dagobert50er | 24.07.2013 15:31 | Nach PC-Neuaufsetzen nach Adware-Befall - PC sauber? Guten Tag,
am Sonntag bemerkte nach einem Scan mit Kaspersky PURE 2.0 Chipedition der Windows-Defender, dass ich eine Adware auf dem PC habe - "Lyrics-Pal". Diese ließ sich mit dem Defender nicht entfernen (bzw. nach Entfernung war sie immernoch da), ließ sich aber über die Systemsteuerung über einen einfachen Uninstaller entfernen .. ungewöhnlich wie ich finde und freundlicherweise wird man noch auf h**p://unp.staticlib.net/sd/uninstall/index.html geleitet, auf der steht: "Thank you for giving our software a shot!"
Ich war mir nicht ganz sicher, ob nun doch alles wieder sauber ist und sicherte meine Daten und setze den PC neu auf.
Jedoch schon bei der Installation des Grafikkartentreibers für den ASUS EAH5570 meldete sich Kaspersky mit dem "Proaktiven Schutz" und verschob zwei Dateien aus dem system32/drivers-Verzeichnis wegen "PSM.auspicious driver installation" in Quarantäne: http://s14.directupload.net/images/130724/k8tqwv84.jpg
Die Installation funktionierte dennoch (auch wenn diese Version des Treibers nicht den gewünschten Erfolg brachte).
Dann scannte ich mit der BitDefender-LiveCD den PC und dieser fand dann (mit den alten Signaturen von 2010) das hier: http://s1.directupload.net/images/130724/zvz6ma4n.jpg
(Bild ist mit dem Tablet aufgenommen und steht leider Kopf)
Ich ludt im laufenden Windows die Dateien bei Virustotal hoch ... alle sauber.
Ich schloss die Geräte mit den gesicherten Dateien wieder an (Autostart deaktiviert) und scannte sie mit malwarebytes und kaspersky ... alle sauber. Ich zog die Daten wieder rüber und machte einen Komplettscan mit Malwarebytes und Kaspersky - beide fanden nichts mehr.
Nun bin ich mir aber nicht sicher ob nicht doch irgendwo noch ein Virus ist.
Und ja, ich gebe zu, dieses Thema wurde auf hxxp://www.computerbase.de/forum/showthread.php?t=1233218 bereits behandelt, jedoch konnte mir dort nicht gesagt werden, ob mein PC nun 100%ig sauber ist und mir wurde dieses Board hier empfohlen.
Im Folgenden nun die Logs, in denen mein Realname durch "Dagobert" ersetzt wurde und Gmer Probleme machte, dazu am Ende des Threads mehr:
defogger_disable.txt: Zitat:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 14:40 on 24/07/2013 (Dagobert)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
| OTL.txt: Zitat:
OTL logfile created on: 24.07.2013 14:40:34 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dagobert\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,75 Gb Total Physical Memory | 1,88 Gb Available Physical Memory | 68,26% Memory free
5,50 Gb Paging File | 4,15 Gb Available in Paging File | 75,42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297,99 Gb Total Space | 169,60 Gb Free Space | 56,91% Space Free | Partition Type: NTFS
Drive J: | 7,64 Gb Total Space | 6,11 Gb Free Space | 79,99% Space Free | Partition Type: NTFS
Computer Name: Dagobert-PC | User Name: Dagobert | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ==========
PRC - [2013.07.24 14:38:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dagobert\Desktop\OTL.exe
PRC - [2013.06.20 11:29:38 | 000,173,192 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
PRC - [2012.08.30 22:26:56 | 000,202,328 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe
PRC - [2011.03.28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2009.12.21 17:34:38 | 000,743,992 | ---- | M] (Infowatch) -- C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
PRC - [2009.10.03 11:01:14 | 001,748,992 | ---- | M] (NETGEAR) -- C:\Program Files (x86)\NETGEAR\WNA1000\WNA1000.exe ========== Modules (No Company Name) ==========
MOD - [2012.08.30 22:24:20 | 007,422,392 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtGui4.dll
MOD - [2012.08.30 22:24:18 | 001,270,200 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtScript4.dll
MOD - [2012.08.30 22:24:18 | 000,192,952 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtSql4.dll
MOD - [2012.08.30 22:24:16 | 002,453,944 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtDeclarative4.dll
MOD - [2012.08.30 22:24:16 | 002,126,264 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtCore4.dll
MOD - [2012.08.30 22:24:16 | 000,795,064 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtNetwork4.dll
MOD - [2012.08.30 22:23:02 | 000,459,192 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\dblite.dll
MOD - [2011.09.05 19:36:52 | 000,025,088 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qgif4.dll
MOD - [2011.09.05 19:36:50 | 000,180,224 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qjpeg4.dll ========== Services (SafeList) ==========
SRV:64bit: - [2011.05.24 23:18:38 | 000,365,568 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2009.12.11 09:44:52 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2007.11.28 15:51:42 | 001,039,872 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\lxdncoms.exe -- (lxdn_device)
