Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Probleme nach Ad-Aware 10

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 14.06.2012, 15:12   #1
Ich bin ich
 
Probleme nach Ad-Aware 10 - Standard

Probleme nach Ad-Aware 10



Hallo zusammen!
(Sollte das das falsche Forum sein, tut es mir Leid. Fast jedes passte irgendwie)
Bei meinem PC sind fehler aufgetreten, als ich erfolglos versucht habe Ad-Aware 10 zu installieren. Er blieb jedesmal beim installationsfenster hängen "Installiert... Bitte warten..."
Seitdem habe ich massive Probleme mit dem PC, er läuft zum Teil recht lahm, hin und wieder treten bei Programmen "Keine Rückmeldung" auf, wobei mir aufgefallen ist, das die Programme die von Microsoft sind, nach ein paar Sekunden wieder gehen. Andere Programme, kann ich nur über die Taskleiste beenden.
Meine Systemwiederherstellung war leider deaktiviert.
Zu meinen eigenen Versuchen:
1. Eine Festplattenüberprüfung, wo einige Sektoren repariert wurden (sollte es dazu eine Log file geben, hab ich keine Ahnung wo die zu finden ist).
2. Antivir scan
Code:
ATTFilter
 

Avira Free Antivirus
Erstellungsdatum der Reportdatei: Mittwoch, 13. Juni 2012  03:28

Es wird nach 3830208 Virenstämmen gesucht.

Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer   : Avira AntiVir Personal - Free Antivirus
Seriennummer   : 0000149996-ADJIE-0000001
Plattform      : Windows 7 Ultimate
Windowsversion : (Service Pack 1)  [6.1.7601]
Boot Modus     : Normal gebootet
Benutzername   : Homeservice
Computername   : HOMESERVICE-PC

Versionsinformationen:
BUILD.DAT      : 12.0.0.1125          Bytes  02.05.2012 16:34:00
AVSCAN.EXE     : 12.3.0.15     466896 Bytes  08.05.2012 23:03:39
AVSCAN.DLL     : 12.3.0.15      66256 Bytes  08.05.2012 23:03:39
LUKE.DLL       : 12.3.0.15      68304 Bytes  08.05.2012 23:03:40
AVSCPLR.DLL    : 12.3.0.14      97032 Bytes  08.05.2012 23:03:40
AVREG.DLL      : 12.3.0.17     232200 Bytes  10.05.2012 15:17:10
VBASE000.VDF   : 7.10.0.0    19875328 Bytes  06.11.2009 18:18:34
VBASE001.VDF   : 7.11.0.0    13342208 Bytes  14.12.2010 23:31:49
VBASE002.VDF   : 7.11.19.170 14374912 Bytes  20.12.2011 21:44:54
VBASE003.VDF   : 7.11.21.238  4472832 Bytes  01.02.2012 21:44:58
VBASE004.VDF   : 7.11.26.44   4329472 Bytes  28.03.2012 15:08:11
VBASE005.VDF   : 7.11.29.136  2166272 Bytes  10.05.2012 15:16:55
VBASE006.VDF   : 7.11.29.137     2048 Bytes  10.05.2012 15:16:55
VBASE007.VDF   : 7.11.29.138     2048 Bytes  10.05.2012 15:16:55
VBASE008.VDF   : 7.11.29.139     2048 Bytes  10.05.2012 15:16:55
VBASE009.VDF   : 7.11.29.140     2048 Bytes  10.05.2012 15:16:55
VBASE010.VDF   : 7.11.29.141     2048 Bytes  10.05.2012 15:16:55
VBASE011.VDF   : 7.11.29.142     2048 Bytes  10.05.2012 15:16:55
VBASE012.VDF   : 7.11.29.143     2048 Bytes  10.05.2012 15:16:55
VBASE013.VDF   : 7.11.29.144     2048 Bytes  10.05.2012 15:16:55
VBASE014.VDF   : 7.11.30.3     198144 Bytes  14.05.2012 22:34:33
VBASE015.VDF   : 7.11.30.69    186368 Bytes  17.05.2012 15:00:44
VBASE016.VDF   : 7.11.30.143   223744 Bytes  21.05.2012 15:00:26
VBASE017.VDF   : 7.11.30.207   287744 Bytes  23.05.2012 15:00:21
VBASE018.VDF   : 7.11.31.57    188416 Bytes  28.05.2012 15:00:32
VBASE019.VDF   : 7.11.31.111   214528 Bytes  30.05.2012 15:00:45
VBASE020.VDF   : 7.11.31.151   116736 Bytes  31.05.2012 23:03:46
VBASE021.VDF   : 7.11.31.205   134144 Bytes  03.06.2012 15:00:12
VBASE022.VDF   : 7.11.32.9     169472 Bytes  05.06.2012 23:03:56
VBASE023.VDF   : 7.11.32.85    155648 Bytes  08.06.2012 15:00:13
VBASE024.VDF   : 7.11.32.133   127488 Bytes  11.06.2012 23:04:07
VBASE025.VDF   : 7.11.32.171   182784 Bytes  12.06.2012 23:04:15
VBASE026.VDF   : 7.11.32.172     2048 Bytes  12.06.2012 23:04:15
VBASE027.VDF   : 7.11.32.173     2048 Bytes  12.06.2012 23:04:15
VBASE028.VDF   : 7.11.32.174     2048 Bytes  12.06.2012 23:04:15
VBASE029.VDF   : 7.11.32.175     2048 Bytes  12.06.2012 23:04:15
VBASE030.VDF   : 7.11.32.176     2048 Bytes  12.06.2012 23:04:15
VBASE031.VDF   : 7.11.32.180     2560 Bytes  12.06.2012 23:04:15
Engineversion  : 8.2.10.80 
AEVDF.DLL      : 8.1.2.8       106867 Bytes  01.06.2012 18:16:45
AESCRIPT.DLL   : 8.1.4.24      450939 Bytes  31.05.2012 15:03:55
AESCN.DLL      : 8.1.8.2       131444 Bytes  08.02.2012 21:45:03
AESBX.DLL      : 8.2.5.10      606580 Bytes  29.05.2012 15:02:15
AERDL.DLL      : 8.1.9.15      639348 Bytes  14.12.2011 23:31:02
AEPACK.DLL     : 8.2.16.16     807288 Bytes  29.05.2012 15:02:15
AEOFFICE.DLL   : 8.1.2.28      201082 Bytes  26.04.2012 23:03:11
AEHEUR.DLL     : 8.1.4.36     4874615 Bytes  31.05.2012 15:03:51
AEHELP.DLL     : 8.1.21.0      254326 Bytes  11.05.2012 06:41:09
AEGEN.DLL      : 8.1.5.28      422260 Bytes  26.04.2012 23:03:09
AEEXP.DLL      : 8.1.0.44       82293 Bytes  29.05.2012 15:02:15
AEEMU.DLL      : 8.1.3.0       393589 Bytes  14.12.2011 23:30:58
AECORE.DLL     : 8.1.25.10     201080 Bytes  31.05.2012 15:02:10
AEBB.DLL       : 8.1.1.0        53618 Bytes  14.12.2011 23:30:58
AVWINLL.DLL    : 12.3.0.15      27344 Bytes  08.05.2012 23:03:39
AVPREF.DLL     : 12.3.0.15      51920 Bytes  08.05.2012 23:03:39
AVREP.DLL      : 12.3.0.15     179208 Bytes  08.05.2012 23:03:40
AVARKT.DLL     : 12.3.0.15     211408 Bytes  08.05.2012 23:03:39
AVEVTLOG.DLL   : 12.3.0.15     169168 Bytes  08.05.2012 23:03:39
SQLITE3.DLL    : 3.7.0.1       398288 Bytes  08.05.2012 23:03:40
AVSMTP.DLL     : 12.3.0.15      63440 Bytes  08.05.2012 23:03:39
NETNT.DLL      : 12.3.0.15      17104 Bytes  08.05.2012 23:03:40
RCIMAGE.DLL    : 12.3.0.15    4447952 Bytes  08.05.2012 23:03:39
RCTEXT.DLL     : 12.3.0.15      98512 Bytes  08.05.2012 23:03:39

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: Manuelle Auswahl
Konfigurationsdatei...................: C:\ProgramData\Avira\AntiVir Desktop\PROFILES\folder.avp
Protokollierung.......................: standard
Primäre Aktion........................: interaktiv
Sekundäre Aktion......................: ignorieren
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: ein
Bootsektoren..........................: C:, 
Durchsuche aktive Programme...........: ein
Durchsuche Registrierung..............: ein
Suche nach Rootkits...................: aus
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Intelligente Dateiauswahl
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: erweitert
Auszulassende Dateien.................: C:\Windows\AutoKMS\AutoKMS.exe, E:\Chris\Downloads\game\Drawn 2  - Dark Flight\Uninstall.exe, E:\Dimension_Re\Dream Chronicles - The Book of Air\Dream Chronicles - The Book Of Air.exe, 

Beginn des Suchlaufs: Mittwoch, 13. Juni 2012  03:28

Der Suchlauf über die Masterbootsektoren wird begonnen:
Masterbootsektor HD0
    [INFO]      Es wurde kein Virus gefunden!
    [INFO]      Bitte starten Sie den Suchlauf erneut mit Administratorrechten

Der Suchlauf über die Bootsektoren wird begonnen:
Bootsektor 'C:\'
    [INFO]      Es wurde kein Virus gefunden!
    [INFO]      Bitte starten Sie den Suchlauf erneut mit Administratorrechten

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'avscan.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avcenter.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'FlashPlayerPlugin_11_3_300_257.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'FlashPlayerPlugin_11_3_300_257.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'plugin-container.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'firefox.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'InputPersonalization.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'TuneUpUtilitiesApp32.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'Pen_TabletUser.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'sidebar.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'KHALMNPR.EXE' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvtray.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'SpywareTerminatorShield.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'SetPoint.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'ForceField.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'taskhost.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'Explorer.EXE' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'Dwm.exe' - '1' Modul(e) wurden durchsucht

Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen:
Die Registry wurde durchsucht ( '4225' Dateien ).


Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\'
C:\Program Files\WinRAR\rarnew.dat
  [WARNUNG]   Das Archiv ist unbekannt oder defekt
C:\Users\Homeservice\AppData\Local\Temp\minizip.ppl
  [WARNUNG]   Einige Dateien dieses Archives sind auf mehrere Teilarchive verteilt  (multiple volume)
C:\Users\Homeservice\AppData\Local\Temp\pinfect.zip
  [WARNUNG]   Die Datei ist kennwortgeschützt
C:\Users\Homeservice\AppData\Local\Temp\tmp00004c2a\tmp000c6cc1
  [FUND]      Ist das Trojanische Pferd TR/Crypt.XPACK.Gen3
C:\Users\Homeservice\AppData\Roaming\TuneUp Software\TuneUp Utilities 2011\WinStyler\LogonScreens\AlmostGolden.tls
  [WARNUNG]   Der Archivheader ist defekt
C:\Users\Homeservice\AppData\Roaming\TuneUp Software\TuneUp Utilities 2011\WinStyler\LogonScreens\Asightforsoreeyes.tls
  [WARNUNG]   Der Archivheader ist defekt
C:\Users\Homeservice\AppData\Roaming\TuneUp Software\TuneUp Utilities 2011\WinStyler\LogonScreens\FlamingWall.tls
  [WARNUNG]   Der Archivheader ist defekt
C:\Users\Homeservice\AppData\Roaming\TuneUp Software\TuneUp Utilities 2011\WinStyler\LogonScreens\LavaFlow.tls
  [WARNUNG]   Der Archivheader ist defekt
C:\Users\Homeservice\AppData\Roaming\TuneUp Software\TuneUp Utilities 2012\WinStyler\LogonScreens\AlmostGolden.tls
  [WARNUNG]   Der Archivheader ist defekt
C:\Users\Homeservice\AppData\Roaming\TuneUp Software\TuneUp Utilities 2012\WinStyler\LogonScreens\Asightforsoreeyes.tls
  [WARNUNG]   Der Archivheader ist defekt
C:\Users\Homeservice\AppData\Roaming\TuneUp Software\TuneUp Utilities 2012\WinStyler\LogonScreens\FlamingWall.tls
  [WARNUNG]   Der Archivheader ist defekt
C:\Users\Homeservice\AppData\Roaming\TuneUp Software\TuneUp Utilities 2012\WinStyler\LogonScreens\LavaFlow.tls
  [WARNUNG]   Der Archivheader ist defekt
C:\Windows\Resources\Themes\675\HUD Premium Theme\7tsp_GUI_v0.3_B(3003).exe
  [WARNUNG]   Das Archivformat ist ungültig oder fehlerhaft
C:\Windows\Resources\Themes\675\HUD Premium Theme\HUD, Winstep Xtreme Theme.rar
  [WARNUNG]   Der Archivheader ist defekt
C:\Windows\Resources\Themes\675\HUD Premium Theme\HUD.xtreme
  [WARNUNG]   Der Archivheader ist defekt
C:\Windows\Resources\Themes\Pack_Themez_Win_Sev7en_p5_19\metro_lite_suite_by_exsess\Metro Lite\explorerframe\Se7en File Replacer.exe
  [WARNUNG]   Das Archivformat ist ungültig oder fehlerhaft

Beginne mit der Desinfektion:
C:\Users\Homeservice\AppData\Local\Temp\tmp00004c2a\tmp000c6cc1
  [FUND]      Ist das Trojanische Pferd TR/Crypt.XPACK.Gen3
  [HINWEIS]   Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '5543569f.qua' verschoben!


Ende des Suchlaufs: Mittwoch, 13. Juni 2012  04:04
Benötigte Zeit: 35:17 Minute(n)

Der Suchlauf wurde vollständig durchgeführt.

  29771 Verzeichnisse wurden überprüft
 433986 Dateien wurden geprüft
      1 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      1 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
 433985 Dateien ohne Befall
   3854 Archive wurden durchsucht
     15 Warnungen
      1 Hinweise
         
Antivir teilte mir mit das es sich bei der '5543569f.qua' um Malware handelt.
Diese habe ich dann manuell gelöscht.
3. Mit der Windows 7 CD habe ich mal das Diagnosetool durchlaufen lassen. Es hat aber keine Probleme gefunden. (Wenn dies Tool überhaupt was bringt)
4. Malwarebytes
Code:
ATTFilter
 Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.12.01

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Homeservice :: HOMESERVICE-PC [Administrator]

12.06.2012 03:05:17
mbam-log-2012-06-12 (03-05-17).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 614738
Laufzeit: 3 Stunde(n), 26 Minute(n), 16 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Windows\Resources\Themes\675\HUD Premium Theme\1 Theme Patcher if not ever made ​​the patches you here\SoftonicDownloader_for_universal-theme-patcher.exe (PUP.OfferBundler.ST) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)
         
Da ist mir aufgefallen, ich habe noch nie was von Softonic heruntergeladen und einen downloader von denen hab ich auch nicht, soweit ich weiß.
5. OTL
OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 13.06.2012 00:07:04 - Run 1
OTL by OldTimer - Version 3.2.48.0     Folder = C:\Users\Homeservice\Desktop
 Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 1,92 Gb Available Physical Memory | 58,98% Memory free
6,79 Gb Paging File | 5,25 Gb Available in Paging File | 77,37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 29,29 Gb Total Space | 6,26 Gb Free Space | 21,37% Space Free | Partition Type: NTFS
Drive D: | 48,82 Gb Total Space | 12,26 Gb Free Space | 25,10% Space Free | Partition Type: NTFS
Drive E: | 387,63 Gb Total Space | 106,83 Gb Free Space | 27,56% Space Free | Partition Type: NTFS
 
Computer Name: HOMESERVICE-PC | User Name: Homeservice | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.06.12 23:55:00 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Homeservice\Desktop\OTL.exe
PRC - [2012.05.29 13:09:52 | 001,528,672 | ---- | M] (TuneUp Software) -- D:\Programme\TuneUpUtilitiesService32.exe
PRC - [2012.05.29 13:09:52 | 001,220,960 | ---- | M] (TuneUp Software) -- D:\Programme\TuneUpUtilitiesApp32.exe
PRC - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012.05.15 11:28:16 | 001,820,480 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvtray.exe
PRC - [2012.05.15 11:27:34 | 000,857,920 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.05.09 01:03:40 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.09 01:03:39 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.05.09 01:03:39 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.09 01:03:39 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.05.03 14:10:02 | 002,446,872 | ---- | M] (Check Point Software Technologies LTD) -- D:\Programme\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2012.05.03 14:07:06 | 000,073,360 | ---- | M] (Check Point Software Technologies LTD) -- D:\Programme\CheckPoint\ZoneAlarm\zatray.exe
PRC - [2012.04.30 21:05:22 | 000,497,280 | ---- | M] (Check Point Software Technologies) -- C:\Programme\CheckPoint\ZAForceField\ISWSVC.exe
PRC - [2012.04.30 21:04:28 | 000,738,944 | ---- | M] (Check Point Software Technologies) -- C:\Programme\CheckPoint\ZAForceField\ForceField.exe
PRC - [2012.03.27 05:32:42 | 000,482,992 | ---- | M] (Crawler.com) -- C:\Programme\Spyware Terminator\st_rsser.exe
PRC - [2012.03.27 05:32:36 | 003,669,680 | ---- | M] (Crawler.com) -- C:\Programme\Spyware Terminator\SpywareTerminatorUpdate.exe
PRC - [2012.03.27 05:32:26 | 002,786,480 | ---- | M] (Crawler.com) -- C:\Programme\Spyware Terminator\SpywareTerminatorShield.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.06.24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 14:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.11.20 14:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2010.01.29 23:20:26 | 000,112,208 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
PRC - [2010.01.27 13:30:16 | 001,312,848 | ---- | M] (Logitech, Inc.) -- C:\Programme\Logitech\SetPointP\SetPoint.exe
PRC - [2009.07.15 18:13:06 | 003,662,632 | ---- | M] (Wacom Technology, Corp.) -- C:\Programme\WTouch\WTouchUser.exe
PRC - [2009.07.15 18:13:04 | 000,393,512 | ---- | M] (Wacom Technology, Corp.) -- C:\Windows\System32\WTablet\Pen_TabletUser.exe
PRC - [2009.07.15 18:13:04 | 000,112,936 | ---- | M] (Wacom Technology, Corp.) -- C:\Programme\WTouch\WTouchService.exe
PRC - [2009.07.15 18:13:02 | 004,408,616 | ---- | M] (Wacom Technology, Corp.) -- C:\Windows\System32\Pen_Tablet.exe
PRC - [2009.07.14 03:14:42 | 000,181,760 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\TabTip.exe
PRC - [2009.07.14 03:14:21 | 000,294,400 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\ink\InputPersonalization.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.07.04 23:32:38 | 000,010,752 | ---- | M] () -- D:\Programme\Unlocker\UnlockerCOM.dll
MOD - [2010.03.15 11:28:22 | 000,141,824 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012.06.12 19:42:44 | 000,257,224 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.05.29 13:09:52 | 001,528,672 | ---- | M] (TuneUp Software) [Auto | Running] -- D:\Programme\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012.05.29 13:09:50 | 000,029,024 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2012.05.15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.05.15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.05.09 01:03:40 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.09 01:03:39 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.05.03 14:10:02 | 002,446,872 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- D:\Programme\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon)
SRV - [2012.04.30 21:05:22 | 000,497,280 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Programme\CheckPoint\ZAForceField\ISWSVC.exe -- (IswSvc)
SRV - [2012.03.27 05:32:42 | 000,482,992 | ---- | M] (Crawler.com) [Auto | Running] -- C:\Programme\Spyware Terminator\st_rsser.exe -- (ST2012_Svc)
SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.12.02 00:14:03 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011.06.12 12:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- D:\Programme\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010.02.18 15:01:06 | 000,462,632 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Programme\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2010.01.29 23:17:14 | 000,292,944 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2010.01.09 22:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.09 22:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
SRV - [2009.07.15 18:13:04 | 000,112,936 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Programme\WTouch\WTouchService.exe -- (WTouchService)
SRV - [2009.07.15 18:13:02 | 004,408,616 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Windows\System32\Pen_Tablet.exe -- (TabletServicePen)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.04.13 17:49:00 | 000,101,528 | ---- | M] () [Disabled | Stopped] -- C:\Programme\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2003.04.18 20:06:26 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\System32\srvany.exe -- (KMService)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\siusbmod.sys -- (siusbmod)
DRV - File not found [File_System | Boot | Stopped] -- system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\Programme\Lavasoft\KernExplorer.sys -- (Lavasoft Kernexplorer)
DRV - [2012.05.15 12:26:00 | 011,354,944 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012.05.09 01:03:40 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.09 01:03:40 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.04.30 21:05:40 | 000,027,016 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Programme\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
DRV - [2012.01.09 18:59:32 | 000,468,272 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV - [2012.01.09 18:59:30 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\kl1.sys -- (KL1)
DRV - [2012.01.09 18:59:30 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\kl2.sys -- (kl2)
DRV - [2011.12.15 16:00:00 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011.11.24 16:34:44 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- D:\Programme\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2011.11.06 02:03:17 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2011.06.21 11:24:06 | 000,032,768 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\sp_rsdrv2.sys -- (sp_rsdrv2)
DRV - [2011.05.07 18:51:28 | 000,455,256 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\Windows\System32\drivers\vsdatant.sys -- (Vsdatant)
DRV - [2010.11.20 14:30:17 | 000,296,064 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcvmm.sys -- (vpcvmm)
DRV - [2010.11.20 14:30:17 | 000,172,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpchbus.sys -- (vpcbus)
DRV - [2010.11.20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 12:50:38 | 000,078,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpcusb.sys -- (vpcusb)
DRV - [2010.11.20 12:50:37 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010.11.20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010.07.04 21:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- D:\Programme\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.11.10 13:55:32 | 000,028,560 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2009.11.10 13:55:08 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2009.11.10 13:54:52 | 000,035,984 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2009.05.21 00:14:32 | 000,013,224 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WacomVTHid.sys -- (WacomVTHid)
DRV - [2009.05.20 21:54:06 | 000,013,736 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wacomvhid.sys -- (wacomvhid)
DRV - [2007.02.16 21:12:36 | 000,011,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV - [2007.02.16 02:11:28 | 000,011,440 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WacomVKHid.sys -- (WacomVKHid)
DRV - [2005.07.18 15:34:22 | 000,047,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vserial.sys -- (vserial)
DRV - [2005.07.18 15:34:18 | 000,015,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vsb.sys -- (vsbus)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.arcor.de
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.arcor.de
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = hxxp://www.arcor.de
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.arcor.de
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.arcor.de
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2645238
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = hxxp://www.arcor.de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.arcor.de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.arcor.de
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2645238
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaultthis.engineName: "ZoneAlarm-Sicherheit Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2613550&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)"
FF - prefs.js..browser.startup.homepage: "www.yahoo.de"
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?sourceid=navclient&hl=de&q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_257.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\PROGRA~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: D:\PROGRA~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012.06.03 17:55:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: D:\Programme\components [2012.06.06 18:08:56 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: D:\Programme\components [2012.06.06 18:08:56 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: D:\Programme\plugins [2012.06.04 01:06:33 | 000,000,000 | ---D | M]
 
