Hallo auch und vielen Dank für die schnelle Unterstützung. Auch wenn manche es anders sehen - ich bin für soetwas sehr dankbar.
OTL.txt:
OTL Logfile: Code:
OTL logfile created on: 13.11.2012 11:20:04 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = c:\dokumente und einstellungen\Username\desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,87 Gb Total Physical Memory | 1,26 Gb Available Physical Memory | 67,35% Memory free
3,72 Gb Paging File | 3,34 Gb Available in Paging File | 89,64% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 108,67 Gb Total Space | 86,07 Gb Free Space | 79,20% Space Free | Partition Type: NTFS
Computer Name: Notebook03| User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - c:\Dokumente und Einstellungen\Username\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Eset\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Programme\Eset\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\Programme\gateProtect\VPN Client\bin\Service.exe ()
PRC - C:\Programme\gateProtect\VPN Client\bin\VpnClient.exe (gateProtect Aktiengesellschaft Germany)
PRC - C:\Programme\gateProtect\VPN Client\bin\openvpn.exe ()
PRC - C:\WINDOWS\system32\DKabcoms.exe ( )
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
PRC - C:\Programme\FreePDF_XP\fpassist.exe (shbox.de)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Programme\UltraVNC\winvnc.exe (UltraVNC)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\sdb4mlm.dll ()
MOD - C:\WINDOWS\system32\SaXPWIA.dll ()
MOD - C:\Programme\gateProtect\VPN Client\bin\Service.exe ()
MOD - C:\Programme\gateProtect\VPN Client\bin\openvpn.exe ()
MOD - C:\Programme\gateProtect\VPN Client\bin\libssl32.dll ()
MOD - C:\Programme\gateProtect\VPN Client\bin\libeay32.dll ()
MOD - C:\Programme\gateProtect\VPN Client\bin\libpkcs11-helper-1.dll ()
MOD - C:\Programme\Plustek\Plustek SmartOffice PS286\Scanapi.dll ()
MOD - C:\Programme\Adobe\Reader 8.0\Reader\AdobeXMP.dll ()
MOD - C:\WINDOWS\system32\bcm1xsup.dll ()
MOD - C:\WINDOWS\system32\redmonnt.dll ()
MOD - C:\WINDOWS\system32\HPBHEALR.DLL ()
========== Services (SafeList) ==========
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe
Systems Incorporated)
SRV - (ESHASRV) -- C:\Programme\Eset\ESET NOD32 Antivirus\EShaSrv.exe (ESET)
SRV - (EhttpSrv) -- C:\Programme\Eset\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn) -- C:\Programme\Eset\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (PSEXESVC) -- C:\WINDOWS\PSEXESVC.EXE (Sysinternals)
SRV - (odserv) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (GPVPNService) -- C:\Programme\gateProtect\VPN Client\bin\Service.exe ()
SRV - (dkab_device) -- C:\WINDOWS\system32\DKabcoms.exe ( )
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (winvnc) -- C:\Programme\UltraVNC\winvnc.exe (UltraVNC)
========== Driver Services (SafeList) ==========
DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (OMCI) -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (eamon) -- C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (ehdrv) -- C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (epfwtdir) -- C:\WINDOWS\system32\drivers\epfwtdir.sys (ESET)
DRV - (SSPORT) -- C:\WINDOWS\system32\drivers\SSPORT.sys (Samsung Electronics)
DRV - (tap0901) -- C:\WINDOWS\system32\drivers\tap0901.sys (The OpenVPN Project)
DRV - (BCM43XX) -- C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rimmptsk) -- C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (odysseyIM4) -- C:\WINDOWS\system32\drivers\odysseyIM4.sys (Funk Software, Inc.)
