| Heureka! |  06.08.2010 07:37 |        Infektion mit Alureon.B - was tun..?    Hallo liebe Helfer und Helferinnen,  
erstmal ein herzliches DANKESCHÖN dafür, dass Ihr diese Plattform am Laufen haltet und Dusern wie mir Hilfe angedeien lasst!  
Ich bin neu hier und habe im Großen und Ganzen keine Ahnung von Computern ;-) 
Gestern hat mich mein Antivir (Premium) darauf Aufmerksam gemacht, dass ich dem Trojaner Alureon.B ein Heim biete... Entfernen mit Antivir war nicht wirklich erfolgreich, d.h. der Alureon.B kommt immer wieder. 
Meine Sche im Netz war elider wenig erfolgreich, hier im Forum habe ich zwar einen Thread gefunden, der behandelt aber nicht den Typ Alureon. B. Ich weiss leider nicht, ob alle Typen gleich zu behandeln sind, daher mein Posting. Ich hoffe, die Formvorgaben soweit wie möglich eingehalten zu haben...  
CC Cleaner habe ich laufen lassen. 
Mir ist aufgefallen, dass mein Antivir bei den Scans den "Autostart" blockiert - was tun..?  
Hier 'mal die Logfiles, die ich bislang erstellen konnte:  
HiJackthis Logfile:   Code:  
 Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 07:59:50, on 06.08.2010 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet Explorer v8.00 (8.00.6001.18702) 
Boot mode: Normal   
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\System32\svchost.exe 
C:\WINDOWS\system32\spoolsv.exe 
C:\Programme\Avira\AntiVir Desktop\sched.exe 
C:\Programme\Avira\AntiVir Desktop\avguard.exe 
C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe 
C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe 
C:\Programme\Java\jre6\bin\jqs.exe 
C:\WINDOWS\system32\nvsvc32.exe 
C:\Programme\Avira\AntiVir Desktop\avshadow.exe 
C:\Programme\PDF Complete\pdfsvc.exe 
C:\WINDOWS\system32\hpzipm12.exe 
c:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe 
C:\WINDOWS\system32\svchost.exe 
C:\Programme\Avira\AntiVir Desktop\avmailc.exe 
C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE 
C:\WINDOWS\system32\wbem\wmiapsrv.exe 
C:\WINDOWS\Explorer.EXE 
C:\WINDOWS\system32\RUNDLL32.EXE 
C:\WINDOWS\SMINST\Scheduler.exe 
C:\Programme\Winamp\winampa.exe 
C:\Programme\HP\HP Software Update\HPWuSchd2.exe 
C:\Programme\Avira\AntiVir Desktop\avgnt.exe 
C:\Programme\Nero\Nero 7\InCD\NBHGui.exe 
C:\Programme\Nero\Nero 7\InCD\InCD.exe 
C:\WINDOWS\system32\ctfmon.exe 
C:\Programme\Winamp Remote\bin\OrbTray.exe 
C:\Programme\MP4 Player\mp4Player.exe 
C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe 
C:\Programme\OpenOffice.org 3\program\soffice.exe 
C:\Programme\OpenOffice.org 3\program\soffice.bin 
C:\PROGRA~1\HEWLET~1\Toolbox\STATUS~1\STATUS~1.EXE 
C:\Programme\HP\Digital Imaging\bin\hpqgalry.exe 
C:\Programme\Winamp Remote\bin\Orb.exe 
C:\Programme\Hewlett-Packard\Toolbox\jre\bin\javaw.exe 
c:\programme\avira\antivir desktop\avcenter.exe 
C:\Programme\Avira\AntiVir Desktop\avscan.exe 
C:\Programme\Avira\AntiVir Desktop\avscan.exe 
C:\WINDOWS\system32\dllhost.exe 
C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe 
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe 
C:\Programme\Internet Explorer\iexplore.exe 
C:\Programme\Internet Explorer\iexplore.exe 
C:\Programme\Internet Explorer\iexplore.exe 
C:\Programme\Trend Micro\HijackThis\HijackThis.exe   
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=all&pf=cmdt 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Programme\BS_Player\tbBS_1.dll 
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programme\Winamp Toolbar\winamptb.dll 
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll 
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll 
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll 
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Programme\BS_Player\tbBS_1.dll 
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll 
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Programme\BS_Player\tbBS_1.dll 
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup 
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install 
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit 
O4 - HKLM\..\Run: [amd_dc_opt] C:\Programme\AMD\Dual-Core Optimizer\amd_dc_opt.exe 
O4 - HKLM\..\Run: [PDF Complete] C:\Programme\PDF Complete\pdfsty.exe 
O4 - HKLM\..\Run: [SetRefresh] C:\Programme\Compaq\SetRefresh\SetRefresh.exe 
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe 
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe 
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe 
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe 
O4 - HKLM\..\Run: [HP Software Update] "C:\Programme\HP\HP Software Update\HPWuSchd2.exe" 
O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min 
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe 
O4 - HKLM\..\Run: [SecurDisc] C:\Programme\Nero\Nero 7\InCD\NBHGui.exe 
O4 - HKLM\..\Run: [InCD] C:\Programme\Nero\Nero 7\InCD\InCD.exe 
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Programme\Hewlett-Packard\Toolbox\hpbpsttp.exe 
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 
O4 - HKCU\..\Run: [Orb] "C:\Programme\Winamp Remote\bin\OrbTray.exe" /background 
O4 - HKCU\..\Run: [MP4 Player] "C:\Programme\MP4 Player\mp4Player.exe" hmw 
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') 
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') 
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') 
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') 
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe 
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe 
O4 - Global Startup: HP Image Zone Schnellstart.lnk = C:\Programme\HP\Digital Imaging\bin\hpqthb08.exe 
O8 - Extra context menu item: &Winamp Search - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html 
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL 
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe 
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe 
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\avmailc.exe 
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\sched.exe 
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\avguard.exe 
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE 
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe 
O23 - Service: IviRegMgr - InterVideo - C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe 
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe 
O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe 
O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe 
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe 
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe 
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Programme\PDF Complete\pdfsvc.exe 
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\hpzipm12.exe   
-- 
End of file - 8317 bytes   --- --- ---     Zitat:      
			