SRV - [2013.06.20 11:29:38 | 000,173,192 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe -- (BingDesktopUpdate)
SRV - [2013.06.18 16:21:21 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.08.30 22:26:56 | 000,202,328 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe -- (AVP)
SRV - [2011.04.01 11:14:30 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011.03.28 21:11:06 | 002,292,096 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011.03.28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010.09.22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.12.21 17:34:38 | 000,743,992 | ---- | M] (Infowatch) [Auto | Running] -- C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe -- (CSObjectsSrv)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.02.29 02:07:18 | 000,942,080 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\NETGEAR\WNA1000\jswpsapi.exe -- (jswpsapi) ========== Driver Services (SafeList) ==========
DRV:64bit: - [2013.07.22 20:42:57 | 000,636,760 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\SysNative\drivers\klif.sys -- (KLIF)
DRV:64bit: - [2012.08.23 16:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.08.23 16:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.03.08 18:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.10.20 11:48:00 | 000,458,032 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\kl1.sys -- (KL1)
DRV:64bit: - [2011.10.20 11:48:00 | 000,013,616 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kl2.sys -- (kl2)
DRV:64bit: - [2011.03.30 14:46:44 | 000,114,704 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.03.10 18:36:24 | 000,029,488 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\klim6.sys -- (KLIM6)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.12.14 12:44:24 | 000,085,048 | ---- | M] (Infowatch) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\CSCrySec.sys -- (CSCrySec)
DRV:64bit: - [2009.12.14 12:44:24 | 000,066,104 | ---- | M] (Infowatch) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys -- (CSVirtualDiskDrv)
DRV:64bit: - [2009.12.11 10:04:44 | 006,228,480 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009.12.11 10:04:44 | 006,228,480 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
DRV:64bit: - [2009.12.11 08:51:08 | 000,160,256 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2009.11.18 12:30:56 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009.11.02 20:27:10 | 000,022,544 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klmouflt.sys -- (klmouflt)
DRV:64bit: - [2009.10.21 12:01:34 | 000,767,488 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WNA1000w7x.sys -- (WNA1000)
DRV:64bit: - [2009.09.28 09:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008.10.01 16:44:06 | 000,026,624 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\jswpslwfx.sys -- (JSWPSLWF)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://www.tagesschau.de/|hxxp://www.dradio.de/|hxxp://www.swr.de/swrinfo"
FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130515
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.6.9
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\linkfilter@kaspersky.ru [2013.07.22 20:43:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\virtualKeyboard@kaspersky.ru [2013.07.22 20:43:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\KavAntiBanner@Kaspersky.ru [2013.07.22 20:43:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2013.07.23 05:47:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dagobert\AppData\Roaming\mozilla\Extensions
[2013.07.23 07:57:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dagobert\AppData\Roaming\mozilla\Firefox\Profiles\6nco7zoy.default\extensions
[2013.07.23 07:57:17 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Dagobert\AppData\Roaming\mozilla\Firefox\Profiles\6nco7zoy.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013.07.23 07:57:17 | 000,534,063 | ---- | M] () (No name found) -- C:\Users\Dagobert\AppData\Roaming\mozilla\firefox\profiles\6nco7zoy.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013.07.23 07:56:20 | 000,818,491 | ---- | M] () (No name found) -- C:\Users\Dagobert\AppData\Roaming\mozilla\firefox\profiles\6nco7zoy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.07.23 07:57:17 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\Dagobert\AppData\Roaming\mozilla\firefox\profiles\6nco7zoy.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
[2013.07.23 05:47:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2013.07.23 05:47:02 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ie_banner_deny.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ie_banner_deny.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O9:64bit: - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\ievkbd.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ievkbd.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D84DAC0-DDC0-4A46-8108-2267B9F46221}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 0
