Traxxcell | 08.05.2013 21:25 | Bitdefender zeigte Virendatei an, die aber nicht vorhanden war. Hallo Forum,
Bitdefender zeigte im Ordner C:/Benutzer/xxx/AppData/Local/Temp eine *.exe Datei als Virus an, die angeblich nicht gelöscht werden konnte. Im angegebenen Ordner war diese Datei nicht zu sehen. Ein Scan mit Bitdefender hat auch nichts gefunden. Da auf der Festplatte Win7 und XP installiert sind, habe ich Win7 von XP aus nochmal mit Bitdefender scannen lassen, ebenso ohne Fund. Mbam hat auch nichts gefunden. Da es sich bei dieser Datei um eine "exe" gehandelt haben soll, bin ich jetzt etwas unsicher. Ich stelle mal die Protokolle von Mbam und OTL rein. Es wäre sehr nett, wenn ihr euch die mal anseht, ob was verdächtiges zu sehen ist.
Danke schon mal im voraus. Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.05.08.04
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16540
Fujitsu :: FUJITSU-PC [Administrator]
08.05.2013 17:26:06
mbam-log-2013-05-08 (17-26-06).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 265443
Laufzeit: 32 Minute(n), 35 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) Zitat:
OTL logfile created on: 08.05.2013 20:23:36 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Fujitsu\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 1,20 Gb Available Physical Memory | 60,18% Memory free
3,98 Gb Paging File | 2,89 Gb Available in Paging File | 72,53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48,83 Gb Total Space | 30,17 Gb Free Space | 61,79% Space Free | Partition Type: NTFS
Drive D: | 19,53 Gb Total Space | 9,64 Gb Free Space | 49,37% Space Free | Partition Type: NTFS
Drive E: | 97,65 Gb Total Space | 93,92 Gb Free Space | 96,17% Space Free | Partition Type: NTFS
Drive F: | 66,86 Gb Total Space | 63,60 Gb Free Space | 95,13% Space Free | Partition Type: NTFS
Computer Name: FUJITSU-PC | User Name: Fujitsu | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ==========
PRC - C:\Users\Fujitsu\Desktop\otl.exe (OldTimer Tools)
PRC - C:\Programme\Bitdefender\Bitdefender 2013\bdagent.exe (Bitdefender)
PRC - C:\Programme\Bitdefender\Bitdefender 2013\vsserv.exe (Bitdefender)
PRC - C:\Programme\Bitdefender\Bitdefender 2013\updatesrv.exe (Bitdefender)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Programme\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - F:\ZonerPhoto15\Photo Studio 15\Program32\ZPSTray.exe (ZONER software)
PRC - F:\TuneUp\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - F:\TuneUp\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.)
PRC - F:\Nitro PDF\NitroPDFDriverService2.exe (Nitro PDF Software)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - c:\Programme\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Programme\FSC\Wireless Utility\WirelessSelector.exe (ITE Tech Inc.) ========== Modules (No Company Name) ==========
MOD - C:\Programme\Bitdefender\Bitdefender 2013\txmlutil.dll ()
MOD - C:\Programme\Bitdefender\Bitdefender 2013\bdmetrics.dll ()
MOD - F:\Nitro PDF\NPShellExtension.dll () ========== Services (SafeList) ==========
SRV - (VSSERV) -- C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe (Bitdefender)
SRV - (UPDATESRV) -- C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe (Bitdefender)
SRV - (BdDesktopParental) -- C:\Programme\Bitdefender\Bitdefender 2013\bdparentalservice.exe (Bitdefender)
SRV - (SkypeUpdate) -- F:\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Secunia PSI Agent) -- C:\Programme\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) -- C:\Programme\Secunia\PSI\sua.exe (Secunia)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (TuneUp.UtilitiesSvc) -- F:\TuneUp\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (wlidsvc) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (NitroDriverReadSpool2) -- F:\Nitro PDF\NitroPDFDriverService2.exe (Nitro PDF Software)
SRV - (odserv) -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) -- c:\Programme\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation) ========== Driver Services (SafeList) ==========
DRV - (BdfNdisf) -- c:\Programme\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys (BitDefender LLC)
DRV - (avckf) -- C:\Windows\System32\drivers\avckf.sys (BitDefender)
DRV - (avc3) -- C:\Windows\System32\drivers\avc3.sys (BitDefender)
DRV - (gzflt) -- C:\Windows\System32\drivers\gzflt.sys (BitDefender LLC)
DRV - (tbhsd) -- C:\Windows\System32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (RRNetCapMP) -- C:\Windows\System32\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV - (RRNetCap) -- C:\Windows\System32\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV - (IT9135BDA) -- C:\Windows\System32\drivers\IT9135BDA.sys (ITE )
DRV - (GT72UBUS) -- C:\Windows\System32\drivers\gt72ubus.sys (Option N.V.)
