Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Hallo, habe gestern abend seit Dezember mein Laptop wieder benutzt. Habe Antivir aktualisiert und bin im Internet gewesen. Zudem hat mir der PC angezeigt, dass Windows updates vorliegen würden. Ich habe mich sehr gewundert, weil es insgesamt nur 3 waren, obwohl ich seit so langer Zeit das Laptop nicht benutzt habe. Ich habe auch nur die Märzversion Windows tool for removal of malicious... zum Download ausgewählt. Meines Erachtens ist der Download auch gar nicht erfolgt, da mir heute bei einem der zahlreichen Versuche Herunterzufahren bzw. Neuzustarten mehrfach die Option Install updates and shut down angeboten wurde... In der Folge traten in rascher Folge Fehlermeldungen auf, erst bezgl. der Festplatte, dann mit der Warnung, dass private Daten gefährdet seien. Windows Recovery öffnete sich spontan und führte wiederholt Scans durch, die multiple Probleme anzeigten, die natürlich so nicht gefixt werden konnte. Es erfolgte die Aufforderung die advanced version runterzuladen und Zone alarm zeigte an, dass eine "18865972.exe"-Anwendung Zugriff verlange. Ich habe das abgelehnt. Das Desktop war bis auf den Papierkorb und einen Bluetooth-Symbol komplett leer. Ich habe den Computer runtergefahren und heute erneut gestartet, aber es hatte sich nichts getan. Ich habe dann mit meinem anderen Laptop ge-googlet und Eure Anleitung zur Entfernung von Windows Recovery gefunden. Bei mir ist Windows XP installiert sowie Antivir Produktversion und Zone Alarm. Folgendes habe ich gemacht: rkill.com heruntergeladen und laufen lassen, dann Malwarebytes-vollständiger Scan (file s. unten), die gefundenen Sachen gelöscht, OTH-Othelper installiert und Malwarebytes nochmal-diesmal Quickscan (file-s.unten), dann habe ich auch einen OTL-Scan gemacht- file s. unten. Es wurde nur beim 1. Mal Malwarebytes etwas gefunden, beim 2. Mal nach OTH nicht mehr. Wenn ich den PC jetzt starte: sind alle Dateien wieder auf dem Desktop, aber nur das Malwarebytes-Icon ist normal, alle anderen sehe aus wie markiert. Ich kann aber alle Dateien normal öffnen. Das Hintergrundbild ist weg, die Schnellstartleiste ist leer, die Symbole sind weg und es befindet sich noch ein Shortcut auf dem Desktop mit eben dem NAmen "Windows Recovery", unter Eigenschaften verweist der auf: "C:\Documents and Settings\All Users\Application Data\18865972.exe". Meine Frage nun: 1. ist mein System wegen des verbliebenen Shortcuts immer noch infiziert und was kann ich tun oder habe ich irgendwann mal vergessen neuzustarten und es ist daher nicht ordentlich gelöscht? Vielen, vielen Dank schon mal ! PS: Sorry, ich muss gleich zur Arbeit, bin aber ab 22.30h wieder da, falls ich nicht sofort antworte ! Malwarebytes' Anti-Malware www.malwarebytes.org Datenbank Version: 6140 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 23.03.2011 15:17:11 mbam-log-2011-03-23 (15-17-11).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 291918 Laufzeit: 1 Stunde(n), 27 Minute(n), 29 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 1 Infizierte Verzeichnisse: 0 Infizierte Dateien: 3 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\XyeIUNjAcxCNDqR (Trojan.Downloader) -> Value: XyeIUNjAcxCNDqR -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\documents and settings\all users\application data\xyeiunjacxcndqr.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\documents and settings\all users\application data\18865972.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully. c:\documents and settings\***\local settings\Temp\jar_cache1484479699214413479.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. Malwarebytes' Anti-Malware www.malwarebytes.org Datenbank Version: 6141 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 23.03.2011 16:02:44 mbam-log-2011-03-23 (16-02-44).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 206921 Laufzeit: 28 Minute(n), 4 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) LogOTL Logfile: Code:
ATTFilter OTL logfile created on: 23.03.2011 16:44:05 - Run 1 OTL by OldTimer - Version Folder = C:\Documents and Settings\***\My Documents\Downloads Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy 1.022,00 Mb Total Physical Memory | 418,00 Mb Available Physical Memory | 41,00% Memory free 2,00 Gb Paging File | 2,00 Gb Available in Paging File | 74,00% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 82,62 Gb Total Space | 33,49 Gb Free Space | 40,53% Space Free | Partition Type: NTFS Computer Name: *** | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\***\My Documents\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD) PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD) PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies) PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies) PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH) PRC - C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation) PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\SAMSUNG\AVStation Premium 3.75\AVSAgent.exe () PRC - C:\Program Files\SAMSUNG\Samsung Battery Manager\BatteryManager.exe () PRC - C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe (SAMSUNG Electronics Co., Ltd.) PRC - C:\Program Files\SAMSUNG\DisplayManager\DisplayManager.exe (SAMSUNG) PRC - C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.) PRC - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.) PRC - C:\Program Files\SAMSUNG\Samsung Network Manager\SNMWLANService.exe () PRC - C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation) PRC - C:\Program Files\SAMSUNG\Samsung Update Plus\SLUTrayNotifier.exe () PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.) PRC - C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe (SafeNet) PRC - C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe (SafeNet) ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\***\My Documents\Downloads\OTL.exe (OldTimer Tools) MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies) MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll (Microsoft Corporation) MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll (Microsoft Corporation) MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation) MOD - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.) MOD - C:\WINDOWS\system32\SynTPFcs.dll (Synaptics, Inc.) ========== Win32 Services (SafeList) ========== SRV - (HidServ) -- File not found SRV - (gupdate) Google Update Service (gupdate) -- File not found SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (vsmon) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD) SRV - (IswSvc) -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies) SRV - (getPlusHelper) getPlus(R) -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.) SRV - (SRS_PostInstaller) -- C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.) SRV - (SNM WLAN Service) -- C:\Program Files\SAMSUNG\Samsung Network Manager\SNMWLANService.exe () SRV - (bgsvcgen) -- C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation) SRV - (Samsung Update Plus) -- C:\Program Files\SAMSUNG\Samsung Update Plus\SLUBackgroundService.exe () SRV - (IPSECMON) -- C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe (SafeNet) SRV - (IreIKE) -- C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe (SafeNet) ========== Driver Services (SafeList) ========== DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH) DRV - (ISWKL) -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies) DRV - (vsdatant) -- C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD) DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH) DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (motmodem) -- C:\WINDOWS\system32\drivers\motmodem.sys (Motorola) DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation) DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems) DRV - (w39n51) Intel(R) -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation) DRV - (BTSERIAL) -- C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.) DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.) DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.) DRV - (BsStor) -- C:\WINDOWS\System32\drivers\BsStor.sys (Cyberlink Co.,Ltd.) DRV - (BsUDF) -- C:\WINDOWS\System32\drivers\BsUDF.sys (CyberLink Corporation.) DRV - (wowfilter) -- C:\WINDOWS\system32\drivers\WOWFilter.sys () DRV - (rimmptsk) -- C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC) DRV - (rismxdp) -- C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC) DRV - (rimsptsk) -- C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC) DRV - (SUEPD) -- C:\WINDOWS\system32\drivers\SUE_PD.sys (Samsung) DRV - (HdAudAddService) -- C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows (R) Server 2003 DDK provider) DRV - (IPSECDRV) -- C:\WINDOWS\system32\drivers\IpSecDrv.sys (SafeNet) DRV - (Crypto) -- C:\WINDOWS\System32\drivers\Crypto.sig () DRV - (DNE) -- C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.) DRV - (DniVap) SafeNet WAN Miniport (VA) -- C:\WINDOWS\system32\drivers\vap.sys (Deterministic Networks Inc.) DRV - (DOSMEMIO) -- C:\WINDOWS\system32\MEMIO.SYS () ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "hxxp://de.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:de:official" FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011.03.22 22:49:42 | 000,000,000 | -H-D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.23 13:24:47 | 000,000,000 | -H-D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.12.18 00:12:09 | 000,000,000 | -H-D | M] [2009.01.20 23:33:40 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Extensions [2007.02.12 10:18:16 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\gn1x3wbj.default\extensions [2011.03.23 13:25:02 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions [2010.02.09 19:40:21 | 000,000,000 | -H-D | M] (F5 Networks Cache Cleaner Plugin) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{3191E4CE-790E-42be-B2E0-223475263B7E} [2010.11.05 17:48:23 | 000,000,000 | -H-D | M] (Adblock Plus) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010.06.25 17:27:05 | 000,000,000 | -H-D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2011.03.23 13:26:36 | 000,000,000 | -H-D | M] (IE Tab Plus) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\ietab@ip.cn [2010.02.22 20:29:08 | 000,000,000 | -H-D | M] (Advertising Cookie Opt-out) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\optout@google.com [2011.03.22 23:12:03 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2007.03.10 00:16:44 | 000,189,496 | -H-- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll [2010.11.04 22:17:04 | 000,001,392 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.11.04 22:17:04 | 000,002,344 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml [2010.11.04 22:17:04 | 000,006,805 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.11.04 22:17:04 | 000,001,178 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.11.04 22:17:04 | 000,001,105 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.08.05 22:47:22 | 000,396,932 | RH-- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: localhost O1 - Hosts: www.007guard.com O1 - Hosts: 007guard.com O1 - Hosts: 008i.com O1 - Hosts: www.008k.com O1 - Hosts: 008k.com O1 - Hosts: www.00hq.com O1 - Hosts: 00hq.com O1 - Hosts: 010402.com O1 - Hosts: www.032439.com O1 - Hosts: 032439.com O1 - Hosts: www.0scan.com O1 - Hosts: 0scan.com O1 - Hosts: www.1000gratisproben.com O1 - Hosts: 1000gratisproben.com O1 - Hosts: www.1001namen.com O1 - Hosts: 1001namen.com O1 - Hosts: www.100888290cs.com O1 - Hosts: 100888290cs.com O1 - Hosts: www.100sexlinks.com O1 - Hosts: 100sexlinks.com O1 - Hosts: 10sek.com O1 - Hosts: www.10sek.com O1 - Hosts: 1-2005-search.com O1 - Hosts: www.1-2005-search.com O1 - Hosts: 13702 more lines... O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [AVStation Premium 3.75] C:\Program Files\SAMSUNG\AVStation Premium 3.75\AVSAgent.exe () O4 - HKLM..