Guten Tag, ich habe folgendes Problem:

(Zusätzliche Informationen:
Betriebssystem: Windows XP SP3
AV: Avast mit Guard, Mbam)

Ich habe gestern versucht, die Datei "MechTexturizer.exe" runterzuladen, als mein AV plötzlich Alarm schlug und die Datei direkt in den Viruscontainer verschob. Bei dieser Datei handelt es sich angeblich um ein Mod/Tool für das Spiel Mechwarrior 3, und um sicherzugehen, das es nicht einfach nur um ein False-Positive handelt (wäre nicht das Erste mal, ist mir schon öfters vorgekommen dass eine Datei nur von einem oder zwei AV's als infiziert beschrieben wurde, obwohl dies im Endeffekt nicht der Fall war. Und zusätzlich wurde darauf hingewiesen dass in der Vergangenheit einige AV's diese Datei als "False-Positive" erkannt haben), habe ich:

- In Avast's Viruscontainer die Datei ausgewählt, und auf "Aus Container extrahieren..." geklickt und die Datei auf den Desktop kopiert, mit dem Ziel, sie auf Virustotal hochzuladen. Dummerweise hat mein Internet gebockt (macht es manchmal) und ich musste den PC neu starten (Anmerkung: Avast sagte die Datei sei immer noch im Viruscontainer)

- Nach dem Neustart habe ich direkt versucht die Datei auf VT hochzuladen, aber als sich das Fenster öffnet und ich auf die Datei klicke, fährt der PC direkt runter und startet neu. (Anmerkung: Avast sagte immer noch die Datei sei im Viruscontainer, habe überprüft bevor ich versucht habe sie hochzuladen: sie ist einmal auf dem Desktop und einmal in Avast's Viruscontainer...)

- Nach diesem (dem Zweiten) Neustart habe ich versucht die auf dem Desktop befindliche Datei mit Mbam zu scannen, und der der PC fuhr wieder runter und startet neu.

- Nur diesmal waren beide vorher genannten Dateien fort, einfach verschwunden (selbst die in Avast's Viruscontainer).

- Habe nun den PC manuell neu gestartet (im abgesicherten Modus) und habe sowohl mit Mbam als Avast einen Komplettscan durchgeführt, wobei nur Avast irgendwas in der Systemwiederherstellung gefunden hat, eine Infektion namens "Win32:Malware-gen", wobei es sich wohl um Überreste der vorher genannten Dateien handelt, die ich auch prompt entfernt habe (anschließend habe ich die Systemwiederherstellung deaktiviert und nach einem Neustart wieder aktiviert)

Nun bin ich doch etwas verwirrt ob diese Datei wirklich sicher war (nach 2 shutdowns meines PC's), und was eigentlich mit ihr passiert ist (da ich sie definitiv nicht gelöscht habe, und noch nie gehört habe, dass Avast oder irgendein anderes Antiviren Programm einfach so suspekte Dateien löscht, ohne irgendwie dazu aufgefordert zu werden...)

Hoffe ihr könnt mir bei diesem Problem(?) helfen... (ich bin doch sehr verwirrt hier und nicht nur ein bísschen besorgt...)

Anbei sind: Screenshot von Avast (Komplettscan) und die Logs von Defogger, OTL, aswMBR, MBR, Catchme.exe, Gmer und Mbam (von gestern)... habe Computer/Benutzername durch * ersetzt.

Vielen Dank im Voraus.

Edit: Beim Scan von Mbam habe ich die Dateien auf dem unter Desktop im zweiten (eingeschränkten) Benutzerkonto ausgelassen/ausgeschlossen (hauptsächlich Bilder und Videos), weil diese Mbam's Scan doch sehr verlangsamen wenn vom Administrator Konto ausgeführt (aber nicht wenn vom vorher genannten eingeschränkten Konto)...

cosinus
TB-Süch-Tiger™
Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.


Habe leider keine älteren Logs mehr, habe aber in der Zwischenzeit noch zweimal mit einer upgedateten Version gescannt (wurde beides mal nichts gefunden)

Anbei sind dei neuen Logs.

cosinus
TB-Süch-Tiger™
Führ bitte auch ESET aus, danach sehen wir weiter.

Hinweis: ESET zeigt durchaus öfter ein paar Fehlalarme. Deswegen soll auch von ESET immer nur erst das Log gepostet und nichts entfernt werden.

ESET Online Scanner

Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.
  • Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt so öffnen: per Rechtsklick => als Administrator ausführen
  • Dein Anti-Virus-Programm während des Scans deaktivieren.

