ruthmeral | 06.12.2010 21:08 | Hi rea,
dake für deine Antwort!
Ich habe Schritt 1) komplett machen können, hier die Logfiles: Code:
OTL Extras logfile created on: 06.12.2010 20:00:17 - Run 2
OTL by OldTimer - Version Folder = C:\Users\ruthmeral\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 43,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 67,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 88,15 Gb Total Space | 48,82 Gb Free Space | 55,38% Space Free | Partition Type: NTFS
Drive D: | 50,89 Gb Total Space | 50,81 Gb Free Space | 99,83% Space Free | Partition Type: NTFS
Computer Name: RUTHMERAL-PC | User Name: ruthmeral | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== Firewall Settings ==========
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
"{35022BA8-F78E-42E2-BCC6-86375ABF6664}" = lport=445 | protocol=6 | dir=in | app=system |
"{37F940DD-853A-49DE-9213-22805D7B6842}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{39AD47B5-0668-4715-B1D1-F8FE2A6B2BF9}" = lport=138 | protocol=17 | dir=in | app=system |
"{3BA9B1F6-410F-474E-9554-D37DDF1958DE}" = rport=445 | protocol=6 | dir=out | app=system |
"{54014D48-D0F2-44C2-A726-3805099F86B2}" = lport=137 | protocol=17 | dir=in | app=system |
"{62E8CE25-FB30-4987-88DF-D640C9C2C779}" = rport=139 | protocol=6 | dir=out | app=system |
"{7354BA13-D452-4572-B8F3-0010DC8B4423}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B17C4238-BFEE-4DC1-9417-6E7CF2AC0918}" = rport=138 | protocol=17 | dir=out | app=system |
"{C3B906ED-6F29-416D-9792-C5875AF87EB4}" = rport=137 | protocol=17 | dir=out | app=system |
"{C726397B-2F22-45AC-8E9E-0B411B2A56C9}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{CCF3BD2A-BA0B-4741-893C-0DE9E20F573E}" = lport=139 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
"{01CDE996-E1B6-437D-A120-34B59993EB25}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{1958473D-E642-4CA1-BC96-5743F1606E7B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{340E9C23-DE14-44A6-8125-7D130B271D4B}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{463BBACC-C624-49CD-957F-6BFCFA00F9CD}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8F7C56A6-F9C3-45A8-BB11-4E0A9BF92617}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{92D5E5CB-9840-46A3-B32F-EC801A2FB748}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AF554E26-FCB4-429F-A906-794A62BC151D}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe |
"{B991874F-400E-4268-8E0D-B006482C7524}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{C0AAD67B-D63D-44FF-AA1F-F1C14E753317}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{D078DE76-2038-44C8-B69B-B1AC2A43A1CA}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{E65727EE-C5DD-43CC-87C1-2EE5BE582A5C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"TCP Query User{824FBDCF-00EC-4E56-8DA3-0BA6B8B71AA5}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"TCP Query User{A0CFD0B0-D893-4D81-8BA5-0632220FD1DD}C:\program files\miranda im\miranda32.exe" = protocol=6 | dir=in | app=c:\program files\miranda im\miranda32.exe |
"TCP Query User{CE8E0072-F404-41BA-8104-396ADB11BBFB}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"TCP Query User{F87D4B81-1442-4530-B3C7-8CA9538BF216}C:\program files\pidgin\pidgin.exe" = protocol=6 | dir=in | app=c:\program files\pidgin\pidgin.exe |