\Run: [BatteryManager] C:\Program Files\SAMSUNG\Samsung Battery Manager\BatteryManager.exe () O4 - HKLM..\Run: [B'sCLiP] C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.) O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation) O4 - HKLM..\Run: [DisplayManager] C:\Program Files\SAMSUNG\DisplayManager\DMLoader.exe (SAMSUNG) O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows (R) Server 2003 DDK provider) O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies) O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKbd.exe () O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.) O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.) O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD) O4 - HKCU..\Run: [Power2GoExpress] File not found O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk = C:\Programme\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NetScreen-Remote.lnk = C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe (SafeNet) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe () O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe () O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe () O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe () O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} https://access.uke.de/vdesk/cachecleaner.cab#version=6031,2009,1010,0301 (F5 Networks CacheCleaner) O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} https://access.uke.de/vdesk/terminal/InstallerControl.cab (F5 Networks Auto Update) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171391294718 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11) O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} https://*** O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mfi.ku.dk O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.04.05 12:49:33 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.03.23 15:32:35 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\***\Desktop\mbam-setup.exe [2011.03.23 13:46:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\Application Data\Malwarebytes [2011.03.23 13:46:02 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2011.03.23 13:46:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.03.23 13:46:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2011.03.23 13:45:57 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2011.03.23 13:45:56 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2011.03.23 13:27:15 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\***\Recent [2011.03.23 00:51:46 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\***\Start Menu\Programs\Windows Recovery [2011.03.22 22:34:02 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\***\Application Data\Avira [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.03.23 16:40:00 | 000,001,102 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2011.03.23 16:12:41 | 000,000,077 | -HS- | M] () -- C:\cj.ini [2011.03.23 16:11:58 | 000,001,098 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2011.03.23 16:11:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011.03.23 15:33:50 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2011.03.23 15:32:35 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\***\Desktop\mbam-setup.exe [2011.03.23 13:21:58 | 000,043,616 | -H-- | M] () -- C:\WINDOWS\System32\nvapps.xml [2011.03.23 00:53:27 | 000,000,400 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\18865972 [2011.03.23 00:51:48 | 000,000,813 | -H-- | M] () -- C:\Documents and Settings\***\Desktop\Windows Recovery.lnk [2011.03.22 22:39:06 | 000,000,990 | -H-- | M] () -- C:\Documents and Settings\***\Desktop\Install PartyPoker.net.lnk [2011.03.22 22:35:14 | 000,137,656 | -H-- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys [2011.03.22 22:32:33 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.03.23 13:46:02 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2011.03.23 00:51:48 | 000,000,813 | -H-- | C] () -- C:\Documents and Settings\***\Desktop\Windows Recovery.lnk [2011.03.23 00:51:41 | 000,000,400 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\18865972 [2011.03.22 22:39:05 | 000,000,990 | -H-- | C] () -- C:\Documents and Settings\***\Desktop\Install PartyPoker.net.lnk [2009.12.06 12:55:46 | 000,006,656 | -H-- | C] () -- C:\WINDOWS\System32\CNMVS58.DLL [2009.11.25 19:42:23 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat [2009.07.17 20:34:28 | 000,007,168 | -H-- | C] () -- C:\Documents and Settings\***\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.06.29 11:27:37 | 000,116,224 | -H-- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2008.12.27 21:13:04 | 000,003,286 | -H-- | C] () -- C:\WINDOWS\tm.ini [2008.07.17 20:43:16 | 000,000,016 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\obtf501 [2007.10.24 16:48:08 | 000,001,755 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache [2007.09.16 15:32:31 | 000,000,025 | -H-- | C] () -- C:\WINDOWS\cdplayer.ini [2007.03.04 00:33:12 | 000,000,116 | -H-- | C] () -- C:\WINDOWS\NeroDigital.ini [2007.02.18 14:59:33 | 000,335,872 | -H-- | C] () -- C:\WINDOWS\System32\ldf252.dll [2007.02.12 11:47:48 | 000,003,183 | -H-- | C] () -- C:\WINDOWS\mozver.dat [2007.02.12 10:18:17 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\nsreg.dat [2007.02.07 22:35:50 | 000,006,550 | -H-- | C] () -- C:\WINDOWS\jautoexp.dat [2007.01.31 11:01:53 | 000,143,360 | -H-- | C] () -- C:\WINDOWS\System32\nsldap32v50.dll [2007.01.31 11:01:47 | 000,000,342 | -H-- | C] () -- C:\WINDOWS\OemOut.ini [2007.01.27 22:18:35 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI [2007.01.27 22:16:36 | 000,192,976 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2007.01.27 22:08:14 | 000,363,520 | -H-- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2007.01.27 21:59:31 | 000,000,135 | RH-- | C] () -- C:\WINDOWS\System32\lngEng.ini [2007.01.27 21:59:31 | 000,000,117 | -H-- | C] () -- C:\WINDOWS\System32\lngKor.ini [2007.01.27 21:57:10 | 000,001,522 | -H-- | C] () -- C:\WINDOWS\System32\MagicKBD.INI [2007.01.27 21:57:10 | 000,001,520 | ---- | C] () -- C:\WINDOWS\System32\***_KBD.ini [2007.01.27 21:57:08 | 000,004,300 | -H-- | C] () -- C:\WINDOWS\System32\MEMIO.SYS [2007.01.27 21:57:08 | 000,003,425 | -H-- | C] () -- C:\WINDOWS\System32\KBDR.INI [2007.01.27 21:57:08 | 000,002,741 | -H-- | C] () -- C:\WINDOWS\System32\KBDD.INI [2007.01.27 21:57:08 | 000,002,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDO.INI [2007.01.27 21:57:08 | 000,002,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDC.INI [2007.01.27 21:57:08 | 000,002,606 | -H-- | C] () -- C:\WINDOWS\System32\KBDB.INI [2007.01.27 21:57:08 | 000,002,236 | -H-- | C] () -- C:\WINDOWS\System32\KBDQ.INI [2007.01.27 21:57:08 | 000,001,956 | -H-- | C] () -- C:\WINDOWS\System32\KBDE.INI [2007.01.27 21:57:08 | 000,001,885 | -H-- | C] () -- C:\WINDOWS\System32\KBDP.INI [2007.01.27 21:57:08 | 000,001,835 | -H-- | C] () -- C:\WINDOWS\System32\KBDG.INI [2007.01.27 21:57:08 | 000,001,835 | -H-- | C] () -- C:\WINDOWS\System32\KBDA.INI [2007.01.27 21:57:08 | 000,001,834 | -H-- | C] () -- C:\WINDOWS\System32\KBDU.INI [2007.01.27 21:57:08 | 000,001,819 | -H-- | C] () -- C:\WINDOWS\System32\KBDN.INI [2007.01.27 21:57:08 | 000,001,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDT.INI [2007.01.27 21:57:08 | 000,001,697 | -H-- | C] () -- C:\WINDOWS\System32\KBDV.INI [2007.01.27 21:57:08 | 000,001,522 | -H-- | C] () -- C:\WINDOWS\System32\KBDS.INI [2007.01.27 21:57:08 | 000,001,476 | -H-- | C] () -- C:\WINDOWS\System32\KBDF.INI [2007.01.27 21:45:43 | 000,016,480 | -H-- | C] () -- C:\WINDOWS\System32\rixdicon.dll [2007.01.27 21:34:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2007.01.27 21:28:03 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2006.01.25 15:00:50 | 000,081,920 | -H-- | C] () -- C:\WINDOWS\System32\AVSAudioAmp.dll [2006.01.25 15:00:50 | 000,061,440 | -H-- | C] () -- C:\WINDOWS\System32\AVSAudioWideStereoDMO.dll [2005.12.08 02:53:00 | 001,662,976 | -H-- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2005.12.08 02:53:00 | 001,519,616 | -H-- | C] () -- C:\WINDOWS\System32\nwiz.exe [2005.12.08 02:53:00 | 001,466,368 | -H-- | C] () -- C:\WINDOWS\System32\nview.dll [2005.12.08 02:53:00 | 001,339,392 | -H-- | C] () -- C:\WINDOWS\System32\nvdspsch.exe [2005.12.08 02:53:00 | 001,019,904 | -H-- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2005.12.08 02:53:00 | 000,466,944 | -H-- | C] () -- C:\WINDOWS\System32\nvshell.dll [2005.12.08 02:53:00 | 000,442,368 | -H-- | C] () -- C:\WINDOWS\System32\nvappbar.exe [2005.12.08 02:53:00 | 000,110,592 | -H-- | C] () -- C:\WINDOWS\System32\nvapi.dll [2005.12.02 14:14:56 | 000,090,112 | -H-- | C] () -- C:\WINDOWS\System32\btprn2k.dll [2005.11.28 12:06:22 | 000,038,144 | -H-- | C] () -- C:\WINDOWS\System32\drivers\WOWXT_kern_i386.sys [2005.11.28 12:06:22 | 000,019,456 | -H-- | C] () -- C:\WINDOWS\System32\drivers\WOWFilter.sys [2005.11.28 12:06:20 | 000,031,232 | -H-- | C] () -- C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys [2004.08.02 14:20:40 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat [2003.07.07 17:00:00 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin [2003.07.07 17:00:00 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat [2003.07.07 17:00:00 | 000,432,690 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat [2003.07.07 17:00:00 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat [2003.07.07 17:00:00 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat [2003.07.07 17:00:00 | 000,067,646 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat [2003.07.07 17:00:00 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin [2003.07.07 17:00:00 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat [2003.07.07 17:00:00 | 000,004,463 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat [2003.07.07 17:00:00 | 000,001,788 | -H-- | C] () -- C:\WINDOWS\System32\dcache.bin [2003.07.07 17:00:00 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat [2002.09.17 23:45:00 | 000,119,808 | -H-- | C] () -- C:\WINDOWS\lsb_un20.exe [2001.11.14 12:56:00 | 001,802,240 | -H-- | C] () -- C:\WINDOWS\System32\lcppn21.dll ========== LOP Check ========== [2010.11.21 23:19:30 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software [2009.12.17 14:48:31 