    Button (<< klick) drücken.
    • Firefox-User:
      Bitte esetsmartinstaller_enu.exe downloaden.Das Firefox-Addon auf dem Desktop speichern und dann installieren.
    • IE-User:
      müssen das Installieren eines ActiveX Elements erlauben.
  • Setze den einen Haken bei Yes, i accept the Terms of Use.
  • Drücke den Button.
  • Warte bis die Komponenten herunter geladen wurden.
  • Setze einen Haken bei "Scan archives".
  • Gehe sicher das bei Remove Found Threats kein Hacken gesetzt ist.
  • drücken.
  • Die Signaturen werden herunter geladen.Der Scan beginnt automatisch.
Wenn der Scan beendet wurde
  • Klicke Finish.
  • Browser schließen.
Drücke bitte die + R Taste und kopiere folgenden Text in das Ausführen Fenster.
"%PROGRAMFILES%\Eset\Eset Online Scanner\log.txt"
Hinweis: Falls du ein 64-Bit-Windows einsetzt, lautet der Pfad so:

"%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\log.txt"
Poste nun den Inhalt der log.txt.
Logfiles bitte immer in CODE-Tags posten

Hier ist das Log von ESET

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=a56c216b71233e4e8002a48358d68438
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2012-07-13 05:33:53
# local_time=2012-07-13 07:33:53 (+0100, Paris, Madrid (heure d'été))
# country="France"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 50974567 50974567 0 0
# compatibility_mode=8192 67108863 100 0 328 328 0 0
# scanned=65936
# found=0
# cleaned=0
# scan_time=3713

cosinus
TB-Süch-Tiger™
adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.
--> Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter

Hier ist das Log von AdwCleaner (habe Benutzer/Computernamen mit * editiert)

# AdwCleaner v1.702 - Rapport créé le 14/07/2012 à 01:23:13
# Mis à jour le 13/07/2012 par Xplode
# Système d'exploitation : Microsoft Windows XP Service Pack 3 (32 bits)
# Nom d'utilisateur : ****** - *****-37AD7B7B3
# Exécuté depuis : C:\Documents and Settings\******\Bureau\adwcleaner0.exe
# Option [Recherche]

***** [Services] *****

***** [Fichiers / Dossiers] *****

***** [Registre] *****

Clé Présente : HKLM\SOFTWARE\Canneverbe Limited\OpenCandy
Clé Présente : HKLM\SOFTWARE\DT Soft
Clé Présente : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43

***** [Registre - GUID] *****

Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1}
Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999}

***** [Navigateurs] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Le registre ne contient aucune entrée illégitime.

-\\ Mozilla Firefox v13.0.1 (de)

Nom du profil : default 
Fichier : C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\prefs.js

[OK] Le fichier ne contient aucune entrée illégitime.

-\\ Google Chrome v [Impossible d'obtenir la version]

Fichier : C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] Le fichier ne contient aucune entrée illégitime.

-\\ Opera v12.0.1467.0

Fichier : C:\Documents and Settings\******\Application Data\Opera\Opera\operaprefs.ini

[OK] Le fichier ne contient aucune entrée illégitime.


AdwCleaner[R1].txt - [1633 octets] - [14/07/2012 01:23:13]

########## EOF - C:\AdwCleaner[R1].txt - [1761 octets] ##########

cosinus
TB-Süch-Tiger™
adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.
Logfiles bitte immer in CODE-Tags posten

Hier ist das zweite Log von AdwCleaner

# AdwCleaner v1.702 - Rapport créé le 14/07/2012 à 21:08:21
# Mis à jour le 13/07/2012 par Xplode
# Système d'exploitation : Microsoft Windows XP Service Pack 3 (32 bits)
# Nom d'utilisateur : ****** - *****-37AD7B7B3
# Exécuté depuis : C:\Documents and Settings\******\Bureau\adwcleaner0.exe
# Option [Suppression]

***** [Services] *****

***** [Fichiers / Dossiers] *****

***** [Registre] *****

Clé Supprimée : HKLM\SOFTWARE\Canneverbe Limited\OpenCandy
Clé Supprimée : HKLM\SOFTWARE\DT Soft
Clé Supprimée : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43

***** [Registre - GUID] *****

Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999}

***** [Navigateurs] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Le registre ne contient aucune entrée illégitime.

-\\ Mozilla Firefox v13.0.1 (de)

Nom du profil : default 
Fichier : C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\prefs.js

[OK] Le fichier ne contient aucune entrée illégitime.

-\\ Google Chrome v [Impossible d'obtenir la version]

Fichier : C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] Le fichier ne contient aucune entrée illégitime.

-\\ Opera v12.0.1467.0

Fichier : C:\Documents and Settings\******\Application Data\Opera\Opera\operaprefs.ini

[OK] Le fichier ne contient aucune entrée illégitime.