DRV - (vnccom) -- C:\WINDOWS\system32\drivers\vnccom.SYS (RDV Soft)
DRV - (vncdrv) -- C:\WINDOWS\system32\drivers\vncdrv.sys (RDV Soft)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
hxxp://www.google.de
IE - HKU\S-1-5-21-1825349137-338196624-3985880893-1184\..\SearchScopes,DefaultScope =
{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1825349137-338196624-3985880893-1184\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:
"URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-1825349137-338196624-3985880893-1184\Software\Microsoft\Windows\CurrentVersion\Internet
Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page
Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page
Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page
Redirect Cache_TIMESTAMP = 56 52 7F E4 0D 8C CD 01 [binary data]
IE - HKU\S-1-5-21-1825349137-338196624-3985880893-1226\..\SearchScopes,DefaultScope =
{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1825349137-338196624-3985880893-1226\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:
"URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-1825349137-338196624-3985880893-1226\Software\Microsoft\Windows\CurrentVersion\Internet
Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
(Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5:
c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
O1 HOSTS File: ([2010.12.15 18:31:52 | 000,000,908 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 192.168.8.1 domainfs02
O1 - Hosts: 192.168.4.2. domainsrv02
O1 - Hosts: 192.168.3.2 domainsrv01
O1 - Hosts: 192.168.3.2 domain-server
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame
Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
(Sun Microsystems, Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Programme\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [egui] C:\Programme\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [FreePDF Assistant] C:\Programme\FreePDF_XP\fpassist.exe (shbox.de)
O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [WinVNC] C:\Programme\UltraVNC\WinVNC.exe (UltraVNC)
O4 - HKU\S-1-5-21-1825349137-338196624-3985880893-1184..\Run: [JHHUNHM] rundll32 "C:\Dokumente und
Einstellungen\Username\Anwendungsdaten\olepro32R.dll",wkoceupvmph File not found
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\DocAction (Plustek
SmartOffice PS286).lnk = C:\Programme\Plustek\Plustek SmartOffice PS286\DocuAction.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\IEDevTools present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Privacy present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Recovery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Safety present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Security present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\SQM present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylockeduserid = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1825349137-338196624-3985880893-1184\Software\Policies\Microsoft\Internet
Explorer\SearchScopes present
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDriveTypeAutoRun = 181
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoWindowsUpdate = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoSMHelp = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoSMMyPictures = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoStartMenuMyMusic = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoTaskGrouping = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoAutoTrayNotify = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoStartMenuPinnedList = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoSMConfigurePrograms = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoWelcomeScreen = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoWebServices = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoInternetOpenWith = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoPublishingWizard = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoOnlinePrintsWizard = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoManageMyComputerVerb = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoFolderOptions = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoNetConnectDisconnect = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDFSTab = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoHardwareTab = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoPropertiesMyComputer = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoPropertiesMyDocuments = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoPropertiesRecycleBin = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoCloseDragDropBands = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDesktopCleanupWizard = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
RestrictCpl = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoStartMenuNetworkPlaces = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoRecentDocsNetHood = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
GreyMSIAds = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
ForceStartMenuLogOff = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoThemesTab = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoActiveDesktop = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
SpecifyDefaultButtons = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Back = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Forward = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Stop = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Refresh = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Home = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Search = 2
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Favorites = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_History = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Folders = 2
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Fullscreen = 2
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Tools = 2
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_MailNews = 2
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Size = 2
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Print = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Edit = 2
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Discussions = 2
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Cut = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Copy = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Paste = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
Btn_Encoding = 2
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