DRV - (GTPTSER) -- C:\Windows\System32\drivers\gtptser.sys (Option N.V.)
DRV - (GT72NDISIPXP) -- C:\Windows\System32\drivers\Gt51Ip.sys (Option N.V.)
DRV - (BDSandBox) -- C:\Windows\System32\drivers\bdsandbox.sys (BitDefender SRL)
DRV - (avchv) -- C:\Windows\System32\drivers\avchv.sys (BitDefender)
DRV - (trufos) -- C:\Windows\System32\drivers\trufos.sys (BitDefender S.R.L.)
DRV - (bdselfpr) -- C:\Programme\Bitdefender\Bitdefender 2013\bdselfpr.sys (BitDefender LLC)
DRV - (TuneUpUtilitiesDrv) -- F:\TuneUp\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbGD) -- C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (bdfwfpf) -- C:\Programme\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys (BitDefender LLC)
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (dmvsc) -- C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (PSI) -- C:\Windows\System32\drivers\psi_mf.sys (Secunia)
DRV - (smserial) -- C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (Serial) -- C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (yukonw7) -- C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (netw5v32) -- C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (zntport) -- C:\Windows\System32\drivers\zntport.sys (Zeal SoftStudio)
DRV - (DCamUSBEMPIA) -- C:\Windows\System32\drivers\emDevice.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBEMPIA) -- C:\Windows\System32\drivers\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) -- C:\Windows\System32\drivers\emScan.sys (eMPIA Technology, Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 09 A8 2A F3 C4 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{00C93BEF-5717-4446-BAD9-025A94D80801}: "URL" = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ==========
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de"
FF - prefs.js..extensions.enabledAddons: %7Bdf4e4df5-5cb7-46b0-9aef-6c784c3249f8%7D:1.2.0
FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.14
FF - prefs.js..extensions.enabledAddons: %7B1018e4d6-728f-4b20-ad56-37578a4de76b%7D:4.2.8
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: F:\VLC-Player\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: F:\FireFox\components [2013.04.11 21:41:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\bdThunderbird@bitdefender.com: C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013.02.16 09:28:21 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: F:\FireFox\components [2013.04.11 21:41:58 | 000,000,000 | ---D | M]
[2012.11.17 20:56:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Fujitsu\AppData\Roaming\mozilla\Extensions
[2013.04.16 07:55:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Fujitsu\AppData\Roaming\mozilla\Firefox\Profiles\q0csvptr.default\extensions
[2013.04.16 07:55:12 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Fujitsu\AppData\Roaming\mozilla\Firefox\Profiles\q0csvptr.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2013.02.23 23:09:38 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Fujitsu\AppData\Roaming\mozilla\Firefox\Profiles\q0csvptr.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2013.02.15 15:16:54 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Fujitsu\AppData\Roaming\mozilla\firefox\profiles\q0csvptr.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.02.21 14:12:01 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\Fujitsu\AppData\Roaming\mozilla\firefox\profiles\q0csvptr.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
