|
Plagegeister aller Art und deren Bekämpfung: Ordner auf Festplatten "unsichtbar"Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.03.2011, 11:48 | #1 |
| Ordner auf Festplatten "unsichtbar" sorry habs bereits in einem anderen Thread gepostet, musste aber feststelen, dass jeder seinen eigenen Thread verwenden sollte, daher nochmal: gestern habe ich mich blöd gespielt und aufeinmal gabs probleme. einerseits wurde mir von einem bis dahin nicht gekannten windows tool (fraglich) festgestellt, dass die festplatte defekt wäre. außerdem war der desktop nicht mehr zu benutzen. das hat die startleiste aber auch die laufenden programme betroffen. irgendwie ist es mir vorgekommen, als würde einfach eine grafik über den desktop drübergelegt sein. ich verwende dual monitoring und der zweite bildschirm war interessanterweise davon nicht betroffen. wenn ich mittels explorer mir die boot partition ansehe, dann fehlen ca 90% der verzeichnisse, komischerweise kann ich aber über die commmand diese zwar nicht sehen aber doch durchklicken (als cd program files geht obwohl der ordner üprogram files nicht angezeigt wird). habe mir jetzt das Anti-Malware runtergeladen und einen durchlauf gestartet und natürlich hat der etwas gefunden. hier nun das logfile. ich hoffe ihr könnt mir helfen: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 6130 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 22.03.2011 11:31:07 mbam-log-2011-03-22 (11-31-07).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 162266 Laufzeit: 7 Minute(n), 31 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 1 Infizierte Registrierungsschlüssel: 4 Infizierte Registrierungswerte: 2 Infizierte Dateiobjekte der Registrierung: 3 Infizierte Verzeichnisse: 1 Infizierte Dateien: 10 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: c:\Windows\System32\ikzefrfi.dll (Trojan.Boaxxe) -> Delete on reboot. Infizierte Registrierungsschlüssel: HKEY_CLASSES_ROOT\CLSID\{641A3761-0C8C-410E-4BE9-FDB9A3C200E7} (Trojan.Boaxxe) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Bjvzwoti (Trojan.Boaxxe) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{641A3761-0C8C-410E-4BE9-FDB9A3C200E7} (Trojan.Boaxxe) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\engel (Backdoor.Bot) -> Value: engel -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\cleansweep.exe (Trojan.Agent) -> Value: cleansweep.exe -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallPaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Infizierte Verzeichnisse: c:\cleansweep.exe (Trojan.Agent) -> Quarantined and deleted successfully. Infizierte Dateien: c:\Windows\System32\ikzefrfi.dll (Trojan.Boaxxe) -> Quarantined and deleted successfully. c:\programdata\34725640.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully. c:\Users\erdferkel\AppData\Local\Temp\aroyba.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. c:\Users\erdferkel\AppData\Local\Temp\iuvrsmb.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Users\erdferkel\local settings\temporary internet files\Content.IE5\61RR2V94\qanarmz[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Users\erdferkel\local settings\temporary internet files\Content.IE5\8E1NE1PF\dreiizm[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Users\erdferkel\local settings\temporary internet files\Content.IE5\FI73YBE1\xklypptgx[1].htm (Trojan.Proxy) -> Quarantined and deleted successfully. c:\Users\erdferkel\local settings\temporary internet files\Content.IE5\N820UMQQ\ererijznnr[1].htm (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\erdferkel\local settings\temporary internet files\Content.IE5\N820UMQQ\oxybcg[1].htm (Malware.Packer.Gen) -> Quarantined and deleted successfully. c:\cleansweep.exe\config.bin (Trojan.Agent) -> Quarantined and deleted successfully. |
22.03.2011, 12:13 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ordner auf Festplatten "unsichtbar" Hallo und
__________________Bitte routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ |
22.03.2011, 13:24 | #3 | ||
| Ordner auf Festplatten "unsichtbar" okay, hab alles erledigt! die daten sind wieder sichtbar, der trick mit unsichtbare daten anzeigen hat funktioniert!