				Malwarebytes' Anti-Malware 1.46 
www.malwarebytes.org   
Datenbank Version: 4397   
Windows 5.1.2600 Service Pack 3 
Internet Explorer 8.0.6001.18702   
06.08.2010 08:20:05 
mbam-log-2010-08-06 (08-20-05).txt   
Art des Suchlaufs: Quick-Scan 
Durchsuchte Objekte: 138305 
Laufzeit: 6 Minute(n), 8 Sekunde(n)   
Infizierte Speicherprozesse: 0 
Infizierte Speichermodule: 0 
Infizierte Registrierungsschlüssel: 0 
Infizierte Registrierungswerte: 0 
Infizierte Dateiobjekte der Registrierung: 0 
Infizierte Verzeichnisse: 0 
Infizierte Dateien: 0   
Infizierte Speicherprozesse: 
(Keine bösartigen Objekte gefunden)   
Infizierte Speichermodule: 
(Keine bösartigen Objekte gefunden)   
Infizierte Registrierungsschlüssel: 
(Keine bösartigen Objekte gefunden)   
Infizierte Registrierungswerte: 
(Keine bösartigen Objekte gefunden)   
Infizierte Dateiobjekte der Registrierung: 
(Keine bösartigen Objekte gefunden)   
Infizierte Verzeichnisse: 
(Keine bösartigen Objekte gefunden)   
Infizierte Dateien: 
(Keine bösartigen Objekte gefunden)
			
			   |       OTL Logfile:   Code:  
 OTL logfile created on: 06.08.2010 08:28:46 - Run 1 
OTL by OldTimer - Version 3.2.9.1     Folder = C:\Dokumente und Einstellungen\Administrator\Desktop 
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.6001.18702) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 54,00% Memory free 
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 79,00% Paging File free 
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme 
Drive C: | 137,03 Gb Total Space | 96,32 Gb Free Space | 70,29% Space Free | Partition Type: NTFS 
Drive D: | 12,00 Gb Total Space | 4,39 Gb Free Space | 36,58% Space Free | Partition Type: NTFS 
E: Drive not present or media not loaded 
F: Drive not present or media not loaded 
G: Drive not present or media not loaded 
H: Drive not present or media not loaded 
I: Drive not present or media not loaded 
  
Computer Name: HP21842302391 
Current User Name: Administrator 
Logged in as Administrator. 
  