AdwCleaner[R1].txt - [1762 octets] - [14/07/2012 01:23:13]
AdwCleaner[S2].txt - [1700 octets] - [14/07/2012 21:08:21]

########## EOF - C:\AdwCleaner[S2].txt - [1828 octets] ##########

cosinus
TB-Süch-Tiger™
Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

 hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
  • Starte bitte die OTL.exe.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Kopiere nun den kompletten Inhalt aus der untenstehenden Codebox in die Textbox von OTL - wenn OTL auf deutsch ist wird sie mit beschriftet
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.exe /s
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Klick auf .
  • Kopiere nun den Inhalt aus OTL.txt hier in Deinen Thread
Logfiles bitte immer in CODE-Tags posten

Hier ist das zweite Log von OTL

[2011/10/13 04:59:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\EurekaLog
[2010/11/11 00:35:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\FreeFLVConverter
[2011/12/24 09:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Help
[2010/11/10 02:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Identities
[2012/07/15 03:39:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Macromedia
[2010/11/11 00:32:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Malwarebytes
[2012/07/08 06:02:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Media Player Classic
[2012/02/14 17:04:23 | 000,000,000 | --SD | M] -- C:\Documents and Settings\******\Application Data\Microsoft
[2010/11/11 00:36:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Mozilla
[2012/07/15 01:26:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Notepad++
[2010/11/12 04:33:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\OpenOffice.org
[2010/11/11 00:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Opera
[2012/06/16 01:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\PhotoFiltre
[2012/01/08 03:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\RenPy
[2011/09/28 23:43:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Sudeki
[2011/02/27 14:02:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Sun
[2010/11/12 04:37:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Thunderbird
[2012/07/15 03:44:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\uTorrent
[2012/06/25 20:58:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\vlc
[2011/12/12 21:27:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\ZipGenius
< %APPDATA%\*.exe /s >
[2008/06/02 00:25:02 | 000,737,192 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\keyscrambler@qfx.software.corporation\installer\setup.exe
< %SYSTEMDRIVE%\*.exe >
[2008/04/11 08:03:48 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< MD5 for: AGP440.SYS  >
[2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS  >
[2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/05 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL  >
[2004/08/05 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=21E83876A6287F15538EF187D286FE11 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008/04/14 04:33:24 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 04:33:24 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL  >
[2008/04/14 04:33:34 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 04:33:34 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\system32\netlogon.dll
[2009/02/06 20:46:49 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ECD7791E0E9246CA5F218A19F3911EB9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 20:46:49 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ECD7791E0E9246CA5F218A19F3911EB9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/05 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=FAF07FDCDE76000621A28D19F8E2E8EB -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL  >
[2008/04/14 04:33:40 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 04:33:40 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\system32\scecli.dll
[2004/08/05 14:00:00 | 000,186,368 | ---- | M] (Microsoft Corporation) MD5=DEC0397F35D027874804EC72979D03CC -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
< MD5 for: USER32.DLL  >
[2005/03/02 20:10:36 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=0DF75FB73F705B011630159A43D7C354 -- C:\WINDOWS\$NtUninstallKB925902$\user32.dll
[2007/03/08 17:50:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=4D88AAF39ADABFE45958EA1384E2C4FF -- C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
[2007/03/08 17:37:50 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=753354F594809A9B96F73999B435A533 -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2005/03/02 20:20:32 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=C34920EB988CE98910BD6B0417F334EB -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2004/08/05 14:00:00 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=E46FB493E3B33704F0715020CF52106B -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll
[2008/04/14 04:33:48 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=E853F84D3CE2FAA2A802E33CF89AC023 -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008/04/14 04:33:48 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=E853F84D3CE2FAA2A802E33CF89AC023 -- C:\WINDOWS\system32\user32.dll
< MD5 for: USERINIT.EXE  >
[2004/08/05 14:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D6D65EA32B190401B57EDB6706F29669 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 04:34:26 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 04:34:26 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE  >
[2012/07/03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2004/08/05 14:00:00 | 000,506,368 | ---- | M] (Microsoft Corporation) MD5=D2DE785AEAB0BB8CA4C14A8A199DBE4E -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 04:34:28 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 04:34:28 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2IFSL.SYS  >
[2004/08/05 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2004/08/05 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2010/11/01 14:12:00 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2010/11/01 14:12:00 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2010/11/01 14:11:59 | 000,475,136 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
<           >

< End of report >
--- --- ---

PRC - [2012/07/03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2012/06/20 00:09:40 | 003,069,752 | ---- | M] (Emsisoft GmbH) -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe
Ähm sage mal hast du Emsisoft und Avast parallel am Treiben?