[2012.11.18 13:25:26 | 000,026,136 | ---- | M] () (No name found) -- C:\Users\Fujitsu\AppData\Roaming\mozilla\firefox\profiles\q0csvptr.default\extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKCU..\Run: [Zoner Photo Studio Autoupdate] F:\ZonerPhoto15\Photo Studio 15\Program32\ZPSTray.exe (ZONER software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - F:\MS-Office\Office12\EXCEL.EXE (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{460E4A91-B261-4109-A4FE-202F621323C8}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2012.11.17 17:31:30 | 000,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{c22fbbe1-4ff2-11e2-ada9-00f1d000f1d0}\Shell - "" = AutoRun
O33 - MountPoints2\{c22fbbe1-4ff2-11e2-ada9-00f1d000f1d0}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O33 - MountPoints2\{c22fbbea-4ff2-11e2-ada9-00f1d000f1d0}\Shell - "" = AutoRun
O33 - MountPoints2\{c22fbbea-4ff2-11e2-ada9-00f1d000f1d0}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (sdnclean.exe)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ==========
[2013.05.08 17:51:36 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Fujitsu\Desktop\OTL.exe
[2013.05.08 17:17:34 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Fujitsu\Desktop\HiJackThis204.exe
[2013.05.06 09:33:00 | 000,000,000 | ---D | C] -- C:\Users\Fujitsu\Desktop\Fotos
[2013.05.02 21:19:28 | 000,000,000 | ---D | C] -- C:\Users\Fujitsu\AppData\Roaming\NetSpeedMonitor
[2013.04.29 17:40:14 | 000,486,536 | ---- | C] (BitDefender) -- C:\Windows\System32\drivers\avckf.sys
[2013.04.29 17:40:13 | 000,633,344 | ---- | C] (BitDefender) -- C:\Windows\System32\drivers\avc3.sys
[2013.04.29 11:01:11 | 000,000,000 | ---D | C] -- C:\Users\Fujitsu\Desktop\Neuer Ordner
[2013.04.18 13:25:20 | 000,000,000 | ---D | C] -- C:\Users\Fujitsu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Skat-Online
[2013.04.18 11:26:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013.04.18 11:17:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013.04.18 11:17:15 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013.04.18 11:17:15 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013.04.18 11:17:15 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013.04.15 08:25:27 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\Setup1.exe
[2013.04.15 08:25:26 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\ST6UNST.EXE
[2013.04.10 07:17:23 | 002,706,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.04.10 07:17:22 | 002,877,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.04.10 07:17:22 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.04.10 07:17:21 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.04.10 07:17:21 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013.04.10 07:17:20 | 000,493,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.04.10 07:17:20 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013.04.10 07:17:20 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013.04.10 07:17:20 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013.04.10 07:17:20 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013.04.10 07:13:52 | 003,968,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2013.04.10 07:13:52 | 003,913,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013.04.10 07:13:51 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2013.04.10 07:13:50 | 002,347,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.04.18 23:51:20 | 000,653,136 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Common Files\MSVCR90.dll
[2011.04.18 23:51:20 | 000,569,680 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Common Files\MSVCP90.dll
[2010.12.16 22:39:36 | 000,302,592 | ---- | C] (Google) -- C:\Program Files\Common Files\webmmux.dll
[2010.12.16 22:39:16 | 000,701,440 | ---- | C] (Google) -- C:\Program Files\Common Files\vp8encoder.dll
[2010.12.16 22:39:16 | 000,412,672 | ---- | C] (Google) -- C:\Program Files\Common Files\vp8decoder.dll