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ==========
[2013.07.24 14:38:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Dagobert\Desktop\OTL.exe
[2013.07.23 23:41:17 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Roaming\Malwarebytes
[2013.07.23 23:41:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.07.23 23:41:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.07.23 23:41:06 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.07.23 23:41:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.07.23 23:40:56 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Local\Programs
[2013.07.23 12:13:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
[2013.07.23 11:52:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013.07.23 11:50:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2013.07.23 11:50:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2013.07.23 11:48:48 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2013.07.23 11:47:46 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Local\Microsoft Help
[2013.07.23 11:47:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2013.07.23 11:47:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2013.07.23 11:47:12 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2013.07.23 11:16:59 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2013.07.23 11:14:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2013.07.23 11:13:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2013.07.23 11:13:02 | 000,055,296 | ---- | C] (AMD) -- C:\Windows\SysNative\coinst.dll
[2013.07.23 11:12:46 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2013.07.23 11:12:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2013.07.23 11:06:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013.07.23 11:06:07 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013.07.23 10:45:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\My Company Name
[2013.07.23 10:42:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2013.07.23 08:18:12 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2013.07.23 08:09:44 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Local\AMD
[2013.07.23 08:09:35 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Roaming\ATI
[2013.07.23 08:09:35 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Local\ATI
[2013.07.23 08:06:14 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2013.07.23 08:04:05 | 000,000,000 | ---D | C] -- C:\AMD
[2013.07.23 05:54:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2013.07.23 05:54:52 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2013.07.23 05:47:16 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Roaming\Mozilla
[2013.07.23 05:47:16 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Local\Mozilla
[2013.07.23 05:47:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2013.07.23 05:47:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2013.07.23 05:46:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.07.23 05:04:59 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Roaming\Adobe
[2013.07.23 02:47:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2013.07.23 02:15:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2013.07.23 02:15:10 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[2013.07.23 01:47:52 | 000,116,224 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll
[2013.07.23 01:47:31 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll
[2013.07.23 01:19:43 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
[2013.07.23 01:10:19 | 000,000,000 | ---D | C] -- C:\Windows\de
[2013.07.23 01:08:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2013.07.23 01:07:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
[2013.07.23 01:06:43 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2013.07.23 01:06:33 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2013.07.23 00:21:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013.07.23 00:19:33 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2013.07.23 00:19:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2013.07.22 23:24:48 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2013.07.22 23:21:59 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Local\Windows Live
[2013.07.22 23:21:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live
[2013.07.22 23:16:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bing-Desktop
[2013.07.22 23:16:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
[2013.07.22 22:46:45 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Local\WindowsUpdate
[2013.07.22 22:06:33 | 000,000,000 | ---D | C] -- C:\ProgramData\lx_Cats
[2013.07.22 21:48:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR WNA1000 Adapter
[2013.07.22 21:24:54 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.07.22 21:13:15 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2013.07.22 21:12:06 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Local\ElevatedDiagnostics