DisallowRun = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 1 = teamviewer_setup_de.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 2 = teamviewerqs_de.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 3 = teamviewer_host_setup.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 4 = teamviewerqj_de.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 5 = teamviewer_.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 6 = teamviewer_desktop.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 7 = teamviewer_service.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 8 = tv_w32.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 9 = teamviewer.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 10 = teamviewerportable.zip
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Re
strictCpl: 1 = access.cpl (Microsoft Corporation)
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Re
strictCpl: 2 = desk.cpl (Microsoft Corporation)
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Re
strictCpl: 3 = Drucker und Faxgeräte
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Re
strictCpl: 4 = inetcpl.cpl (Microsoft Corporation)
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Re
strictCpl: 5 = main.cpl (Microsoft Corporation)
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Re
strictCpl: 6 = ncpa.cpl (Microsoft Corporation)
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Re
strictCpl: 7 = Netzwerkverbindungen
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
NoSizeChoice = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
NoVisualStyleChoice = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
NoColorChoice = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
NoDispAppearancePage = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
HideLogonScripts = 0
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
RunLogonScriptSync = 1
O7 - HKU\S-1-5-21-1825349137-338196624-3985880893-1226\Software\Policies\Microsoft\Internet
Explorer\SearchScopes present
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDriveTypeAutoRun = 145
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
DisallowRun = 1
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 1 = teamviewer_setup_de.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 2 = teamviewerqs_de.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 3 = teamviewer_host_setup.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 4 = teamviewerqj_de.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 5 = teamviewer_.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 6 = teamviewer_desktop.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 7 = teamviewer_service.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 8 = tv_w32.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 9 = teamviewer.exe
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Di
sallowRun: 10 = teamviewerportable.zip
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
HideLogonScripts = 0
O7 -
HKU\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
RunLogonScriptSync = 1
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Programme\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
(DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg
Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.4.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = domain.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{22EE4D86-E7E0-4173-A1D7-A824831BB6AE}:
DhcpNameServer = 192.168.4.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4E6FD560-B6A4-4E90-A33E-D443B7A988EB}:
DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame
Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame
Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame
Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame
Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\t-mobile - No CLSID value found
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame
Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft
Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies
Inc.)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.01.08 20:36:49 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{5ab0c3ca-be24-11dc-aeeb-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{5ab0c3ca-be24-11dc-aeeb-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5ab0c3ca-be24-11dc-aeeb-806d6172696f}\Shell\AutoRun\command - "" = D:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall
%SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE
/CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection
C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Sicherheitsupdate für Windows XP (KB923789)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection
C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB
/CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe
c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9309DD7E-EBFE-3C95-8B47-30D3A012F606} - .NET Framework
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C314CE45-3392-3B73-B4E1-139CD41CA933} - .NET Framework
ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\INF\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe"
"C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.11.13 11:20:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.11.13 08:18:05 | 000,517,804 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2012.11.13 08:18:05 | 000,494,358 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.11.13 08:18:05 | 000,084,902 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.11.13 08:18:04 | 000,101,656 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2012.11.13 07:58:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.11.11 12:15:31 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.11.12 12:02:48 | 000,000,884 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.09.06 10:59:38 | 000,950,585 | ---- | C] () -- C:\WINDOWS\System32\libiconv-2.dll
[2012.09.06 10:58:23 | 000,124,224 | R--- | C] () -- C:\WINDOWS\wiainst.exe
[2012.09.06 10:56:47 | 000,307,200 | ---- | C] () -- C:\WINDOWS\System32\SaXPWIA.dll
[2012.09.06 10:56:46 | 000,145,408 | ---- | C] () -- C:\WINDOWS\System32\SaXPUIEx.dll
[2012.09.06 10:56:19 | 000,024,064 | ---- | C] () -- C:\WINDOWS\System32\sdb4mlm.dll
[2012.09.06 09:51:43 | 000,026,280 | RHS- | C] () -- C:\Dokumente und Einstellungen\Admin\ntuser.pol
[2012.02.15 09:00:42 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011.11.02 13:18:18 | 000,368,640 | ---- | C] ( ) -- C:\WINDOWS\System32\lexlog.dll
[2011.11.02 13:17:39 | 000,851,968 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabusb1.dll