[2010.12.16 22:39:14 | 000,292,352 | ---- | C] (Google) -- C:\Program Files\Common Files\webmsplit.dll
[1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files - Modified Within 30 Days ==========
[2013.05.08 20:20:22 | 000,021,904 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.05.08 20:20:22 | 000,021,904 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.05.08 20:17:30 | 000,696,870 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.05.08 20:17:30 | 000,652,148 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.05.08 20:17:30 | 000,148,134 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.05.08 20:17:30 | 000,121,080 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.05.08 20:12:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.05.08 17:51:37 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Fujitsu\Desktop\OTL.exe
[2013.05.08 17:17:34 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Fujitsu\Desktop\HiJackThis204.exe
[2013.04.29 21:36:58 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013.04.29 17:40:14 | 000,486,536 | ---- | M] (BitDefender) -- C:\Windows\System32\drivers\avckf.sys
[2013.04.29 17:40:13 | 000,633,344 | ---- | M] (BitDefender) -- C:\Windows\System32\drivers\avc3.sys
[2013.04.21 08:03:18 | 000,281,936 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.04.18 13:25:20 | 000,002,400 | ---- | M] () -- C:\Users\Fujitsu\Desktop\Skat-Online V9.lnk
[2013.04.18 11:22:51 | 000,691,592 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013.04.18 11:22:51 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013.04.15 08:28:33 | 000,253,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\Setup1.exe
[2013.04.15 08:28:32 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\ST6UNST.EXE
[1 C:\*.tmp files -> C:\*.tmp -> ] ========== Files Created - No Company Name ==========
[2013.04.21 08:02:53 | 000,281,936 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.04.18 13:25:20 | 000,002,400 | ---- | C] () -- C:\Users\Fujitsu\Desktop\Skat-Online V9.lnk
[2013.04.01 11:40:08 | 000,125,440 | ---- | C] () -- C:\Windows\System32\lua5.1a.dll
[2013.03.05 23:46:31 | 000,007,601 | ---- | C] () -- C:\Users\Fujitsu\AppData\Local\Resmon.ResmonCfg
[2013.02.17 17:50:54 | 000,004,509 | ---- | C] () -- C:\Users\Fujitsu\AppData\Roaming\CamStudio.cfg
[2013.02.17 17:50:54 | 000,000,408 | ---- | C] () -- C:\Users\Fujitsu\AppData\Roaming\CamShapes.ini
[2013.02.17 17:50:54 | 000,000,408 | ---- | C] () -- C:\Users\Fujitsu\AppData\Roaming\CamLayout.ini
[2013.02.17 17:50:54 | 000,000,096 | ---- | C] () -- C:\Users\Fujitsu\AppData\Roaming\Camdata.ini
[2013.02.16 09:29:40 | 001,098,914 | ---- | C] () -- C:\ProgramData\1360998461.bdinstall.bin
[2013.01.30 13:13:21 | 000,000,418 | ---- | C] () -- C:\Windows\wiso.ini
[2013.01.01 14:16:06 | 000,000,101 | ---- | C] () -- C:\Windows\System32\ud-boot-time.ini
[2012.11.19 12:41:35 | 000,373,513 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2012.11.18 15:15:29 | 000,000,014 | ---- | C] () -- C:\Windows\System32\SysInfo_6.dll
[2012.11.18 15:13:22 | 000,000,245 | ---- | C] () -- C:\Windows\System32\AF15IRTBL.bin
[2012.11.18 12:03:30 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2012.10.29 17:44:56 | 000,315,392 | ---- | C] () -- C:\Windows\System32\EMRegSys.dll
[2012.05.11 15:16:16 | 000,171,520 | ---- | C] () -- C:\Program Files\Common Files\dsfOggDemux2.dll
[2011.01.12 03:00:44 | 000,030,208 | ---- | C] () -- C:\Program Files\Common Files\wmpinfo.dll
[2011.01.12 03:00:42 | 000,240,128 | ---- | C] () -- C:\Program Files\Common Files\dsfVorbisDecoder.dll
[2011.01.12 03:00:42 | 000,146,944 | ---- | C] () -- C:\Program Files\Common Files\dsfFLACDecoder.dll
[2011.01.12 03:00:40 | 000,221,184 | ---- | C] () -- C:\Program Files\Common Files\dsfFLACEncoder.dll