__________________ich habe zwei antimalware logs und zwei OTL logfiles. aus meiner sicht schauts schon wieder ganz gut aus! aber die diagnose lasse ich lieber den experten. aja ich befinde mich die ganze zeitim abgesicherten modus, nur zur info. Zitat:
Zitat:
OTL Logfile: Code:
ATTFilter OTL logfile created on: 22.03.2011 13:08:32 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\landsau\Desktop Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 63,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 87,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 97,56 Gb Total Space | 10,23 Gb Free Space | 10,48% Space Free | Partition Type: NTFS Drive H: | 498,51 Gb Total Space | 405,90 Gb Free Space | 81,42% Space Free | Partition Type: NTFS Drive K: | 1397,27 Gb Total Space | 0,04 Gb Free Space | 0,00% Space Free | Partition Type: NTFS Drive L: | 7317,40 Gb Total Space | 3268,70 Gb Free Space | 44,67% Space Free | Partition Type: NTFS Drive M: | 1397,27 Gb Total Space | 574,94 Gb Free Space | 41,15% Space Free | Partition Type: NTFS Drive N: | 465,76 Gb Total Space | 41,82 Gb Free Space | 8,98% Space Free | Partition Type: NTFS Computer Name: | User Name: landsau | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\landsau\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - H:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) PRC - C:\Windows\explorer.exe (Microsoft Corporation) ========== Modules (SafeList) ========== MOD - C:\Users\landsau\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (xxajaedb) USB Audio (WDM) -- File not found SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation) SRV - (NIHardwareService) -- C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Native Instruments GmbH) SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation) SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG) SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation) SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys () DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (Lbd) -- C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys () DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys () DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.) DRV - (ivusb) -- C:\Windows\System32\drivers\ivusb.sys (Initio Corporation) DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation) DRV - (UDXTTM6010) -- C:\Windows\System32\drivers\UDXTTM6010.sys () DRV - (TTHID) -- C:\Windows\System32\drivers\Cinergy_Hybrid-Stick_HID.sys (DTV-DVB) DRV - (a4djavs) -- C:\Windows\System32\drivers\a4djavs.sys (Native Instruments GmbH) DRV - (a4djusb) -- C:\Windows\System32\drivers\a4djusb.sys (Native Instruments GmbH) DRV - (volsnap) -- C:\Windows\system32\DRIVERS\volsnap.sys () DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation) DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation) DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation) DRV - (WINUSB) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation) DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation) DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation) DRV - (netr28u) -- C:\Windows\System32\drivers\netr28u.sys (Ralink Technology Corp.) DRV - (ipgd) -- C:\Windows\System32\drivers\ipgdnd60.sys (IC Plus Corp.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 B1 A9 E7 49 C0 CA 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.12.0.36605 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900 FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900 FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2010.12.15 13:12:54 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2010.12.15 13:12:55 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.13 15:40:51 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.13 15:40:50 | 000,000,000 | ---D | M] [2010.04.26 19:59:51 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\landsau\AppData\Roaming\mozilla\Extensions [2011.03.22 11:55:33 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\landsau\AppData\Roaming\mozilla\Firefox\Profiles\ib9ih0dw.default\extensions [2010.06.15 15:42:43 | 000,000,000 | -H-D | M] (Cooliris) -- C:\Users\landsau\AppData\Roaming\mozilla\Firefox\Profiles\ib9ih0dw.default\extensions\piclens@cooliris.com [2010.11.20 15:55:23 | 000,000,000 | -H-D | M] (vShare) -- C:\Users\landsau\AppData\Roaming\mozilla\Firefox\Profiles\ib9ih0dw.default\extensions\vshare@toolbar [2011.03.22 11:08:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2010.10.16 20:38:54 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2010.12.15 13:16:33 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2010.12.15 