[2013.07.22 21:05:32 | 000,000,000 | -H-D | C] -- C:\$WINDOWS.~Q
[2013.07.22 21:05:07 | 000,000,000 | -H-D | C] -- C:\$INPLACE.~TR
[2013.07.22 20:47:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NETGEAR
[2013.07.22 20:47:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\installshield installation information
[2013.07.22 20:47:24 | 000,000,000 | ---D | C] -- C:\ProgramData\NETGEAR
[2013.07.22 20:47:06 | 000,000,000 | ---D | C] -- C:\Windows\Downloaded Installations
[2013.07.22 20:45:02 | 000,000,000 | R--D | C] -- C:\Backup
[2013.07.22 20:43:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky PURE 2.0
[2013.07.22 20:43:30 | 000,085,048 | ---- | C] (Infowatch) -- C:\Windows\SysNative\drivers\CSCrySec.sys
[2013.07.22 20:43:30 | 000,066,104 | ---- | C] (Infowatch) -- C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys
[2013.07.22 20:43:30 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2013.07.22 20:43:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InfoWatch
[2013.07.22 20:43:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2013.07.22 20:43:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Kaspersky Lab
[2013.07.22 20:42:57 | 000,636,760 | ---- | C] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2013.07.22 20:42:07 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2013.07.22 20:28:45 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2013.07.22 20:28:45 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2013.07.22 20:28:45 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2013.07.22 20:28:45 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2013.07.22 20:28:45 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2013.07.22 20:28:45 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2013.07.22 20:28:45 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2013.07.22 20:28:45 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2013.07.22 20:28:45 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2013.07.22 20:17:52 | 000,000,000 | --SD | C] -- C:\Users\Dagobert\AppData\Roaming\Microsoft
[2013.07.22 20:17:52 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\Videos
[2013.07.22 20:17:52 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\Saved Games
[2013.07.22 20:17:52 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\Pictures
[2013.07.22 20:17:52 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\Music
[2013.07.22 20:17:52 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013.07.22 20:17:52 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\Links
[2013.07.22 20:17:52 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\Favorites
[2013.07.22 20:17:52 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\Downloads
[2013.07.22 20:17:52 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\Documents
[2013.07.22 20:17:52 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\Desktop
[2013.07.22 20:17:52 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Vorlagen
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\AppData\Local\Verlauf
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\AppData\Local\Temporary Internet Files
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Startmenü
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\SendTo
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Recent
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Netzwerkumgebung
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Lokale Einstellungen
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Documents\Eigene Videos
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Documents\Eigene Musik
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Eigene Dateien
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Documents\Eigene Bilder
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Druckumgebung
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Cookies
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\AppData\Local\Anwendungsdaten
[2013.07.22 20:17:52 | 000,000,000 | -HSD | C] -- C:\Users\Dagobert\Anwendungsdaten
[2013.07.22 20:17:52 | 000,000,000 | -H-D | C] -- C:\Users\Dagobert\AppData
[2013.07.22 20:17:52 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Local\Temp
[2013.07.22 20:17:52 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Local\Microsoft
[2013.07.22 20:17:52 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Roaming\Media Center Programs
[2013.07.22 20:14:07 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2013.07.22 19:22:49 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013.07.22 19:22:49 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\Searches
[2013.07.22 19:22:49 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013.07.22 19:22:41 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Roaming\Identities
[2013.07.22 19:22:39 | 000,000,000 | R--D | C] -- C:\Users\Dagobert\Contacts
[2013.07.22 19:22:37 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\AppData\Local\VirtualStore