[2011.11.02 13:17:39 | 000,655,360 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabpmui.dll
[2011.11.02 13:17:39 | 000,339,968 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabiesc.dll
[2011.11.02 13:17:38 | 001,044,480 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabserv.dll
[2011.11.02 13:17:38 | 000,573,440 | ---- | C] ( ) -- C:\WINDOWS\System32\dkablmpm.dll
[2011.11.02 13:17:38 | 000,483,328 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabpar1.dll
[2011.11.02 13:17:37 | 000,864,256 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabip1.dll
[2011.11.02 13:17:37 | 000,454,656 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabiobj.dll
[2011.11.02 13:17:37 | 000,438,272 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabhcp.dll
[2011.11.02 13:17:37 | 000,364,544 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabinpa.dll
[2011.11.02 13:17:36 | 000,819,200 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabcomc.dll
[2011.11.02 13:17:36 | 000,586,992 | ---- | C] ( ) -- C:\WINDOWS\System32\DKabcoms.exe
[2011.11.02 13:17:36 | 000,376,832 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabcomm.dll
[2010.12.17 17:11:48 | 000,064,000 | ---- | C] () -- C:\WINDOWS\System32\CDASpl.dll
[2008.01.09 17:49:09 | 000,111,582 | RHS- | C] () -- C:\Dokumente und Einstellungen\All Users\ntuser.pol
========== ZeroAccess Check ==========
[2008.01.09 14:47:13 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 06:52:26 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 11:51:44 | 000,473,600 | ---- | M] (Microsoft
Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 06:52:34 | 000,273,920 | ---- | M] (Microsoft
Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2009.11.10 18:00:55 | 000,000,000 | ---D | M] -- C:\Dokumente und
Einstellungen\Admin\Anwendungsdaten\gateProtect
[2012.09.06 14:28:57 | 000,000,000 | ---D | M] -- C:\Dokumente und
Einstellungen\Admin\Anwendungsdaten\postgresql
[2012.09.06 11:00:44 | 000,000,000 | ---D | M] -- C:\Dokumente und
Einstellungen\Admin\Anwendungsdaten\Samsung
[2008.05.28 12:03:52 | 000,000,000 | ---D | M] -- C:\Dokumente und
Einstellungen\Administrator\Anwendungsdaten\gateProtect
[2008.01.09 18:02:07 | 000,000,000 | ---D | M] -- C:\Dokumente und
Einstellungen\Administrator.domain\Anwendungsdaten\gateProtect
[2012.09.06 13:48:57 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All
Users\Anwendungsdaten\catalog.wci
[2012.09.12 09:27:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET
[2008.01.09 18:02:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All
Users\Anwendungsdaten\gateProtect
[2012.05.15 08:15:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All
Users\Anwendungsdaten\GroupPolicy
[2008.01.11 12:57:49 | 000,000,000 | ---D | M] -- C:\Dokumente und
Einstellungen\Username\Anwendungsdaten\gateProtect
[2012.09.06 10:26:20 | 000,000,000 | ---D | M] -- C:\Dokumente und
Einstellungen\Username\Anwendungsdaten\ScanSoft
[2009.11.10 17:53:23 | 000,000,000 | ---D | M] -- C:\Dokumente und
Einstellungen\Username\Anwendungsdaten\TeamViewer
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2009.04.02 11:05:48 | 000,000,000 | ---D | M] -- C:\0e879178f524f79b48d972edae98ca
[2008.01.08 20:46:29 | 000,000,000 | ---D | M] -- C:\DELL
[2012.09.06 14:24:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen
[2012.05.09 11:05:26 | 000,000,000 | ---D | M] -- C:\f61568063dd41ca28217b41279f7a3
[2008.01.08 20:48:19 | 000,000,000 | ---D | M] -- C:\Intel
[2012.04.02 10:35:36 | 000,000,000 | ---D | M] -- C:\lj1015
[2008.01.09 17:53:35 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2012.09.06 12:05:51 | 000,000,000 | R--D | M] -- C:\Programme
[2009.09.16 09:33:28 | 000,000,000 | -HSD | M] -- C:\RECYCLER
[2012.09.06 11:00:40 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2012.11.13 07:59:20 | 000,000,000 | ---D | M] -- C:\WINDOWS
< %PROGRAMFILES%\*.exe >
Invalid Environment Variable: LOCALAPPDATA
< %systemroot%\*. /mp /s >
< C:\Windows\system32\*.tsp >
[2008.04.14 06:53:10 | 000,266,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\h323.tsp
[2008.04.14 06:53:10 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2008.04.14 06:53:10 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ipconf.tsp
[2008.04.14 06:53:10 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2008.04.14 06:53:10 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2008.04.14 06:53:10 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2008.04.14 06:53:10 | 000,207,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
[2008.01.08 20:34:27 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2008.01.08 20:41:46 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2012.11.12 12:02:48 | 000,000,884 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
< MD5 for: AGP440.SYS >
[2004.08.04 11:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 07:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 07:03:54 | 020,108,202 | ---- | M] () .cab file --
C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 --
C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 --
C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004.08.04 11:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 07:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 07:03:54 | 020,108,202 | ---- | M] () .cab file --
C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 --
C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 --
C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.04 11:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 --
C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008.04.14 06:52:12 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA --
C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 06:52:12 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA --
C:\WINDOWS\system32\eventlog.dll
[2004.08.04 11:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 --
C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2004.08.04 11:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=22FE1BE02EADDE1632E478E4125639E0 --
C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007.06.13 14:10:08 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=331ED93570BAF3CFE30340298762CD56 --
C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2008.04.14 06:52:46 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E --
C:\WINDOWS\explorer.exe
[2008.04.14 06:52:46 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E --
C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007.06.13 14:21:45 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=64D320C0E301EEDC5A4ADBBDC5024F7F --
