOnArrival" HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\CDAudio_HandleCDBurningOnArrival\command\(Default) = "C:\Programme\Nero\Nero8\Nero Burning Rom\nero.exe -w /New:AudioCD" ["Nero AG"] NeroAutoPlay8CopyCD\ "Provider" = "Nero Burning ROM" "InvokeProgID" = "Nero.AutoPlay8" "InvokeVerb" = "CopyCD_PlayMusicFilesOnArrival" HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\CopyCD_PlayMusicFilesOnArrival\command\(Default) = "C:\Programme\Nero\Nero8\Nero Burning Rom\nero.exe /Dialog ![]() NeroAutoPlay8DataDisc_CD\ "Provider" = "Nero Express" "InvokeProgID" = "Nero.AutoPlay8" "InvokeVerb" = "DataDisc_CD_HandleCDBurningOnArrival" HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\DataDisc_CD_HandleCDBurningOnArrival\command\(Default) = "C:\Programme\Nero\Nero8\Nero Burning Rom\nero.exe -w /New:ISODisc /Media:CD %L" ["Nero AG"] NeroAutoPlay8DataDisc_DVD\ "Provider" = "Nero Express" "InvokeProgID" = "Nero.AutoPlay8" "InvokeVerb" = "DataDisc_DVD_HandleDVDBurningOnArrival" HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\DataDisc_DVD_HandleDVDBurningOnArrival\command\(Default) = "C:\Programme\Nero\Nero8\Nero Burning Rom\nero.exe -w /New:ISODisc /Media ![]() NeroAutoPlay8LaunchNeroStartSmart\ "Provider" = "Nero StartSmart" "InvokeProgID" = "Nero.AutoPlay8" "InvokeVerb" = "LaunchNeroStartSmart_HandleDVDBurningOnArrival" HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\LaunchNeroStartSmart_HandleDVDBurningOnArrival\command\(Default) = "C:\Programme\Nero\Nero8\Nero StartSmart\NeroStartSmart.exe /AutoPlay" ["Nero AG"] NeroAutoPlay8PlayAudioCD\ "Provider" = "Nero ShowTime" "InvokeProgID" = "Nero.AutoPlay8" "InvokeVerb" = "PlayAudioCD_PlayMusicFilesOnArrival" HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\PlayAudioCD_PlayMusicFilesOnArrival\command\(Default) = "C:\Programme\Nero\Nero8\Nero ShowTime\ShowTime.exe /Play %L" ["Nero AG"] NeroAutoPlay8PlayDVD\ "Provider" = "Nero ShowTime" "InvokeProgID" = "Nero.AutoPlay8" "InvokeVerb" = "PlayDVD_PlayVideoFilesOnArrival" HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\PlayDVD_PlayVideoFilesOnArrival\command\(Default) = "C:\Programme\Nero\Nero8\Nero ShowTime\ShowTime.exe /Play %L" ["Nero AG"] NeroAutoPlay8RipCD\ "Provider" = "Nero Burning ROM" "InvokeProgID" = "Nero.AutoPlay8" "InvokeVerb" = "RipCD_PlayCDAudioOnArrival" HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\RipCD_PlayCDAudioOnArrival\command\(Default) = "C:\Programme\Nero\Nero8\Nero Burning Rom\nero.exe /Dialog:SaveTracks %L" ["Nero AG"] NeroAutoPlay8TranscodeVideo\ "Provider" = "Nero Recode" "InvokeProgID" = "Nero.AutoPlay8" "InvokeVerb" = "TranscodeVideo_PlayDVDMovieOnArrival" HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\TranscodeVideo_PlayDVDMovieOnArrival\command\(Default) = "C:\Programme\Nero\Nero8\Nero Recode\Recode.exe /New:CopyDVDVideo" ["Nero AG"] NeroAutoPlay8VideoCapture\ "Provider" = "Nero Vision" "ProgID" = "Shell.HWEventHandlerShellExecute" "InitCmdLine" = ""C:\Programme\Nero\Nero8\Nero Vision\NeroVision.exe" /New:VideoCapture" HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" -> {HKLM...CLSID} = "ShellExecute HW Event Handler" \LocalServer32\(Default) = "rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS] NeroAutoPlay8ViewPhotos\ "Provider" = "Nero PhotoSnap Viewer" "InvokeProgID" = "Nero.AutoPlay8" "InvokeVerb" = "ViewPhotos_ShowPicturesOnArrival" HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\ViewPhotos_ShowPicturesOnArrival\command\(Default) = "C:\Programme\Nero\Nero8\Nero