[2013.07.22 19:22:22 | 000,000,000 | -HSD | C] -- C:\Recovery
[2013.07.22 19:22:22 | 000,000,000 | -HSD | C] -- C:\Programme
[2013.07.22 19:22:22 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2013.07.22 19:16:34 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2013.07.22 19:13:48 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2013.07.22 16:48:51 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\Desktop\Radioarchiv
[2013.07.22 16:43:59 | 000,000,000 | ---D | C] -- C:\Users\Dagobert\Desktop\20121029 ========== Files - Modified Within 30 Days ==========
[2013.07.24 14:40:08 | 000,000,000 | ---- | M] () -- C:\Users\Dagobert\defogger_reenable
[2013.07.24 14:38:10 | 000,377,856 | ---- | M] () -- C:\Users\Dagobert\Desktop\gmer_2.1.19163.exe
[2013.07.24 14:38:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dagobert\Desktop\OTL.exe
[2013.07.24 14:36:10 | 000,050,477 | ---- | M] () -- C:\Users\Dagobert\Desktop\Defogger.exe
[2013.07.24 14:28:16 | 000,019,776 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.24 14:28:16 | 000,019,776 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.24 14:25:23 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.07.24 14:25:23 | 000,653,928 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.07.24 14:25:23 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.07.24 14:25:23 | 000,129,800 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.07.24 14:25:23 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.07.24 14:20:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.24 14:20:40 | 2213,945,344 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.23 23:36:23 | 000,312,496 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.07.23 11:16:42 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2013.07.23 05:47:08 | 000,001,151 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.07.23 04:22:33 | 000,025,185 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2013.07.23 04:22:32 | 000,025,185 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2013.07.22 22:17:49 | 000,000,382 | ---- | M] () -- C:\Users\Public\Desktop\Complete Installation of Lexmark 2600 Series.LNK
[2013.07.22 22:06:33 | 000,000,134 | ---- | M] () -- C:\Windows\SysNative\LexFiles.ulf
[2013.07.22 21:48:42 | 000,002,071 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA1000 Setup-Assistent.lnk
[2013.07.22 21:48:42 | 000,002,051 | ---- | M] () -- C:\Users\Public\Desktop\NETGEAR WNA1000 Setup-Assistent.lnk
[2013.07.22 20:45:05 | 000,017,408 | ---- | M] () -- C:\Users\Dagobert\AppData\Local\WebpageIcons.db
[2013.07.22 20:43:59 | 000,153,053 | ---- | M] () -- C:\Windows\SysNative\drivers\klin.dat
[2013.07.22 20:43:59 | 000,107,384 | ---- | M] () -- C:\Windows\SysNative\drivers\klick.dat
[2013.07.22 20:42:57 | 000,636,760 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2013.07.22 20:25:56 | 000,056,735 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2013.07.22 20:25:56 | 000,056,735 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2013.07.22 20:23:35 | 000,022,960 | ---- | M] () -- C:\Windows\SysNative\emptyregdb.dat
[2013.07.22 20:15:54 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013.07.22 19:49:08 | 000,002,544 | ---- | M] () -- C:\Windows\diagwrn.xml
[2013.07.22 19:49:02 | 000,001,890 | ---- | M] () -- C:\Windows\diagerr.xml ========== Files Created - No Company Name ==========
[2013.07.24 14:40:08 | 000,000,000 | ---- | C] () -- C:\Users\Dagobert\defogger_reenable
[2013.07.24 14:38:09 | 000,377,856 | ---- | C] () -- C:\Users\Dagobert\Desktop\gmer_2.1.19163.exe
[2013.07.24 14:36:08 | 000,050,477 | ---- | C] () -- C:\Users\Dagobert\Desktop\Defogger.exe
[2013.07.24 02:10:54 | 353,288,236 | ---- | C] () -- C:\Users\Dagobert\Desktop\20130724_ROH.WAV
[2013.07.24 02:02:19 | 359,671,852 | ---- | C] () -- C:\Users\Dagobert\Desktop\20130723_ROH.WAV
[2013.07.23 11:16:42 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013.07.23 11:13:03 | 000,001,035 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2013.07.23 11:13:03 | 000,001,035 | ---- | C] () -- C:\Windows\SysNative\atipblag.dat
[2013.07.23 11:13:02 | 000,019,462 | ---- | C] () -- C:\Windows\atiogl.xml
[2013.07.23 05:55:32 | 000,166,624 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2013.07.23 05:47:08 | 000,001,163 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013.07.23 05:47:08 | 000,001,151 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.07.23 04:22:33 | 000,025,185 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2013.07.23 04:22:32 | 000,025,185 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2013.07.23 01:49:14 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd
[2013.07.23 01:47:11 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml
[2013.07.23 01:46:56 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml
[2013.07.23 01:46:56 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml
[2013.07.23 01:46:36 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml
[2013.07.23 01:09:18 | 000,001,305 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2013.07.23 01:09:03 | 000,001,374 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2013.07.23 01:08:41 | 000,001,458 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2013.07.23 01:08:23 | 000,002,486 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2013.07.23 00:10:15 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013.07.22 23:44:25 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013.07.22 22:17:49 | 000,000,382 | ---- | C] () -- C:\Users\Public\Desktop\Complete Installation of Lexmark 2600 Series.LNK
[2013.07.22 22:06:33 | 000,000,134 | ---- | C] () -- C:\Windows\SysNative\LexFiles.ulf
[2013.07.22 21:48:42 | 000,002,071 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA1000 Setup-Assistent.lnk
[2013.07.22 21:48:42 | 000,002,051 | ---- | C] () -- C:\Users\Public\Desktop\NETGEAR WNA1000 Setup-Assistent.lnk
[2013.07.22 20:45:04 | 000,017,408 | ---- | C] () -- C:\Users\Dagobert\AppData\Local\WebpageIcons.db
[2013.07.22 20:43:59 | 000,153,053 | ---- | C] () -- C:\Windows\SysNative\drivers\klin.dat
[2013.07.22 20:43:59 | 000,107,384 | ---- | C] () -- C:\Windows\SysNative\drivers\klick.dat
[2013.07.22 20:29:02 | 000,001,425 | ---- | C] () -- C:\Users\Dagobert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013.07.22 20:26:53 | 2213,945,344 | -HS- | C] () -- C:\hiberfil.sys
[2013.07.22 20:23:35 | 000,022,960 | ---- | C] () -- C:\Windows\SysNative\emptyregdb.dat
[2013.07.22 20:17:37 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2013.07.22 20:17:37 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2013.07.22 20:15:54 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013.07.22 19:49:01 | 000,002,544 | ---- | C] () -- C:\Windows\diagwrn.xml
[2013.07.22 19:49:01 | 000,001,890 | ---- | C] () -- C:\Windows\diagerr.xml ========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== ========== Purity Check ==========
< End of report >
| Extras.txt: Zitat:
OTL Extras logfile created on: 24.07.2013 14:40:34 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dagobert\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,75 Gb Total Physical Memory | 1,88 Gb Available Physical Memory | 68,26% Memory free
5,50 Gb Paging File | 4,15 Gb Available in Paging File | 75,42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297,99 Gb Total Space | 169,60 Gb Free Space | 56,91% Space Free | Partition Type: NTFS
Drive J: | 7,64 Gb Total Space | 6,11 Gb Free Space | 79,99% Space Free | Partition Type: NTFS
Computer Name: Dagobert-PC | User Name: Dagobert | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L"
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L"
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{311A4840-7A0D-4F85-8C4A-1B81F9903160}" = lport=137 | protocol=17 | dir=in | app=system |
"{4809ECCC-5B99-4B04-8ABE-30EE4FFC9205}" = lport=445 | protocol=6 | dir=in | app=system |
"{63F4E8D3-F623-4A84-9CED-D1CE1C0E7C8C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{686072E9-8D17-4FAE-BBFB-6C32CA03D8CF}" = rport=139 | protocol=6 | dir=out | app=system |
"{6E1B2E87-B769-4034-B537-E84B226068BB}" = rport=138 | protocol=17 | dir=out | app=system |
"{7A5E4FAB-93BC-4698-8AFB-CA3FF2DF00B8}" = lport=139 | protocol=6 | dir=in | app=system |
"{8C6B655D-A504-44C7-94F8-F55BFBC90452}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8CCCF101-1AD4-4B74-8AD6-DA4F7FAA5192}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AAF3BD45-8FC3-4040-AF5F-0D563D6AF4B0}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{AB5EB0E1-44E9-421C-A378-1C4B44651641}" = rport=445 | protocol=6 | dir=out | app=system |
"{B2FD7ACE-FCA0-4643-AF50-0F612A94E38A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{DA83E03C-9FAA-46FD-BADD-38954C3B1EE5}" = lport=138 | protocol=17 | dir=in | app=system |
"{DB6F2E66-96AB-4436-9CCA-978500D7FE62}" = rport=137 | protocol=17 | dir=out | app=system |
"{F505AC3E-D677-4338-9078-98A80DF3B9B9}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | ========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{077BA58D-4C1C-44F9-B1C1-3A120298EAA8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{0D7E071B-D8AE-43E5-90EC-1B41890FDE89}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1EFA8A03-B004-4ED9-92E4-067ED11A0DA9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{23D3162E-3230-4C7D-8529-02044ABE7163}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{3BDAEC5D-0B5A-435D-9103-209E28116571}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{45FD015C-6DFC-4CE4-9299-95135CE64DEA}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{485A40C9-543D-4CFF-85CF-2BB32BD89F8A}" = protocol=6 | dir=in | app=c:\windows\system32\lxdncoms.exe |