Willst du dein System in die Knie zwingen? Zwei solcher Virenscanner installiert man niemals parallel! Deinstalliere einen der beiden! Am besten behälst du Avast

Max. Malwarebytes kann man zu einem installierten Virenscanner benutzen, bei Malwarebytes würde ich aber die reine Free-Variante ohne Hintergrundschutz-Modul verwenden.
(die anderen Scanner die ich hier in der Bereinigung/Analyse verwende kommen den anderen auch nichts ins Gehege)
Logfiles bitte immer in CODE-Tags posten

Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter - Standard

Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter

Ich habe Emsisoft jetzt deinstalliert, hatte immer nur bei Avast den Guard/Hintergrundwächter aktiviert (habe bei Emsisoft nur die normale Scan Funktion benutzt, ohne Hintergrundwächter, selbes gilt für Mbam).

Sonst alles in Ordnung?

Ok, mach bitte wieder ein neues OTL-Log wie o.g.
Habe OTL nochmal neu heruntergeladen. Hier ist das neue Log:

OTL logfile created on: 15/07/2012 21:53:00 - Run 3
OTL by OldTimer - Version     Folder = C:\Documents and Settings\******\Bureau
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 1,61 Gb Available Physical Memory | 80,78% Memory free
3,91 Gb Paging File | 3,63 Gb Available in Paging File | 92,64% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76,68 Gb Total Space | 6,35 Gb Free Space | 8,29% Space Free | Partition Type: NTFS
Drive K: | 7,45 Gb Total Space | 3,00 Gb Free Space | 40,28% Space Free | Partition Type: FAT32
Computer Name: *****-37AD7B7B3 | User Name: ****** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/07/15 21:44:04 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\******\Bureau\OTL.exe
PRC - [2012/07/03 18:21:30 | 004,273,976 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2012/07/03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011/01/05 12:31:34 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\sua.exe
PRC - [2011/01/05 12:31:32 | 000,988,216 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psia.exe
PRC - [2008/04/14 04:34:03 | 001,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/03/22 12:07:22 | 000,040,960 | ---- | M] () -- C:\Program Files\System Control Manager\edd.exe
PRC - [2005/01/27 10:33:58 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\o2flash.exe
========== Modules (No Company Name) ==========
MOD - [2012/07/15 10:56:50 | 001,783,296 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12071500\algo.dll
MOD - [2006/03/22 12:07:22 | 000,040,960 | ---- | M] () -- C:\Program Files\System Control Manager\edd.exe
MOD - [2005/01/27 10:33:58 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\o2flash.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012/07/03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012/06/15 00:17:46 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2011/01/05 12:31:34 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2011/01/05 12:31:32 | 000,988,216 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\psia.exe -- (Secunia PSI Agent)
SRV - [2006/03/22 12:07:22 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Program Files\System Control Manager\edd.exe -- (NishService)
SRV - [2005/01/27 10:33:58 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\o2flash.exe -- (O2Flash)
SRV - [2004/10/22 04:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\WINDOWS\\SystemRoot\System32\Drivers\sptd.sys -- (sptd)
DRV - File not found [Kernel | Auto | Stopped] -- system32\DRIVERS\RtNdPt5x.sys -- (RtNdPt5x)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RTLVLAN.SYS -- (RTLVLAN)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RTLTEAMING.SYS -- (RTLTEAMING)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - [2012/07/03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/07/03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/07/03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/07/03 18:21:53 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012/07/03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2012/07/03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/07/03 18:21:52 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012/06/29 19:39:20 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011/10/17 13:49:49 | 000,078,848 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SSHDRV85.sys -- (SSHDRV85)
DRV - [2010/11/02 20:36:26 | 006,188,648 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2010/09/11 04:19:16 | 005,417,472 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2010/09/01 10:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\psi_mf.sys -- (PSI)
DRV - [2010/07/21 13:30:32 | 000,101,904 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtihdXP3.sys -- (AtiHDAudioService)
DRV - [2010/07/06 03:13:10 | 000,234,392 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2010/07/04 21:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2010/05/24 21:09:28 | 004,003,008 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtKHDMI.sys -- (RTHDMIAzAudService)
DRV - [2010/03/09 12:09:32 | 000,594,048 | R--- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rtl8192su.sys -- (RTL8192su)
DRV - [2010/02/11 14:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2009/11/18 08:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009/11/18 08:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/10/29 07:34:40 | 000,644,096 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt2870.sys -- (rt2870)
DRV - [2008/10/09 15:42:42 | 000,017,408 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KMWDFILTER.sys -- (KMWDFILTER)
DRV - [2008/04/13 20:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/04/13 20:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008/03/22 23:37:20 | 000,113,896 | ---- | M] (QFX Software Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\keyscrambler.sys -- (KeyScrambler)
DRV - [2006/07/03 11:31:26 | 000,009,088 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MGHwCtrl.sys -- (MGHwCtrl)
DRV - [2006/03/01 19:53:54 | 000,032,128 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pcandis5.sys -- (PCANDIS5)
DRV - [2004/08/05 14:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2004/08/05 14:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2004/08/03 23:29:38 | 000,161,020 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2003/09/23 11:38:34 | 000,034,688 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pcampr5.sys -- (PCAMPR5)