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\e-Safekey [2009.11.25 19:42:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier [2010.10.03 20:20:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\RapidTyping [2009.11.25 18:05:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Sophos [2007.02.18 15:00:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\ACD Systems [2009.10.21 22:39:16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\Amazon [2010.08.16 13:56:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\CheckPoint [2007.08.29 14:42:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\FUJIFILM [2008.07.17 20:43:15 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\GraphPad Software [2007.01.28 16:27:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\ISI ResearchSoft [2010.10.03 20:20:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\RapidTyping [2009.11.25 18:05:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\stickies ========== Purity Check ========== < End of report > OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 23.03.2011 16:44:05 - Run 1 OTL by OldTimer - Version Folder = C:\Documents and Settings\***\My Documents\Downloads Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy 1.022,00 Mb Total Physical Memory | 418,00 Mb Available Physical Memory | 41,00% Memory free 2,00 Gb Paging File | 2,00 Gb Available in Paging File | 74,00% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 82,62 Gb Total Space | 33,49 Gb Free Space | 40,53% Space Free | Partition Type: NTFS Computer Name: *** | User Name: ***| Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) .url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [ACDBrowse] -- "C:\PROGRA~2\ACDSYS~1\ACDSee\ACDSee.exe" "%1" Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [FinePix] -- "C:\Programme\FinePixViewer\FinePixViewer.exe" "%1" (FUJIFILM Corporation.) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] "DisableMonitoring" = 1 ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe" = C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe:*:Enabled:IreIke -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe" = C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe: -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe" = C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe: -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\vpn.exe" = C:\Program Files\Juniper\NetScreen-Remote\vpn.exe: Connection Manager -- (SafeNet) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon -- (Check Point Software Technologies LTD) "C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe" = C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe:*:Enabled:IreIke -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe" = C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe: -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe" = C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe: -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\vpn.exe" = C:\Program Files\Juniper\NetScreen-Remote\vpn.exe: Connection Manager -- (SafeNet) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{17283B95-21A8-4996-97DA-547A48DB266F}" = DisplayManager "{17CA6206-7109-4426-8EE0-1BD0BE54BCC9}" = Management Center "{19C64880-BBCA-11D4-9EEE-0004ACDDDB3B}" = CyberLink InstantBurn "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = PowerStarter "{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.3 "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13 "{2F931B84-0CEE-11D1-AA7D-0080AD1AC47A}" = NetScreen-Remote "{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11 "{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 4.0 "{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver "{55B1E4FA-F2E0-45DF-9B36-0B30A7949984}" = NWZ-S540 WALKMAN Guide "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Samsung Battery Manager "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38}" = Microsoft .NET Framework 2.0 Language Pack - DEU "{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (German) 12 "{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 "{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 "{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 "{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007 "{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs "{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007 "{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A48A8684-A104-44DA-B3DF-0178A125D8D9}" = WOW XT and TSXT Filter Driver "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A999CE76-D054-4684-80C7-53FC9243E019}" = EasyBox "{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0 "{B093990A-AAF2-44AC-9216-14BB7A2189B6}" = ImageMixer VCD2 LE for FinePix "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B44529FF-501E-47CD-A06D-223C161BE058}" = FinePixViewer Resource "{B5924CA6-24A7-48F5-BC9C-8BFA94ED4564}" = LightScribe "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer "{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75 "{BC892294-7616-49A2-B165-0E60305CB6EA}" = Eudora "{BD723E53-A42C-4702-AA04-1D74A0311590}" = Magic Keyboard "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C0B0893D-6DA2-4F14-B1D0-3C0F1272B398}" = Reference Manager 11.0.1 "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint 1.0 "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer "{D5A9B7C0-8751-11D8-9D75-000129760D75}" = MediaShow 3.0 "{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime "{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0 "{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager "{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}" = FinePix Studio "{E5E54037-31CD-4EBD-9211-4C384F4E7E79}" = e-Safekey "{E96FF910-1BC9-4EE5-BC12-0A30D4E20F37}" = NWZ-E440 WALKMAN Guide "{EF99C14B-17C2-4994-B5C1-EB204A343A6F}" = User's Guide "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player "AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54 "AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts "Agere Systems Soft Modem" = SENS LT56ADW Modem "Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.5 "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "CANONBJ_Deinstall_CNMCP58.DLL" = Canon i560 "CDex" = CDex extraction audio "ENTERPRISE" = Microsoft Office Enterprise 2007 "InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "InstallShield_{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75 "InstallShield_{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0 "ISI ResearchSoft - Export Helper" = ISI ResearchSoft - Export Helper "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 2.0 Language Pack - DEU" = Microsoft .NET Framework 2.0 Language Pack - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13) "NeroMultiInstaller!UninstallKey" = Nero Suite "NVIDIA Drivers" = NVIDIA Drivers "PartyPoker" = PartyPoker "PartyPokerNet" = PartyPokerNet "PDF Blender" = PDF Blender "ProInst" = Intel(R) PROSet/Wireless Software "RapidTyping" = RapidTyping "RealPlayer 6.0" = RealPlayer "ShockwaveFlash" = Adobe Flash Player 9 ActiveX "SynTPDeinstKey" = Synaptics Pointing Device Driver "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 "WIC" = Windows Imaging Component "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows XP Service Pack" = Windows XP Service Pack 2 "WinLems_is1" = WinLems 1.24 "WinRAR archiver" = WinRAR "WMFDist11" = Windows Media Format 11 runtime "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Widget Engine" = Yahoo! Widgets "ZoneAlarm" = ZoneAlarm "ZoneAlarm Toolbar" = ZoneAlarm Toolbar ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 23.03.2011 07:49:54 | Computer Name = MF2249 | Source = Userenv | ID = 1054 Description = Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Error - 23.03.2011 07:50:56 | Computer Name = MF2249 | Source = AutoEnrollment | ID = 15 Description = Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. Error - 23.03.2011 07:59:13 | Computer Name = MF2249 | Source = Userenv | ID = 1054 Description = Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Error - 23.03.2011 08:00:24 | Computer Name = MF2249 | Source = AutoEnrollment | ID = 15 Description = Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. Error - 23.03.2011 08:22:13 | Computer Name = *** | Source = Userenv | ID = 1054 Description = Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Error - 23.03.2011 08:23:14 | Computer Name = MF2249 | Source = AutoEnrollment | ID = 15 Description = Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. Error - 23.03.2011 10:21:12 | Computer Name = *** | Source = Userenv | ID = 1054 Description = Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Error - 23.03.2011 10:22:12 | Computer Name = *** | Source = AutoEnrollment | ID = 15 Description = Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. Error - 23.03.2011 11:12:14 | Computer Name = *** | Source = Userenv | ID = 1054 Description = Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Error - 23.03.2011 11:13:14 | Computer Name = *** | Source = AutoEnrollment | ID = 15 Description = Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. [ OSession Events ] Error - 10.06.2007 13:27:03 | Computer Name = *** | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20380 seconds with 8580 seconds of active time. This session ended with a crash. [ System Events ] Error - 23.03.2011 10:25:40 | Computer Name = *** | Source = Service Control Manager | ID = 7034 Description = The SNM WLAN Service service terminated unexpectedly. It has done this 1 time(s). Error - 23.03.2011 10:25:40 | Computer Name = *** | Source = Service Control Manager | ID = 7034 Description = The SRS PostInstaller Service service terminated unexpectedly. It has done this 1 time(s). Error - 23.03.2011 10:29:59 | Computer Name = ***| Source = Service Control Manager | ID = 7031 Description = The Bluetooth Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error - 23.03.2011 10:36:16 | Computer Name = ***| Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 29 minutes. NtpClient has no source of accurate time. Error - 23.03.2011 11:06:22 | Computer Name = ***| Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 59 minutes. NtpClient has no source of accurate time. Error - 23.03.2011 11:12:14 | Computer Name = ***| Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. Error - 23.03.2011 11:12:14 | Computer Name = ***| Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. Error - 23.03.2011 11:12:15 | Computer Name = ***| Source = NETLOGON | ID = 5719 Description = No Domain Controller is available for domain CSAM due to the following: %%1311. Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator. Error - 23.03.2011 11:13:18 | Computer Name = ***| Source = Service Control Manager | ID = 7000 Description = The Google Update Service (gupdate) service failed to start due to the following error: %%3 Error - 23.03.2011 11:27:23 | Computer Name = ***| Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 29 minutes. NtpClient has no source of accurate time. < End of report > |
Zitat:
Mach danach bitte frische Logs mit OTL.exe und poste sie.