"{533D191A-2830-4807-8357-3435125E1639}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{55EFDB3F-EDF1-4217-B233-F4D719BBF66C}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{642334FC-E6D0-4674-8363-969DB4A55289}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{88BD1EB6-EED0-4012-B5AC-1D6667D93111}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{89BDDA41-E91E-473C-8344-B1F1A6747B5E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{B22D7920-B022-4B26-BB2E-D6B252E89E62}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{B80067B2-F329-4D66-9A21-EC1C8FBA9B65}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BCF96485-A20B-4D11-BE95-E3EA4345D331}" = protocol=17 | dir=in | app=c:\windows\system32\lxdncoms.exe |
"{E0AA7610-E74D-445A-A1B6-6939C5840B43}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{EA0992C8-0C28-4D89-931D-59E8B29C816A}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{19CAB44F-2F88-BCB1-873C-0AAA40E2CE71}" = ccc-utility64
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1B7FF76E-10FF-6EC1-1289-E8089B6423CC}" = AMD Fuel
"{2128559D-BBCD-4744-87F0-7C0CD5CFB464}" = Windows Live Family Safety
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{734B340D-D3C0-824A-E26A-BBB78E12A16A}" = ATI Catalyst Install Manager
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B4CA5A58-2759-7FCF-4F19-952E05FBA493}" = ATI AVIVO64 Codecs
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{168BEE42-1F65-1AFF-CD77-3DB5A9F91B5E}" = CCC Help Danish
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1E61121B-87BA-469B-A294-2516B20AC1D1}" = WNA1000
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2278744E-73C3-38C4-6991-3E1601785913}" = CCC Help Greek
"{2D270A67-B7CD-4281-B2FE-60DF18D19B8E}" = Kaspersky PURE 2.0
"{2FAD5D8B-56E2-1C4D-E84E-ED162C32D4C5}" = Catalyst Control Center Graphics Light
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{364B2826-EEB6-A31B-F25B-5CBB78273414}" = CCC Help English
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{449CE12D-E2C7-4B97-B19E-55D163EA9435}" = Bing Bar
"{4B8C04D7-47E2-AB0B-B573-65893836AD10}" = ccc-core-static
"{54FB1D26-CB8F-2B7C-1B22-344AA1896FE1}" = Catalyst Control Center Graphics Full Existing
"{57AC79C8-157E-403A-A8D0-DD74EF71BAE2}" = Catalyst Control Center - Branding
"{60D0F028-7458-98F9-AF92-F9F83AF4F568}" = Catalyst Control Center InstallProxy
"{660787DD-68B3-4E67-9073-4A66DD7AD193}" = ASUS VGA Driver
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6B8364EA-9B85-EF54-6DEC-FC3CE9C55123}" = CCC Help Spanish
"{72AF0D20-AC75-3335-97C3-84599E1385BB}" = CCC Help German
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}" = Bing-Desktop
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8C9BD943-2017-7E76-D945-DF02DF919D96}" = Catalyst Control Center Core Implementation
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0407-1000-0000000FF1CE}_HOMESTUDENTR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A961C6FD-C583-45F6-A0A4-5E4376C29E41}" = Catalyst Control Center - Branding
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B794F825-BBA6-C4BB-79C4-CC657CA130AA}" = Catalyst Control Center Graphics Previews Vista
"{BBC25C82-FE8E-9A34-07B9-F182879E44CD}" = Catalyst Control Center Localization All
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{CE186519-9D34-3BA5-4CAB-8C3457D18F65}" = Catalyst Control Center Graphics Full New
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F2F7E361-D336-1338-A453-AB03B4818927}" = CCC Help Czech
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{1E61121B-87BA-469B-A294-2516B20AC1D1}" = Wireless-N 150 USB Adapter WNA1000
"InstallWIX_{2D270A67-B7CD-4281-B2FE-60DF18D19B8E}" = Kaspersky PURE 2.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300
"Mozilla Firefox 22.0 (x86 de)" = Mozilla Firefox 22.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"WinLiveSuite" = Windows Live Essentials ========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 22.07.2013 23:13:54 | Computer Name = Dagobert-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 22.07.2013 23:14:22 | Computer Name = Dagobert-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 22.07.2013 23:14:32 | Computer Name = Dagobert-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 22.07.2013 23:16:35 | Computer Name = Dagobert-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 22.07.2013 23:16:56 | Computer Name = Dagobert-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 22.07.2013 23:17:31 | Computer Name = Dagobert-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 22.07.2013 23:17:31 | Computer Name = Dagobert-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 22.07.2013 23:18:13 | Computer Name = Dagobert-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 23.07.2013 02:06:33 | Computer Name = Dagobert-PC | Source = MsiInstaller | ID = 10005
Description =
Error - 23.07.2013 02:19:17 | Computer Name = Dagobert-PC | Source = MsiInstaller | ID = 10005
Description =
[ System Events ]
Error - 22.07.2013 19:17:15 | Computer Name = Dagobert-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
Microsoft .NET Framework NGEN v2.0.50727_X86 erreicht.