"UDP Query User{4F870C1E-0002-4A52-A5F8-9EA0CF94F565}C:\program files\pidgin\pidgin.exe" = protocol=17 | dir=in | app=c:\program files\pidgin\pidgin.exe |
"UDP Query User{60E61A42-762A-4B79-A6AF-28344763A6FF}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"UDP Query User{8D61CF19-B8F8-480A-90CC-DB4413E41B6C}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"UDP Query User{A4C5A896-BFD4-4B4A-9DB4-596BFFDD6325}C:\program files\miranda im\miranda32.exe" = protocol=17 | dir=in | app=c:\program files\miranda im\miranda32.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 05.12.2010 15:45:08 | Computer Name = ruthmeral-PC | Source = Application Hang | ID = 1002
Description = Programm firefox.exe, Version arbeitet nicht mehr mit Windows
zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen
für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem
zu suchen. Prozess-ID: 24c Anfangszeit: 01cb94b3a580ab60 Zeitpunkt der Beendigung:
Error - 05.12.2010 15:51:05 | Computer Name = ruthmeral-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung plugin-container.exe, Version, Zeitstempel
0x4cc7add9, fehlerhaftes Modul ntdll.dll, Version 6.0.6000.16386, Zeitstempel 0x4549bdc9,
Ausnahmecode 0xc0000005, Fehleroffset 0x00042e7b, Prozess-ID 0xe78, Anwendungsstartzeit
Error - 05.12.2010 15:51:11 | Computer Name = ruthmeral-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung AcroRd32.exe, Version, Zeitstempel
0x446abf60, fehlerhaftes Modul unknown, Version, Zeitstempel 0x00000000,
Ausnahmecode 0xc0000005, Fehleroffset 0x0c2eff4c, Prozess-ID 0x15e4, Anwendungsstartzeit
Error - 05.12.2010 16:07:13 | Computer Name = ruthmeral-PC | Source = VSS | ID = 12289
Description =
Error - 05.12.2010 16:18:17 | Computer Name = ruthmeral-PC | Source = WerSvc | ID = 5007
Description =
Error - 05.12.2010 17:07:55 | Computer Name = ruthmeral-PC | Source = WerSvc | ID = 5007
Description =
Error - 05.12.2010 18:22:40 | Computer Name = ruthmeral-PC | Source = EventSystem | ID = 4621
Description =
Error - 05.12.2010 18:42:44 | Computer Name = ruthmeral-PC | Source = WerSvc | ID = 5007
Description =
Error - 05.12.2010 20:13:30 | Computer Name = ruthmeral-PC | Source = WerSvc | ID = 5007
Description =
Error - 06.12.2010 03:17:40 | Computer Name = ruthmeral-PC | Source = WerSvc | ID = 5007
Description =
[ System Events ]
Error - 01.11.2010 09:11:41 | Computer Name = ruthmeral-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 01.11.2010 09:27:42 | Computer Name = ruthmeral-PC | Source = BROWSER | ID = 8032
Description =
Error - 01.11.2010 10:51:09 | Computer Name = ruthmeral-PC | Source = DCOM | ID = 10010
Description =
Error - 01.11.2010 12:25:15 | Computer Name = ruthmeral-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
2, Funktion 0. Wenden Sie sich an den Systemhersteller, um technische Unterstützung
zu erhalten.
Error - 01.11.2010 12:25:15 | Computer Name = ruthmeral-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
5, Funktion 0. Wenden Sie sich an den Systemhersteller, um technische Unterstützung
zu erhalten.
Error - 01.11.2010 12:25:15 | Computer Name = ruthmeral-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
6, Funktion 0. Wenden Sie sich an den Systemhersteller, um technische Unterstützung
zu erhalten.
Error - 01.11.2010 12:25:16 | Computer Name = ruthmeral-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
7, Funktion 0. Wenden Sie sich an den Systemhersteller, um technische Unterstützung
zu erhalten.