[2011.01.12 03:00:40 | 000,204,800 | ---- | C] () -- C:\Program Files\Common Files\dsfNativeFLACSource.dll ========== ZeroAccess Check ==========
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 23:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >
| Zitat:
OTL Extras logfile created on: 08.05.2013 20:23:36 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Fujitsu\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 1,20 Gb Available Physical Memory | 60,18% Memory free
3,98 Gb Paging File | 2,89 Gb Available in Paging File | 72,53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48,83 Gb Total Space | 30,17 Gb Free Space | 61,79% Space Free | Partition Type: NTFS
Drive D: | 19,53 Gb Total Space | 9,64 Gb Free Space | 49,37% Space Free | Partition Type: NTFS
Drive E: | 97,65 Gb Total Space | 93,92 Gb Free Space | 96,17% Space Free | Partition Type: NTFS
Drive F: | 66,86 Gb Total Space | 63,60 Gb Free Space | 95,13% Space Free | Partition Type: NTFS
Computer Name: FUJITSU-PC | User Name: Fujitsu | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- F:\FireFox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "F:\MS-Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "F:\MS-Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "F:\VLC-Player\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Digital Photo Professional] -- C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Mit Corel PaintShop Pro X4 durchsuchen] -- "F:\PaintShop\Corel PaintShop Pro X4\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [PlayWithVLC] -- "F:\VLC-Player\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0 ========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] ========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{027EED35-4076-4F44-82CB-F28DEAE0BAE2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{18748310-B32B-452F-9C5C-B60B84EDCB6D}" = lport=31931 | protocol=6 | dir=in | name=audials localhttpserver 31931 |
"{30CE9969-1030-4035-B69F-EE218141FD3E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{326DDBE2-350A-4874-ADBF-F130DFF2AB82}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6C9B985D-EDD5-4BF3-B5A7-8FE7D3BD3F58}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{712ED333-0903-4A8D-9049-E06125CB209C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{805339A0-C93D-4554-B531-25033877A58D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{86B6C3A3-3DCA-4306-8638-204A905873F6}" = rport=10243 | protocol=6 | dir=out | app=system |
"{A52765A5-CD6A-4C43-B4A2-32C7440AA110}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CBEAF140-F02F-4BE3-8FE8-8AA3D93AA140}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{D92571B8-C17F-48A1-8CE9-ED165418D0F3}" = lport=10243 | protocol=6 | dir=in | app=system |
"{DB9CFB16-9821-46F2-9CD7-9F1DEBE557D3}" = lport=12972 | protocol=6 | dir=in | name=audials localhttpserver 12972 |
"{E2D11A1E-8017-42A0-9F0C-C62FE1414EF1}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{F9D0D684-553F-4500-B3BB-09010407BEBB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FF9E81E2-8B49-423E-ABB7-F3C77AB4EDB8}" = lport=14714 | protocol=6 | dir=in | name=audials localhttpserver 14714 | ========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{013E4DC0-1AE1-4AC9-928E-148ADB194889}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{205D183C-4A47-4848-9811-EEE4E0A70973}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2D1FF28D-5A5C-41B9-A00E-005FA934C4CB}" = protocol=6 | dir=in | app=f:\maxthon3\bin\mxup.exe |
"{32069C4B-73DA-4DF9-BDC7-5F1C867E7045}" = protocol=17 | dir=in | app=f:\maxthon3\bin\mxup.exe |