C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: IASTOR.SYS >
[2007.07.12 22:35:02 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 --
C:\WINDOWS\dell\iastor\iastor.sys
< MD5 for: NETLOGON.DLL >
[2008.04.14 06:52:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 --
C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 06:52:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 --
C:\WINDOWS\system32\netlogon.dll
[2004.08.04 11:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C --
C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: NVATA.SYS >
[2006.10.18 23:31:38 | 000,105,472 | ---- | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A --
C:\WINDOWS\dell\nvraid\nvata.sys
< MD5 for: NVATABUS.SYS >
[2006.10.18 22:31:38 | 000,105,472 | ---- | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A --
C:\WINDOWS\dell\nvraid\NvAtaBus.sys
< MD5 for: SCECLI.DLL >
[2008.04.14 06:52:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 --
C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 06:52:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 --
C:\WINDOWS\system32\scecli.dll
[2004.08.04 11:00:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 --
C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
< MD5 for: USER32.DLL >
[2005.03.02 19:09:46 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A --
C:\WINDOWS\$NtUninstallKB925902$\user32.dll
[2007.03.08 16:36:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=492E166CFD26A50FB9160DB536FF7D2B --
C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2005.03.02 19:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF --
C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2004.08.04 11:00:00 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=56785FD5236D7B22CF471A6DA9DB46D8 --
C:\WINDOWS\$NtUninstallKB890859$\user32.dll
[2007.03.08 16:48:39 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=78785EFF8CB90CEC1862A4CCFD9A3C3A --
C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
[2008.04.14 06:52:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD --
C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.14 06:52:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD --
C:\WINDOWS\system32\user32.dll
< MD5 for: USERINIT.EXE >
[2008.04.14 06:53:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 --
C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 06:53:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 --
C:\WINDOWS\system32\userinit.exe
[2004.08.04 11:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 --
C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.04 11:00:00 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 --
C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 06:53:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A --
C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 06:53:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A --
C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2004.08.04 11:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 --
C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2004.08.04 11:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 --
C:\WINDOWS\system32\drivers\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2008.01.08 21:10:03 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2008.01.08 21:10:03 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2008.01.08 21:10:03 | 000,450,560 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %USERPROFILE%\*.* >
[2012.11.13 11:22:34 | 002,621,440 | -H-- | M] () -- C:\Dokumente und Einstellungen\Admin\NTUSER.DAT
[2012.11.13 11:32:12 | 000,001,024 | -H-- | M] () -- C:\Dokumente und Einstellungen\Admin\NTUSER.DAT.LOG
[2012.10.05 14:08:45 | 000,000,190 | -HS- | M] () -- C:\Dokumente und Einstellungen\Admin\ntuser.ini
[2012.09.06 09:51:43 | 000,026,280 | RHS- | M] () -- C:\Dokumente und Einstellungen\Admin\ntuser.pol
< %USERPROFILE%\Local Settings\Temp\*.exe >
< %USERPROFILE%\Local Settings\Temp\*.dll >
< %USERPROFILE%\Application Data\*.exe >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
>
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Kmode:
%SystemRoot%\system32\win32k.sys [2012.07.03 19:25:08 | 001,866,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary
data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows:
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On
SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3
ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
< End of report > --- --- ---
Extras.txt:
OTL Logfile: Code:
OTL Extras logfile created on: 13.11.2012 11:20:04 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = c:\dokumente und einstellungen\username\desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,87 Gb Total Physical Memory | 1,26 Gb Available Physical Memory | 67,35% Memory free
3,72 Gb Paging File | 3,34 Gb Available in Paging File | 89,64% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 108,67 Gb Total Space | 86,07 Gb Free Space | 79,20% Space Free | Partition Type: NTFS
Computer Name: Notebook03 | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_USERS\S-1-5-21-1825349137-338196624-3985880893-1184\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
[HKEY_USERS\S-1-5-21-1825349137-338196624-3985880893-1226\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications]
"Enabled" = 0
"AllowUserPrefMerge" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts]
"Enabled" = 0
"AllowUserPrefMerge" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings]
"AllowOutboundDestinationUnreachable" = 0
"AllowOutboundSourceQuench" = 0
"AllowRedirect" = 0
"AllowInboundEchoRequest" = 0
"AllowInboundRouterRequest" = 0
"AllowOutboundTimeExceeded" = 0
"AllowOutboundParameterProblem" = 0
"AllowInboundTimestampRequest" = 0
"AllowInboundMaskRequest" = 0
"AllowOutboundPacketTooBig" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging]
"LogDroppedPackets" = 0
"LogSuccessfulConnections" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings]
"Enabled" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
"Enabled" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
"Enabled" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\UPnPFramework]
"Enabled" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"DisableNotifications" = 1
"DisableUnicastResponsesToMulticastBroadcast" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\AuthorizedApplications]
"Enabled" = 0
"AllowUserPrefMerge" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\GloballyOpenPorts]
"AllowUserPrefMerge" = 0
"Enabled" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings]