Current Boot Mode: Normal 
Scan Mode: Current user 
Company Name Whitelist: Off 
Skip Microsoft Files: Off 
File Age = 30 Days 
Output = Minimal 
   ========== Processes (SafeList) ========== 
  
PRC - C:\Dokumente und Einstellungen\Administrator\Desktop\OTL.exe (OldTimer Tools) 
PRC - C:\Programme\Trend Micro\HijackThis\HijackThis.exe (Trend Micro Inc.) 
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) 
PRC - C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe (Avira GmbH) 
PRC - C:\Programme\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH) 
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) 
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) 
PRC - c:\Programme\Avira\AntiVir Desktop\avcenter.exe (Avira GmbH) 
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) 
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH) 
PRC - C:\Programme\Hewlett-Packard\Toolbox\jre\bin\javaw.exe () 
PRC - C:\Programme\MP4 Player\Mp4Player.exe () 
PRC - C:\Programme\OpenOffice.org 3\program\soffice.bin (OpenOffice.org) 
PRC - C:\Programme\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) 
PRC - C:\Programme\Winamp\winampa.exe () 
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) 
PRC - C:\Programme\PDF Complete\pdfsvc.exe (PDF Complete Inc) 
PRC - C:\Programme\Winamp Remote\bin\OrbTray.exe (Orb Networks) 
PRC - C:\Programme\Winamp Remote\bin\Orb.exe (Orb Networks, Inc.) 
PRC - C:\Programme\Nero\Nero 7\InCD\NBHGui.exe (Nero AG) 
PRC - C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG) 
PRC - C:\Programme\Nero\Nero 7\InCD\InCD.exe (Nero AG) 
PRC - c:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) 
PRC - c:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) 
PRC - C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) 
PRC - C:\WINDOWS\SMINST\Scheduler.exe () 
PRC - C:\Programme\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe (Hewlett-Packard) 
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP) 
  
   ========== Modules (SafeList) ========== 
  
MOD - C:\Dokumente und Einstellungen\Administrator\Desktop\OTL.exe (OldTimer Tools) 
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation) 
  
   ========== Win32 Services (SafeList) ========== 
  
SRV - (HidServ) -- C:\WINDOWS\System32\hidserv.dll File not found 
SRV - (AntiVirWebService) -- C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira GmbH) 
SRV - (AntiVirMailService) -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH) 
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) 
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) 
SRV - (pdfcDispatcher) -- C:\Programme\PDF Complete\pdfsvc.exe (PDF Complete Inc) 
SRV - (InCDsrv) -- C:\Programme\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG) 
SRV - (NMIndexingService) -- C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe (Nero AG) 
SRV - (SQLWriter) -- c:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) 
SRV - (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ) -- c:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) 
SRV - (SQLBrowser) -- c:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) 
SRV - (IviRegMgr) -- C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) 
SRV - (odserv) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation) 
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) 
SRV - (MSSQLServerADHelper) -- c:\Programme\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation) 
SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV - (MBAMSwissArmy) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation) 
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)[/QUOTE]   
[QUOTE]OTL Extras logfile created on: 06.08.2010 08:28:46 - Run 1 
OTL by OldTimer - Version 3.2.9.1     Folder = C:\Dokumente und Einstellungen\Administrator\Desktop 
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.6001.18702) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 54,00% Memory free 
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 79,00% Paging File free 
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme 
Drive C: | 137,03 Gb Total Space | 96,32 Gb Free Space | 70,29% Space Free | Partition Type: NTFS 
Drive D: | 12,00 Gb Total Space | 4,39 Gb Free Space | 36,58% Space Free | Partition Type: NTFS 
E: Drive not present or media not loaded 
F: Drive not present or media not loaded 
G: Drive not present or media not loaded 
H: Drive not present or media not loaded 
I: Drive not present or media not loaded 
  
Computer Name: HP21842302391 
Current User Name: Administrator 
Logged in as Administrator. 
  