Error - 01.11.2010 12:25:34 | Computer Name = ruthmeral-PC | Source = atikmdag | ID = 43034
Description = Unknown EDID version
Error - 01.11.2010 12:27:16 | Computer Name = ruthmeral-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 01.11.2010 12:34:12 | Computer Name = ruthmeral-PC | Source = BROWSER | ID = 8032
Description =
< End of report > Code:
OTL logfile created on: 06.12.2010 20:00:17 - Run 2
OTL by OldTimer - Version Folder = C:\Users\ruthmeral\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 43,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 67,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 88,15 Gb Total Space | 48,82 Gb Free Space | 55,38% Space Free | Partition Type: NTFS
Drive D: | 50,89 Gb Total Space | 50,81 Gb Free Space | 99,83% Space Free | Partition Type: NTFS
Computer Name: RUTHMERAL-PC | User Name: ruthmeral | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010.12.06 19:22:53 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\ruthmeral\Downloads\OTL.exe
PRC - [2010.11.04 21:04:21 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2010.11.04 21:04:20 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.11.04 21:04:20 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2010.10.31 05:15:43 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.10.30 03:14:35 | 001,232,896 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2010.10.27 07:13:18 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2010.10.27 07:13:18 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\plugin-container.exe
PRC - [2010.09.16 21:04:06 | 001,164,584 | ---- | M] () -- C:\Programme\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.08.13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010.05.20 22:59:30 | 011,312,128 | ---- | M] ( -- C:\Programme\ 3\program\soffice.bin
PRC - [2010.05.20 22:59:28 | 011,318,784 | ---- | M] ( -- C:\Programme\ 3\program\soffice.exe
PRC - [2010.01.14 21:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2008.12.04 13:24:30 | 000,665,424 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Programme\Epson Software\Event Manager\EEventManager.exe
PRC - [2008.08.29 13:58:16 | 001,528,608 | ---- | M] (Cisco Systems, Inc.) -- C:\Programme\Cisco Systems\VPN Client\cvpnd.exe
PRC - [2007.08.08 00:01:08 | 001,006,264 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Defender\MSASCui.exe
PRC - [2007.06.29 00:15:06 | 000,352,256 | ---- | M] (SAMSUNG Electronics co., LTD.) -- C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe
PRC - [2007.06.28 10:57:52 | 000,085,672 | ---- | M] () -- C:\Programme\Samsung\Samsung Update Plus\SLUTrayNotifier.exe
PRC - [2007.06.13 05:11:30 | 004,489,216 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007.06.01 11:36:00 | 000,684,032 | ---- | M] (SAMSUNG Electronics) -- C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2007.04.26 03:20:48 | 000,045,056 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
PRC - [2007.04.24 13:49:02 | 000,565,248 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2007.04.24 10:50:32 | 000,723,760 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2006.11.02 13:35:35 | 000,643,072 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Games\Solitaire\Solitaire.exe
PRC - [2006.10.05 04:10:12 | 000,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2006.04.14 02:07:20 | 028,933,976 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
========== Modules (SafeList) ==========
MOD - [2010.12.06 19:22:53 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\ruthmeral\Downloads\OTL.exe
MOD - [2006.11.02 10:38:57 | 001,648,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2010.11.04 21:04:21 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.11.04 21:04:20 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010.08.13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2008.08.29 13:58:16 | 001,528,608 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
SRV - [2007.08.08 00:01:07 | 000,265,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.06.28 10:54:42 | 000,073,728 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe -- (Samsung Update Plus)
SRV - [2006.10.05 04:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http:\\
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.10.31 20:07:57 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.10.31 20:07:57 | 000,000,000 | ---D | M]
[2010.10.29 17:19:25 | 000,000,000 | ---D | M] -- C:\Users\ruthmeral\AppData\Roaming\mozilla\Extensions
[2010.12.06 01:24:40 | 000,000,000 | ---D | M] -- C:\Users\ruthmeral\AppData\Roaming\mozilla\Firefox\Profiles\9xtv64ye.default\extensions
[2010.11.01 23:16:49 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\ruthmeral\AppData\Roaming\mozilla\Firefox\Profiles\9xtv64ye.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.11.10 16:49:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ruthmeral\AppData\Roaming\mozilla\Firefox\Profiles\9xtv64ye.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.10.30 13:31:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ruthmeral\AppData\Roaming\mozilla\Firefox\Profiles\9xtv64ye.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010.10.29 21:55:12 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.10.29 21:55:12 | 000,000,000 | ---D | M] (Skype extension) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.10.27 06:44:13 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.10.27 06:44:13 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.10.27 06:44:13 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.10.27 06:44:13 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.10.27 06:44:13 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programme\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EEventManager] C:\Programme\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [EPSON SX210 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIFDE.EXE (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Users\ruthmeral\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ 3.2.lnk = C:\Programme\ 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoHotStart = 0
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\ruthmeral\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\ [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
< End of report > Was Schritt 2) angeht:
Habe alles genau befolgt und den gmer scan gestartet, der lief auch anfangs glatt, bis zu einem bestimmten Punkt, wo unten links etwas angezeigt wurde, ich glaube es war \cfds oder \cdfs. Dann hängte sich der Computer auf, zweimal ist mir das passiert...
Ich habe ihn dann einfach ausgeschaltet und neu gestartet. Was hat das zu bedeuten? Hätte ich warten sollen, ob noch was passiert? Es funktionierte halt nix mehr, auch kein Strg Alt Entf...
Lieben Gruß,
Ruth |