"AllowOutboundDestinationUnreachable" = 0
"AllowOutboundSourceQuench" = 0
"AllowRedirect" = 0
"AllowInboundEchoRequest" = 0
"AllowInboundRouterRequest" = 0
"AllowOutboundTimeExceeded" = 0
"AllowOutboundParameterProblem" = 0
"AllowInboundTimestampRequest" = 0
"AllowInboundMaskRequest" = 0
"AllowOutboundPacketTooBig" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\RemoteAdminSettings]
"Enabled" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services\FileAndPrint]
"Enabled" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services\RemoteDesktop]
"Enabled" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services\UPnPFramework]
"Enabled" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Globa
llyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"5985:TCP" = 5985:TCP:*:Disabled:Windows-Remoteverwaltung
"80:TCP" = 80:TCP:*:Disabled:Windows-Remoteverwaltung - Kompatibilitätsmodus (HTTP eingehend)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Glo
ballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Autho
rizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft
Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network
Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\WINDOWS\system32\DKabcoms.exe" = C:\WINDOWS\system32\DKabcoms.exe:*:Enabled:Dell Enhanced TCP/IP -- ( )
"C:\WINDOWS\twain_32\Dell\DELL1265\SCNSearch\USDAgent.exe" =
C:\WINDOWS\twain_32\Dell\DELL1265\SCNSearch\USDAgent.exe:*:Enabled:Dell Scanner Discovery Module V2 -- ()
"C:\Programme\Dell\Dell B1265dnf Laser MFP\Dell Scan Assistant\USDAgent.exe" = C:\Programme\Dell\Dell B1265dnf
Laser MFP\Dell Scan Assistant\USDAgent.exe:*:Enabled:Dell B1265dnf Laser MFP Scan Assistant - USDAgent.exe -- ()
"C:\Programme\Gemeinsame Dateien\Common Desktop Agent\CDASrv.exe" = C:\Programme\Gemeinsame Dateien\Common
Desktop Agent\CDASrv.exe:*:Enabled:CDA Server -- ()
"C:\Programme\Dell\Dell Printer Manager\Dell.Application.exe" = C:\Programme\Dell\Dell Printer
Manager\Dell.Application.exe:*:Enabled:Dell Printer Manager -- (Dell Inc.)
"C:\Programme\Dell\Dell Printer Manager\Dell.OrderSupplies.exe" = C:\Programme\Dell\Dell Printer
Manager\Dell.OrderSupplies.exe:*:Enabled:Dell Order Supplies -- (Dell Inc.)
"C:\Programme\Dell\Dell Printer Manager\Dell.Alert.exe" = C:\Programme\Dell\Dell Printer
Manager\Dell.Alert.exe:*:Enabled:Dell Alert -- (Dell Inc.)
"C:\Programme\Dell\Dell Printer Manager\uninstall.exe" = C:\Programme\Dell\Dell Printer
Manager\uninstall.exe:*:Enabled:Dell uninstaller -- (Dell Inc.)
"C:\Programme\Dell\Dell Printer Manager\CDAS2PC\Dell.CDAS2PC.exe" = C:\Programme\Dell\Dell Printer
Manager\CDAS2PC\Dell.CDAS2PC.exe:*:Enabled:Dell CDA Scan2PC -- ()
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Aut
horizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft
Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network
Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\WINDOWS\system32\DKabcoms.exe" = C:\WINDOWS\system32\DKabcoms.exe:*:Enabled:Dell Enhanced TCP/IP -- ( )
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04DB82C1-94DF-45AE-88C4-C32489EE1E85}" = DI Capture
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{2DBE349F-FF05-42FE-81A9-2B3A0EC22BBE}" = Common Desktop Agent
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{4771CFBF-A680-419C-9447-BB9D3EAE12A1}" = ESET Endpoint Antivirus
"{612B9183-67A9-4B44-9877-2F059E35B86A}" = Broadcom 440x 10/100 Integrated Controller
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (German) 12
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office
2007 Service Pack 3 (SP3)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office
2007 Service Pack 3 (SP3)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office
2007 Service Pack 3 (SP3)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office
2007 Service Pack 3 (SP3)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office
2007 Service Pack 3 (SP3)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office
2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PROHYBRIDR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office
Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office
Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office
Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_PROHYBRIDR_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office
Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_PROHYBRIDR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office
2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office
2007 Service Pack 3 (SP3)
"{9BC1E722-AE07-46A3-B7A6-556DBE18E22A}" = SmarThru Office
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A8AD990E-355A-4413-8647-A9B168978423}_is1" = UltraVNC v1.0.2
"{A8D93648-9F7F-407D-915C-62044644C3DA}" = MSI to redistribute MS VS2005 CRT libraries
"{AC76BA86-7AD7-1031-7B44-A81000000003}" = Adobe Reader 8.1.1 - Deutsch
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU
"{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D01750A5-49E5-4BF4-92CC-F72F5F20DBEC}" = Adobe Flash Player 11 ActiveX
"{D9A717D8-6C94-43EA-9E83-7C2A5B7DFA65}" = Plustek SmartOffice PS286
"{EF40BAC3-372B-46F4-A32D-B37CF4217CE7}" = ATI Catalyst Control Center
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"4569969E1360D2854474C661EF9B4D54F143EB16" = Windows-Treiberpaket - Ricoh Company (rimsptsk) hdc (11/14/2006
6.00.01.04)
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"All ATI Software" = ATI - Dienstprogramm zur Deinstallation der Software
"ATI Display Driver" = ATI Display Driver
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"Dell B1265dnf Laser MFP" = Dell B1265dnf Laser MFP
"Dell B1265dnf Laser MFP Scan Assistant" = Dell B1265dnf Laser MFP Scan Assistant
"Dell_HostCD" = Dell Druckersoftware-Deinstallation
"FreePDF_XP" = FreePDF XP (Remove only)
"gateProtect VPN Client 3.0" = gateProtect VPN Client 3.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"iDRS(tm) OCR Software by I.R.I.S" = iDRS(tm) OCR Software by I.R.I.S
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU
Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROHYBRIDR" = 2007 Microsoft Office system
"Redirection Port Monitor" = RedMon - Redirection Port Monitor
"sv.net" = sv.net
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 12.11.2012 14:48:29 | Computer Name = Notebook03 | Source = AutoEnrollment | ID = 15
Description = Die automatische Zertifikatregistrierung für "lokaler Computer" konnte
keine Verbindung zum Active Directory (0x8007054b) herstellen. Die angegebene Domäne
ist nicht vorhanden oder es konnte keine Verbindung hergestellt werden. Die Registrierung
wird nicht durchgeführt.