Current Boot Mode: Normal 
Scan Mode: Current user 
Company Name Whitelist: Off 
Skip Microsoft Files: Off 
File Age = 30 Days 
Output = Minimal 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
   ========== Shell Spawning ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
exefile [open] -- "%1" %* 
htmlfile [edit] -- "C:\Programme\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- "C:\Programme\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Directory [Winamp.Bookmark] -- "C:\Programme\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) 
Directory [Winamp.Enqueue] -- "C:\Programme\Winamp\winamp.exe" /ADD "%1" (Nullsoft) 
Directory [Winamp.Play] -- "C:\Programme\Winamp\winamp.exe" "%1" (Nullsoft) 
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) 
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
   ========== Security Center Settings ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"FirstRunDisabled" = 1 
"AntiVirusDisableNotify" = 0 
"FirewallDisableNotify" = 0 
"UpdatesDisableNotify" = 0 
"AntiVirusOverride" = 0 
"FirewallOverride" = 0 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"EnableFirewall" = 1 
"DoNotAllowExceptions" = 0 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] 
   ========== Authorized Applications List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 
"C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation) 
"C:\WINDOWS\SMINST\Scheduler.exe" = C:\WINDOWS\SMINST\Scheduler.exe:*:Enabled:Scheduler  -- () 
"C:\Programme\Winamp Remote\bin\Orb.exe" = C:\Programme\Winamp Remote\bin\Orb.exe:*:Enabled:Orb -- (Orb Networks, Inc.) 
"C:\Programme\Winamp Remote\bin\OrbTray.exe" = C:\Programme\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray -- (Orb Networks) 
"C:\Programme\Winamp Remote\bin\OrbStreamerClient.exe" = C:\Programme\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client -- (Orb Networks) 
"C:\Programme\Hewlett-Packard\Toolbox\jre\bin\javaw.exe" = C:\Programme\Hewlett-Packard\Toolbox\jre\bin\javaw.exe:*:Enabled:javaw -- () 
"C:\Programme\Java\jre6\bin\java.exe" = C:\Programme\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.) 
"E:\CDS\Nero\Installation\SetupX.exe" = E:\CDS\Nero\Installation\SetupX.exe:*:Enabled:Nero ProductSetup -- File not found 
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Disabled:Windows Explorer -- (Microsoft Corporation) 
  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{028ED9C4-25EE-4DEE-9CF4-91034BC89B18}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) 
"{04B45310-A5FE-4425-BFCA-1A6D8920DE74}" = OpenOffice.org 3.0 
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu 
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) 
"{1030DCDC-2425-407d-BEE1-13558B837FCA}" = HP Color LaserJet 2820/2830/2840 2.0 
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare 
"{1D1D8ADC-BF08-4E61-9393-5FA305B16864}" = Microsoft SQL Server Native Client 
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp 
"{2154375F-A35D-4CB5-A996-3466251F6B3B}" = hpp2800usg 
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 11 
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload 
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP 
"{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}" = HP Backup and Recovery Manager 
"{45B3A3BD-F90D-48FE-A147-D74878A51031}" = Nero 7 Essentials 
"{4cb9f93c-9edc-4be9-ae61-af128ddbecfa}" = Business Contact Manager für Outlook 2007 
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies 
"{55508A44-8225-47AB-9666-1F57A5B5CE2E}" = CP_PLSBusinessFlyers 
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml 
"{59073DF9-3D3D-4FFC-AF41-C2C268A1A31E}" = hppTooCool 
"{5A347920-4AFC-11D5-9FB0-800649886934}" = SDFormatter 
"{5C759B74-34F4-43C6-A5D9-039CB754C5E9}" = Microsoft SQL Server VSS Writer 
"{606E5C0D-6039-42A7-988E-9D51DE773AFF}" = hppFonts 
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects 
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery 
"{64FC0C98-B035-4530-B15D-3D30610B6DF1}" = HP Software Update 
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites 