13:12:54 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\HTML5VIDEO [2010.12.15 13:12:55 | 000,000,000 | ---D | M] (DivX HiQ) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\WPA [2010.12.15 13:16:25 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2011.03.03 19:06:04 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.03.03 19:06:04 | 000,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2011.03.03 19:06:04 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2011.03.03 19:06:04 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2011.03.03 19:06:04 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll () O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll () O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL (TerraTec Electronic GmbH) O3 - HKCU\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll () O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] h:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [WinampAgent] H:\Programme\Winamp\winampa.exe (Nullsoft, Inc.) O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [Remote Control Editor] C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe (Elgato Systems) O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\System32\grpconv.exe (Microsoft Corporation) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] h:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - Startup: C:\Users\landsau\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object) O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.200.1 O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll () O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2009.09.17 12:12:56 | 000,000,000 | RH-D | M] - K:\autorun -- [ NTFS ] O32 - AutoRun File - [2002.10.17 03:56:50 | 000,000,036 | RH-- | M] () - K:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2009.09.17 12:12:56 | 000,000,000 | R--D | M] - M:\autorun -- [ NTFS ] O32 - AutoRun File - [2002.10.17 03:56:50 | 000,000,036 | RH-- | M] () - M:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2007.07.02 07:34:56 | 000,000,045 | ---- | M] () - N:\autorun.inf -- [ NTFS ] O33 - MountPoints2\{6c1865ff-ac22-11df-8093-40618601ac44}\Shell - "" = AutoRun O33 - MountPoints2\{6c1865ff-ac22-11df-8093-40618601ac44}\Shell\AutoRun\command - "" = "L:\WD SmartWare.exe" autoplay=true O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.03.22 12:15:56 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\landsau\Desktop\OTL.exe [2011.03.22 11:50:34 | 000,000,000 | ---D | C] -- C:\avrescue [2011.03.22 11:07:15 | 000,000,000 | ---D | C] -- C:\Users\landsau\AppData\Roaming\Malwarebytes [2011.03.22 11:06:53 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2011.03.22 11:06:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.03.22 11:06:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011.03.22 11:06:45 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011.03.22 10:48:51 | 000,000,000 | ---D | C] -- C:\Users\landsau\AppData\Roaming\Avira [2011.03.22 10:47:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2011.03.22 10:47:12 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2011.03.22 10:47:12 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2011.03.22 10:47:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2011.03.22 10:47:11 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [2011.03.22 10:39:58 | 000,000,000 | ---D | C] -- C:\ProgramData\{870E601A-FE70-4098-94B2-6E9963FCAA51} [2011.03.21 22:09:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Diagnostic [2011.03.21 22:09:13 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Diagnostic [2011.03.21 21:59:50 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Roaming\updates [2011.03.21 13:55:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FM Genie Scout 11 [2011.03.16 21:23:18 | 000,000,000 | ---D | C] -- C:\Users\landsau\Documents\Native Instruments [2011.03.16 21:19:44 | 000,000,000 | ---D | C] -- C:\ProgramData\{47803536-1938-4D3F-86D6-F4876B645542} [2011.03.16 21:19:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Native Instruments [2011.03.16 21:19:10 | 000,000,000 | ---D | C] -- C:\ProgramData\{20EFD19B-675C-417B-A498-B0161D72FF88} [2011.03.16 21:19:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Native Instruments [2011.03.16 21:18:30 | 000,000,000 | ---D | C] -- C:\ProgramData\{B5F0C192-874D-49A8-88D7-8431E3714756} [2011.03.11 17:19:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wave Editor [2011.03.11 17:13:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony [2011.03.11 17:13:37 | 000,000,000 | ---D | C] -- C:\Program Files\Vstplugins [2011.03.11 