"{3AB1218C-8D32-45FF-AD74-FEB5FB1F91F8}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{4400908B-6A00-4BC6-A6C8-A16D64FC7937}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{49BD0CA3-7BC4-4126-B873-F77829F1FF4E}" = dir=in | app=f:\skype\phone\skype.exe |
"{59023592-6680-499B-BFD2-FD95276192CC}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6273396A-7E12-481E-A975-05F571F3491B}" = protocol=6 | dir=in | app=f:\maxthon3\bin\maxthon.exe |
"{6F832B96-D77B-4C39-83DE-C23B98A60C0C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{74F41D34-46CA-4AFC-9EA0-2B383001E206}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{945BF5E1-58C1-4B35-8257-F917B61AC20F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B6CEAA28-9B93-45DF-AFF7-F06D8AB0E1E0}" = protocol=6 | dir=out | app=system |
"{B8EBA7AD-F397-4768-9F9E-81D1A8A567D8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C5AE1185-93CF-4B54-9262-0974B501973D}" = protocol=17 | dir=in | app=f:\maxthon3\bin\maxthon.exe |
"{D708CE33-0292-49C4-A0AC-71BE978878FB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E2398916-089E-4622-87E8-30C9B449EFC3}" = dir=in | app=f:\radiotracker\audials.exe |
"{EE5A817B-43F9-47CE-A432-EE69A90E7B30}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F0F846FB-027F-4525-B70C-32C6BB9F1B52}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{00580795-581C-4587-B9F2-37320D7AB37F}" = Corel PaintShop Pro X4
"{003CD4FD-DB3E-4D12-9A34-8C00FA8A680F}" = WirelessControl
"{00580795-581C-4587-B9F2-37320D7AB37F}" = ICA
"{006CAAEF-CA96-4181-AC22-FE56D61432E4}" = PSPPContent
"{00AE1A2D-7BC2-4359-A0EC-E19F36E391BB}" = Corel PaintShop Pro X4
"{00BEE329-BAAB-49FF-9B66-55E4B12B9ADD}" = IPM_PSP_COM
"{00D13418-7DDF-4D3D-A237-E297B103BB6B}" = Setup
"{00D74A7A-F7AD-4D00-ABD2-0973836292C7}" = PSPPHelp
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D8C5BCA-6133-4C96-A81E-B901E60F0E1E}" = GlobeTrotter Connect
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{690F5BA3-5DEB-42CD-962B-F687EE59FAA7}" = Windows Live Essentials
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{8256F87F-8554-4457-8C3D-3F3324697D9F}" = Windows Live ID Sign-in Assistant
"{86501894-E722-4385-A792-B7C2F28FAE7B}" = NetSpeedMonitor 2.5.4.0 x86
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.02) - Deutsch
"{AE364ACC-B9DF-466B-B4EA-AEECD0CD581E}" = Windows Live Messenger
"{B0897D06-68ED-4EB2-0001-2F36270D8621}" = DVR Converter 3.0
"{B727564C-47D3-473A-AC9E-F4BE7B1BD5D3}" = Windows Live UX Platform Language Pack
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}" = TuneUp Utilities 2013
"{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{CE61E024-462A-4E06-A886-660F09C12E28}" = Nitro Pro 7
"{D6CC2FAF-F827-4091-96A1-D32CC9B69C79}" = WISO Steuer-Sparbuch 2013
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1203F8C-FF34-4968-A4A5-B4F1F8533DAB}" = Photo Common
"{EB99ED57-FF42-4272-8EDA-E367DFF29596}" = Audials
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2235E5E-7881-4293-9B6F-04B2609FBFF0}" = Windows Live Messenger
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4811919-F252-4B25-9AB2-8859A85810B5}" = TuneUp Utilities Language Pack (de-DE)
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"7-Zip" = 7-Zip 9.22beta
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Ashampoo Burning Studio 2012_is1" = Ashampoo Burning Studio 2012 v10.0.15
"Ashampoo Photo Optimizer 4_is1" = Ashampoo Photo Optimizer 4 v.4.0.3
"Audacity_is1" = Audacity 2.0.3
"Bitdefender" = Bitdefender Internet Security 2013
"BlazeDTV 6.0_is1" = BlazeDTV 6.0
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"Canon RAW Codec" = Canon RAW Codec
"CCleaner" = CCleaner
"CrystalDiskInfo_is1" = CrystalDiskInfo 5.4.2
"Digital Photo Professional" = Canon Utilities Digital Photo Professional
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"EasyBCD" = EasyBCD 2.2