"{688EC50D-0155-4490-8DBF-686CD3B2893F}" = hppScanTo 
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations 
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =  
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm 
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable 
"{74E5E862-F1FF-412B-B824-9582ED7DE84A}" = hppSendFax 
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics 
"{7D7F2CB5-F9A4-4E86-853D-1BADD936DDAD}" = hppscan2800 
"{8043D1B8-81AE-4597-AAA8-1E1F49D6E4DF}" = hppManuals2800 
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1 
"{851D5410-0851-46F0-8836-74E0D8D20196}" = hppDustDevil 
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder 
"{8B2EF64A-1D1F-4AD8-91BF-7B5F1BC36E00}" = hppFaxDrv 
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc 
"{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders  (German) 12 
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 
"{909B62B0-8ACA-4061-A83B-09CAEF609619}" = MSXML 6.0 Parser 
"{90A40407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components 
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007 
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD 
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 
"{A28F43DA-258F-42EC-9C95-E6C9A7475670}" = hppIOFiles 
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components 
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support 
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director 
"{BD29EBAC-AD7D-4b27-B727-4CC6AC52D36B}" = MarketResearch 
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver 
"{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU 
"{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU 
"{C3E6DC57-473A-4424-9617-AF60BA8403C3}" = hppCLJ2800 
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg 
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer 
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack 
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver 
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager 
"{FE3F3C9B-2C29-4FEE-A74F-11E436729F2C}" = Scan 
"{FF3D660E-E5CC-47FD-8050-1B4DE3BA81A9}" = Dual-Core Optimizer 
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites 
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX 
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9 
"Audiograbber" = Audiograbber 1.83 SE  
"Audiograbber-Lame" = Audiograbber Lame-MP3-Plugin 
"Avira AntiVir Desktop" = Avira AntiVir Premium 
"AVS Update Manager_is1" = AVS Update Manager 1.0 
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3 
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6 
"BS_Player Toolbar" = BS_Player Toolbar 
"BSPlayerf" = BS.Player FREE 
"Business Contact Manager für Outlook 2007" = Business Contact Manager für Outlook 2007 
"CCleaner" = CCleaner 
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1 
"HaaliMkx" = Haali Media Splitter 
"HijackThis" = HijackThis 2.0.2 
"HP Photo & Imaging" = HP Image Zone 4.7 
"HPExtendedCapabilities" = HP Extended Capabilities 4.7 
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs 
"ie8" = Windows Internet Explorer 8 
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware 
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1 
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU 
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005 
"MP4 Player" = MP4 Player  
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP 
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs 
"NVIDIA Drivers" = NVIDIA Drivers 
"Orb" = Winamp Remote 
"PDF Complete" = PDF Complete 
"PROHYBRIDR" = 2007 Microsoft Office system 
"Winamp" = Winamp 
"Winamp Toolbar" = Winamp Toolbar for Internet Explorer 
"Winamp Toolbar for Firefox" = Winamp Toolbar for Firefox 
"Windows Media Format Runtime" = Windows Media Format 11 runtime 
"Windows Media Player" = Windows Media Player 11 
"Windows XP Service Pack" = Windows XP Service Pack 3 
"WMFDist11" = Windows Media Format 11 runtime 
"wmp11" = Windows Media Player 11 
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0 
   ========== Last 10 Event Log Errors ========== 
  