[2011.10.31 03:02:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Homeservice\AppData\Roaming\mozilla\Extensions
[2012.05.03 02:47:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Homeservice\AppData\Roaming\mozilla\Firefox\Profiles\2nf8hg2q.default\extensions
[2011.10.31 03:17:51 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\Homeservice\AppData\Roaming\mozilla\Firefox\Profiles\2nf8hg2q.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011.10.31 03:17:52 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Users\Homeservice\AppData\Roaming\mozilla\Firefox\Profiles\2nf8hg2q.default\extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29}
[2012.05.03 02:47:05 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Homeservice\AppData\Roaming\mozilla\Firefox\Profiles\2nf8hg2q.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.10.31 03:17:53 | 000,000,000 | ---D | M] (ZoneAlarm-Sicherheit Community Toolbar) -- C:\Users\Homeservice\AppData\Roaming\mozilla\Firefox\Profiles\2nf8hg2q.default\extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}
[2012.06.03 17:26:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Homeservice\AppData\Roaming\mozilla\Firefox\Profiles\vf9d9aga.default\extensions
[2011.10.31 03:26:06 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\Homeservice\AppData\Roaming\mozilla\Firefox\Profiles\vf9d9aga.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2012.05.04 07:12:58 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Users\Homeservice\AppData\Roaming\mozilla\Firefox\Profiles\vf9d9aga.default\extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29}
[2012.05.03 02:47:05 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Homeservice\AppData\Roaming\mozilla\Firefox\Profiles\vf9d9aga.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.18 08:28:51 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Homeservice\AppData\Roaming\mozilla\Firefox\Profiles\vf9d9aga.default\extensions\ich@maltegoetz.de
[2012.05.12 09:17:00 | 000,000,000 | ---D | M] (Lavasoft Search Plugin) -- C:\Users\Homeservice\AppData\Roaming\mozilla\Firefox\Profiles\vf9d9aga.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
[2011.10.25 21:52:54 | 000,000,943 | ---- | M] () -- C:\Users\Homeservice\AppData\Roaming\Mozilla\Firefox\Profiles\2nf8hg2q.default\searchplugins\conduit.xml
[2012.06.03 17:55:40 | 000,000,000 | ---D | M] (ZoneAlarm Security Engine) -- C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER
[2011.10.30 01:18:36 | 000,084,346 | ---- | M] () (No name found) -- C:\USERS\HOMESERVICE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2NF8HG2Q.DEFAULT\EXTENSIONS\{0545B830-F0AA-4D7E-8820-50A4629A56FE}.XPI
[2011.10.29 21:23:29 | 000,627,675 | ---- | M] () (No name found) -- C:\USERS\HOMESERVICE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2NF8HG2Q.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011.10.29 21:24:40 | 000,098,306 | ---- | M] () (No name found) -- C:\USERS\HOMESERVICE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2NF8HG2Q.DEFAULT\EXTENSIONS\ADBLOCKPOPUPS@JESSEHAKANEN.NET.XPI
File not found (No name found) -- D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
 
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Programme\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Programme\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Programme\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [SpywareTerminatorShield] C:\Programme\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKLM..\Run: [SpywareTerminatorUpdater] C:\Programme\Spyware Terminator\SpywareTerminatorUpdate.exe (Crawler.com)
O4 - HKLM..\Run: [ZoneAlarm] D:\Programme\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives =  [binary data]
O8 - Extra context menu item: An OneNote s&enden - D:\Programme\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Homeservice\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - D:\Programme\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Programme\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Programme\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D:\Programme\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D:\Programme\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22 - SharedTaskScheduler: {F791A188-699D-4FD4-955A-EB59E89B1907} - Theme Resource Changer - No CLSID value found.
O27 - HKLM IFEO\backitup.exe: Debugger - D:\Programme\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\uninst.exe: Debugger - D:\Programme\TUAutoReactivator32.exe (TuneUp Software)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Programme\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.06.12 23:54:56 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Homeservice\Desktop\OTL.exe
[2012.06.12 23:41:55 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.06.12 23:41:53 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.06.12 23:41:53 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.06.12 23:41:53 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.06.12 23:41:52 | 001,800,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.06.12 23:41:52 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.06.12 23:41:50 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012.06.12 23:39:50 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2012.06.12 23:39:50 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2012.06.12 23:39:50 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2012.06.12 23:39:49 | 000,919,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll
[2012.06.12 23:39:47 | 002,343,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.06.12 23:39:46 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2012.06.12 23:26:12 | 000,000,000 | ---D | C] -- C:\Users\Homeservice\AppData\Local\Macromedia
[2012.06.12 19:35:52 | 000,000,000 | ---D | C] -- C:\Users\Homeservice\AppData\Roaming\Spyware Terminator
[2012.06.12 19:35:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Spyware Terminator
[2012.06.12 19:35:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012
[2012.06.12 19:35:47 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Terminator
[2012.06.12 00:21:07 | 000,000,000 | ---D | C] -- C:\Users\Homeservice\AppData\Local\MigWiz
[2012.06.11 20:45:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2012.06.11 20:43:18 | 019,607,872 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll
[2012.06.11 20:43:18 | 011,354,944 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys
[2012.06.11 20:43:18 | 005,982,528 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll
[2012.06.11 20:43:18 | 002,524,992 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll
[2012.06.11 20:43:18 | 002,445,120 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll
[2012.06.11 20:43:17 | 017,551,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll
[2012.06.11 03:39:30 | 000,000,000 | ---D | C] -- C:\temp
[2012.06.09 04:00:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2012.06.07 15:51:54 | 000,000,000 | ---D | C] -- D:\Program Files\NeroVision
[2012.06.04 01:07:24 | 000,000,000 | ---D | C] -- C:\Users\Homeservice\AppData\Local\Apple Computer
[2012.06.03 17:32:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Browsing Protection
[2012.06.03 17:26:50 | 000,011,352 | ---- | C] (Kaspersky Lab ZAO) -- C:\Windows\System32\drivers\kl2.sys
[2012.06.03 17:26:48 | 000,133,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\Windows\System32\drivers\kl1.sys
[2012.06.03 17:26:46 | 000,468,272 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys
[2012.06.03 17:26:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
[2012.05.31 01:51:58 | 004,479,832 | ---- | C] (Microsoft Corporation) -- C:\Users\Homeservice\vcredist_x86.08.exe
[2012.05.27 03:08:01 | 000,000,000 | ---D | C] -- C:\Users\Homeservice\AppData\Roaming\Audacity
[2012.05.27 03:01:14 | 000,000,000 | ---D | C] -- C:\Users\Homeservice\AppData\Roaming\Ahead
[2012.05.25 23:49:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Zylom
[2012.05.24 23:50:03 | 000,000,000 | ---D | C] -- C:\Users\Homeservice\AppData\Roaming\ShamanGS
[2012.05.20 23:17:48 | 000,000,000 | ---D | C] -- C:\Users\Homeservice\AppData\Local\Daedalic Entertainment
[2012.05.20 23:01:10 | 000,000,000 | ---D | C] -- C:\Windows\AutoKMS
[2012.05.14 01:24:34 | 000,000,000 | ---D | C] -- C:\ProgramData\GFI Software
[2011.10.29 20:26:12 | 000,013,264 | ---- | C] (Arcor Online GmbH) -- C:\Users\Homeservice\AppData\Local\cmdial32.dll
[26 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.06.13 00:02:43 | 000,023,632 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.13 00:02:43 | 000,023,632 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.12 23:56:52 | 000,425,008 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.06.12 23:56:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.12 23:55:00 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Homeservice\Desktop\OTL.exe
[2012.06.12 23:54:01 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.12 23:48:22 | 000,698,514 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.06.12 23:48:22 | 000,652,496 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.06.12 23:48:22 | 000,148,570 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.06.12 23:48:22 | 000,121,428 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.06.12 23:42:27 | 000,919,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll
[2012.06.12 23:42:17 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.06.12 23:42:16 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.06.12 23:42:16 | 001,800,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.06.12 23:42:16 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012.06.12 23:42:16 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.06.12 23:42:16 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.06.12 23:42:16 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.06.12 23:41:40 | 002,343,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.06.12 23:41:35 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2012.06.12 23:41:35 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2012.06.12 23:41:33 | 000,129,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2012.06.12 19:42:43 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.06.12 19:42:43 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.06.11 23:09:21 | 000,003,528 | ---- | M] () -- C:\bootsqm.dat
[2012.06.05 20:28:05 | 000,000,064 | ---- | M] () -- C:\Windows\System32\rp_stats.dat
[2012.06.05 20:28:05 | 000,000,044 | ---- | M] () -- C:\Windows\System32\statistics.dat
[2012.06.05 20:28:05 | 000,000,044 | ---- | M] () -- C:\Windows\System32\rp_rules.dat
[2012.06.04 01:06:24 | 000,001,478 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012.06.03 17:40:25 | 000,415,915 | ---- | M] () -- C:\Windows\System32\drivers\vsconfig.xml
[2012.06.03 17:26:36 | 000,000,529 | ---- | M] () -- C:\Users\Public\Desktop\ZoneAlarm Security.lnk
[2012.05.31 01:52:02 | 004,479,832 | ---- | M] (Microsoft Corporation) -- C:\Users\Homeservice\vcredist_x86.08.exe
[2012.05.29 13:09:54 | 000,031,584 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2012.05.29 13:09:50 | 000,029,024 | ---- | M] (TuneUp Software) -- C:\Windows\System32\uxtuneup.dll
[2012.05.29 13:09:50 | 000,021,344 | ---- | M] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2012.05.15 19:21:24 | 000,016,400 | ---- | M] (Logitech, Inc.) -- C:\Windows\System32\drivers\LNonPnP.sys
[2012.05.15 12:26:00 | 019,607,872 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll
[2012.05.15 12:26:00 | 017,551,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll
[2012.05.15 12:26:00 | 015,322,432 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvd3dum.dll
[2012.05.15 12:26:00 | 011,354,944 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys
[2012.05.15 12:26:00 | 008,105,280 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvwgf2um.dll
[2012.05.15 12:26:00 | 005,982,528 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll
[2012.05.15 12:26:00 | 002,524,992 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll
[2012.05.15 12:26:00 | 002,445,120 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll
[2012.05.15 12:26:00 | 002,368,832 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvapi.dll
[2012.05.15 12:26:00 | 001,000,768 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco32.dll
[2012.05.15 12:26:00 | 000,883,008 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvgenco32.dll
[2012.05.15 12:26:00 | 000,061,248 | ---- | M] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2012.05.15 12:26:00 | 000,011,190 | ---- | M] () -- C:\Windows\System32\nvinfo.pb
[2012.05.15 11:28:50 | 002,561,344 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvsvcr.dll
[2012.05.15 11:28:49 | 000,108,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvmctray.dll
[2012.05.15 11:28:49 | 000,062,272 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvshext.dll
[2012.05.15 11:28:48 | 003,931,456 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcpl.dll
[2012.05.15 11:27:28 | 002,759,488 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvsvc.dll
[2012.05.15 02:21:50 | 000,423,744 | ---- | M] () -- C:\Windows\System32\nvStreaming.exe
[26 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.06.12 19:35:54 | 000,032,768 | ---- | C] () -- C:\Windows\System32\drivers\sp_rsdrv2.sys
[2012.06.11 23:09:21 | 000,003,528 | ---- | C] () -- C:\bootsqm.dat
[2012.06.05 20:28:05 | 000,000,044 | ---- | C] () -- C:\Windows\System32\statistics.dat
[2012.06.04 01:06:24 | 000,001,478 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012.06.03 17:26:36 | 000,000,529 | ---- | C] () -- C:\Users\Public\Desktop\ZoneAlarm Security.lnk
[2012.05.15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
[2012.02.22 21:43:34 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat
[2012.01.18 19:31:08 | 002,425,055 | ---- | C] () -- C:\Windows\launch4j-3.0.2-win32.exe
[2012.01.14 07:41:39 | 000,044,544 | ---- | C] () -- C:\Windows\System32\Gif89.dll
[2011.11.18 06:12:27 | 000,008,192 | ---- | C] () -- C:\Windows\System32\srvany.exe
[2011.11.07 14:25:44 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2011.10.31 04:24:08 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011.10.31 04:23:12 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.10.30 15:27:16 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2011.10.30 09:31:54 | 000,000,117 | ---- | C] () -- C:\Windows\lotus.ini
[2011.10.30 09:31:36 | 000,000,000 | ---- | C] () -- C:\Windows\winhelp.ini
[2011.10.30 06:08:04 | 000,000,022 | ---- | C] () -- C:\Users\Homeservice\AppData\Local\cmdial32.ini
[2011.10.30 00:38:06 | 000,000,017 | ---- | C] () -- C:\Users\Homeservice\AppData\Local\resmon.resmoncfg
[2011.10.29 22:50:08 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat
[2011.10.29 22:50:08 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat
 