__________________ |
![]() | #3 |
![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Hallo Arne,
__________________vielen Dank erstmal für Deine Antwort. Ich habe Zone Alarm deinstalliert und die Windows Firewall aktiviert. Nun kann ich nicht mehr auf das Internet zugreifen, obwohl ich unter Exceptions firefox.exe angegeben habe. Mache ich etwas falsch oder hängt das eine mit dem anderen nicht zusammen ? Vielen Dank schon mal shaiko |
![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Hi Arne, Jetzt geht es wieder. Und Danke nochmal für Deine zukünftigen Antworten. Hier sind die neuen Logfiles nach Deinstallation von Zone Alarm und Aktivierung der Windows Firewall:OTL Logfile: Code:
ATTFilter OTL logfile created on: 24.03.2011 22:00:10 - Run 2 OTL by OldTimer - Version Folder = C:\Documents and Settings\***\Desktop Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy 1.022,00 Mb Total Physical Memory | 561,00 Mb Available Physical Memory | 55,00% Memory free 2,00 Gb Paging File | 2,00 Gb Available in Paging File | 83,00% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 82,62 Gb Total Space | 33,61 Gb Free Space | 40,68% Space Free | Partition Type: NTFS Computer Name: ***| User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\***\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH) PRC - C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation) PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\SAMSUNG\AVStation Premium 3.75\AVSAgent.exe () PRC - C:\Program Files\SAMSUNG\Samsung Battery Manager\BatteryManager.exe () PRC - C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe (SAMSUNG Electronics Co., Ltd.) PRC - C:\Program Files\SAMSUNG\DisplayManager\DisplayManager.exe (SAMSUNG) PRC - C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.) PRC - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.) PRC - C:\Program Files\SAMSUNG\Samsung Network Manager\SNMWLANService.exe () PRC - C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation) PRC - C:\Program Files\SAMSUNG\Samsung Update Plus\SLUTrayNotifier.exe () PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.) PRC - C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe (SafeNet) PRC - C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe (SafeNet) ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\***\Desktop\OTL.exe (OldTimer Tools) MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation) MOD - C:\WINDOWS\system32\SynTPFcs.dll (Synaptics, Inc.) ========== Win32 Services (SafeList) ========== SRV - (HidServ) -- File not found SRV - (gupdate) Google Update Service (gupdate) -- File not found SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (getPlusHelper) getPlus(R) -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.) SRV - (SRS_PostInstaller) -- C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe (SRS Labs, Inc.) SRV - (SNM WLAN Service) -- C:\Program Files\SAMSUNG\Samsung Network Manager\SNMWLANService.exe () SRV - (bgsvcgen) -- C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation) SRV - (Samsung Update Plus) -- C:\Program Files\SAMSUNG\Samsung Update Plus\SLUBackgroundService.exe () SRV - (IPSECMON) -- C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe (SafeNet) SRV - (IreIKE) -- C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe (SafeNet) ========== Driver Services (SafeList) ========== DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH) DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH) DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (motmodem) -- C:\WINDOWS\system32\drivers\motmodem.sys (Motorola) DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation) DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems) DRV - (w39n51) Intel(R) -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation) DRV - (BTSERIAL) -- C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.) DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.) DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.) DRV - (BsStor) -- C:\WINDOWS\System32\drivers\BsStor.sys (Cyberlink Co.,Ltd.) DRV - (BsUDF) -- C:\WINDOWS\System32\drivers\BsUDF.sys (CyberLink Corporation.) DRV - (wowfilter) -- C:\WINDOWS\system32\drivers\WOWFilter.sys () DRV - (rimmptsk) -- C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC) DRV - (rismxdp) -- C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC) DRV - (rimsptsk) -- C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC) DRV - (SUEPD) -- C:\WINDOWS\system32\drivers\SUE_PD.sys (Samsung) DRV - (HdAudAddService) -- C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows (R) Server 2003 DDK provider) DRV - (IPSECDRV) -- C:\WINDOWS\system32\drivers\IpSecDrv.sys (SafeNet) DRV - (Crypto) -- C:\WINDOWS\System32\drivers\Crypto.sig () DRV - (DNE) -- C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.) DRV - (DniVap) SafeNet WAN Miniport (VA) -- C:\WINDOWS\system32\drivers\vap.sys (Deterministic Networks Inc.) DRV - (DOSMEMIO) -- C:\WINDOWS\system32\MEMIO.SYS () ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "hxxp://de.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:de:official" FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.23 13:24:47 | 000,000,000 | -H-D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.12.18 00:12:09 | 000,000,000 | -H-D | M] [2009.01.20 23:33:40 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Extensions [2007.02.12 10:18:16 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\gn1x3wbj.default\extensions [2011.03.23 13:25:02 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions [2010.02.09 19:40:21 | 000,000,000 | -H-D | M] (F5 Networks Cache Cleaner Plugin) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{3191E4CE-790E-42be-B2E0-223475263B7E} [2010.11.05 17:48:23 | 000,000,000 | -H-D | M] (Adblock Plus) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010.06.25 17:27:05 | 000,000,000 | -H-D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2011.03.23 13:26:36 | 000,000,000 | -H-D | M] (IE Tab Plus) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\ietab@ip.cn [2010.02.22 20:29:08 | 000,000,000 | -H-D | M] (Advertising Cookie Opt-out) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\extensions\optout@google.com [2011.03.22 23:12:03 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2007.03.10 00:16:44 | 000,189,496 | -H-- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll [2010.11.04 22:17:04 | 000,001,392 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010.11.04 22:17:04 | 000,002,344 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml [2010.11.04 22:17:04 | 000,006,805 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010.11.04 22:17:04 | 000,001,178 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010.11.04 22:17:04 | 000,001,105 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2010.08.05 22:47:22 | 000,396,932 | RH-- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: localhost O1 - Hosts: www.007guard.com O1 - Hosts: 007guard.com O1 - Hosts: 008i.com O1 - Hosts: www.008k.com O1 - Hosts: 008k.com O1 - Hosts: www.00hq.com O1 - Hosts: 00hq.com O1 - Hosts: 010402.com O1 - Hosts: www.032439.com O1 - Hosts: 032439.com O1 - Hosts: www.0scan.com O1 - Hosts: 0scan.com O1 - Hosts: www.1000gratisproben.com O1 - Hosts: 1000gratisproben.com O1 - Hosts: www.1001namen.com O1 - Hosts: 1001namen.com O1 - Hosts: www.100888290cs.com O1 - Hosts: 100888290cs.com O1 - Hosts: www.100sexlinks.com O1 - Hosts: 100sexlinks.com O1 - Hosts: 10sek.com O1 - Hosts: www.10sek.com O1 - Hosts: 1-2005-search.com O1 - Hosts: www.1-2005-search.com O1 - Hosts: 13702 more lines... O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (no name) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - No CLSID value found. O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found. O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [AVStation Premium 3.75] C:\Program Files\SAMSUNG\AVStation Premium 3.75\AVSAgent.exe () O4 - HKLM..\Run: [BatteryManager] C:\Program Files\SAMSUNG\Samsung Battery Manager\BatteryManager.exe () O4 - HKLM..\Run: [B'sCLiP] C:\Program Files\CyberLink\InstantBurn\Win2K\IBurn.exe (CyberLink Corporation.) O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation) O4 - HKLM..\Run: [DisplayManager] C:\Program Files\SAMSUNG\DisplayManager\DMLoader.exe (SAMSUNG) O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows (R) Server 2003 DDK provider) O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKbd.exe () O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.) O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.) O4 - HKCU..\Run: [Power2GoExpress] File not found O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk = C:\Programme\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NetScreen-Remote.lnk = C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe (SafeNet) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe () O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe () O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe () O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe () O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} https://access.uke.de/vdesk/cachecleaner.cab#version=6031,2009,1010,0301 (F5 Networks CacheCleaner) O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} https://access.uke.de/vdesk/terminal/InstallerControl.cab (F5 Networks Auto Update) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171391294718 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11) O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} https://*** O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mfi.ku.dk O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.04.05 12:49:33 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.03.24 21:51:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs [2011.03.23 16:14:22 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\***\Desktop\OTL.exe [2011.03.23 15:32:35 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\***\Desktop\mbam-setup.exe [2011.03.23 13:46:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\Application Data\Malwarebytes [2011.03.23 13:46:02 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2011.03.23 13:46:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware [2011.03.23 13:46:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2011.03.23 13:45:57 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2011.03.23 13:45:56 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2011.03.23 