DRV - [2001/08/23 17:59:36 | 000,075,392 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atimpae.sys -- (atirage3)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: en-GB@dictionaries.addons.mozilla.org:1.19.1
FF - prefs.js..extensions.enabledItems: en-US@dictionaries.addons.mozilla.org:5.0.1
FF - prefs.js..extensions.enabledItems: de_DE@dicts.j3e.de:20111003
FF - prefs.js..extensions.enabledItems: fr-reforme1990@dictionaries.addons.mozilla.org:4.0.3
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.1.2
FF - prefs.js..extensions.enabledItems: adblockpopups@jessehakanen.net:0.2.9
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.8
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.87
FF - prefs.js..extensions.enabledItems: optimizegoogle@optimizegoogle.com:0.78.2
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.7
FF - prefs.js..extensions.enabledItems: {fe0258ab-4f74-43a1-8781-bcdf340f9ee9}:2.6.4
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.67
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.6
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.2
FF - prefs.js..extensions.enabledItems: keyscrambler@qfx.software.corporation:
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: wrc@avast.com:6.0.1289
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012/07/09 21:32:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/25 15:27:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/25 15:06:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Programme\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/06/25 14:59:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/11/12 04:37:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\******\Application Data\Mozilla\Extensions
[2010/11/12 04:37:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\******\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/12 07:24:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions
[2010/11/12 05:40:55 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/04/21 11:56:02 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2012/04/01 14:32:09 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/11/12 04:39:37 | 000,000,000 | ---D | M] (Redirect Remover) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\{fe0258ab-4f74-43a1-8781-bcdf340f9ee9}
[2012/06/29 21:13:08 | 000,000,000 | ---D | M] (Wörterbuch Deutsch (de-DE), Hunspell-unterstützt) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\de_DE@dicts.j3e.de
[2010/12/12 16:34:32 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\en-GB@dictionaries.addons.mozilla.org
[2012/05/26 20:30:36 | 000,000,000 | ---D | M] (United States English Spellchecker) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\en-US@dictionaries.addons.mozilla.org
[2011/11/11 23:30:41 | 000,000,000 | ---D | M] (Dictionnaire français «Réforme 1990») -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\fr-reforme1990@dictionaries.addons.mozilla.org
[2010/11/12 04:48:56 | 000,000,000 | ---D | M] (KeyScrambler) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\keyscrambler@qfx.software.corporation
[2011/03/16 06:10:12 | 000,000,000 | ---D | M] (Personas) -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\personas@christopher.beard
[2012/06/25 15:27:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/06/25 15:06:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/07/12 07:24:19 | 000,525,390 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
[2012/07/11 01:06:27 | 000,061,228 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI
[2012/01/21 13:52:58 | 000,138,614 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\******\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\YSF54H3B.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
[2012/06/15 00:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/06/15 00:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/06/15 00:46:56 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/06/15 00:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012/06/15 00:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/06/15 00:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/06/15 00:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome  ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\Application\10.0.648.204\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\Application\10.0.648.204\pdf.dll
CHR - plugin: Google Gears (Enabled) = C:\Documents and Settings\******\Local Settings\Application Data\Google\Chrome\Application\10.0.648.204\gears.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
O1 HOSTS File: ([2012/07/13 18:20:21 | 000,443,529 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts:       localhost
O1 - Hosts:	www.007guard.com
O1 - Hosts:	007guard.com
O1 - Hosts:	008i.com
O1 - Hosts:	www.008k.com
O1 - Hosts:	008k.com
O1 - Hosts:	www.00hq.com
O1 - Hosts:	00hq.com
O1 - Hosts:	010402.com
O1 - Hosts:	www.032439.com
O1 - Hosts:	032439.com
O1 - Hosts:	www.0scan.com
O1 - Hosts:	0scan.com
O1 - Hosts:	1000gratisproben.com
O1 - Hosts:	www.1000gratisproben.com
O1 - Hosts:	1001namen.com
O1 - Hosts:	www.1001namen.com
O1 - Hosts:	100888290cs.com
O1 - Hosts:	www.100888290cs.com
O1 - Hosts:	www.100sexlinks.com
O1 - Hosts:	100sexlinks.com
O1 - Hosts:	10sek.com
O1 - Hosts:	www.10sek.com
O1 - Hosts:	www.1-2005-search.com
O1 - Hosts:	1-2005-search.com
O1 - Hosts: 15235 more lines...
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (CKeyScramblerBHO Object) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKU\S-1-5-21-796845957-1425521274-1801674531-1005..\Run: [PeerBlock] C:\Program Files\PeerBlock\peerblock.exe (PeerBlock, LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKU\S-1-5-21-796845957-1425521274-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FB FF FF 03  [binary data]
O9 - Extra 'Tools' menuitem : &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289332900642 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C4C5D9D8-EF89-402D-AE7C-D249AB041AE4}: DhcpNameServer =
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Colline verdoyante.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Colline verdoyante.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/10/26 15:39:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{58af6740-ff7d-11e0-b98e-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{58af6740-ff7d-11e0-b98e-806d6172696f}\Shell\AutoRun\command - "" = J:\arun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (aswBoot.exe /M:d7880c91)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: Irmon -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: WmdmPmSp -  File not found