Error - 12.11.2012 14:48:31 | Computer Name = Notebook03 | Source = Userenv | ID = 1054
Description = Der Domänencontrollername für das Computernetzwerk konnte nicht ermittelt
werden. (Die angegebene Domäne ist nicht vorhanden oder es konnte keine Verbindung
hergestellt werden. ). Die Verarbeitung der Gruppenrichtlinie wurde abgebrochen.
Error - 12.11.2012 15:04:43 | Computer Name = Notebook03 | Source = Userenv | ID = 1054
Description = Der Domänencontrollername für das Computernetzwerk konnte nicht ermittelt
werden. (Die angegebene Domäne ist nicht vorhanden oder es konnte keine Verbindung
hergestellt werden. ). Die Verarbeitung der Gruppenrichtlinie wurde abgebrochen.
Error - 12.11.2012 15:04:44 | Computer Name = Notebook03 | Source = AutoEnrollment | ID = 15
Description = Die automatische Zertifikatregistrierung für "lokaler Computer" konnte
keine Verbindung zum Active Directory (0x8007054b) herstellen. Die angegebene Domäne
ist nicht vorhanden oder es konnte keine Verbindung hergestellt werden. Die Registrierung
wird nicht durchgeführt.
Error - 12.11.2012 15:08:58 | Computer Name = Notebook03 | Source = Userenv | ID = 1054
Description = Der Domänencontrollername für das Computernetzwerk konnte nicht ermittelt
werden. (Die angegebene Domäne ist nicht vorhanden oder es konnte keine Verbindung
hergestellt werden. ). Die Verarbeitung der Gruppenrichtlinie wurde abgebrochen.
Error - 13.11.2012 02:59:11 | Computer Name = Notebook03 | Source = Userenv | ID = 1054
Description = Der Domänencontrollername für das Computernetzwerk konnte nicht ermittelt
werden. (Die angegebene Domäne ist nicht vorhanden oder es konnte keine Verbindung
hergestellt werden. ). Die Verarbeitung der Gruppenrichtlinie wurde abgebrochen.
Error - 13.11.2012 02:59:11 | Computer Name = Notebook03 | Source = AutoEnrollment | ID = 15
Description = Die automatische Zertifikatregistrierung für "lokaler Computer" konnte
keine Verbindung zum Active Directory (0x8007054b) herstellen. Die angegebene Domäne
ist nicht vorhanden oder es konnte keine Verbindung hergestellt werden. Die Registrierung
wird nicht durchgeführt.
Error - 13.11.2012 03:06:35 | Computer Name = Notebook03 | Source = Ci | ID = 4124
Description = Der Inhaltsindex auf c:\system volume information\catalog.wci ist
beschädigt. Fahren Sie den Indexdienst (cisvc) herunter, und starten Sie ihn erneut.
Error - 13.11.2012 03:06:35 | Computer Name = Notebook03 | Source = Ci | ID = 4126
Description = Die Metadaten des Inhaltsindex auf c:\system volume information\catalog.wci
werden aufgeräumt. Wiederherstellen des Indexes erfolgt automatisch durch erneutes
Filtern aller Dokumente.