17:00:23 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Roaming\Sony [2011.03.11 17:00:23 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Local\Sony [2011.03.11 16:58:56 | 000,000,000 | ---D | C] -- C:\Program Files\Sony [2011.03.11 16:50:14 | 000,000,000 | ---D | C] -- C:\Users\landsau\Documents\DVDVideoSoft [2011.03.11 16:50:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft [2011.03.11 16:50:00 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Roaming\DVDVideoSoft [2011.03.11 16:49:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft [2011.03.09 10:57:14 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll [2011.03.09 10:57:14 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll [2011.03.09 10:57:11 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll [2011.03.09 10:57:11 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll [2011.03.09 10:57:11 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll [2011.03.09 10:57:11 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax [2011.03.08 20:21:43 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Local\Apps [2011.02.28 19:16:37 | 000,000,000 | ---D | C] -- C:\Users\landsau\Documents\My Games [2011.02.28 19:14:57 | 003,485,696 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_p4.dll [2011.02.28 19:14:57 | 000,839,680 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_vml_p4.dll [2011.02.28 19:14:57 | 000,532,480 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_vml_p3.dll [2011.02.28 19:14:57 | 000,512,000 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_vml_def.dll [2011.02.28 19:14:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound [2011.02.28 19:14:56 | 002,793,472 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_p3.dll [2011.02.28 19:14:56 | 002,441,216 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_def.dll [2011.02.28 19:14:56 | 002,174,976 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_lapack32.dll [2011.02.28 19:14:56 | 002,125,824 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_lapack64.dll [2011.02.28 19:14:56 | 000,872,448 | ---- | C] (Blue Ripple Sound Limited) -- C:\Windows\System32\rapture3d_oal.dll [2011.02.28 19:14:56 | 000,184,320 | ---- | C] (Intel Corporation) -- C:\Windows\System32\libguide40.dll [2011.02.28 19:14:55 | 000,000,000 | ---D | C] -- C:\Program Files\BRS [2011.02.21 19:43:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Solidshield [4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.03.22 12:15:58 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\landsau\Desktop\OTL.exe [2011.03.22 11:57:59 | 000,692,038 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.03.22 11:57:59 | 000,650,212 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.03.22 11:57:59 | 000,145,404 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.03.22 11:57:59 | 000,119,282 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.03.22 11:53:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.03.22 11:53:20 | 2415,370,240 | -HS- | M] () -- C:\hiberfil.sys [2011.03.22 11:06:53 | 000,000,746 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.03.22 11:06:53 | 000,000,746 | ---- | M] () -- C:\Users\landsau\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk [2011.03.22 10:47:19 | 000,002,016 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2011.03.22 07:47:00 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011.03.22 07:40:19 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011.03.22 07:40:19 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011.03.21 23:17:15 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011.03.21 23:10:08 | 000,309,360 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011.03.21 22:09:24 | 000,000,128 | ---- | M] () -- C:\ProgramData\~34725640r [2011.03.21 22:09:24 | 000,000,104 | ---- | M] () -- C:\ProgramData\~34725640 [2011.03.21 22:09:23 | 000,000,635 | ---- | M] () -- C:\Users\landsau\Desktop\Windows Diagnostic.lnk [2011.03.21 22:09:11 | 000,000,344 | ---- | M] () -- C:\ProgramData\34725640 [2011.03.16 21:19:42 | 000,000,743 | ---- | M] () -- C:\Users\Public\Desktop\Traktor.lnk [2011.03.16 21:19:09 | 000,001,094 | ---- | M] () -- C:\Users\Public\Desktop\Controller Editor.lnk [2011.03.16 21:18:27 | 000,001,059 | ---- | M] () -- C:\Users\Public\Desktop\Service Center.lnk [2011.03.13 15:40:52 | 000,001,913 | -H-- | M] () -- C:\Users\landsau\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk [2011.03.13 15:40:52 | 000,001,889 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2011.03.11 17:19:17 | 000,000,629 | -H-- | M] () -- C:\Users\landsau\Application Data\Microsoft\Internet