13:27:15 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\***\Recent [2011.03.23 00:51:46 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\***\Start Menu\Programs\Windows Recovery [2011.03.22 22:34:02 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\***\Application Data\Avira [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.03.24 21:51:59 | 000,000,077 | -HS- | M] () -- C:\cj.ini [2011.03.24 21:51:41 | 000,001,098 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2011.03.24 21:51:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011.03.24 21:44:17 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl [2011.03.23 17:40:00 | 000,001,102 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2011.03.23 16:14:26 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\***\Desktop\OTL.exe [2011.03.23 15:33:50 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2011.03.23 15:32:35 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\***\Desktop\mbam-setup.exe [2011.03.23 13:21:58 | 000,043,616 | -H-- | M] () -- C:\WINDOWS\System32\nvapps.xml [2011.03.23 00:53:27 | 000,000,400 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\18865972 [2011.03.23 00:51:48 | 000,000,813 | -H-- | M] () -- C:\Documents and Settings\***\Desktop\Windows Recovery.lnk [2011.03.22 22:39:06 | 000,000,990 | -H-- | M] () -- C:\Documents and Settings\***\Desktop\Install PartyPoker.net.lnk [2011.03.22 22:35:14 | 000,137,656 | -H-- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.03.23 13:46:02 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2011.03.23 00:51:48 | 000,000,813 | -H-- | C] () -- C:\Documents and Settings\***\Desktop\Windows Recovery.lnk [2011.03.23 00:51:41 | 000,000,400 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\18865972 [2011.03.22 22:39:05 | 000,000,990 | -H-- | C] () -- C:\Documents and Settings\***\Desktop\Install PartyPoker.net.lnk [2009.12.06 12:55:46 | 000,006,656 | -H-- | C] () -- C:\WINDOWS\System32\CNMVS58.DLL [2009.11.25 19:42:23 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat [2009.07.17 20:34:28 | 000,007,168 | -H-- | C] () -- C:\Documents and Settings\***\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.06.29 11:27:37 | 000,116,224 | -H-- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2008.12.27 21:13:04 | 000,003,286 | -H-- | C] () -- C:\WINDOWS\tm.ini [2008.07.17 20:43:16 | 000,000,016 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\obtf501 [2007.10.24 16:48:08 | 000,001,755 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache [2007.09.16 15:32:31 | 000,000,025 | -H-- | C] () -- C:\WINDOWS\cdplayer.ini [2007.03.04 00:33:12 | 000,000,116 | -H-- | C] () -- C:\WINDOWS\NeroDigital.ini [2007.02.18 14:59:33 | 000,335,872 | -H-- | C] () -- C:\WINDOWS\System32\ldf252.dll [2007.02.12 11:47:48 | 000,003,183 | -H-- | C] () -- C:\WINDOWS\mozver.dat [2007.02.12 10:18:17 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\nsreg.dat [2007.02.07 22:35:50 | 000,006,550 | -H-- | C] () -- C:\WINDOWS\jautoexp.dat [2007.01.31 11:01:53 | 000,143,360 | -H-- | C] () -- C:\WINDOWS\System32\nsldap32v50.dll [2007.01.31 11:01:47 | 000,000,342 | -H-- | C] () -- C:\WINDOWS\OemOut.ini [2007.01.27 22:18:35 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI [2007.01.27 22:16:36 | 000,192,976 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2007.01.27 22:08:14 | 000,363,520 | -H-- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2007.01.27 21:59:31 | 000,000,135 | RH-- | C] () -- C:\WINDOWS\System32\lngEng.ini [2007.01.27 21:59:31 | 000,000,117 | -H-- | C] () -- C:\WINDOWS\System32\lngKor.ini [2007.01.27 21:57:10 | 000,001,522 | -H-- | C] () -- C:\WINDOWS\System32\MagicKBD.INI [2007.01.27 21:57:10 | 000,001,520 | ---- | C] () -- C:\WINDOWS\System32\***_KBD.ini [2007.01.27 21:57:08 | 000,004,300 | -H-- | C] () -- C:\WINDOWS\System32\MEMIO.SYS [2007.01.27 21:57:08 | 000,003,425 | -H-- | C] () -- C:\WINDOWS\System32\KBDR.INI [2007.01.27 21:57:08 | 000,002,741 | -H-- | C] () -- C:\WINDOWS\System32\KBDD.INI [2007.01.27 21:57:08 | 000,002,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDO.INI [2007.01.27 21:57:08 | 000,002,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDC.INI [2007.01.27 21:57:08 | 000,002,606 | -H-- | C] () -- C:\WINDOWS\System32\KBDB.INI [2007.01.27 21:57:08 | 000,002,236 | -H-- | C] () -- C:\WINDOWS\System32\KBDQ.INI [2007.01.27 21:57:08 | 000,001,956 | -H-- | C] () -- C:\WINDOWS\System32\KBDE.INI [2007.01.27 21:57:08 | 000,001,885 | -H-- | C] () -- C:\WINDOWS\System32\KBDP.INI [2007.01.27 21:57:08 | 000,001,835 | -H-- | C] () -- C:\WINDOWS\System32\KBDG.INI [2007.01.27 21:57:08 | 000,001,835 | -H-- | C] () -- C:\WINDOWS\System32\KBDA.INI [2007.01.27 21:57:08 | 000,001,834 | -H-- | C] () -- C:\WINDOWS\System32\KBDU.INI [2007.01.27 21:57:08 | 000,001,819 | -H-- | C] () -- C:\WINDOWS\System32\KBDN.INI [2007.01.27 21:57:08 | 000,001,699 | -H-- | C] () -- C:\WINDOWS\System32\KBDT.INI [2007.01.27 21:57:08 | 000,001,697 | -H-- | C] () -- C:\WINDOWS\System32\KBDV.INI [2007.01.27 21:57:08 | 000,001,522 | -H-- | C] () -- C:\WINDOWS\System32\KBDS.INI [2007.01.27 21:57:08 | 000,001,476 | -H-- | C] () -- C:\WINDOWS\System32\KBDF.INI [2007.01.27 21:45:43 | 000,016,480 | -H-- | C] () -- C:\WINDOWS\System32\rixdicon.dll [2007.01.27 21:34:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2007.01.27 21:28:03 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2006.01.25 15:00:50 | 000,081,920 | -H-- | C] () -- C:\WINDOWS\System32\AVSAudioAmp.dll [2006.01.25 15:00:50 | 000,061,440 | -H-- | C] () -- C:\WINDOWS\System32\AVSAudioWideStereoDMO.dll [2005.12.08 02:53:00 | 001,662,976 | -H-- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2005.12.08 02:53:00 | 001,519,616 | -H-- | C] () -- C:\WINDOWS\System32\nwiz.exe [2005.12.08 02:53:00 | 001,466,368 | -H-- | C] () -- C:\WINDOWS\System32\nview.dll [2005.12.08 02:53:00 | 001,339,392 | -H-- | C] () -- C:\WINDOWS\System32\nvdspsch.exe [2005.12.08 02:53:00 | 001,019,904 | -H-- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2005.12.08 02:53:00 | 000,466,944 | -H-- | C] () -- C:\WINDOWS\System32\nvshell.dll [2005.12.08 02:53:00 | 000,442,368 | -H-- | C] () -- C:\WINDOWS\System32\nvappbar.exe [2005.12.08 02:53:00 | 000,110,592 | -H-- | C] () -- C:\WINDOWS\System32\nvapi.dll [2005.12.02 14:14:56 | 000,090,112 | -H-- | C] () -- C:\WINDOWS\System32\btprn2k.dll [2005.11.28 12:06:22 | 000,038,144 | -H-- | C] () -- C:\WINDOWS\System32\drivers\WOWXT_kern_i386.sys [2005.11.28 12:06:22 | 000,019,456 | -H-- | C] () -- C:\WINDOWS\System32\drivers\WOWFilter.sys [2005.11.28 12:06:20 | 000,031,232 | -H-- | C] () -- C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys [2004.08.02 14:20:40 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat [2003.07.07 17:00:00 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin [2003.07.07 17:00:00 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat [2003.07.07 17:00:00 | 000,432,690 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat [2003.07.07 17:00:00 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat [2003.07.07 17:00:00 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat [2003.07.07 17:00:00 | 000,067,646 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat [2003.07.07 17:00:00 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin [2003.07.07 17:00:00 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat [2003.07.07 17:00:00 | 000,004,463 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat [2003.07.07 17:00:00 | 000,001,788 | -H-- | C] () -- C:\WINDOWS\System32\dcache.bin [2003.07.07 17:00:00 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat [2002.09.17 23:45:00 | 000,119,808 | -H-- | C] () -- C:\WINDOWS\lsb_un20.exe [2001.11.14 12:56:00 | 001,802,240 | -H-- | C] () -- C:\WINDOWS\System32\lcppn21.dll ========== LOP Check ========== [2010.11.21 23:19:30 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software [2009.12.17 14:48:31 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\e-Safekey [2009.11.25 19:42:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier [2010.10.03 20:20:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\RapidTyping [2009.11.25 18:05:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Sophos [2007.02.18 15:00:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\ACD Systems [2009.10.21 22:39:16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\Amazon [2010.08.16 13:56:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\***\Application Data\CheckPoint [2007.08.29 14:42:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\FUJIFILM [2008.07.17 20:43:15 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\GraphPad Software [2007.01.28 16:27:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\ISI ResearchSoft [2010.10.03 20:20:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\RapidTyping [2009.11.25 18:05:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\***\Application Data\stickies ========== Purity Check ========== < End of report > OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 24.03.2011 22:00:10 - Run 2 OTL by OldTimer - Version Folder = C:\Documents and Settings\***\Desktop Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy 1.022,00 Mb Total Physical Memory | 561,00 Mb Available Physical Memory | 55,00% Memory free 2,00 Gb Paging File | 2,00 Gb Available in Paging File | 83,00% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 82,62 Gb Total Space | 33,61 Gb Free Space | 40,68% Space Free | Partition Type: NTFS Computer Name: *** | User Name: ***| Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) .url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [ACDBrowse] -- "C:\PROGRA~2\ACDSYS~1\ACDSee\ACDSee.exe" "%1" Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [FinePix] -- "C:\Programme\FinePixViewer\FinePixViewer.exe" "%1" (FUJIFILM Corporation.) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe" = C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe:*:Enabled:IreIke -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe" = C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe: -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe" = C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe: -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\vpn.exe" = C:\Program Files\Juniper\NetScreen-Remote\vpn.exe: Connection Manager -- (SafeNet) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe" = C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe:*:Enabled:IreIke -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe" = C:\Program Files\Juniper\NetScreen-Remote\ViewLog.exe: -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe" = C:\Program Files\Juniper\NetScreen-Remote\CmonApp.exe: -- (SafeNet) "C:\Program Files\Juniper\NetScreen-Remote\vpn.exe" = C:\Program Files\Juniper\NetScreen-Remote\vpn.exe: Connection Manager -- (SafeNet) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{17283B95-21A8-4996-97DA-547A48DB266F}" = DisplayManager "{17CA6206-7109-4426-8EE0-1BD0BE54BCC9}" = Management Center "{19C64880-BBCA-11D4-9EEE-0004ACDDDB3B}" = CyberLink InstantBurn "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = PowerStarter "{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.3 "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13 "{2F931B84-0CEE-11D1-AA7D-0080AD1AC47A}" = NetScreen-Remote "{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11 "{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 4.0 "{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver "{55B1E4FA-F2E0-45DF-9B36-0B30A7949984}" = NWZ-S540 WALKMAN Guide "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Samsung Battery Manager "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38}" = Microsoft .NET Framework 2.0 Language Pack - DEU "{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (German) 12 "{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 "{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 "{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 "{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 "{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 "{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 "{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 "{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007 "{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 "{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 "{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs "{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007 "{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A48A8684-A104-44DA-B3DF-0178A125D8D9}" = WOW XT and TSXT Filter Driver "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A999CE76-D054-4684-80C7-53FC9243E019}" = EasyBox "{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0 "{B093990A-AAF2-44AC-9216-14BB7A2189B6}" = ImageMixer VCD2 LE for FinePix "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B44529FF-501E-47CD-A06D-223C161BE058}" = FinePixViewer Resource "{B5924CA6-24A7-48F5-BC9C-8BFA94ED4564}" = LightScribe "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer "{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75 "{BC892294-7616-49A2-B165-0E60305CB6EA}" = Eudora "{BD723E53-A42C-4702-AA04-1D74A0311590}" = Magic Keyboard "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C0B0893D-6DA2-4F14-B1D0-3C0F1272B398}" = Reference Manager 11.0.1 "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint 1.0 "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer "{D5A9B7C0-8751-11D8-9D75-000129760D75}" = MediaShow 3.0 "{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime "{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0 "{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager "{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}" = FinePix Studio "{E5E54037-31CD-4EBD-9211-4C384F4E7E79}" = e-Safekey "{E96FF910-1BC9-4EE5-BC12-0A30D4E20F37}" = NWZ-E440 WALKMAN Guide "{EF99C14B-17C2-4994-B5C1-EB204A343A6F}" = User's Guide "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player "AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54 "AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts "Agere Systems Soft Modem" = SENS LT56ADW Modem "Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.5 "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "CANONBJ_Deinstall_CNMCP58.DLL" = Canon i560 "CDex" = CDex extraction audio "ENTERPRISE" = Microsoft Office Enterprise 2007 "InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus "InstallShield_{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75 "InstallShield_{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0 "ISI ResearchSoft - Export Helper" = ISI ResearchSoft - Export Helper "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 2.0 Language Pack - DEU" = Microsoft .NET Framework 2.0 Language Pack - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13) "NeroMultiInstaller!UninstallKey" = Nero Suite "NVIDIA Drivers" = NVIDIA Drivers "PartyPoker" = PartyPoker "PartyPokerNet" = PartyPokerNet "PDF Blender" = PDF Blender "ProInst" = Intel(R) PROSet/Wireless Software "RapidTyping" = RapidTyping "RealPlayer 6.0" = RealPlayer "ShockwaveFlash" = Adobe Flash Player 9 ActiveX "SynTPDeinstKey" = Synaptics Pointing Device Driver "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 "WIC" = Windows Imaging Component "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows XP Service Pack" = Windows XP Service Pack 2 "WinLems_is1" = WinLems 1.24 "WinRAR archiver" = WinRAR "WMFDist11" = Windows Media Format 11 runtime "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 23.03.2011 10:21:12 | Computer Name = MF2249 | Source = Userenv | ID = 1054 Description = Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Error - 23.03.2011 10:22:12 | Computer Name = MF2249 | Source = AutoEnrollment | ID = 15 Description = Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. Error - 23.03.2011 11:12:14 | Computer Name = MF2249 | Source = Userenv | ID = 1054 Description = Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Error - 23.03.2011 11:13:14 | Computer Name = ***| Source = AutoEnrollment | ID = 15 Description = Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. Error - 23.03.2011 12:49:31 | Computer Name = ***| Source = Userenv | ID = 1054 Description = Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Error - 23.03.2011 12:50:31 | Computer Name = ***| Source = AutoEnrollment | ID = 15 Description = Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. Error - 24.03.2011 16:44:49 | Computer Name = ***| Source = Userenv | ID = 1054 Description = Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Error - 24.03.2011 16:45:49 | Computer Name = ***| Source = AutoEnrollment | ID = 15 Description = Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. Error - 24.03.2011 16:52:04 | Computer Name = ***| Source = Userenv | ID = 1054 Description = Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Error - 24.03.2011 16:53:04 | Computer Name = ***| Source = AutoEnrollment | ID = 15 Description = Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. [ OSession Events ] Error - 10.06.2007 13:27:03 | Computer Name = ***| Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20380 seconds with 8580 seconds of active time. This session ended with a crash. [ System Events ] Error - 23.03.2011 12:49:34 | Computer Name = ***| Source = NETLOGON | ID = 5719 Description = No Domain Controller is available for domain CSAM due to the following: %%1311. Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator. Error - 23.03.2011 12:50:36 | Computer Name = ***| Source = Service Control Manager | ID = 7000 Description = The Google Update Service (gupdate) service failed to start due to the following error: %%3 Error - 24.03.2011 16:44:49 | Computer Name = ***| Source = NETLOGON | ID = 5719 Description = No Domain Controller is available for domain CSAM due to the following: %%1311. Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator. Error - 24.03.2011 16:44:50 | Computer Name = ***| Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. Error - 24.03.2011 16:44:50 | Computer Name = ***| Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time. Error - 24.03.2011 16:45:50 | Computer Name = ***| Source = Service Control Manager | ID = 7000 Description = The Google Update Service (gupdate) service failed to start due to the following error: %%3 Error - 24.03.2011 16:52:03 | Computer Name = ***| Source = NETLOGON | ID = 5719 Description = No Domain Controller is available for domain CSAM due to the following: %%1311. Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator. Error - 24.03.2011 16:52:04 | Computer Name = ***| Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. Error - 24.03.2011 16:52:04 | Computer Name = ***| Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time. Error - 24.03.2011 16:53:08 | Computer Name = ***| Source = Service Control Manager | ID = 7000 Description = The Google Update Service (gupdate) service failed to start due to the following error: %%3 < End of report > |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL [2011.03.24 21:51:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs [2011.03.24 21:51:59 | 000,000,077 | -HS- | M] () -- C:\cj.ini :Commands [purity] [resethosts] [emptytemp] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Sollen die Einstellungen in OTL so wie vorher sein, d.h. LOP Prüfung und Purity Prüfung aktiviert sowie bei Extra-Registrierung "Benutze SafeList" ? Danke und Gruß shaiko |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Ja lass es so.
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Hi, ich habe es so gemacht wie beschrieben: All processes killed ========== OTL ========== C:\WINDOWS\Internet Logs folder moved successfully. C:\cj.ini moved successfully. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: *** ->Temp folder emptied: 1082521008 bytes ->Temporary Internet Files folder emptied: 171016015 bytes ->Java cache emptied: 47030067 bytes ->FireFox cache emptied: 47632263 bytes ->Flash cache emptied: 1250 bytes User: LocalService ->Temp folder emptied: 2046690 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 1978776 bytes ->Temporary Internet Files folder emptied: 2216765 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1119318 bytes %systemroot%\System32 .tmp files removed: 2832913 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 114589941 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23442704 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1.427,00 mb OTL by OldTimer - Version log created on 03252011_153849 Files\Folders moved on Reboot... Registry entries deleted on Reboot... |
![]() | #9 |
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Soll während das Programm arbeitet, auch die Internetverbindung gekappt werden ? Vielen Dank shaiko |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Nein, die bitte aktiv lassen, damit CF sich ggf. selbst aktualisieren kann.