========== Files - Unicode (All) ==========
[2012.03.16 06:02:00 | 000,000,000 | ---D | M](C:\Users\Homeservice\AppData\Roaming\Boolat Games?) -- C:\Users\Homeservice\AppData\Roaming\Boolat Games⫈
[2012.03.16 06:02:00 | 000,000,000 | ---D | C](C:\Users\Homeservice\AppData\Roaming\Boolat Games?) -- C:\Users\Homeservice\AppData\Roaming\Boolat Games⫈
[2012.03.16 05:29:51 | 000,000,000 | ---D | M](C:\Users\Homeservice\AppData\Roaming\Boolat Games?) -- C:\Users\Homeservice\AppData\Roaming\Boolat Games⫖
[2012.03.16 05:29:51 | 000,000,000 | ---D | C](C:\Users\Homeservice\AppData\Roaming\Boolat Games?) -- C:\Users\Homeservice\AppData\Roaming\Boolat Games⫖
(C:\Users\Homeservice\AppData\Roaming\Boolat Games?) -- C:\Users\Homeservice\AppData\Roaming\Boolat Games⫖
(C:\Users\Homeservice\AppData\Roaming\Boolat Games?) -- C:\Users\Homeservice\AppData\Roaming\Boolat Games⫈
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:57B2B96C
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:70E897B5
@Alternate Data Stream - 189 bytes -> C:\ProgramData\TEMP:89CC3B44
@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:F26F5952
@Alternate Data Stream - 179 bytes -> C:\ProgramData\TEMP:B2112128
@Alternate Data Stream - 176 bytes -> C:\ProgramData\TEMP:58E38390
@Alternate Data Stream - 171 bytes -> C:\ProgramData\TEMP:6EE8565A
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:E3615992
@Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:B4258C5D
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:1B389835
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:0785072C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:F5D01D7C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:65C4D44A
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:13019F4B
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:474022C7
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:2AF322BF
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:DBC3D477
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4EC7F009
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:587F3582
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:D026A5A4
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:870649A4
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:3D36932D