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Secunia PSI Tray.lnk - C:\Program Files\Secunia\PSI\psi_tray.exe - (Secunia)
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Sitecom 300N USB Wireless LAN Utility.lnk - C:\Program Files\SITECOM\300N USB Wireless LAN Utility\RtWLan.exe - (Realtek Semiconductor Corp.)
MsConfig - StartUpFolder: C:^Documents and Settings^*******^Menu Démarrer^Programmes^Démarrage^Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe - (Secunia)
MsConfig - StartUpFolder: C:^Documents and Settings^******^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.4.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe - ()
MsConfig - StartUpFolder: C:^Documents and Settings^******^Menu Démarrer^Programmes^Démarrage^Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe - (Secunia)
MsConfig - StartUpFolder: C:^Documents and Settings^*****^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.4.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe - ()
MsConfig - StartUpFolder: C:^Documents and Settings^******^Menu Démarrer^Programmes^Démarrage^Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe - (Secunia)
MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
MsConfig - StartUpReg: KernelFaultCheck - hkey= - key= -  File not found
MsConfig - StartUpReg: MGSysCtrl - hkey= - key= - C:\Program Files\System Control Manager\MGSysCtrl.exe (MSI)
MsConfig - StartUpReg: ORAHSSSessionManager - hkey= - key= - C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe (France Telecom SA)
MsConfig - StartUpReg: SpybotSD TeaTimer - hkey= - key= - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg: UnlockerAssistant - hkey= - key= - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: nm - C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
SafeBootNet: nm.sys - C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {0213C6AF-5562-4D09-884C-2ADCFC8C2F35} - Microsoft .NET Framework 1.1 Security Update (KB2656353)
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Rendu VML (Vector Graphics Rendering)
ActiveX: {1897C549-AE52-4571-8996-44854F5612B2} - Microsoft .NET Framework 1.1 Security Update (KB2656370)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Liaison de données Dynamic HTML pour Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Création avancée
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - Classes Java DirectAnimation
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {72AD53CC-CCC0-3757-8480-9EE176866A7C} - .NET Framework
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {9A394342-4A68-4EBA-85A6-55B559F4E700} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Planificateur de tâches
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate
ActiveX: {F196AC50-7C95-42E1-9947-BDAB18BF3C8C} - .NET Framework
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
ActiveX: Microsoft Base Smart Card Crypto Provider Package - 
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/07/15 21:48:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\******\Recent
[2012/07/15 21:43:56 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\******\Bureau\OTL.exe
[2012/07/13 18:26:50 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/07/08 22:45:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Logs
[2012/07/06 08:15:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Nouv
[2012/07/05 21:42:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Nou
[2012/07/02 18:02:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\DOSBox
[2012/07/02 17:09:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Local Settings\Application Data\DOSBox
[2012/07/02 17:05:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\DOSBox-0.74
[2012/07/02 16:37:39 | 000,000,000 | ---D | C] -- C:\DOS
[2012/07/02 01:36:49 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2012/07/01 21:08:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Bureau\Ma
[2012/06/29 19:39:20 | 000,242,240 | ---- | C] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys
[2012/06/25 18:10:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\dwhelper
[2012/06/16 01:48:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\******\Application Data\PhotoFiltre
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/15 21:51:45 | 000,576,084 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2012/07/15 21:51:45 | 000,502,718 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/07/15 21:51:45 | 000,104,688 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2012/07/15 21:51:45 | 000,088,242 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/07/15 21:49:05 | 000,000,318 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/07/15 21:47:34 | 000,013,728 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/07/15 21:47:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/07/15 21:44:04 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\******\Bureau\OTL.exe
[2012/07/14 23:55:27 | 000,113,541 | ---- | M] () -- C:\Documents and Settings\******\Bureau\screen2.png
[2012/07/13 18:20:21 | 000,443,529 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/07/12 03:19:54 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\ Malwarebytes Anti-Malware .lnk
[2012/07/11 01:10:07 | 000,196,160 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/07/09 21:40:27 | 000,003,121 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/07/09 21:31:04 | 000,443,055 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120713-182021.backup
[2012/07/09 21:30:09 | 000,443,055 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120709-213104.backup
[2012/07/08 20:22:41 | 000,210,944 | ---- | M] () -- C:\Documents and Settings\******\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/07/03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/07/03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/07/03 18:21:53 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/07/03 18:21:53 | 000,089,624 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/07/03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/07/03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/07/03 18:21:52 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/07/03 18:21:32 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/07/03 18:21:28 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012/07/03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/07/02 23:30:54 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\******\peerblock.dmp