[ Application Events ] 
Error - 20.07.2010 11:18:42 | Computer Name = HP21842302391 | Source = crypt32 | ID = 131083 
Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> 
 ist fehlgeschlagen mit dem Fehler: Ein erforderliches Zertifikat befindet sich  
nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel 
 in der signierten Datei.  . 
  
Error - 20.07.2010 11:18:42 | Computer Name = HP21842302391 | Source = crypt32 | ID = 131083 
Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> 
 ist fehlgeschlagen mit dem Fehler: Ein erforderliches Zertifikat befindet sich  
nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel 
 in der signierten Datei.  . 
  
Error - 28.07.2010 10:38:06 | Computer Name = HP21842302391 | Source = Application Hang | ID = 1002 
Description = Stillstehende Anwendung iexplore.exe, Version 8.0.6001.18702, Stillstandmodul 
 hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. 
  
Error - 28.07.2010 10:38:07 | Computer Name = HP21842302391 | Source = Application Hang | ID = 1002 
Description = Stillstehende Anwendung iexplore.exe, Version 8.0.6001.18702, Stillstandmodul 
 hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. 
  
Error - 28.07.2010 10:38:07 | Computer Name = HP21842302391 | Source = Application Hang | ID = 1002 
Description = Stillstehende Anwendung iexplore.exe, Version 8.0.6001.18702, Stillstandmodul 
 hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. 
  
Error - 01.08.2010 10:16:08 | Computer Name = HP21842302391 | Source = Application Hang | ID = 1002 
Description = Stillstehende Anwendung iexplore.exe, Version 8.0.6001.18702, Stillstandmodul 
 hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. 
  
Error - 05.08.2010 03:53:55 | Computer Name = HP21842302391 | Source = Application Hang | ID = 1002 
Description = Stillstehende Anwendung iexplore.exe, Version 8.0.6001.18702, Stillstandmodul 
 hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. 
  
[ System Events ] 
Error - 28.07.2010 15:03:21 | Computer Name = HP21842302391 | Source = DCOM | ID = 10010 
Description = Der Server "{5A5AA0AA-1DEB-4683-96B0-B43301E83971}" konnte innerhalb 
 des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. 
  
Error - 28.07.2010 15:03:51 | Computer Name = HP21842302391 | Source = DCOM | ID = 10010 
Description = Der Server "{5A5AA0AA-1DEB-4683-96B0-B43301E83971}" konnte innerhalb 
 des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. 
  
Error - 28.07.2010 15:04:21 | Computer Name = HP21842302391 | Source = DCOM | ID = 10010 
Description = Der Server "{5A5AA0AA-1DEB-4683-96B0-B43301E83971}" konnte innerhalb 
 des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. 
  
Error - 28.07.2010 15:04:51 | Computer Name = HP21842302391 | Source = DCOM | ID = 10010 
Description = Der Server "{5A5AA0AA-1DEB-4683-96B0-B43301E83971}" konnte innerhalb 
 des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. 
  
Error - 28.07.2010 15:05:21 | Computer Name = HP21842302391 | Source = DCOM | ID = 10010 
Description = Der Server "{5A5AA0AA-1DEB-4683-96B0-B43301E83971}" konnte innerhalb 
 des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. 
  
Error - 28.07.2010 15:06:21 | Computer Name = HP21842302391 | Source = DCOM | ID = 10010 
Description = Der Server "{5A5AA0AA-1DEB-4683-96B0-B43301E83971}" konnte innerhalb 
 des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. 
  
Error - 28.07.2010 15:06:51 | Computer Name = HP21842302391 | Source = DCOM | ID = 10010 
Description = Der Server "{5A5AA0AA-1DEB-4683-96B0-B43301E83971}" konnte innerhalb 
 des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. 
  
Error - 28.07.2010 15:07:21 | Computer Name = HP21842302391 | Source = DCOM | ID = 10010 
Description = Der Server "{5A5AA0AA-1DEB-4683-96B0-B43301E83971}" konnte innerhalb 
 des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. 
  
Error - 28.07.2010 15:07:52 | Computer Name = HP21842302391 | Source = DCOM | ID = 10010 
Description = Der Server "{5A5AA0AA-1DEB-4683-96B0-B43301E83971}" konnte innerhalb 
 des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. 
  
Error - 28.07.2010 15:22:27 | Computer Name = HP21842302391 | Source = DCOM | ID = 10010 
Description = Der Server "{5A5AA0AA-1DEB-4683-96B0-B43301E83971}" konnte innerhalb 
 des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. 
  
  
< End of report >   --- --- ---   
Viele Grüße,  
Heureka!    |