< End of report >
         
--- --- ---

6. eScan
Code:
ATTFilter
13 Jun 2012 01:15:36 - ********************************************************** 13 Jun 2012 01:15:36 - eScan Antivirus und Spyware Werkzeugsatz. 13 Jun 2012 01:15:36 - Copyright © MicroWorld 13 Jun 2012 01:15:36 - ********************************************************** 13 Jun 2012 01:15:36 - Source: D:\Downloads\mwav.exe 13 Jun 2012 01:15:36 - Version 12.0.243 (C:\USERS\HOMESERVICE\APPDATA\LOCAL\TEMP\MEXE.COM) 13 Jun 2012 01:15:36 - Logdatei: C:\Users\Homeservice\AppData\Local\Temp\MWAV.LOG 13 Jun 2012 01:15:36 - MWAV Registered: TRUE 13 Jun 2012 01:15:36 - User Account: Homeservice (Administrator Mode) 13 Jun 2012 01:15:36 - OS Type: Windows Workstation 13 Jun 2012 01:15:36 - OS: Windows 7 [OS Install Date: 29 Oct 2011 19:30:11] 13 Jun 2012 01:15:36 - Ver: Professional Service Pack 1 (Build 7601) 13 Jun 2012 01:15:36 - System Up Time: 1 Hour, 19 Minutes, 26 Seconds  13 Jun 2012 01:15:36 - Parent Process Name : D:\Downloads\mwav.exe 13 Jun 2012 01:15:36 - Windows Root  Folder: C:\Windows 13 Jun 2012 01:15:36 - Windows Sys32 Folder: C:\Windows\system32 13 Jun 2012 01:15:36 - Interface0 NameServer: 195.50.140.116 195.50.140.246 13 Jun 2012 01:15:36 - Local Fixed Drives: c:\,d:\,e:\ 13 Jun 2012 01:15:36 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware) 13 Jun 2012 01:15:36 - [CREATED ZIP FILE: C:\Users\Homeservice\AppData\Local\Temp\pinfect.zip]   13 Jun 2012 01:15:36 - ********** Die in den letzten 14 Tagen im Windows- und ROOT-Ordner erstellten/modifizierten Dateien ********** 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll (5120), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll (3584), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll (3584), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll (3584), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll (4096), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll (4096), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll (3584), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll (4096), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll (3584), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll (3584), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll (4608), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll (4096), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll (4096), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll (4608), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll (3072), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll (3584), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll (6144), 30-Oct-2011 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-security-lsalookup-l1-1-0.dll (3584), 13-Jul-2009 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-security-sddl-l1-1-0.dll (3072), 13-Jul-2009 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-service-core-l1-1-0.dll (2560), 13-Jul-2009 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-service-management-l1-1-0.dll (2560), 13-Jul-2009 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-service-management-l2-1-0.dll (2560), 13-Jul-2009 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\api-ms-win-service-winsvc-l1-1-0.dll (3584), 13-Jul-2009 [H], Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\authuitu.dll (21344), 29-May-2012, TuneUp Software, TuneUp Utilities 2012 13 Jun 2012 01:15:37 - C:\Windows\system32\crypt32.dll (1158656), 12-Jun-2012, Microsoft Corporation, Betriebssystem Microsoft® Windows® 13 Jun 2012 01:15:37 - C:\Windows\system32\cryptnet.dll (103936), 12-Jun-2012, Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:37 - C:\Windows\system32\cryptsvc.dll (140288), 12-Jun-2012, Microsoft Corporation, Betriebssystem Microsoft® Windows® 13 Jun 2012 01:15:37 - C:\Windows\system32\FlashPlayerApp.exe (426184), 12-Jun-2012, Adobe Systems Incorporated, Adobe Flash Player Control Panel Applet 13 Jun 2012 01:15:37 - C:\Windows\system32\FlashPlayerCPLApp.cpl (70344), 12-Jun-2012, Adobe Systems Incorporated, Adobe Flash Player Control Panel Applet 13 Jun 2012 01:15:37 - C:\Windows\system32\ieframe.dll (9737728), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:37 - C:\Windows\system32\iertutil.dll (1793024), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:37 - C:\Windows\system32\ieui.dll (176640), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:37 - C:\Windows\system32\ieUnatt.exe (142848), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:37 - C:\Windows\system32\inetcpl.cpl (1427968), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:37 - C:\Windows\system32\jscript.dll (716800), 12-Jun-2012, Microsoft Corporation, Microsoft (R) JScript 13 Jun 2012 01:15:37 - C:\Windows\system32\jscript9.dll (1800192), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:37 - C:\Windows\system32\jsproxy.dll (65024), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:38 - C:\Windows\system32\MRT.exe (56731752), 12-Jun-2012, Microsoft Corporation, Microsoft Windows-Tool zum Entfernen bösartiger Software 13 Jun 2012 01:15:38 - C:\Windows\system32\mshtml.dll (12314624), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:38 - C:\Windows\system32\mshtmled.dll (73216), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:38 - C:\Windows\system32\msi.dll (2342400), 12-Jun-2012, Microsoft Corporation, Windows Installer - Unicode 13 Jun 2012 01:15:38 - C:\Windows\system32\nvcompiler.dll (17551680), 11-Jun-2012, NVIDIA Corporation, NVIDIA Compiler 13 Jun 2012 01:15:38 - C:\Windows\system32\nvcuda.dll (5982528), 11-Jun-2012, NVIDIA Corporation, NVIDIA CUDA 4.2.1 driver 13 Jun 2012 01:15:38 - C:\Windows\system32\nvcuvenc.dll (2445120), 11-Jun-2012, NVIDIA Corporation, NVIDIA CUDA Video Encoder 13 Jun 2012 01:15:38 - C:\Windows\system32\nvcuvid.dll (2524992), 11-Jun-2012, NVIDIA Corporation, NVIDIA CUDA Video Decode API 13 Jun 2012 01:15:38 - C:\Windows\system32\nvoglv32.dll (19607872), 11-Jun-2012, NVIDIA Corporation, NVIDIA Compatible OpenGL ICD 13 Jun 2012 01:15:38 - C:\Windows\system32\profsvc.dll (164352), 12-Jun-2012, Microsoft Corporation, Betriebssystem Microsoft® Windows® 13 Jun 2012 01:15:38 - C:\Windows\system32\qdvd.dll (514560), 12-Jun-2012, Microsoft Corporation, Betriebssystem Microsoft® Windows® 13 Jun 2012 01:15:38 - C:\Windows\system32\rdpcorekmts.dll (129536), 12-Jun-2012, Microsoft Corporation, Betriebssystem Microsoft® Windows® 13 Jun 2012 01:15:38 - C:\Windows\system32\rdpcorets.dll (919040), 12-Jun-2012, Microsoft Corporation, Betriebssystem Microsoft® Windows® 13 Jun 2012 01:15:38 - C:\Windows\system32\rdpwsx.dll (58880), 12-Jun-2012, Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:38 - C:\Windows\system32\rdrmemptylst.exe (8192), 12-Jun-2012, Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:38 - C:\Windows\system32\TURegOpt.exe (31584), 29-May-2012, TuneUp Software, TuneUp Utilities 2012 13 Jun 2012 01:15:38 - C:\Windows\system32\url.dll (231936), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:38 - C:\Windows\system32\urlmon.dll (1103872), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:38 - C:\Windows\system32\uxtuneup.dll (29024), 29-May-2012, TuneUp Software, TuneUp Utilities 2012 13 Jun 2012 01:15:38 - C:\Windows\system32\win32k.sys (2343936), 12-Jun-2012, Microsoft Corporation, Betriebssystem Microsoft® Windows® 13 Jun 2012 01:15:38 - C:\Windows\system32\wininet.dll (1129472), 12-Jun-2012, Microsoft Corporation, Windows® Internet Explorer 13 Jun 2012 01:15:38 - C:\Windows\system32\drivers\kl1.sys (133208), 03-Jun-2012, Kaspersky Lab ZAO, Kaspersky Anti-Virus 13 Jun 2012 01:15:38 - C:\Windows\system32\drivers\kl2.sys (11352), 03-Jun-2012, Kaspersky Lab ZAO, Kaspersky Anti-Virus 13 Jun 2012 01:15:38 - C:\Windows\system32\drivers\klif.sys (468272), 03-Jun-2012, Kaspersky Lab, Kaspersky™ Anti-Virus ® 13 Jun 2012 01:15:38 - C:\Windows\system32\drivers\nvlddmkm.sys (11354944), 11-Jun-2012, NVIDIA Corporation, NVIDIA Windows Kernel Mode Driver, Version 301.42 13 Jun 2012 01:15:38 - C:\Windows\system32\drivers\rdpwd.sys (183808), 12-Jun-2012, Microsoft Corporation, Betriebssystem Microsoft® Windows® 13 Jun 2012 01:15:38 - C:\Windows\system32\drivers\sp_rsdrv2.sys (32768), 12-Jun-2012, Crawler.com, Spyware Terminator 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\bdc.exe (182792), 12-Jun-2012, BitDefender, BitDefender Console Scanner 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\bdfltlib2k.dll (231944), 12-Jun-2012, MicroWorld Technologies Inc., eScan for Windows 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\encdec.dll (221992), 11-Jun-2012, MicroWorld Technologies Inc., eScan/MailScan/eConceal 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\erootdrv.sys (22920), 12-Jun-2012, MicroWorld Technologies Inc., eScan/MWAV 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\mexe.com (760168), 11-Jun-2012, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility (MWAV) 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\msvclnt.dll (249128), 11-Jun-2012, MicroWorld Technologies Inc., MailScan 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\mwavdwnl.exe (931112), 11-Jun-2012, MicroWorld Technologies Inc., eScan 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\MWAVSCAN.COM (760168), 11-Jun-2012, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility (MWAV) 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\red32.dll (11048), 11-Jun-2012, Microsoft Corporation, Microsoft® Windows® Operating System 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\Reload.exe (184104), 11-Jun-2012, MicroWorld Technologies Inc., eScan for Windows 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\setpriv.exe (82216), 11-Jun-2012, MicroWorld Technologies Inc., eScan AntiVirus Toolkit Utility 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\tmpB359.tmp (17485), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\tmpB359.tmp to ZIP FILE] 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\tmpCD4A.tmp (20967), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\tmpCD4A.tmp to ZIP FILE] 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\trufos.dll (353792), 12-Jun-2012, MicroWorld Technologies Inc., eScan for Windows 13 Jun 2012 01:15:38 - C:\Users\HOMESE~1\AppData\Local\Temp\unregx.exe (93480), 11-Jun-2012, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\viewtcp.exe (576296), 11-Jun-2012, MicroWorld Technologies Inc., ViewTCP 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF0D2241C6B19F8066.TMP (65536), 12-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF0D2241C6B19F8066.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF1898B66B6B236083.TMP (65536), 12-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF1898B66B6B236083.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF18F3D135C4DE798B.TMP (65536), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF18F3D135C4DE798B.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF196CEE09B4ECA8F9.TMP (65536), 12-Jun-2012 [Unable to Add C:\Users\HOMESE~1\AppData\Local\Temp\~DF196CEE09B4ECA8F9.TMP to ZIP FILE! ResultCode: 512] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF257DDF7E13213983.TMP (32768), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF257DDF7E13213983.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF2998F32B3E9F52AC.TMP (65536), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF2998F32B3E9F52AC.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF313100314A995176.TMP (32768), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF313100314A995176.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF4E1CA488E11B7557.TMP (65536), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF4E1CA488E11B7557.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF579E00422C39337C.TMP (32768), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF579E00422C39337C.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF5802FCD65402DFAF.TMP (32768), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF5802FCD65402DFAF.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF5A24CC07DE401800.TMP (32768), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF5A24CC07DE401800.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF5C25AD8FBF11EF77.TMP (114688), 12-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF5C25AD8FBF11EF77.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF65160FA9B78AACC1.TMP (32768), 12-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF65160FA9B78AACC1.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF8C14CD687E8A2CFB.TMP (32768), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF8C14CD687E8A2CFB.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF8FD4A394CBECF15A.TMP (32768), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF8FD4A394CBECF15A.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DF9C225CC9D53CF9BB.TMP (65536), 12-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DF9C225CC9D53CF9BB.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DFB0BA494266269012.TMP (32768), 12-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DFB0BA494266269012.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DFBF5F7CC8BC87BB12.TMP (32768), 12-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DFBF5F7CC8BC87BB12.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DFC087440B1772C486.TMP (32768), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DFC087440B1772C486.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DFCB375D78CC6C7B41.TMP (32768), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DFCB375D78CC6C7B41.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DFCC65C3CB85171B9E.TMP (32768), 11-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DFCC65C3CB85171B9E.TMP to ZIP FILE] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\~DFF5EB797951FDE48F.TMP (65536), 12-Jun-2012 [Added C:\Users\HOMESE~1\AppData\Local\Temp\~DFF5EB797951FDE48F.TMP to ZIP FILE]   13 Jun 2012 01:15:39 - C:\Windows\BitLockerDiscoveryVolumeContents, 14-Jul-2009 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\Windows\Fonts, 14-Jul-2009 [SR] [Ordner] 13 Jun 2012 01:15:39 - C:\Windows\Icons, 29-Oct-2011 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\Windows\Media, 14-Jul-2009 [SR] [Ordner] 13 Jun 2012 01:15:39 - C:\Windows\system32\AI_RecycleBin, 17-Jan-2012 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\Windows\system32\CanonIJ Uninstaller Information, 30-Oct-2011 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\Windows\system32\GroupPolicy, 14-Jul-2009 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\Windows\system32\Microsoft, 14-Jul-2009 [S] [Ordner] 13 Jun 2012 01:15:39 - C:\Boot, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\Documents and Settings, 14-Jul-2009 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\Dokumente und Einstellungen, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData, 14-Jul-2009 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\Programme, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\Recovery, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\acro_rd_dir, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\hsperfdata_Homeservice, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\is-5FC4N.tmp, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\is-C5RMB.tmp, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\is-D0JGK.tmp, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\is-SR04I.tmp, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\plugins, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\WPDNSE, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\Users\HOMESE~1\AppData\Local\Temp\{67C40C83-BE67-4010-9DE8-C27B49C21120}, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\Users\Homeservice\AppData\Roaming\Download Manager, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\Users\Homeservice\AppData\Roaming\Microsoft, 29-Oct-2011 [S] [Ordner] 13 Jun 2012 01:15:39 - C:\Users\Homeservice\AppData\Roaming\Spyware Terminator, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Ad-Aware Browsing Protection, 03-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Anwendungsdaten, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Application Data, 14-Jul-2009 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\CanonBJ, 30-Oct-2011 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Common Files, 18-Apr-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Desktop, 14-Jul-2009 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Documents, 14-Jul-2009 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Dokumente, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Favoriten, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Lavasoft, 09-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Microsoft, 14-Jul-2009 [S] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\MicroWorld, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Spyware Terminator, 12-Jun-2012 [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Start Menu, 14-Jul-2009 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Startmenü, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Templates, 14-Jul-2009 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\Vorlagen, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}, 06-Dec-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{34007C15-AD5B-4CB2-A047-04AB415A841A}, 24-Feb-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{35056848-1DF5-4D37-85C5-0134DA6F6DFD}, 24-Feb-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{363BD091-AD58-44AC-B0F8-EACEFD969001}, 24-Feb-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{4B0F043C-7F75-4273-8BB4-DA0455DFBF5F}, 24-Feb-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{54AE07EB-BBE5-4429-9DF3-C156DB112B54}, 24-Feb-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{7313A1C0-A06F-4C38-B9ED-E538350C744F}, 24-Feb-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{9895E7A6-4CCD-48CD-89C6-05677BEDDFE7}, 24-Feb-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{9C90450F-E325-424C-B16B-8809320C3F92}, 24-Feb-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{A6DDF46E-C493-470C-89D0-A1338DDA580F}, 24-Feb-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{B21E6C95-1429-4BC6-AA4D-4219C78235A1}, 24-Feb-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\{EC2F7042-ADE8-4F04-9A7E-2316AD6311E2}, 24-Feb-2012 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\..\Boot, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\..\Documents and Settings, 14-Jul-2009 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\..\Dokumente und Einstellungen, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\..\ProgramData, 14-Jul-2009 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\..\Programme, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\ProgramData\..\Recovery, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\Program Files\CanonBJ, 02-Nov-2011 [H] [Ordner] 13 Jun 2012 01:15:39 - C:\Program Files\Gemeinsame Dateien, 29-Oct-2011 [HS] [Ordner] 13 Jun 2012 01:15:39 - C:\Program Files\Spyware Terminator, 12-Jun-2012 [Ordner]   13 Jun 2012 01:15:39 - *********************************************************************************************   13 Jun 2012 01:15:39 - Aktuellstes  Datum der in MWAV enthaltenen Dateien: Mon Jun 11 15:13:59 2012. 13 Jun 2012 01:15:39 - Plugins FileCount: 918 Sign Version: 7.42563 13 Jun 2012 01:15:41 - ** Create Value of "1001" in "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" : DWORD:1 13 Jun 2012 01:15:41 - ** Create Value of "1004" in "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" : DWORD:3 13 Jun 2012 01:15:41 - ** Deleted Value of "DisableCAD" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon". Its value was DWORD:1. 13 Jun 2012 01:15:41 - ** Changed Value of "Path" 13 Jun 2012 01:15:41 - ** Changed Value of "HKEY_CLASSES_ROOT\.htm" from "FirefoxHTML" to "htmlfile" 13 Jun 2012 01:15:41 - ** Changed Value of "HKEY_CLASSES_ROOT\.html" from "FirefoxHTML" to "htmlfile" 13 Jun 2012 01:15:41 - Loading/Creating FileScan Database C:\ProgramData\MicroWorld\MWAV\ESCANDBX.MDB [Log: C:\Users\Homeservice\AppData\Local\Temp\ESCANDB.LOG] 13 Jun 2012 01:15:43 - Loaded/Created FileScan Database... 13 Jun 2012 01:15:43 - Loading AV Library [DB]... 13 Jun 2012 01:16:09 - ArchiveScan: DISABLED 13 Jun 2012 01:16:11 - AV Library Loaded [DB-DIRECT]. 13 Jun 2012 01:16:11 - MWAV doing self scanning... 13 Jun 2012 01:16:11 - MWAV files are clean.
13 Jun 2012 01:16:24 - ArchiveScan: DISABLED
13 Jun 2012 01:16:24 - Virus Database Date: 11 Jun 2012
13 Jun 2012 01:16:24 - Virus Database Count: 7278758
13 Jun 2012 01:17:05 - ArchiveScan: ENABLED
 