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Hi Arne, hier das Logfile: Combofix Logfile: Code:
ATTFilter ComboFix 11-03-24.06 - ***25.03.2011 21:53:07.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.49.1033.18.1022.682 [GMT 1:00] ausgeführt von:: c:\documents and settings\***\Desktop\cofi.exe AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\ntuser.pol c:\documents and settings\***\Application Data\ACD Systems\ACDSee\ImageDB.ddf . . ((((((((((((((((((((((( Dateien erstellt von 2011-02-25 bis 2011-03-25 )))))))))))))))))))))))))))))) . . 2011-03-25 20:41 . 2011-03-25 20:41 -------- d-----w- c:\program files\CCleaner 2011-03-25 14:38 . 2011-03-25 14:38 -------- d-----w- C:\_OTL 2011-03-23 12:46 . 2011-03-23 12:46 -------- d-----w- c:\documents and settings\***\Application Data\Malwarebytes 2011-03-23 12:46 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-03-23 12:46 . 2011-03-23 12:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-03-23 12:45 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-03-23 12:45 . 2011-03-23 14:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-03-22 21:34 . 2011-03-22 21:34 -------- d--h--w- c:\documents and settings\***\Application Data\Avira . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-22 21:35 . 2009-11-26 11:02 137656 ---ha-w- c:\windows\system32\drivers\avipbb.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Power2GoExpress"="NA" [X] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2005-12-08 7340032] "nwiz"="nwiz.exe" [2005-12-08 1519616] "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-19 925696] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 692316] "AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 88204] "MagicKeyboard"="c:\program files\SAMSUNG\MagicKBD\PreMKBD.exe" [2005-04-11 151552] "DisplayManager"="c:\program files\Samsung\DisplayManager\DMLoader.exe" [2005-11-16 356352] "AVStation Premium 3.75"="c:\program files\Samsung\AVStation Premium 3.75\AVSAgent.exe" [2006-04-27 155648] "BatteryManager"="c:\program files\Samsung\Samsung Battery Manager\BatteryManager.exe" [2006-04-25 2764800] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768] "B'sCLiP"="c:\progra~2\CYBERL~1\INSTAN~1\Win2K\IBurn.exe" [2005-11-30 700416] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-06 148888] "REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248] "ContentTransferWMDetector.exe"="c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe" [2009-07-30 497000] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-23 281768] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360] . c:\documents and settings\***\Start Menu\Programs\Startup\ OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696] BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-12-2 618557] Exif Launcher 2.lnk - c:\programme\FinePixViewer\QuickDCF2.exe [2007-8-29 294912] NetScreen-Remote.lnk - c:\program files\Juniper\NetScreen-Remote\SafeCfg.exe [2007-1-31 65588] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\Qualcomm\Eudora\EuShlExt.dll" [2005-06-08 86016] . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Juniper\\NetScreen-Remote\\IreIKE.exe"= "c:\program files\Juniper\NetScreen-Remote\ViewLog.exe"= c:\program files\Juniper\NetScreen-Remote\ViewLog.exe: "c:\program files\Juniper\NetScreen-Remote\CmonApp.exe"= c:\program files\Juniper\NetScreen-Remote\CmonApp.exe: "c:\program files\Juniper\NetScreen-Remote\vpn.exe"= c:\program files\Juniper\NetScreen-Remote\vpn.exe: Connection Manager . R0 BsStor;B.H.A Storage Helper Driver;c:\windows\system32\drivers\BsStor.sys [27.01.2007 22:14 10368] R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [26.11.2009 12:02 135336] R2 BsUDF;B.H.A UDF Filesystem;c:\windows\system32\drivers\BsUDF.sys [27.01.2007 22:14 164480] R2 Crypto;Crypto;c:\windows\system32\drivers\Crypto.sys [31.01.2007 11:02 521786] R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [27.01.2007 21:57 4300] R2 IPSECDRV;SafeNet IPSec Plugin;c:\windows\system32\drivers\IpSecDrv.sys [31.01.2007 11:02 119864] R2 SRS_PostInstaller;SRS PostInstaller Service;c:\program files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe [28.11.2005 12:06 31744] R3 DniVap;SafeNet WAN Miniport (VA);c:\windows\system32\drivers\vap.sys [31.01.2007 11:01 36188] R3 wowfilter;WOW XT Filter Driver;c:\windows\system32\drivers\WOWFilter.sys [28.11.2005 12:06 19456] S2 gupdate;Google Update Service (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?] S2 SNM WLAN Service;SNM WLAN Service;c:\program files\SAMSUNG\Samsung Network Manager\SNMWLANService.exe [28.05.2005 08:35 36864] S3 SUEPD;SUE NDIS Protocol Driver;c:\windows\system32\drivers\SUE_PD.sys [20.06.2008 23:07 19840] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] getPlusHelper REG_MULTI_SZ getPlusHelper . Inhalt des "geplante Tasks" Ordners . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.de/ IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: Senden an &Bluetooth-Gerät... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm TCP: {695B57C1-1A75-454E-B7F7-AA7A0E90A072} = TCP: {A933426E-4E69-43A5-B75C-A4EEE9D6F76A} = DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\***\Application Data\Mozilla\Firefox\Profiles\zvs5iub8.***\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.de FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Ext: Advertising Cookie Opt-out: optout@google.com - %profile%\extensions\optout@google.com FF - Ext: IE Tab Plus: ietab@ip.cn - %profile%\extensions\ietab@ip.cn FF - Ext: Adobe DLM (powered by getPlus(R)): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . - - - - Entfernte verwaiste Registrierungseinträge - - - - . ShellIconOverlayIdentifiers-{8ABABC80-67A4-4494-BF3F-A0D2AB31D39F} - (no file) AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9b.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2011-03-25 21:57 Windows 5.1.2600 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\ . Zeit der Fertigstellung: 2011-03-25 21:59:27 ComboFix-quarantined-files.txt 2011-03-25 20:59 . Vor Suchlauf: 37.604.007.936 bytes free Nach Suchlauf: 37.592.354.816 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn . - - End Of File - - 77DB21B80FF0DC03377D0A623FB464AE |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Hi Arne, hier das Logfile und nochmal vielen, vielen Dank für Deine Mühen bisher. Gruß shaiko 2011/03/26 20:55:46.0484 0368 TDSS rootkit removing tool Mar 10 2011 12:26:28 2011/03/26 20:55:46.0843 0368 ================================================================================ 2011/03/26 20:55:46.0843 0368 SystemInfo: 2011/03/26 20:55:46.0843 0368 2011/03/26 20:55:46.0843 0368 OS Version: 5.1.2600 ServicePack: 2.0 2011/03/26 20:55:46.0843 0368 Product type: Workstation 2011/03/26 20:55:46.0843 0368 ComputerName: *** 2011/03/26 20:55:46.0843 0368 UserName: *** 2011/03/26 20:55:46.0843 0368 Windows directory: C:\WINDOWS 2011/03/26 20:55:46.0843 0368 System windows directory: C:\WINDOWS 2011/03/26 20:55:46.0843 0368 Processor architecture: Intel x86 2011/03/26 20:55:46.0843 0368 Number of processors: 2 2011/03/26 20:55:46.0843 0368 Page size: 0x1000 2011/03/26 20:55:46.0843 0368 Boot type: Normal boot 2011/03/26 20:55:46.0843 0368 ================================================================================ 2011/03/26 20:55:47.0078 0368 Initialize success 2011/03/26 20:56:12.0078 2504 ================================================================================ 2011/03/26 20:56:12.0078 2504 Scan started 2011/03/26 20:56:12.0078 2504 Mode: Manual; 2011/03/26 20:56:12.0078 2504 ================================================================================ 2011/03/26 20:56:12.0390 2504 61883 (86d7b1e70661d754685b9ac6d749aae5) C:\WINDOWS\system32\DRIVERS\61883.sys 2011/03/26 20:56:12.0500 2504 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/03/26 20:56:12.0531 2504 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 2011/03/26 20:56:12.0578 2504 ADIHdAudAddService (ff1c174f7d55da14e04d561a5a181a02) C:\WINDOWS\system32\drivers\ADIHdAud.sys 2011/03/26 20:56:12.0656 2504 AEAudioService (c984de22ed71414abc42c1e03d412e33) C:\WINDOWS\system32\drivers\AEAudio.sys 2011/03/26 20:56:12.0734 2504 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys 2011/03/26 20:56:12.0781 2504 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 2011/03/26 20:56:12.0890 2504 AgereSoftModem (c41a5740468d0b9cb46e6390a0e15ce3) C:\WINDOWS\system32\DRIVERS\AGRSM.sys 2011/03/26 20:56:13.0234 2504 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 2011/03/26 20:56:13.0343 2504 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/03/26 20:56:13.0375 2504 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/03/26 20:56:13.0421 2504 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/03/26 20:56:13.0468 2504 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/03/26 20:56:13.0578 2504 Avc (87c223adb8f7596b31caae3c67b16ddd) C:\WINDOWS\system32\DRIVERS\avc.sys 2011/03/26 20:56:13.0703 2504 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys 2011/03/26 20:56:13.0765 2504 avgntflt (47b879406246ffdced59e18d331a0e7d) C:\WINDOWS\system32\DRIVERS\avgntflt.sys 2011/03/26 20:56:13.0828 2504 avipbb (5fedef54757b34fb611b9ec8fb399364) C:\WINDOWS\system32\DRIVERS\avipbb.sys 2011/03/26 20:56:13.0875 2504 bcm4sbxp (78e7b52da292fa90bad2f887bbf22159) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 2011/03/26 20:56:13.0906 2504 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/03/26 20:56:13.0953 2504 BsStor (c7552016bb1349be87324637c4d8a89f) C:\WINDOWS\system32\drivers\BsStor.sys 2011/03/26 20:56:14.0031 2504 BsUDF (a2afd1a4b56b6ae4351587c77e10658d) C:\WINDOWS\system32\drivers\BsUDF.sys 2011/03/26 20:56:14.0125 2504 BTKRNL (54e368a1768c627f2adb8ab5624d0bc4) C:\WINDOWS\system32\DRIVERS\btkrnl.sys 2011/03/26 20:56:14.0234 2504 BTSERIAL (8aeca4330654da58423e7fe03a704513) C:\WINDOWS\System32\drivers\btserial.sys 2011/03/26 20:56:14.0265 2504 BTWUSB (fca94255e0a0e65c7c93530bdf10adca) C:\WINDOWS\system32\Drivers\btwusb.sys 2011/03/26 20:56:14.0359 2504 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/03/26 20:56:14.0406 2504 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/03/26 20:56:14.0484 2504 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/03/26 20:56:14.0546 2504 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/03/26 20:56:14.0593 2504 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/03/26 20:56:14.0640 2504 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 2011/03/26 20:56:14.0718 2504 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys 2011/03/26 20:56:14.0828 2504 Crypto (c56a413535292d9e43c563bbf946cbc1) C:\WINDOWS\system32\drivers\Crypto.sys 2011/03/26 20:56:14.0953 2504 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/03/26 20:56:15.0015 2504 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 2011/03/26 20:56:15.0156 2504 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 2011/03/26 20:56:15.0203 2504 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/03/26 20:56:15.0250 2504 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 2011/03/26 20:56:15.0328 2504 DNE (c86fbf607445bf693450d84b775f168c) C:\WINDOWS\system32\DRIVERS\dne2000.sys 2011/03/26 20:56:15.0375 2504 DniVap (88ea1b2acdd0536661d67fdd2f030dd2) C:\WINDOWS\system32\DRIVERS\vap.sys 2011/03/26 20:56:15.0437 2504 DOSMEMIO (8a4cb9438571814b128b6dc30d698064) C:\WINDOWS\System32\MEMIO.SYS 2011/03/26 20:56:15.0515 2504 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/03/26 20:56:15.0562 2504 