[2012/07/02 18:18:00 | 000,000,546 | ---- | M] () -- C:\WINDOWS\System32\autoexec2.nt
[2012/07/01 21:18:39 | 000,000,648 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/06/29 19:46:06 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120709-213008.backup
[2012/06/29 19:39:20 | 000,242,240 | ---- | M] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys
[2012/06/25 15:27:56 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/06/25 15:27:56 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Mozilla Firefox.lnk
[2012/06/25 14:59:59 | 000,001,686 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2012/06/25 14:59:58 | 000,001,668 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Mozilla Thunderbird.lnk
[2012/06/25 14:20:00 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120629-194606.backup
[2012/06/25 14:19:30 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120625-142000.backup
[2012/06/17 12:26:34 | 000,442,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120625-141930.backup
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/14 23:55:26 | 000,113,541 | ---- | C] () -- C:\Documents and Settings\******\Bureau\screen2.png
[2012/07/09 21:32:15 | 000,000,318 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/07/02 18:18:00 | 000,000,546 | ---- | C] () -- C:\WINDOWS\System32\autoexec2.nt
[2012/05/31 01:38:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\******\peerblock.dmp
[2012/02/15 16:38:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/12/12 21:20:53 | 000,000,864 | ---- | C] () -- C:\Documents and Settings\******\Application Data\mainhst.zgh
[2011/11/09 21:17:29 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2011/10/17 13:49:49 | 000,078,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\SSHDRV85.sys
[2011/10/17 09:29:37 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2011/09/29 01:12:24 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2011/09/29 01:12:24 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2011/09/29 01:12:24 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2011/09/28 20:51:00 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2010/12/15 00:39:42 | 000,210,944 | ---- | C] () -- C:\Documents and Settings\******\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/01 15:13:49 | 000,376,832 | ---- | C] () -- C:\WINDOWS\System32\AegisI5Installer.exe
[2010/12/01 15:13:21 | 000,451,072 | ---- | C] () -- C:\WINDOWS\System32\ISSRemoveSP.exe
[2010/11/10 06:02:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2010/11/10 06:01:56 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2010/11/10 06:01:55 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\ATIODE.exe
[2010/11/10 06:01:55 | 000,224,342 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2010/11/10 06:01:55 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ATIODCLI.exe
[2010/11/10 06:01:55 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2010/11/10 03:55:43 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/11/09 21:34:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/11/09 21:08:58 | 000,015,312 | ---- | C] () -- C:\WINDOWS\System32\RaCoInst.dat
[2010/11/01 14:17:35 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/11/01 14:13:12 | 000,196,160 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/01 14:07:21 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\MGHwCtrl.dll
[2010/11/01 14:07:21 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\MGFPCtrl.dll
[2010/11/01 14:07:21 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\MGPwrShm.dll
[2010/11/01 13:32:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/11/01 13:25:17 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
========== LOP Check ==========
[2010/11/22 03:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/11/10 06:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2012/06/29 19:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/12/15 02:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Beerowser
[2010/11/11 00:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Canneverbe Limited
[2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DAEMON Tools Lite
[2010/11/12 04:37:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DeviceDoctorSoftware
[2011/10/13 04:59:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\EurekaLog
[2010/11/11 00:35:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\FreeFLVConverter
[2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Notepad++
[2010/11/12 04:33:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\OpenOffice.org
[2010/11/11 00:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Opera
[2012/06/16 01:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\PhotoFiltre
[2012/01/08 03:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\RenPy
[2011/09/28 23:43:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Sudeki
[2010/11/12 04:37:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Thunderbird
[2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\uTorrent
[2011/12/12 21:27:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\ZipGenius
[2012/07/15 21:49:05 | 000,000,318 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
========== Purity Check ==========
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
[2011/06/23 13:13:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2010/11/22 03:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/11/10 06:04:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ATI
[2010/11/10 06:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2012/06/29 19:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/11/10 08:33:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/11/10 03:41:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2011/05/05 00:13:50 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2012/05/08 20:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Mozilla
[2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/11/10 03:55:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/11/09 22:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
[2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\AcrobatUpdater.exe
[2012/01/03 09:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\AdobeARM.exe
[2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\AdobeARMHelper.exe
[2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\ARM\Reader_10.1.1\17753\ReaderUpdater.exe