Explorer\Quick Launch\Wave Editor.lnk [2011.03.11 17:19:17 | 000,000,629 | ---- | M] () -- C:\Users\landsau\Desktop\Wave Editor.lnk [2011.03.11 17:17:01 | 000,002,560 | ---- | M] () -- C:\Users\landsau\Documents\Register Sound Forge.htm [2011.03.11 17:13:40 | 000,001,934 | ---- | M] () -- C:\Users\Public\Desktop\Sound Forge 9.0.lnk [2011.03.11 16:50:14 | 000,001,201 | ---- | M] () -- C:\Users\landsau\Desktop\DVDVideoSoft Free Studio.lnk [2011.03.11 16:50:04 | 000,000,945 | ---- | M] () -- C:\Users\landsau\Desktop\Free Video to MP3 Converter.lnk [2011.03.11 14:03:18 | 000,024,320 | ---- | M] () -- C:\Users\landsau\Desktop\1322113.jpg [2011.03.04 16:11:12 | 000,137,656 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2011.03.04 14:36:34 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys [2011.03.02 20:42:37 | 000,000,580 | ---- | M] () -- C:\Users\landsau\Desktop\UseNeXT.lnk [2011.02.28 19:14:27 | 000,445,016 | ---- | M] (Creative Labs) -- C:\Windows\System32\wrap_oal.dll [2011.02.28 19:14:27 | 000,109,144 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\System32\OpenAL32.dll [2011.02.27 15:45:53 | 000,263,681 | ---- | M] () -- C:\Users\landsau\Desktop\pt_.pdf [2011.02.21 20:05:03 | 000,001,811 | ---- | M] () -- C:\Users\landsau\Desktop\N1.lnk [4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.03.22 11:06:53 | 000,000,746 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011.03.22 11:06:53 | 000,000,746 | ---- | C] () -- C:\Users\landsau\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk [2011.03.22 10:47:19 | 000,002,016 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2011.03.21 22:09:24 | 000,000,128 | ---- | C] () -- C:\ProgramData\~34725640r [2011.03.21 22:09:24 | 000,000,104 | ---- | C] () -- C:\ProgramData\~34725640 [2011.03.21 22:09:23 | 000,000,635 | ---- | C] () -- C:\Users\landsau\Desktop\Windows Diagnostic.lnk [2011.03.21 22:09:11 | 000,000,344 | ---- | C] () -- C:\ProgramData\34725640 [2011.03.16 21:19:42 | 000,000,743 | ---- | C] () -- C:\Users\Public\Desktop\Traktor.lnk [2011.03.16 21:19:09 | 000,001,094 | ---- | C] () -- C:\Users\Public\Desktop\Controller Editor.lnk [2011.03.16 21:18:27 | 000,001,059 | ---- | C] () -- C:\Users\Public\Desktop\Service Center.lnk [2011.03.11 17:19:17 | 000,000,629 | -H-- | C] () -- C:\Users\landsau\Application Data\Microsoft\Internet Explorer\Quick Launch\Wave Editor.lnk [2011.03.11 17:19:17 | 000,000,629 | ---- | C] () -- C:\Users\landsau\Desktop\Wave Editor.lnk [2011.03.11 16:50:14 | 000,001,201 | ---- | C] () -- C:\Users\landsau\Desktop\DVDVideoSoft Free Studio.lnk [2011.03.11 16:50:04 | 000,000,945 | ---- | C] () -- C:\Users\landsau\Desktop\Free Video to MP3 Converter.lnk [2010.12.21 13:09:51 | 000,106,756 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat [2010.11.04 19:18:27 | 000,763,584 | ---- | C] () -- C:\Windows\System32\drivers\UDXTTM6010.sys [2010.10.14 01:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2010.09.26 16:39:10 | 000,010,240 | -H-- | C] () -- C:\Users\landsau\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.09.15 08:51:44 | 000,002,142 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010.09.06 20:09:13 | 000,000,066 | ---- | C] () -- C:\Windows\3DWarehouseClient.INI [2010.07.07 14:23:30 | 000,000,192 | -H-- | C] () -- C:\Users\landsau\AppData\Roaming\default.rss [2010.07.06 17:27:59 | 000,004,767 | ---- | C] () -- C:\Windows\Irremote.ini [2010.04.28 12:10:33 | 000,278,984 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys [2010.04.28 12:10:32 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys [2010.03.10 13:49:16 | 000,692,038 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2010.03.10 13:49:16 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2010.03.10 13:49:16 | 000,145,404 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2010.03.10 13:49:16 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2010.03.10 13:40:54 | 000,000,170 | ---- | C] () -- C:\ProgramData\nvUnsupRes.dat [2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009.07.14 05:33:53 | 000,309,360 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2009.07.14 03:05:48 | 000,650,212 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2009.07.14 03:05:48 | 000,119,282 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2009.07.14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2009.07.14 00:11:34 | 000,245,328 | ---- | C] () -- C:\Windows\System32\drivers\volsnap.sys [2009.07.14 00:11:12 | 001,659,648 | ---- | C] () -- C:\Windows\System32\auswloxf.dat [2009.07.14 00:11:12 | 000,633,600 | ---- | C] () -- C:\Windows\System32\ecgfxgim.dat [2009.07.14 00:11:12 | 000,152,320 | ---- | C] () -- C:\Windows\System32\gupdchna.dat [2009.07.14 00:11:12 | 000,151,296 | ---- | C] () -- C:\Windows\System32\cshsqkfk.dat [2009.07.14 00:11:12 | 000,050,432 | ---- | C] () -- C:\Windows\System32\vsarhoyt.dat [2009.07.14 00:11:12 | 000,039,680 | ---- | C] () -- C:\Windows\System32\sgzcundw.dat [2009.07.14 00:11:12 | 000,034,560 | ---- | C] () -- C:\Windows\System32\sqetwtbs.dat [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2009.05.25 03:32:14 | 000,013,931 | ---- | C] () -- C:\Windows\System32\RaCoInst.dat [2002.10.15 23:54:04 | 000,153,088 | ---- | C] () -- C:\Windows\System32\unrar.dll < End of report > hier die extra.txt OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 22.03.2011 13:08:32 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Erdferkel\Desktop Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 63,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 87,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 97,56 Gb Total Space | 10,23 Gb Free Space | 10,48% Space Free | Partition Type: NTFS Drive H: | 498,51 Gb Total Space | 405,90 Gb Free Space | 81,42% Space Free | Partition Type: NTFS Drive K: | 1397,27 Gb Total Space | 0,04 Gb Free Space | 0,00% Space Free | Partition Type: NTFS Drive L: | 7317,40 Gb Total Space | 3268,70 Gb Free Space | 44,67% Space Free | Partition Type: NTFS Drive M: | 1397,27 Gb Total Space | 574,94 Gb Free Space | 41,15% Space Free | Partition Type: NTFS Drive N: | 465,76 Gb Total Space | 41,82 Gb Free Space | 8,98% Space Free | Partition Type: NTFS Computer Name: MEDIONPC | User Name: Erdferkel | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [ACDSee Pro 3.Manage] -- "C:\Program Files\ACD Systems\ACDSee Pro\3.0\ACDSeeQVPro3.exe" "%1" (ACD Systems International Inc.) Directory [AddToPlaylistVLC] -- "H:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "H:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Directory [Winamp.Bookmark] -- "H:\Programme\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "H:\Programme\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "H:\Programme\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{013CCA52-DA56-4133-AC2B-1988A9568C30}" = Native Instruments Audio 4 DJ Driver "{0711500B-9912-4D60-9A49-C577B4503D42}" = Nero Recode Help "{07FF7593-9DEA-40B5-9F87-F557E65BBF60}" = Nero Recode "{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant "{0886900B-B2F3-452C-B580-60F1253F7F80}" = Native Instruments Controller Editor "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended "{0B8565BA-BAD5-4732-B122-5FD78EFC50A9}" = Native Instruments Service Center "{1122AAC4-AAAA-43BF-B2D4-3C8C12378952}" = Nero InfoTool "{11A84FCA-C3C7-4AFD-A797-111DB8569DBC}" = Nero BurningROM "{12345674-DE9A-677A-CCEE-666356D89777}" = Nero BurnRights "{177ADA1F-6D3B-404A-99DA-D7E0E2A36621}_is1" = Videograbber 2010 "{1B040683-C390-4711-ABC7-DA8D85E470E7}" = NeroBurningROM "{1B280FAF-AE10-4E31-A41A-DB3917D651DC}" = ACDSee Pro 3 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable "{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 23 "{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour "{2AAC4085-DCBF-417B-AEBD-182197839240}" = Native Instruments Traktor "{2D3455A8-3B15-41A8-99F8-0D4215746463}" = Nero StartSmart "{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support "{3097B151-1F61-4211-A4CC-D70127B226AE}" = SoundTrax "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3F30CC51-0788-487B-AA83-7214A239C0C0}" = Nero Disc Copy Gadget Help "{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4D42353B-533F-4306-AD0B-7FEF292ADE04}" = Nero CoverDesigner Help "{4E8C27C2-D727-4C00-A90E-C3F6376EEE70}" = Nero ControlCenter "{548F99E0-14CC-4D53-A7D6-4A62A5F2C748}" = Nero PhotoSnap "{56BE5CC9-95E6-4128-ABEA-968414CA9C80}" = DolbyFiles "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{5A62A775-A29A-4CE1-BBC2-4A9CD0B211EF}" = Nero Live Help "{5AE12194-3EAA-40DF-B2BF-FE1D6B78BBF4}" = Nero Vision "{5C2E8A0F-80E2-4C68-8CC0-D8D16E7196BF}" = Nero RescueAgent Help "{5C42EAB8-54F9-423A-948C-1CBEF25F8DB4}" = Nero PhotoSnap Help "{5C9BB0B3-E830-4814-BBA4-D93535E1C7B9}" = Nero Live "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{61FFF5E3-1D08-4F66-AC29-EF61963F2619}" = pCon.planner 6 "{63B9BAB5-F36A-4A3B-9E5C-68A7F212BFB9}" = TerraTec Home Cinema "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{75321954-2589-11DC-DDCC-E98356D81493}" = Nero DriveSpeed "{753973C4-B961-43BF-B2D4-3C8C92F7216E}" = Nero DriveSpeed "{758799AB-2DAD-4BBB-83C3-D69A60D12363}_is1" = Emergence Viewer 1.5.2.549 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{78523651-D8B1-11DC-CCEE-741589645873}" = Nero