Error - 22.07.2013 20:40:39 | Computer Name = Dagobert-PC | Source = DCOM | ID = 10010
Description =
Error - 22.07.2013 21:13:19 | Computer Name = Dagobert-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
Windows-Fehlerberichterstattungsdienst erreicht.
Error - 22.07.2013 23:59:47 | Computer Name = Dagobert-PC | Source = DCOM | ID = 10005
Description =
Error - 22.07.2013 23:59:47 | Computer Name = Dagobert-PC | Source = Service Control Manager | ID = 7038
Description = Der Dienst "upnphost" konnte sich nicht als "NT AUTHORITY\LocalService"
mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1352 Vergewissern
Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
Management Console (MMC).
Error - 22.07.2013 23:59:47 | Computer Name = Dagobert-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "UPnP-Gerätehost" wurde aufgrund folgenden Fehlers nicht
gestartet: %%1069
Error - 22.07.2013 23:59:47 | Computer Name = Dagobert-PC | Source = Service Control Manager | ID = 7038
Description = Der Dienst "upnphost" konnte sich nicht als "NT AUTHORITY\LocalService"
mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%50 Vergewissern
Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft
Management Console (MMC).
Error - 22.07.2013 23:59:47 | Computer Name = Dagobert-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "UPnP-Gerätehost" wurde aufgrund folgenden Fehlers nicht
gestartet: %%1069
Error - 23.07.2013 00:14:01 | Computer Name = Dagobert-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?23.?07.?2013 um 06:12:21 unerwartet heruntergefahren.
Error - 23.07.2013 04:51:26 | Computer Name = Dagobert-PC | Source = DCOM | ID = 10010
Description =
< End of report >
| Gmer.txt: Zitat:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-07-24 15:59:48
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD3200AAJS-22B4A0 rev.01.03A01 298,09GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Dagobert\AppData\Local\Temp\aglorpod.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756f1465 2 bytes [6F, 75]
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756f14bb 2 bytes [6F, 75]
.text ... * 2
.text C:\Program Files (x86)\NETGEAR\WNA1000\WNA1000.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756f1465 2 bytes [6F, 75]
.text C:\Program Files (x86)\NETGEAR\WNA1000\WNA1000.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756f14bb 2 bytes [6F, 75]
.text ... * 2
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\WNA1000\Parameters\Wdf
Reg HKLM\SYSTEM\CurrentControlSet\services\WNA1000\Parameters\Wdf@WdfMajorVersion 1
Reg HKLM\SYSTEM\CurrentControlSet\services\WNA1000\Parameters\Wdf@WdfMinorVersion 9
Reg HKLM\SYSTEM\CurrentControlSet\services\WNA1000\Parameters\Wdf@TimeOfLastSqmLog 0x4F 0xF8 0xDC 0xA1 ...
Reg HKLM\SYSTEM\ControlSet002\services\WNA1000\Parameters\Wdf (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\WNA1000\Parameters\Wdf@WdfMajorVersion 1
Reg HKLM\SYSTEM\ControlSet002\services\WNA1000\Parameters\Wdf@WdfMinorVersion 9
Reg HKLM\SYSTEM\ControlSet002\services\WNA1000\Parameters\Wdf@TimeOfLastSqmLog 0x4F 0xF8 0xDC 0xA1 ...
---- EOF - GMER 2.1 ----
| Zu den Problemen bei Gmer:
Aufgrund der Energiespareinstellungen wurde beim ersen Scan irgendwann das Bild schwarz ... nach Reaktivieren des Bildschirms blieb der aber schwarz ... der PC lief jedoch noch, also beendete ich - da auch Strg+Alt+Entf nicht half - den PC mit dem Stromschalter an der Steckdosenleiste und startete ihn erneut. Ich startete den Scan wieder und wackelte regelmäßig mit der Maus, dass er sich nicht wieder verabschiedet. Als ich nach dem Scn dann wieder den WLAN-Stick anschlos, wurde keine Verbindung gefunden. Daher startete ich den PC neu ... jedoch dauerte das Herunterfahren ewig lange, sodass ich nach ein paar Minuten wieder den Stromschalter betätigen musste ... Dann beim Hochfahren wurden mir wieder Verbindungen angezeigt ... und dann konnte ich diesen Beitrag verfassen.
Nun meine Frage: Ist mein PC nach der ganzen Sache und den ggf. Fehlalarmen (wenn es denn welche waren) sauber?
Vielen Dank schonmal! |