PhotoSnap\PhotoSnapViewer.exe /" ["Nero AG"] PCLEVideoCameraArrival\ "Provider" = "Pinnacle Studio" "ProgID" = "Shell.HWEventHandlerShellExecute" "InitCmdLine" = "C:\Programme\Pinnacle\Studio 9\programs\studio.exe" HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" -> {HKLM...CLSID} = "ShellExecute HW Event Handler" \LocalServer32\(Default) = "rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS] RPCDBurningOnArrival\ "Provider" = "RealPlayer" "InvokeProgID" = "RealPlayer.CDBurn.6" "InvokeVerb" = "open" HKCU\Software\Classes\RealPlayer.CDBurn.6\shell\open\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /burn "%1"" ["RealNetworks, Inc."] RPDeviceOnArrival\ "Provider" = "RealPlayer" "ProgID" = "RealPlayer.HWEventHandler" HKLM\SOFTWARE\Classes\RealPlayer.HWEventHandler\CLSID\(Default) = "{67E76F1D-BDE2-4052-913C-2752366192D2}" -> {HKLM...CLSID} = "RealNetworks Scheduler" \LocalServer32\(Default) = ""C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -autoplay" ["RealNetworks, Inc."] RPPlayCDAudioOnArrival\ "Provider" = "RealPlayer" "InvokeProgID" = "RealPlayer.AudioCD.6" "InvokeVerb" = "play" HKCU\Software\Classes\RealPlayer.AudioCD.6\shell\play\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /play %1 " ["RealNetworks, Inc."] RPPlayDVDMovieOnArrival\ "Provider" = "RealPlayer" "InvokeProgID" = "RealPlayer.DVD.6" "InvokeVerb" = "play" HKCU\Software\Classes\RealPlayer.DVD.6\shell\play\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /dvd %1 " ["RealNetworks, Inc."] RPPlayMediaOnArrival\ "Provider" = "RealPlayer" "InvokeProgID" = "RealPlayer.AutoPlay.6" "InvokeVerb" = "open" HKCU\Software\Classes\RealPlayer.AutoPlay.6\shell\open\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /autoplay "%1"" ["RealNetworks, Inc."] VLCPlayCDAudioOnArrival\ "Provider" = "VideoLAN VLC media player" "InvokeProgID" = "VLC.CDAudio" "InvokeVerb" = "play" HKLM\SOFTWARE\Classes\VLC.CDAudio\shell\play\command\(Default) = "C:\Programme\VideoLAN\VLC\vlc.exe --started-from-file cdda:%1" ["VideoLAN Team"] VLCPlayDVDMovieOnArrival\ "Provider" = "VideoLAN VLC media player" "InvokeProgID" = "VLC.DVDMovie" "InvokeVerb" = "play" HKLM\SOFTWARE\Classes\VLC.DVDMovie\shell\play\command\(Default) = "C:\Programme\VideoLAN\VLC\vlc.exe --started-from-file dvd:%1" ["VideoLAN Team"] WinampMTPHandler\ "Provider" = "Winamp" "ProgID" = "Shell.HWEventHandlerShellExecute" "InitCmdLine" = "C:\Programme\Winamp1\winamp.exe" HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" -> {HKLM...CLSID} = "ShellExecute HW Event Handler" \LocalServer32\(Default) = "rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS] Startup items in "OpTiKinG" & "All Users" startup folders: ---------------------------------------------------------- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart "Microsoft Office" -> shortcut to: "C:\Programme\Microsoft Office\Office\OSA9.EXE -b -l" [MS] Enabled Scheduled Tasks: ------------------------ "AED15AE891CECD54" -> launches: "c:\dokume~1\optiking\anwend~1\onceai~1\bits close web.exe" [file not found] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = "C:\WINDOWS\system32\pnrpnsp.dll" [MS] 000000000002\LibraryPath = "C:\WINDOWS\system32\pnrpnsp.dll" [MS] 000000000003\LibraryPath = "C:\Programme\Bonjour\mdnsNSP.dll" ["Apple Computer, Inc."] 