13 Jun 2012 01:17:28 - **********************************************************
13 Jun 2012 01:17:28 - MWAV - eScanAV AntiVirus Toolkit.
13 Jun 2012 01:17:28 - Copyright © MicroWorld Technologies
13 Jun 2012 01:17:28 - 
13 Jun 2012 01:17:28 - Support: support@escanav.com
13 Jun 2012 01:17:28 - Web: hxxp://www.escanav.com
13 Jun 2012 01:17:28 - **********************************************************
13 Jun 2012 01:17:28 - Version 12.0.243[DB] (C:\USERS\HOMESERVICE\APPDATA\LOCAL\TEMP\MEXE.COM)
13 Jun 2012 01:17:28 - Log File: C:\Users\Homeservice\AppData\Local\Temp\MWAV.LOG
13 Jun 2012 01:17:28 - User Account: Homeservice (Administrator Mode)
13 Jun 2012 01:17:28 - Parent Process Name : D:\Downloads\mwav.exe
13 Jun 2012 01:17:28 - Windows Root  Folder: C:\Windows
13 Jun 2012 01:17:28 - Windows Sys32 Folder: C:\Windows\system32
13 Jun 2012 01:17:28 - OS: Windows 7 [OS Install Date: 29 Oct 2011 19:30:11]
13 Jun 2012 01:17:28 - Ver: Professional Service Pack 1 (Build 7601)
13 Jun 2012 01:17:28 - Latest Date of files inside MWAV: Mon Jun 11 15:13:59 2012.
13 Jun 2012 01:17:28 - Plugins FileCount: 918 Sign Version: 7.42563
 
13 Jun 2012 01:17:39 - Options Selected by User:
13 Jun 2012 01:17:39 - Memory Check: Enabled
13 Jun 2012 01:17:39 - Registry Check: Enabled
13 Jun 2012 01:17:39 - StartUp Folder Check: Disabled
13 Jun 2012 01:17:39 - System Folder Check: Disabled
13 Jun 2012 01:17:39 - Services Check: Enabled
13 Jun 2012 01:17:39 - Scan Spyware: Enabled
13 Jun 2012 01:17:39 - Scan Archives: Enabled
13 Jun 2012 01:17:39 - Drive Check: Disabled
13 Jun 2012 01:17:39 - All Drive Check :Enabled
13 Jun 2012 01:17:39 - Folder Check: Disabled
13 Jun 2012 01:17:39 - SCAN: All_Files
13 Jun 2012 01:17:39 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
 
13 Jun 2012 01:17:39 - Scanning DNS Records...
13 Jun 2012 01:17:39 - Scanning Master Boot Record (Kernel)...
 
13 Jun 2012 01:17:40 - ***** Scanning Memory Files *****
 
13 Jun 2012 01:18:05 - ***** Scanning Registry Files *****
 
13 Jun 2012 01:18:07 - ***** Scanning Service Files *****
13 Jun 2012 01:18:11 - ERROR(2)!!! Invalid Entry \??\D:\Programme\Lavasoft\KernExplorer.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\Lavasoft Kernexplorer.
13 Jun 2012 01:18:11 - ERROR(2)!!! Invalid Entry system32\DRIVERS\Lbd.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\Lbd.
13 Jun 2012 01:18:15 - ERROR(2)!!! Invalid Entry system32\DRIVERS\siusbmod.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\siusbmod.
13 Jun 2012 01:18:16 - ERROR(2)!!! Invalid Entry System32\drivers\synth3dvsc.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\Synth3dVsc.
13 Jun 2012 01:18:16 - ERROR(2)!!! Invalid Entry system32\drivers\tsusbhub.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\tsusbhub.
13 Jun 2012 01:18:17 - ERROR(2)!!! Invalid Entry System32\drivers\rdvgkmd.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\VGPU.
 
13 Jun 2012 01:18:19 - ***** Scanning Important System Files *****
 
13 Jun 2012 01:18:20 - ***** Scanning Registry and File system for Adware/Spyware *****
13 Jun 2012 01:18:22 - Loading Spyware Signatures from new External Database [Name: C:\Users\HOMESE~1\AppData\Local\Temp\spydb.avs, Size: 982779]...
13 Jun 2012 01:18:22 - Indexed Spyware Databases Successfully Created...
 
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{0A95BE2D-1543-46BE-AD6D-18653034BF87})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{0B8EDB8D-4575-4942-9C34-55591E415909})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{278EAD7A-2A45-4D4E-ACB4-A1A4AD9BB54B})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{2B539D9C-127A-4F10-855F-EF31C83D2007})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{2D91877A-468C-4802-8CD7-21F6BF776790})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{3120A5E4-552D-4EDF-8C48-70C5D5FF22D2})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{31CE2164-4D5C-4508-BCA7-B10E11D08E6B})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{359A062F-CDA8-4A9C-9B28-588446D35098})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{35EFAD55-134A-47BF-912A-44A9D9FD556F})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{38F95B22-32BF-4378-B3EC-47B2C09DE1F5})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{3D177BA8-BF8C-45E2-8CA2-20ACA6269A68})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{3E1392BB-3B66-4A39-BBD0-259FC2BDC979})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{45128C11-A7E5-46D2-A164-3D1273E92C44})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{47146231-B550-4B13-B9E7-4257F740F39D})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{5C61669E-F0CE-4126-B365-316588E6228F})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{60E5F55E-236F-422D-A5F9-560F1778CCD4})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{62B6A513-3764-42CD-8410-9B81E8DFF135})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{6A5D680A-8F9F-4752-A056-2C0273F60B4E})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{6CCD925E-E833-4BE3-A62E-D3C8838C5D6D})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{6CDD1F89-FC3B-401C-B1F1-932C48F45EB5})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{78412EB9-E06B-4484-BC85-0B1594F6E23A})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{7EE495F3-345B-4CC1-AAB7-A255ED85EED2})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{82B58FCB-73F3-46DC-A52D-74D3FE359702})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{86797248-1A4E-41D0-A0C3-2175A36B3D0E})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{919DF860-D321-4D02-AC3D-1C25EFAE551A})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{AA6CCB5D-0F97-4A37-A077-8B49FB5BC60D})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{C18D120C-B7AB-4499-8BDC-0CD2BD0861FD})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{C1DFD382-E253-434D-B22D-2E47233B6147})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{C52D8C84-C5DD-457B-993B-04E997B330E5})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{CACB61E0-AEEA-404D-88E1-7F3BCA8B8726})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{CD5B9523-6EAF-4D63-8FE8-C081C51D1673})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{D45B0772-5801-4E61-9CBA-84120557A4D7})! Action taken: Entries Removed.
13 Jun 2012 01:19:25 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{D7E6FB7C-A22F-4A9D-A89D-653D1AA37324})! Action taken: Entries Removed.
13 Jun 2012 01:19:26 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{D80AC53D-E102-4A55-A265-529A626515E5})! Action taken: Entries Removed.
13 Jun 2012 01:19:26 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{DBCAD616-BFD4-4C72-8D87-C5926921D378})! Action taken: Entries Removed.
13 Jun 2012 01:19:26 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{E16F1874-C5B1-4400-A9F0-08E7FD4D3F8C})! Action taken: Entries Removed.
13 Jun 2012 01:19:26 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{E3EC74BB-5522-462D-A00F-2728C53FCA04})! Action taken: Entries Removed.
13 Jun 2012 01:19:26 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{EBB4EBA9-D546-4C85-A05A-167BF875FB83})! Action taken: Entries Removed.
13 Jun 2012 01:19:26 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{F71D2854-2609-4A63-B4BF-BF2BA61A61CF})! Action taken: Entries Removed.
13 Jun 2012 01:19:26 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{F7919641-3978-4668-8388-7310329C800E})! Action taken: Entries Removed.
13 Jun 2012 01:19:26 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{F961CE9D-AE2B-4CFB-887C-3A055FF685C9})! Action taken: Entries Removed.
13 Jun 2012 01:19:26 - System found infected with combo Spyware/Adware (HKEY_CLASSES_ROOT\interface\{FFBBDECE-4363-4B4D-B35E-39EFF228C723})! Action taken: Entries Removed.
13 Jun 2012 01:19:26 - Offending Folder found: C:\Windows\Icons
13 Jun 2012 01:19:26 - Deltree of Folder C:\Windows\Icons...
13 Jun 2012 01:19:27 - Object "Holistyc Dialer" found in File System! Action Taken: Entries Removed.

13 Jun 2012 01:19:27 - Offending file found: C:\Windows\winhelp.ini
13 Jun 2012 01:19:27 - System found infected with combo Spyware/Adware (winhelp.ini)! Action taken: File Deleted.
13 Jun 2012 01:19:27 - Offending file found: C:\Windows\TEMP\IswTmp\WH\0
13 Jun 2012 01:19:27 - System found infected with Generic  Protect Antivirus (0)! Action taken: File Deleted.
13 Jun 2012 01:19:27 - Object "Generic  Protect Antivirus" found in File System! Action Taken: File Deleted.

13 Jun 2012 01:19:27 - Offending file found: C:\Users\Homeservice\AppData\Roaming\DarkParablesBriarRose_BFG\Temp\0
13 Jun 2012 01:19:27 - System found infected with Generic  Protect Antivirus (0)! Action taken: File Deleted.
13 Jun 2012 01:19:27 - Object "Generic  Protect Antivirus" found in File System! Action Taken: File Deleted.

13 Jun 2012 01:19:28 - Offending file found: C:\Users\Homeservice\AppData\Roaming\DarkParablesBriarRose_BFG\Temp\43
13 Jun 2012 01:19:28 - System found infected with XPAntivirus (43)! Action taken: File Deleted.
13 Jun 2012 01:19:28 - Object "XPAntivirus" found in File System! Action Taken: File Deleted.

13 Jun 2012 01:19:29 - Offending file found: C:\Users\Homeservice\AppData\Local\Temp\IswTmp\WH\0
13 Jun 2012 01:19:29 - System found infected with Generic  Protect Antivirus (0)! Action taken: File Deleted.
13 Jun 2012 01:19:29 - Object "Generic  Protect Antivirus" found in File System! Action Taken: File Deleted.

13 Jun 2012 01:19:32 - Offending file found: C:\ProgramData\CheckPoint\ZoneAlarm\Data\avsys\bases_csd\SysWHist\amlogs\0
13 Jun 2012 01:19:32 - System found infected with Generic  Protect Antivirus (0)! Action taken: File Deleted.
13 Jun 2012 01:19:32 - Object "Generic  Protect Antivirus" found in File System! Action Taken: File Deleted.

13 Jun 2012 01:19:32 - Offending file found: C:\ProgramData\CheckPoint\ZoneAlarm\Data\avsys\bases_csd\SysWHist\amlogs\43
13 Jun 2012 01:19:32 - System found infected with XPAntivirus (43)! Action taken: File Deleted.
13 Jun 2012 01:19:32 - Object "XPAntivirus" found in File System! Action Taken: File Deleted.

13 Jun 2012 01:19:32 - Offending file found: C:\ProgramData\CheckPoint\ZoneAlarm\Data\avsys\bases_csd\SysWHist\bsslogs\0
13 Jun 2012 01:19:32 - System found infected with Generic  Protect Antivirus (0)! Action taken: File Deleted.
13 Jun 2012 01:19:32 - Object "Generic  Protect Antivirus" found in File System! Action Taken: File Deleted.

13 Jun 2012 01:19:32 - Offending file found: C:\ProgramData\CheckPoint\ZoneAlarm\Data\avsys\bases_csd\SysWHist\bsslogs\43
13 Jun 2012 01:19:32 - System found infected with XPAntivirus (43)! Action taken: File Deleted.
13 Jun 2012 01:19:32 - Object "XPAntivirus" found in File System! Action Taken: File Deleted.

13 Jun 2012 01:19:34 - Offending Registry Entry found: HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters/AutoShareWks
13 Jun 2012 01:19:34 - System found infected with combo Spyware/Adware (HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters/AutoShareWks)! Action taken: Entries Removed.
 