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EOS USB WIA Driver" = EOS USB WIA Driver
"EOS Utility" = Canon Utilities EOS Utility
"EOS Video Snapshot Task" = Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.50
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300
"Maxthon3" = Maxthon 3
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox 16.0.2 (x86 de)" = Mozilla Firefox 16.0.2 (x86 de)
"MyCamera" = Canon Utilities MyCamera
"MyCamera Download Plugin" = CANON iMAGE GATEWAY MyCamera Download Plugin
"Original Data Security Tools" = Canon Utilities Original Data Security Tools
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Secunia PSI" = Secunia PSI (3.0.0.6001)
"SMSERIAL" = Motorola SM56 Speakerphone Modem
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TuneUp Utilities 2013" = TuneUp Utilities 2013
"TVWiz" = Intel(R) TV Wizard
"UltraDefrag" = Ultra Defragmenter
"VLC media player" = VLC media player 2.0.6
"WFTK" = Canon Utilities WFT-E1/E2/E3 Utility
"WinLiveSuite" = Windows Live Essentials
"ZonerPhotoStudio15_DE_is1" = Zoner Photo Studio 15
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility ========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Mozilla Firefox 20.0.1 (x86 de)" = Mozilla Firefox 20.0.1 (x86 de) ========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 06.05.2013 10:13:07 | Computer Name = Fujitsu-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: firefox.exe, Version: 20.0.1.4847,
Zeitstempel: 0x51650aee Name des fehlerhaften Moduls: xul.dll, Version: 20.0.1.4847,
Zeitstempel: 0x51650a09 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000b10e8 ID des fehlerhaften
Prozesses: 0xcf8 Startzeit der fehlerhaften Anwendung: 0x01ce4a62c2f148d1 Pfad der
fehlerhaften Anwendung: F:\FireFox\firefox.exe Pfad des fehlerhaften Moduls: F:\FireFox\xul.dll
Berichtskennung:
12ae2d5f-b657-11e2-b979-00f1d000f1d0
Error - 07.05.2013 01:24:29 | Computer Name = Fujitsu-PC | Source = WinMgmt | ID = 10
Description =
Error - 07.05.2013 02:35:46 | Computer Name = Fujitsu-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: zps.exe, Version: 15.0.1.3, Zeitstempel:
0x50802372 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel:
0x4ec49b60 Ausnahmecode: 0xc0000374 Fehleroffset: 0x000c380b ID des fehlerhaften Prozesses:
0xe30 Startzeit der fehlerhaften Anwendung: 0x01ce4aec66415d1a Pfad der fehlerhaften
Anwendung: F:\ZonerPhoto15\Photo Studio 15\Program32\zps.exe Pfad des fehlerhaften
Moduls: C:\Windows\SYSTEM32\ntdll.dll Berichtskennung: 58b52989-b6e0-11e2-9051-00f1d000f1d0
Error - 07.05.2013 04:30:37 | Computer Name = Fujitsu-PC | Source = WinMgmt | ID = 10
Description =
Error - 07.05.2013 05:26:42 | Computer Name = Fujitsu-PC | Source = WinMgmt | ID = 10
Description =
Error - 07.05.2013 13:25:33 | Computer Name = Fujitsu-PC | Source = WinMgmt | ID = 10
Description =
Error - 08.05.2013 02:10:52 | Computer Name = Fujitsu-PC | Source = WinMgmt | ID = 10
Description =
Error - 08.05.2013 04:39:06 | Computer Name = Fujitsu-PC | Source = WinMgmt | ID = 10
Description =
Error - 08.05.2013 11:59:04 | Computer Name = Fujitsu-PC | Source = Application Hang | ID = 1002
Description = Programm otl.exe, Version 3.2.69.0 kann nicht mehr unter Windows ausgeführt
werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 13a0 Startzeit:
01ce4c040f8a0269 Endzeit: 16 Anwendungspfad: C:\Users\Fujitsu\Desktop\otl.exe Berichts-ID:
Error - 08.05.2013 14:14:27 | Computer Name = Fujitsu-PC | Source = WinMgmt | ID = 10
Description =
[ Media Center Events ]
Error - 20.12.2012 05:46:59 | Computer Name = Fujitsu-PC | Source = MCUpdate | ID = 0
Description = 10:46:27 - Fehler beim Herstellen der Internetverbindung. 10:46:27
- Serververbindung konnte nicht hergestellt werden..