DiscSpeed "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{86A4C6D9-29EE-4719-AFA1-BA3341862B83}" = Microsoft Games for Windows - LIVE "{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes "{8C654BD0-1949-43DE-84F2-EC2A1ABB0CB4}" = Nero ShowTime "{90120000-001A-0000-0000-0000000FF1CE}" = Microsoft Office Outlook 2007 "{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_OUTLOOK_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_OUTLOOK_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_OUTLOOK_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_OUTLOOK_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_OUTLOOK_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_OUTLOOK_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center "{943CC0C0-2253-4FE0-9493-DD386F7857FD}" = Nero Express "{948FFAAE-C57F-447B-9B07-3721E950BFDC}" = Nero ShowTime "{961D53EA-40DC-4156-AD74-25684CE05F81}" = Nero Installer "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter "{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}" = Advertising Center "{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel "{A73BEC3C-40A0-480E-87EF-EFCD33629088}" = NeroExpress "{A8399F58-234A-48C6-BA55-30C15738BF3C}" = Nero CoverDesigner "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AAA12554-2589-11DC-92EF-E98356D81493}" = Nero InfoTool "{AABBCC54-D8B1-11DC-92EF-E98356D81493}" = Nero DiscSpeed "{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3 - Deutsch "{B2C12C8D-65DC-40BD-B309-5ADB0C6C8D8F}" = Nero WaveEditor "{B96C2601-52F5-4D5D-816A-63469EA311EF}" = "Nero SoundTrax Help "{BCD82AB5-670D-4242-90FA-1F97103C16CD}" = Movie Templates - Starter Kit "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update "{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack "{C99C89A3-119A-45E6-B26E-DD5643CAA0C5}" = Menu Templates - Starter Kit "{ca43c673-b052-4801-b5b8-9e420e5c3b19}" = Nero 9 "{CD1826A5-CFCC-4C6E-9F9D-E181876162EA}" = Nero Rescue Agent "{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.22 Game "{D7C206B6-1A63-4389-A8B1-8F607D0BFF1F}" = Nero StartSmart Help "{DB0F5549-0EEE-4421-A1B2-08FB1468D7F1}" = calibre "{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware "{DFFC0648-BC4B-47D1-93D2-6CA6B9457641}" = OpenOffice.org 3.2 "{E4A8DD87-A746-4443-BF25-CAF99CED6767}" = Nero Disc Copy Gadget "{E86156E5-9859-440D-8876-26CED1349802}" = Nero WaveEditor Help "{EA9FFE54-D8B1-11DC-92EF-E98356D81493}" = Nero BurnRights "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01 "{F53F6769-AC46-49E3-ABE3-2C8AFD39D0DD}" = Nero Vision "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Ad-Aware" = Ad-Aware "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Photoshop 7.0" = Adobe Photoshop 7.0 "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "AVS Update Manager_is1" = AVS Update Manager 1.0 "AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4 "AVS4YOU Video Converter 7_is1" = AVS Video Converter 7 "Badaboom" = Badaboom 1.2.1.74 "Cinergy Hybrid Stick" = Cinergy Hybrid Stick V1.00.08.06a "Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09 "ComicRack" = ComicRack v0.9.134 "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "Direct MP3 Joiner_is1" = Direct MP3 Joiner version 3.0.2.9 "Direct WAV MP3 Splitter_is1" = Direct WAV MP3 Splitter version 2.6.0.22 "DirPrinter_is1" = DirPrinter - Deinstallation "DivX Setup.divx.com" = DivX-Setup "Free DVD MP3 Ripper_is1" = Free DVD MP3 Ripper 1.12 "Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 4.2.17.305 "JDownloader" = JDownloader "Keseling DirPrinter 3.1.1_is1" = Keseling DirPrinter 3.1.1 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack "Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15) "Native Instruments Audio 4 DJ Driver" = Native Instruments Audio 4 DJ Driver "Native Instruments Controller Editor" = Native Instruments Controller Editor "Native Instruments Service Center" = Native Instruments Service Center "Native Instruments Traktor" = Native Instruments Traktor "NVIDIA Display Control Panel" = NVIDIA Display Control Panel "NVIDIA Drivers" = NVIDIA Drivers "OpenAL" = OpenAL "OUTLOOK" = Microsoft Office Outlook 2007 "pCon.planner 6" = pCon.planner 6 "Poser 8_is1" = Poser 8 (8.0.0.10157) "QuickPar" = QuickPar 0.9 "Synology Assistant" = Synology Assistant (remove only) "TeraCopy_is1" = TeraCopy 2.12 "TightVNC_is1" = TightVNC 1.3.10 "TmNationsForever_is1" = TmNationsForever Update 2010-03-15 "Ultra Audio Ripper_is1" = Ultra Audio Ripper 2.0 "Uninstall_is1" = Uninstall 1.0.0.1 "Universal Document Converter_is1" = Universal Document Converter (Demo) "Video Thumbnails Maker" = Video Thumbnails Maker by Scorp (remove only) "VLC media player" = VLC media player 1.1.7 "vShare" = vShare Plugin "Wave Editor_is1" = Wave Editor 3.1.0.0 "Winamp" = Winamp "WinRAR archiver" = WinRAR ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Winamp Detect" = Winamp Erkennungs-Plug-in ========== Last 10 Event Log Errors ========== Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt! < End of report > |