13 Jun 2012 01:19:34 - ***** Scanning Registry Files *****
13 Jun 2012 01:19:36 - Clearing Temporary sub-folders as Spyware/Adware found in system...
13 Jun 2012 01:19:37 - Few files will be deleted *ONLY* on reboot...
13 Jun 2012 01:19:37 - Few files will be deleted *ONLY* on reboot...
13 Jun 2012 01:19:37 - ** Value in HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\main/Start Page = hxxp://www.arcor.de
13 Jun 2012 01:19:37 - ** Value in HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main/Start Page = hxxp://www.arcor.de
 
13 Jun 2012 01:19:37 - ***** Scanning All Drives *****
13 Jun 2012 01:19:37 - ***** C:,D:,E: ***** 
13 Jun 2012 01:19:37 - Scanning C:\ Drive
13 Jun 2012 01:19:37 - C:\Boot\BCD not Scanned. Possibly password protected...
13 Jun 2012 01:23:53 - Datei C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4b5f4353.qua wird gescannt
13 Jun 2012 01:23:56 - File C:\ProgramData\Avira\AntiVir Desktop\INFECTED\4b5f4353.qua infected by "Trojan.Generic.6325903[ZP] (DB)" Virus! Action Taken: File Renamed.

13 Jun 2012 01:24:01 - Datei C:\ProgramData\Avira\AntiVir Desktop\INFECTED\55762c1f.qua wird gescannt
13 Jun 2012 01:24:03 - File C:\ProgramData\Avira\AntiVir Desktop\INFECTED\55762c1f.qua infected by "Trojan.Generic.6325903[ZP] (DB)" Virus! Action Taken: File Renamed.

13 Jun 2012 01:25:09 - C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb not Scanned. Possibly password protected...
13 Jun 2012 01:25:09 - C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb not Scanned. Possibly password protected...
13 Jun 2012 01:25:13 - C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\MpSfc.bin not Scanned. Possibly password protected...
13 Jun 2012 01:28:28 - C:\System Volume Information\ISwift3.dat not Scanned. Possibly password protected...
13 Jun 2012 01:28:28 - C:\System Volume Information\Syscache.hve not Scanned. Possibly password protected...
13 Jun 2012 01:28:28 - C:\System Volume Information\Syscache.hve.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:28:29 - Datei C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} wird gescannt
13 Jun 2012 01:28:29 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
13 Jun 2012 01:28:29 - Datei C:\System Volume Information\{bde23800-b4b5-11e1-82a1-00183704109d}{3808876b-c176-4e48-b7ae-04046e6cc752} wird gescannt
13 Jun 2012 01:28:29 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{bde23800-b4b5-11e1-82a1-00183704109d}{3808876b-c176-4e48-b7ae-04046e6cc752}
13 Jun 2012 01:28:29 - Datei C:\System Volume Information\{bde23885-b4b5-11e1-82a1-00183704109d}{3808876b-c176-4e48-b7ae-04046e6cc752} wird gescannt
13 Jun 2012 01:28:29 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{bde23885-b4b5-11e1-82a1-00183704109d}{3808876b-c176-4e48-b7ae-04046e6cc752}
13 Jun 2012 01:28:39 - C:\Users\Homeservice\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:29:03 - Datei C:\Users\Homeservice\AppData\Local\Temp\IswTmp\Logs\ISWSHEX.swl wird gescannt
13 Jun 2012 01:29:03 - ERROR(3)!!! ScanFile fails for C:\Users\Homeservice\AppData\Local\Temp\IswTmp\Logs\ISWSHEX.swl
13 Jun 2012 01:29:03 - Datei C:\Users\Homeservice\AppData\Local\Temp\IswTmp\Logs\TrustcheckerIEPlugin.swl wird gescannt
13 Jun 2012 01:29:03 - ERROR(3)!!! ScanFile fails for C:\Users\Homeservice\AppData\Local\Temp\IswTmp\Logs\TrustcheckerIEPlugin.swl
13 Jun 2012 01:29:51 - INVALID ATTRIBUTES FOR FOLDER [C:\Users\Homeservice\AppData\Roaming\Boolat Games\Timeless Town CE??????????????]. IGNORING.
13 Jun 2012 01:29:51 - INVALID ATTRIBUTES FOR FOLDER [C:\Users\Homeservice\AppData\Roaming\Boolat Games\Timeless Town CE??????????????]. IGNORING.
13 Jun 2012 01:29:51 - INVALID ATTRIBUTES FOR FOLDER [C:\Users\Homeservice\AppData\Roaming\Boolat Games?]. IGNORING.
13 Jun 2012 01:29:51 - INVALID ATTRIBUTES FOR FOLDER [C:\Users\Homeservice\AppData\Roaming\Boolat Games?]. IGNORING.
13 Jun 2012 01:30:51 - C:\Users\Homeservice\ntuser.dat.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:30:55 - C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:30:56 - C:\Users\UpdatusUser\ntuser.dat.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:35:53 - INVALID ATTRIBUTES FOR FOLDER [C:\Windows\Resources\Themes\675\HUD Premium Theme\1 Theme Patcher if not ever made ??the patches you here]. IGNORING.
13 Jun 2012 01:36:22 - Datei C:\Windows\Resources\Themes\Pack_Themez_Win_Sev7en_p5_19\blue_night_by_bigcyco1\Theme\Theme Resource Changer\ThemeResourceChangerX64-v10.exe wird gescannt
13 Jun 2012 01:36:22 - File C:\Windows\Resources\Themes\Pack_Themez_Win_Sev7en_p5_19\blue_night_by_bigcyco1\Theme\Theme Resource Changer\ThemeResourceChangerX64-v10.exe infected by "Gen:Trojan.Heur.VP.wm0@aGp6CSni[ZP] (DB)" Virus! Action Taken: File Renamed.

13 Jun 2012 01:36:22 - Datei C:\Windows\Resources\Themes\Pack_Themez_Win_Sev7en_p5_19\blue_night_by_bigcyco1\Theme\Theme Resource Changer\ThemeResourceChangerX86-v10.exe wird gescannt
13 Jun 2012 01:36:23 - File C:\Windows\Resources\Themes\Pack_Themez_Win_Sev7en_p5_19\blue_night_by_bigcyco1\Theme\Theme Resource Changer\ThemeResourceChangerX86-v10.exe infected by "Gen:Trojan.Heur.VP.wm0@aGp6CSni[ZP] (DB)" Virus! Action Taken: File Renamed.

13 Jun 2012 01:36:39 - Datei C:\Windows\Resources\Themes\sseexec.dat wird gescannt
13 Jun 2012 01:36:39 - File C:\Windows\Resources\Themes\sseexec.dat infected by "Gen:Trojan.Heur.VP.wm0@aGp6CSni (DB)" Virus! Action Taken: File Renamed.

13 Jun 2012 01:36:48 - C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat not Scanned. Possibly password protected...
13 Jun 2012 01:36:48 - C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat not Scanned. Possibly password protected...
13 Jun 2012 01:36:49 - C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:36:50 - C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:37:57 - C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb not Scanned. Possibly password protected...
13 Jun 2012 01:37:57 - C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\DEFAULT not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\DEFAULT.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\RegBack\DEFAULT not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\RegBack\SAM not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\RegBack\SECURITY not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\RegBack\SOFTWARE not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\RegBack\SYSTEM not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\SAM not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\SAM.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\SECURITY not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\SECURITY.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\SOFTWARE not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\SOFTWARE.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\SYSTEM not Scanned. Possibly password protected...
13 Jun 2012 01:38:00 - C:\Windows\System32\config\SYSTEM.LOG1 not Scanned. Possibly password protected...
13 Jun 2012 01:40:31 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl not Scanned. Possibly password protected...
13 Jun 2012 01:40:31 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl not Scanned. Possibly password protected...
13 Jun 2012 01:40:31 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl not Scanned. Possibly password protected...
13 Jun 2012 01:40:31 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl not Scanned. Possibly password protected...
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\FFApi.swl wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\FFApi.swl
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\ISWDMP.swl wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\ISWDMP.swl
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\ISWFWMON.swl wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\ISWFWMON.swl
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\ISWMENUS.swl wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\ISWMENUS.swl
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\ISWSHEX.swl wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\ISWSHEX.swl
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\ISWSHEX.swl.old wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\ISWSHEX.swl.old
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\ISWSPYSCAN.swl wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\ISWSPYSCAN.swl
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\ISWSTATS.swl wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\ISWSTATS.swl
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\ISWSVC.swl wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\ISWSVC.swl
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\ISWUILIB.swl wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\ISWUILIB.swl
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\ISWUL.swl wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\ISWUL.swl
13 Jun 2012 01:42:05 - Datei C:\Windows\Temp\IswTmp\Logs\ISWUPD.swl wird gescannt
13 Jun 2012 01:42:05 - ERROR(3)!!! ScanFile fails for C:\Windows\Temp\IswTmp\Logs\ISWUPD.swl
13 Jun 2012 01:42:09 - C:\Windows\Temp\TMP000000BAB4549EAEE6E75421 not Scanned. Possibly password protected...
13 Jun 2012 01:50:14 - Scanning D:\ Drive
13 Jun 2012 02:10:53 - Scanning E:\ Drive
13 Jun 2012 03:01:01 - Datei E:\Chris\Downloads\game\Vampire Saga 3 Break Out\data\Sound\misc\???.ogg wird gescannt
13 Jun 2012 03:01:01 - ERROR(3)!!! ScanFile fails for E:\Chris\Downloads\game\Vampire Saga 3 Break Out\data\Sound\misc\???.ogg
13 Jun 2012 03:01:01 - Datei E:\Chris\Downloads\game\Vampire Saga 3 Break Out\data\Sound\misc\???? ?????????.ogg wird gescannt
13 Jun 2012 03:01:01 - ERROR(3)!!! ScanFile fails for E:\Chris\Downloads\game\Vampire Saga 3 Break Out\data\Sound\misc\???? ?????????.ogg
13 Jun 2012 03:01:01 - Datei E:\Chris\Downloads\game\Vampire Saga 3 Break Out\data\Sound\misc\???????????? ???? ? ?????.ogg wird gescannt
13 Jun 2012 03:01:01 - ERROR(3)!!! ScanFile fails for E:\Chris\Downloads\game\Vampire Saga 3 Break Out\data\Sound\misc\???????????? ???? ? ?????.ogg
13 Jun 2012 03:01:01 - Datei E:\Chris\Downloads\game\Vampire Saga 3 Break Out\data\Sound\misc\????.ogg wird gescannt
13 Jun 2012 03:01:01 - ERROR(3)!!! ScanFile fails for E:\Chris\Downloads\game\Vampire Saga 3 Break Out\data\Sound\misc\????.ogg
13 Jun 2012 03:03:23 - ScanFile (E:\Chris\Downloads\Media\MESMERiZE\mp3maker.exe) took 45015 ms
13 Jun 2012 03:03:23 - Scanning of E:\Chris\Downloads\Media\MESMERiZE\mp3maker.exe Timed out!!!
 