Error - 13.11.2012 03:16:18 | Computer Name = Notebook03 | Source = Userenv | ID = 1054
Description = Der Domänencontrollername für das Computernetzwerk konnte nicht ermittelt
werden. (Die angegebene Domäne ist nicht vorhanden oder es konnte keine Verbindung
hergestellt werden. ). Die Verarbeitung der Gruppenrichtlinie wurde abgebrochen.
[ OSession Events ]
Error - 14.09.2009 08:57:06 | Computer Name = Notebook03 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 7006
seconds with 5100 seconds of active time. This session ended with a crash.
Error - 11.03.2011 15:17:23 | Computer Name = Notebook03 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 9
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 12.11.2012 14:48:29 | Computer Name = Notebook03 | Source = W32Time | ID = 39452701
Description = Der Zeitanbieter "NtpClient" wurde für die Zeiterfassung von mehreren
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfügbar. Innerhalb der
nächsten 15 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle
herzustellen. Der NtpClient verfügt über keine Quelle mit genauer Zeit.
Error - 12.11.2012 15:04:43 | Computer Name = Notebook03 | Source = NETLOGON | ID = 5719
Description = Es steht kein Domänencontroller für die Domäne Domain aus folgendem Grund
zur Verfügung: %%1311. Stellen Sie sicher, dass der Computer mit dem Netzwerk verbunden
ist, und versuchen Sie es erneut. Wenden Sie sich an den Domänenadministrator, wenn
das
Problem weiterhin besteht.
Error - 12.11.2012 15:04:43 | Computer Name = Notebook03 | Source = W32Time | ID = 39452701
Description = Der Zeitanbieter "NtpClient" wurde für die Zeiterfassung von mehreren
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfügbar. Innerhalb der
nächsten 14 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle
herzustellen. Der NtpClient verfügt über keine Quelle mit genauer Zeit.
Error - 12.11.2012 15:04:43 | Computer Name = Notebook03 | Source = W32Time | ID = 39452701
Description = Der Zeitanbieter "NtpClient" wurde für die Zeiterfassung von mehreren
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfügbar. Innerhalb der
nächsten 15 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle
herzustellen. Der NtpClient verfügt über keine Quelle mit genauer Zeit.
Error - 13.11.2012 02:59:10 | Computer Name = Notebook03 | Source = NETLOGON | ID = 5719
Description = Es steht kein Domänencontroller für die Domäne Domain aus folgendem Grund
zur Verfügung: %%1311. Stellen Sie sicher, dass der Computer mit dem Netzwerk verbunden
ist, und versuchen Sie es erneut. Wenden Sie sich an den Domänenadministrator, wenn
das
Problem weiterhin besteht.
Error - 13.11.2012 02:59:10 | Computer Name = Notebook03 | Source = W32Time | ID = 39452701
Description = Der Zeitanbieter "NtpClient" wurde für die Zeiterfassung von mehreren
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfügbar. Innerhalb der
nächsten 14 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle
herzustellen. Der NtpClient verfügt über keine Quelle mit genauer Zeit.
Error - 13.11.2012 02:59:11 | Computer Name = Notebook03 | Source = W32Time | ID = 39452701
Description = Der Zeitanbieter "NtpClient" wurde für die Zeiterfassung von mehreren
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfügbar. Innerhalb der
nächsten 15 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle
herzustellen. Der NtpClient verfügt über keine Quelle mit genauer Zeit.
Error - 13.11.2012 03:14:14 | Computer Name = Notebook03 | Source = W32Time | ID = 39452701
Description = Der Zeitanbieter "NtpClient" wurde für die Zeiterfassung von mehreren
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfügbar. Innerhalb der
nächsten 29 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle
herzustellen. Der NtpClient verfügt über keine Quelle mit genauer Zeit.
Error - 13.11.2012 03:16:59 | Computer Name = Notebook03 | Source = Dhcp | ID = 1002
Description = Die IP-Adresslease 192.168.9.38 für die Netzwerkkarte mit der Netzwerkadresse
00FF22EE4D86 wurde durch den DHCP-Server 192.168.9.254 abgelehnt (der DHCP-Server
hat eine DHCPNACK-Meldung gesendet).
Error - 13.11.2012 03:17:02 | Computer Name = Notebook03 | Source = W32Time | ID = 39452701
Description = Der Zeitanbieter "NtpClient" wurde für die Zeiterfassung von mehreren
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfügbar. Innerhalb der
nächsten 14 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle
herzustellen. Der NtpClient verfügt über keine Quelle mit genauer Zeit.
< End of report > --- --- ---
Heute Morgen kam beim Systemstart ein Verweis auf die olepro32r.dll, welche fehlt (Virenscanner hat sie ja eliminiert). |