Error - 20.12.2012 06:52:33 | Computer Name = Fujitsu-PC | Source = MCUpdate | ID = 0
Description = 11:52:32 - Fehler beim Herstellen der Internetverbindung. 11:52:32
- Serververbindung konnte nicht hergestellt werden..
Error - 20.12.2012 06:52:50 | Computer Name = Fujitsu-PC | Source = MCUpdate | ID = 0
Description = 11:52:38 - Fehler beim Herstellen der Internetverbindung. 11:52:38
- Serververbindung konnte nicht hergestellt werden..
Error - 20.12.2012 07:53:21 | Computer Name = Fujitsu-PC | Source = MCUpdate | ID = 0
Description = 12:53:21 - Fehler beim Herstellen der Internetverbindung. 12:53:21
- Serververbindung konnte nicht hergestellt werden..
Error - 20.12.2012 07:53:42 | Computer Name = Fujitsu-PC | Source = MCUpdate | ID = 0
Description = 12:53:26 - Fehler beim Herstellen der Internetverbindung. 12:53:26
- Serververbindung konnte nicht hergestellt werden..
Error - 20.12.2012 08:54:11 | Computer Name = Fujitsu-PC | Source = MCUpdate | ID = 0
Description = 13:54:11 - Fehler beim Herstellen der Internetverbindung. 13:54:11
- Serververbindung konnte nicht hergestellt werden..
Error - 20.12.2012 08:54:26 | Computer Name = Fujitsu-PC | Source = MCUpdate | ID = 0
Description = 13:54:16 - Fehler beim Herstellen der Internetverbindung. 13:54:16
- Serververbindung konnte nicht hergestellt werden..
Error - 23.12.2012 04:28:04 | Computer Name = Fujitsu-PC | Source = MCUpdate | ID = 0
Description = 09:28:03 - Fehler beim Herstellen der Internetverbindung. 09:28:04
- Serververbindung konnte nicht hergestellt werden..
Error - 23.12.2012 04:28:24 | Computer Name = Fujitsu-PC | Source = MCUpdate | ID = 0
Description = 09:28:09 - Fehler beim Herstellen der Internetverbindung. 09:28:09
- Serververbindung konnte nicht hergestellt werden..
Error - 21.02.2013 01:59:41 | Computer Name = Fujitsu-PC | Source = MCUpdate | ID = 0
Description = 06:59:37 - Fehler beim Herstellen der Internetverbindung. 06:59:40
- Serververbindung konnte nicht hergestellt werden..
[ System Events ]
Error - 25.01.2013 08:37:21 | Computer Name = Fujitsu-PC | Source = volsnap | ID = 393245
Description = Die Schattenkopien von Volume "C:" wurde während der Ermittlung abgebrochen.
Error - 26.01.2013 04:02:10 | Computer Name = Fujitsu-PC | Source = Schannel | ID = 36887
Description = Es wurde eine schwerwiegende Warnung empfangen: 80.
Error - 28.01.2013 05:00:01 | Computer Name = Fujitsu-PC | Source = DCOM | ID = 10000
Description =
Error - 28.01.2013 17:56:02 | Computer Name = Fujitsu-PC | Source = volsnap | ID = 393245
Description = Die Schattenkopien von Volume "C:" wurde während der Ermittlung abgebrochen.
Error - 28.01.2013 17:56:23 | Computer Name = Fujitsu-PC | Source = DCOM | ID = 10000
Description =
Error - 30.01.2013 08:47:36 | Computer Name = Fujitsu-PC | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
Error - 31.01.2013 03:12:28 | Computer Name = Fujitsu-PC | Source = DCOM | ID = 10010
Description =
Error - 01.02.2013 01:38:34 | Computer Name = Fujitsu-PC | Source = DCOM | ID = 10010
Description =
Error - 04.02.2013 05:00:02 | Computer Name = Fujitsu-PC | Source = DCOM | ID = 10000
Description =
Error - 08.02.2013 07:36:05 | Computer Name = Fujitsu-PC | Source = volsnap | ID = 393245
Description = Die Schattenkopien von Volume "C:" wurde während der Ermittlung abgebrochen.
< End of report >
| |