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/03/26 20:56:15.0593 2504 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys 2011/03/26 20:56:15.0656 2504 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 2011/03/26 20:56:15.0718 2504 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys 2011/03/26 20:56:15.0781 2504 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/03/26 20:56:15.0828 2504 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/03/26 20:56:15.0875 2504 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/03/26 20:56:15.0906 2504 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/03/26 20:56:15.0968 2504 HdAudAddService (2a013e7530beab6e569faa83f517e836) C:\WINDOWS\system32\drivers\HdAudio.sys 2011/03/26 20:56:16.0015 2504 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/03/26 20:56:16.0078 2504 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/03/26 20:56:16.0218 2504 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/03/26 20:56:16.0328 2504 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/03/26 20:56:16.0375 2504 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/03/26 20:56:16.0484 2504 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/03/26 20:56:16.0500 2504 ip6fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/03/26 20:56:16.0531 2504 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/03/26 20:56:16.0562 2504 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/03/26 20:56:16.0609 2504 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/03/26 20:56:16.0640 2504 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/03/26 20:56:16.0703 2504 IPSECDRV (e101e53684f0f3da7558e0c2dbee2a6f) C:\WINDOWS\system32\Drivers\IPSECDRV.sys 2011/03/26 20:56:16.0781 2504 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/03/26 20:56:16.0843 2504 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/03/26 20:56:16.0906 2504 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/03/26 20:56:16.0968 2504 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/03/26 20:56:17.0031 2504 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys 2011/03/26 20:56:17.0062 2504 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/03/26 20:56:17.0171 2504 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/03/26 20:56:17.0203 2504 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 2011/03/26 20:56:17.0312 2504 motmodem (c9f96f5c50bcdfa2a6ee996291ea062a) C:\WINDOWS\system32\DRIVERS\motmodem.sys 2011/03/26 20:56:17.0328 2504 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/03/26 20:56:17.0390 2504 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/03/26 20:56:17.0421 2504 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/03/26 20:56:17.0500 2504 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/03/26 20:56:17.0578 2504 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/03/26 20:56:17.0640 2504 MSDV (6dd721dfd2648f3f6d5808b5ba6cb095) C:\WINDOWS\system32\DRIVERS\msdv.sys 2011/03/26 20:56:17.0656 2504 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 2011/03/26 20:56:17.0718 2504 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/03/26 20:56:17.0765 2504 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/03/26 20:56:17.0828 2504 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/03/26 20:56:17.0890 2504 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/03/26 20:56:17.0921 2504 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/03/26 20:56:17.0953 2504 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 2011/03/26 20:56:18.0000 2504 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/03/26 20:56:18.0031 2504 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 2011/03/26 20:56:18.0078 2504 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/03/26 20:56:18.0125 2504 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/03/26 20:56:18.0187 2504 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/03/26 20:56:18.0203 2504 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/03/26 20:56:18.0234 2504 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/03/26 20:56:18.0265 2504 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/03/26 20:56:18.0343 2504 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/03/26 20:56:18.0390 2504 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys 2011/03/26 20:56:18.0421 2504 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 2011/03/26 20:56:18.0500 2504 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/03/26 20:56:18.0546 2504 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/03/26 20:56:18.0765 2504 nv (3070eb78e5b7f48d390d32c40437335e) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2011/03/26 20:56:18.0968 2504 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/03/26 20:56:19.0046 2504 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/03/26 20:56:19.0109 2504 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 2011/03/26 20:56:19.0140 2504 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\drivers\Parport.sys 2011/03/26 20:56:19.0171 2504 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/03/26 20:56:19.0234 2504 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/03/26 20:56:19.0250 2504 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/03/26 20:56:19.0328 2504 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/03/26 20:56:19.0359 2504 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 2011/03/26 20:56:19.0546 2504 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/03/26 20:56:19.0609 2504 Processor (0d97d88720a4087ec93af7dbb303b30a) C:\WINDOWS\system32\DRIVERS\processr.sys 2011/03/26 20:56:19.0640 2504 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/03/26 20:56:19.0687 2504 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/03/26 20:56:19.0812 2504 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/03/26 20:56:19.0859 2504 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/03/26 20:56:19.0906 2504 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/03/26 20:56:19.0921 2504 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/03/26 20:56:19.0984 2504 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/03/26 20:56:20.0000 2504 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/03/26 20:56:20.0031 2504 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/03/26 20:56:20.0125 2504 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/03/26 20:56:20.0203 2504 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/03/26 20:56:20.0281 2504 rimmptsk (7a6648b61661b1421ffab762e391e33f) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys 2011/03/26 20:56:20.0312 2504 rimsptsk (8f7012d1b6a71ee9c23ce93dcdbf9f4b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys 2011/03/26 20:56:20.0359 2504 rismxdp (3ac17802740c3a4764dc9750e92e6233) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys 2011/03/26 20:56:20.0437 2504 sdbus (02fc71b020ec8700ee8a46c58bc6f276) C:\WINDOWS\system32\DRIVERS\sdbus.sys 2011/03/26 20:56:20.0484 2504 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/03/26 20:56:20.0546 2504 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\drivers\Serial.sys 2011/03/26 20:56:20.0578 2504 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/03/26 20:56:20.0703 2504 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/03/26 20:56:20.0781 2504 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys 2011/03/26 20:56:20.0828 2504 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/03/26 20:56:20.0890 2504 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/03/26 20:56:20.0937 2504 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 2011/03/26 20:56:20.0984 2504 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/03/26 20:56:21.0046 2504 SUEPD (c0137b5947ae3d3fc1c17ba6fdfb3dad) C:\WINDOWS\system32\DRIVERS\SUE_PD.sys 2011/03/26 20:56:21.0093 2504 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/03/26 20:56:21.0156 2504 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 2011/03/26 20:56:21.0421 2504 SynTP (1dbc86da355b5db35174f862c110fd09) C:\WINDOWS\system32\DRIVERS\SynTP.sys 2011/03/26 20:56:21.0468 2504 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/03/26 20:56:21.0531 2504 Tcpip (90caff4b094573449a0872a0f919b178) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/03/26 20:56:21.0593 2504 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/03/26 20:56:21.0625 2504 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/03/26 20:56:21.0640 2504 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/03/26 20:56:21.0718 2504 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 2011/03/26 20:56:21.0875 2504 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys 2011/03/26 20:56:21.0953 2504 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/03/26 20:56:22.0000 2504 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/03/26 20:56:22.0031 2504 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/03/26 20:56:22.0078 2504 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/03/26 20:56:22.0140 2504 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/03/26 20:56:22.0187 2504 usbser (49106ee29074e6a3d3ac9e24c6d791d8) C:\WINDOWS\system32\DRIVERS\usbser.sys 2011/03/26 20:56:22.0265 2504 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/03/26 20:56:22.0343 2504 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/03/26 20:56:22.0390 2504 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 2011/03/26 20:56:22.0453 2504 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/03/26 20:56:22.0593 2504 w39n51 (b1f126e7e28877106d60e6ff3998d033) C:\WINDOWS\system32\DRIVERS\w39n51.sys 2011/03/26 20:56:22.0703 2504 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/03/26 20:56:22.0781 2504 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 2011/03/26 20:56:22.0859 2504 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/03/26 20:56:22.0953 2504 WmiAcpi (ae2c8544e747c20062db27456ea2d67a) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 2011/03/26 20:56:23.0031 2504 wowfilter (bc69c990fa6be63d0af3719f92e0936d) C:\WINDOWS\system32\drivers\wowfilter.sys 2011/03/26 20:56:23.0093 2504 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 2011/03/26 20:56:23.0125 2504 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/03/26 20:56:23.0203 2504 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/03/26 20:56:23.0234 2504 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/03/26 20:56:23.0468 2504 ================================================================================ 2011/03/26 20:56:23.0468 2504 Scan finished 2011/03/26 20:56:23.0468 2504 ================================================================================ |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen. Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst. Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
Themen zu Windows Recovery gibt ständig Warnungen, kein Zugriff mehr auf Festplatte
adblock, antivir, avgntflt.sys, avira, bho, checkpoint, computer, crypto, desktop, disabletaskmgr, error, eudora, excel, failed, festplatte, firefox, flash player, frage, hdaudio.sys, helper, jar_cache, location, logfile, microsoft office word, msvcr80.dll, object, office 2007, oldtimer, otl-scan, otl.exe, plug-in, pum.hijack.taskmanager, registry, safer networking, saver, sched.exe, searchplugins, security, security update, senden, server, shell32.dll, shortcut, shut down, software, start menu, system, updates, windows, windows recovery, windows updates, windows xp, zone alarm |