000000000004\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000005\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 000000000006\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] Transport Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 38 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ "{855F3B16-6D32-4FE6-8A56-BBB695989046}" -> {HKLM...CLSID} = "ICQ Toolbar" \InProcServer32\(Default) = "C:\Programme\ICQToolbar\toolbaru.dll" ["IE Toolbar"] Extensions (Tools menu items, main toolbar menu buttons) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\ {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ "MenuText" = "Sun Java Konsole" "CLSIDExtension" = "{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}" -> {HKCU...CLSID} = "Java Plug-in 1.6.0_05" \InProcServer32\(Default) = "C:\Programme\Java\jre1.6.0_05\bin\ssv.dll" ["Sun Microsystems, Inc."] -> {HKLM...CLSID} = "Java Plug-in 1.6.0_05" \InProcServer32\(Default) = "C:\Programme\Java\jre1.6.0_05\bin\npjpi160_05.dll" ["Sun Microsystems, Inc."] {94EDF7B4-4272-4AF3-8F8B-4E2F68E225B7}\ "ButtonText" = "PacificPoker4" "Exec" = "C:\PROGRA~1\PACIFI~1\pacificpoker.exe" ["Cassava Ent."] {B205A35E-1FC4-4CE3-818B-899DBBB3388C}\ {B863453A-26C3-4E1F-A54D-A2CD196348E9}\ "ButtonText" = "ICQ Lite" "MenuText" = "ICQ Lite" "Exec" = "C:\Programme\ICQLite\ICQLite.exe" ["ICQ Ltd."] {F4430FE8-2638-42E5-B849-800749B94EED}\ "ButtonText" = "PartyPoker.net" "MenuText" = "PartyPoker.net" {FB5F1910-F110-11D2-BB9E-00C04F795683}\ "ButtonText" = "Messenger" "MenuText" = "Windows Messenger" "Exec" = "C:\Programme\Messenger\msmsgs.exe" [MS] Miscellaneous IE Hijack Points ------------------------------ HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\ <<H>> "{855F3B16-6D32-4fe6-8A56-BBB695989046}" = (no title provided) -> {HKLM...CLSID} = "ICQ Toolbar" \InProcServer32\(Default) = "C:\Programme\ICQToolbar\toolbaru.dll" ["IE Toolbar"] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ AntiVir PersonalEdition Classic Guard, AntiVirService, "C:\Programme\AntiVir PersonalEdition Classic\avguard.exe" ["Avira GmbH"] AntiVir PersonalEdition Classic Planer, AntiVirScheduler, "C:\Programme\AntiVir PersonalEdition Classic\sched.exe" ["Avira GmbH"] Ashampoo AntiSpyWare 2 Service, AASW2_Service, "C:\Programme\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWareService.exe" [null data] Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."] Einfache TCP/IP-Dienste, SimpTcp, "C:\WINDOWS\system32\tcpsvcs.exe" [MS] IPv6-Hilfsdienst, 6to4, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\6to4svc.dll" [MS]} Nero BackItUp Scheduler 3, Nero BackItUp Scheduler 3, "C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe" ["Nero AG"] T-Online WLAN Adapter Steuerungsdienst, MZCCntrl, "C:\Programme\Gemeinsame Dateien\Marmiko Shared\MZCCntrl.exe" ["T-Online International AG, Marmiko IT-Solutions GmbH"] Print Monitors: --------------- HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ LPR Port\Driver = "lprmon.dll" [MS] Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS] |
Themen zu Problem System Error. Updates funktionieren nicht |
attention, detected, download, error, fehlermeldung, files, firefox, folge, funktionieren, funktionieren nicht, google, hijacklog, hijackthis, internet, klicke, links, nicht mehr, problem, software, system, this, trend, trojan, updates, windows, windows updates, windows xp |