[2012/07/12 03:19:05 | 010,652,120 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
< %APPDATA%\*. >
[2011/03/25 12:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Adobe
[2010/11/11 00:33:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\ATI
[2010/11/22 04:25:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Avira
[2011/12/15 02:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Beerowser
[2010/11/11 00:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Canneverbe Limited
[2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DAEMON Tools Lite
[2010/11/12 04:37:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\DeviceDoctorSoftware
[2011/10/13 04:59:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\EurekaLog
[2010/11/11 00:35:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\FreeFLVConverter
[2011/12/24 09:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Help
[2010/11/10 02:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Identities
[2012/07/15 21:24:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Macromedia
[2010/11/11 00:32:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Malwarebytes
[2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Media Player Classic
[2012/02/14 17:04:23 | 000,000,000 | --SD | M] -- C:\Documents and Settings\******\Application Data\Microsoft
[2010/11/11 00:36:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Mozilla
[2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Notepad++
[2010/11/12 04:33:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\OpenOffice.org
[2010/11/11 00:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Opera
[2012/06/16 01:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\PhotoFiltre
[2012/01/08 03:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\RenPy
[2011/09/28 23:43:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Sudeki
[2011/02/27 14:02:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Sun
[2010/11/12 04:37:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\Thunderbird
[2012/07/15 21:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\uTorrent
[2012/06/25 20:58:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\vlc
[2011/12/12 21:27:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\******\Application Data\ZipGenius
< %APPDATA%\*.exe /s >
[2008/06/02 00:25:02 | 000,737,192 | ---- | M] () -- C:\Documents and Settings\******\Application Data\Mozilla\Firefox\Profiles\ysf54h3b.default\extensions\keyscrambler@qfx.software.corporation\installer\setup.exe
< %SYSTEMDRIVE%\*.exe >
[2008/04/11 08:03:48 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< MD5 for: AGP440.SYS  >
[2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS  >
[2004/08/05 14:00:00 | 018,779,217 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2010/11/10 04:27:50 | 023,892,017 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/05 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL  >
[2004/08/05 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=21E83876A6287F15538EF187D286FE11 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008/04/14 04:33:24 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 04:33:24 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL  >
[2008/04/14 04:33:34 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 04:33:34 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\system32\netlogon.dll
[2009/02/06 20:46:49 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ECD7791E0E9246CA5F218A19F3911EB9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 20:46:49 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ECD7791E0E9246CA5F218A19F3911EB9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/05 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=FAF07FDCDE76000621A28D19F8E2E8EB -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL  >
[2008/04/14 04:33:40 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 04:33:40 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\system32\scecli.dll
[2004/08/05 14:00:00 | 000,186,368 | ---- | M] (Microsoft Corporation) MD5=DEC0397F35D027874804EC72979D03CC -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
< MD5 for: USER32.DLL  >
[2005/03/02 20:10:36 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=0DF75FB73F705B011630159A43D7C354 -- C:\WINDOWS\$NtUninstallKB925902$\user32.dll
[2007/03/08 17:50:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=4D88AAF39ADABFE45958EA1384E2C4FF -- C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
[2007/03/08 17:37:50 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=753354F594809A9B96F73999B435A533 -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2005/03/02 20:20:32 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=C34920EB988CE98910BD6B0417F334EB -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2004/08/05 14:00:00 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=E46FB493E3B33704F0715020CF52106B -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll
[2008/04/14 04:33:48 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=E853F84D3CE2FAA2A802E33CF89AC023 -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008/04/14 04:33:48 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=E853F84D3CE2FAA2A802E33CF89AC023 -- C:\WINDOWS\system32\user32.dll
< MD5 for: USERINIT.EXE  >
[2004/08/05 14:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D6D65EA32B190401B57EDB6706F29669 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 04:34:26 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 04:34:26 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE  >
[2012/07/03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2004/08/05 14:00:00 | 000,506,368 | ---- | M] (Microsoft Corporation) MD5=D2DE785AEAB0BB8CA4C14A8A199DBE4E -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 04:34:28 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 04:34:28 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2IFSL.SYS  >
[2004/08/05 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2004/08/05 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2010/11/01 14:12:00 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2010/11/01 14:12:00 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2010/11/01 14:11:59 | 000,475,136 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
<           >

< End of report >


Du betrachtest: Win32:Malware-gen in Datei - beim Versuch, sie auf Virustotal hochzuladen fährt der PC runter auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.