22.03.2011, 14:47 | #4 |
| Ordner auf Festplatten "unsichtbar" prinzipiell scheint nun alles wieder zu funktionieren, allerdings gibts probleme mit dem verschieben von dateien. es kommt der windows fehler: "error preparing file list", außerdem ist mir der computer unmotivert mit einem blauen bildschirm abgeschmirt, was mir seit wirklich langer zeit nicht mehr passiert ist. beim reboot wollte sich java updaten und da kam dann ein "Installer: Wrapper.CreateFile failed with error 5: Zugriff verweigert". also ich hab das gefühl, als würd da noch irgendwas nicht passen. |
22.03.2011, 14:51 | #5 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ordner auf Festplatten "unsichtbar" Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL [2009.07.14 00:11:12 | 001,659,648 | ---- | C] () -- C:\Windows\System32\auswloxf.dat [2009.07.14 00:11:12 | 000,633,600 | ---- | C] () -- C:\Windows\System32\ecgfxgim.dat [2009.07.14 00:11:12 | 000,152,320 | ---- | C] () -- C:\Windows\System32\gupdchna.dat [2009.07.14 00:11:12 | 000,151,296 | ---- | C] () -- C:\Windows\System32\cshsqkfk.dat [2009.07.14 00:11:12 | 000,050,432 | ---- | C] () -- C:\Windows\System32\vsarhoyt.dat [2009.07.14 00:11:12 | 000,039,680 | ---- | C] () -- C:\Windows\System32\sgzcundw.dat [2009.07.14 00:11:12 | 000,034,560 | ---- | C] () -- C:\Windows\System32\sqetwtbs.dat [2011.03.21 22:09:24 | 000,000,128 | ---- | C] () -- C:\ProgramData\~34725640r [2011.03.21 22:09:24 | 000,000,104 | ---- | C] () -- C:\ProgramData\~34725640 [2011.03.21 22:09:11 | 000,000,344 | ---- | C] () -- C:\ProgramData\34725640 [2011.03.16 21:19:44 | 000,000,000 | ---D | C] -- C:\ProgramData\{47803536-1938-4D3F-86D6-F4876B645542} [2011.03.16 21:19:10 | 000,000,000 | ---D | C] -- C:\ProgramData\{20EFD19B-675C-417B-A498-B0161D72FF88} [2011.03.16 21:18:30 | 000,000,000 | ---D | C] -- C:\ProgramData\{B5F0C192-874D-49A8-88D7-8431E3714756} O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2009.09.17 12:12:56 | 000,000,000 | RH-D | M] - K:\autorun -- [ NTFS ] O32 - AutoRun File - [2002.10.17 03:56:50 | 000,000,036 | RH-- | M] () - K:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2009.09.17 12:12:56 | 000,000,000 | R--D | M] - M:\autorun -- [ NTFS ] O32 - AutoRun File - [2002.10.17 03:56:50 | 000,000,036 | RH-- | M] () - M:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2007.07.02 07:34:56 | 000,000,045 | ---- | M] () - N:\autorun.inf -- [ NTFS ] O33 - MountPoints2\{6c1865ff-ac22-11df-8093-40618601ac44}\Shell - "" = AutoRun O33 - MountPoints2\{6c1865ff-ac22-11df-8093-40618601ac44}\Shell\AutoRun\command - "" = "L:\WD SmartWare.exe" autoplay=true :Commands [purity] [resethosts] [emptytemp] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.
__________________ Logfiles bitte immer in CODE-Tags posten |
22.03.2011, 15:02 | #6 | |
| Ordner auf Festplatten "unsichtbar" dateien kopieren oder verschieben geht leider noch immer nicht, aber hier das aktuelle logfile von OTL: Zitat:
|
22.03.2011, 15:23 | #7 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ordner auf Festplatten "unsichtbar" Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
__________________ Logfiles bitte immer in CODE-Tags posten |
22.03.2011, 18:06 | #8 |
| Ordner auf Festplatten "unsichtbar" das CCleaner programm habe ich erfolgreich abgearbeitet, aber combofix hat den computer mittels blauen bildschirm ausgeheblt. zweimal gestartet und zweimal ist der computer abgestürzt. drum kann ich auch kein log file posten. gibts einen alternativen plan? so nebenbei: danke für die hilfe, ich find das großartig! |
22.03.2011, 18:21 | #9 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ordner auf Festplatten "unsichtbar" Probier die cofi.exe im abgesicherten Modus von Windows aus.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Ordner auf Festplatten "unsichtbar" |
anti-malware, appdata, backdoor.bot, bildschirm, blöd, boot, browser, dateien, defekt, desktop, disabletaskmgr, explorer, festgestellt, festplatte, festplatte defekt, helper, hijack.zones, microsoft, nicht angezeigt, nicht mehr, ordner, programdata, programme, pum.hijack.displayproperties, pum.hijack.taskmanager, software, system, system32, temp, trojan.agent, trojan.fakealert, windows |