13 Jun 2012 03:07:57 - ***** Checking for specific ITW Viruses *****
 
13 Jun 2012 03:07:57 - ***** Scanning complete. *****
 
13 Jun 2012 03:07:57 - Total Objects Scanned: 431583
13 Jun 2012 03:07:57 - Total Critical Objects: 14
13 Jun 2012 03:07:57 - Total Disinfected Objects: 0
13 Jun 2012 03:07:57 - Total Objects Renamed: 5
13 Jun 2012 03:07:57 - Total Deleted Objects: 9
13 Jun 2012 03:07:57 - Total Errors: 6
13 Jun 2012 03:07:57 - Time Elapsed: 01:50:28
13 Jun 2012 03:07:57 - Virus Database Date: 11 Jun 2012
13 Jun 2012 03:07:57 - Virus Database Count: 7278758
 
13 Jun 2012 03:07:57 - Scan Completed.
         
eScan Extras
OTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 13.06.2012 00:07:04 - Run 1
OTL by OldTimer - Version 3.2.48.0     Folder = C:\Users\Homeservice\Desktop
 Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 1,92 Gb Available Physical Memory | 58,98% Memory free
6,79 Gb Paging File | 5,25 Gb Available in Paging File | 77,37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 29,29 Gb Total Space | 6,26 Gb Free Space | 21,37% Space Free | Partition Type: NTFS
Drive D: | 48,82 Gb Total Space | 12,26 Gb Free Space | 25,10% Space Free | Partition Type: NTFS
Drive E: | 387,63 Gb Total Space | 106,83 Gb Free Space | 27,56% Space Free | Partition Type: NTFS
 
Computer Name: HOMESERVICE-PC | User Name: Homeservice | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- D:\Programme\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "D:\Programme\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "D:\Programme\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] -- cmd.exe /k takeown /f "%1" /r /d j && icacls "%1" /grant administratoren:F /t (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "D:\Programme\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Programme\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Programme\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03AB54BB-8B6C-4889-B954-46C352D4CA8C}" = rport=138 | protocol=17 | dir=out | app=system | 
"{067F2BF0-F67F-499C-8034-E8D6E9669A4D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{0C4A672A-508E-4AF3-9BF6-304E8786C8CB}" = rport=137 | protocol=17 | dir=out | app=system | 
"{1F975B5B-AD8F-413F-BA90-3A94BBFE21CC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{2D5D9166-571E-4C7D-ABE4-32F9A67C775A}" = rport=139 | protocol=6 | dir=out | app=system | 
"{39EF56A0-5DCD-4642-8D89-E5E6103C092F}" = lport=138 | protocol=17 | dir=in | app=system | 
"{57E6E795-FC8B-4602-9CD6-6FF5EEF7973D}" = lport=445 | protocol=6 | dir=in | app=system | 
"{5F675B7F-C91B-4DF9-BAAA-7BB18F35D9E8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{8C357C01-D897-45FA-92DB-995CD91FCF0E}" = lport=6004 | protocol=17 | dir=in | app=d:\programme\office14\outlook.exe | 
"{9F33D608-6EAA-4B36-AA87-3D96A59E32E2}" = lport=137 | protocol=17 | dir=in | app=system | 
"{AD57CBB4-B8A7-4BBD-92E6-DC9FA9924392}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{B02FCDC9-0903-43B1-9E13-3DF29B9D3D0C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{B5C899AB-2FA0-4619-BDCE-95A864C6E9AA}" = lport=139 | protocol=6 | dir=in | app=system | 
"{D22939CA-303E-4D89-8DBF-6A126E1193FD}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{F092F9DF-8B25-45D9-83A5-E3BC1449358F}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe | 
"{F7A0525F-73A5-47A4-B5AE-1A6F33C16215}" = rport=445 | protocol=6 | dir=out | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0ED6B6B3-9C37-400A-AA90-9E1C914E1F06}" = protocol=6 | dir=in | app=c:\windows\system32\mmc.exe | 
"{338082CF-B510-4A6C-9F5A-4B2D916B76F7}" = protocol=17 | dir=in | app=d:\programme\office14\groove.exe | 
"{4AA559D1-40B9-4B88-93C2-46C42B83E908}" = protocol=17 | dir=in | app=d:\programme\office14\onenote.exe | 
"{4E0C01A0-352C-4399-87E1-FE1182E9E035}" = protocol=17 | dir=in | app=c:\program files\windows sidebar\sidebar.exe | 
"{51CE23AB-4A08-4498-89DB-909F459639CE}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{53329FD0-8962-4ACB-9ED9-C994E405D3E0}" = protocol=6 | dir=in | app=c:\program files\spyware terminator\spywareterminator.exe | 
"{56FB5E3B-B882-4790-B98E-2285258B0161}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{591361CF-1BFC-4725-B42A-86D271940B7C}" = protocol=17 | dir=in | app=c:\windows\system32\mmc.exe | 
"{8C3C430C-E6B8-4F1A-94EE-847424098A22}" = protocol=6 | dir=in | app=c:\program files\windows sidebar\sidebar.exe | 
"{8E586F5B-0441-4E94-8AAA-993C1B0335EB}" = protocol=6 | dir=in | app=d:\programme\winamp\winamp.exe | 
"{8FCCF297-5056-4247-B892-E961C53B4162}" = protocol=6 | dir=in | app=c:\program files\spyware terminator\spywareterminatorupdate.exe | 
"{9121B54A-83F9-4E50-B8AD-A9AC1135B0A8}" = protocol=17 | dir=in | app=c:\program files\spyware terminator\spywareterminatorupdate.exe | 
"{94E0567D-26A6-4C34-9BC1-B9FDF840597F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{A010263A-D738-425A-8882-1756D2A70D71}" = protocol=17 | dir=in | app=c:\program files\spyware terminator\spywareterminator.exe | 
"{BA1D6940-F789-464C-868B-8BC5229DEEC2}" = protocol=6 | dir=in | app=d:\programme\office14\onenote.exe | 
"{C0FED08F-198A-4DCD-BEAD-9E1399B04A79}" = protocol=6 | dir=in | app=d:\programme\office14\groove.exe | 
"{D12980C6-EB2E-48D0-A4B1-985E29F086FA}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | 
"{E1B2A2EB-D5D1-41AD-9BB3-55A02405B294}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{E4803C32-2D1D-4AD3-ADA1-1108A307DA0A}" = protocol=17 | dir=in | app=d:\programme\winamp\winamp.exe | 
"TCP Query User{01E682F2-4E29-4B5D-8B72-4565F45CC6E0}D:\programme\winamp\winamp.exe" = protocol=6 | dir=in | app=d:\programme\winamp\winamp.exe | 
"TCP Query User{641C1C2E-E2C7-4E63-A440-CEE7A6AC1EFD}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=6 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe | 
"TCP Query User{66EAA445-BCE5-4E45-BC4D-ECBA4DBDFFE2}C:\program files\windows sidebar\sidebar.exe" = protocol=6 | dir=in | app=c:\program files\windows sidebar\sidebar.exe | 
"TCP Query User{888B0BF4-3227-4EEF-A536-F10E80F64053}C:\windows\system32\mmc.exe" = protocol=6 | dir=in | app=c:\windows\system32\mmc.exe | 
"TCP Query User{CC3B96C7-62C1-4336-BA2C-AA9CA628546A}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | 
"UDP Query User{07D23677-9C3F-40F1-B52A-934659005608}C:\windows\system32\mmc.exe" = protocol=17 | dir=in | app=c:\windows\system32\mmc.exe | 
"UDP Query User{11FA5996-FE09-4DDB-978D-17952932D720}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | 
"UDP Query User{3B822662-8D22-4B31-BB05-2F688E0B7E70}C:\program files\windows sidebar\sidebar.exe" = protocol=17 | dir=in | app=c:\program files\windows sidebar\sidebar.exe | 
"UDP Query User{5A9A8AC8-B3C0-44F6-95FD-3BF73A1D1278}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=17 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe | 
"UDP Query User{78CAC792-85C3-47C8-BD13-CEDC0D8D4E78}D:\programme\winamp\winamp.exe" = protocol=17 | dir=in | app=d:\programme\winamp\winamp.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}" = Nero BackItUp 10 Help (CHM)
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0E8D886F-3205-4472-848E-990F400FF218}" = Microsoft Windows Debugging Symbols
"{10D3FDF4-A68B-4850-8F0D-31D8A93FF98B}_is1" = The Tiny Bang Story Version 1.0
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series" = Canon iP2600 series
"{121634B0-2F4A-11D3-ADA3-00C04F52DD53}" = Windows Installer Clean Up
"{16987E99-C95C-4513-9239-7B44A0A71DB5}" = Nero SoundTrax 10 Help (CHM)
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1C943495-B69F-4D41-AE0E-23C57ECD90EE}" = Debugging Tools for Windows
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}" = Nero MediaHub 10
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{237CCB62-8454-43E3-B158-3ACD0134852E}" = High-Definition Video Playback 10
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{262DA23B-4BAB-463F-B1DC-9B5287CAB5CA}}_is1" = Deinstallation der Arcor Online Software
"{26A24AE4-039D-4CA4-87B4-2F83216021F0}" = Java(TM) 6 Update 21
"{26A24AE4-039D-4CA4-87B4-2F83216029F0}" = Java(TM) 6 Update 29
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10
"{28E7B64D-150F-4A9E-B7A3-5A6AC8C2F822}" = ebgcSDK
"{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012
"{329411A0-19F3-4740-874F-17400B126F27}" = Nero Vision 10 Help (CHM)
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
"{39B1BD87-561E-4762-AED9-7C5213B06C24}" = ebgcInfra
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{42C8B7DF-FEB0-4D51-B169-506B6BEC5797}" = Nero 10 Menu TemplatePack 1
"{43FBAB46-5969-4200-9958-1FF81FEE506F}" = Nero 10 Movie ThemePack 1
"{48F95CE7-69D9-4967-81F7-D763CABFBD53}" = Debugging Tools for Windows (x86)
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{56736259-613E-4A3B-B428-6235F2E76F44}_is1" = Spyware Terminator 2012
"{5884CB45-C54B-4550-BAD5-3E060FD75D17}" = ZoneAlarm Firewall
"{5D4C60AA-84E6-4E1A-8A68-69970D387BE1}" = TuneUp Utilities Language Pack (de-DE)
"{5F548A02-80BC-404D-BAE6-F05F9BF6B449}" = Nero DiscCopyGadget 10 Help (CHM)
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68AB6930-5BFF-4FF6-923B-516A91984FE6}" = Nero BackItUp 10
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{70F19404-B96C-4EBB-AD2B-3574F8736197}" = Nero 10 Movie ThemePack 2
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A295D8F-484B-4FFB-89AB-C1FD497591FE}" = Nero WaveEditor 10 Help (CHM)
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7D6DDE45-FE2F-4D11-A7E7-BC2C2910536C}" = USB/DVD-Downloadtool für Windows 7
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}" = Nero Recode 10
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0015-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUS_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.PROPLUS_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.PROPLUS_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010
"{90140000-0044-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.PROPLUS_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010
"{90140000-00BA-0407-0000-0000000FF1CE}_Office14.PROPLUS_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92146419-AE44-4C8B-A48B-0ABB1B5EC026}" = Nero 10 Menu TemplatePack 3
"{92A10E9D-EA00-4A46-8F22-EEA660992D61}" = Nero 10 Sample Videos
"{92E25238-61A3-4ACD-A407-3C480EEF47A7}" = Nero RescueAgent 10 Help (CHM)
"{92EC1A84-7FFC-42DF-A8F6-79C21C4765A5}" = Nero DiscCopy Gadget 10
"{938D9C57-3CF0-4DA8-B04E-EF99501859B5}" = Mobile Phone Manager
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{95140000-00AF-0407-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{96ED4B78-300E-4033-AE6C-C115CEB4DF07}" = Nero 10 ClipartPack
"{98613C99-1399-416C-A07C-1EE1C585D872}" = SeaTools for Windows
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}" = Nero Vision 10
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3E8FC19-2107-49DA-967F-23E1B5210D9C}" = ZoneAlarm Security
"{A542D955-9F05-4C74-8866-25DDC0DB15DB}" = SIEMENS USB Data Cable
"{A6B7B910-69BE-4873-8CA8-B5C37BAFE9F4}" = Mobile Modem Assistant
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch
"{ACD15FDF-FC42-4175-B477-576F92FF2256}" = Nero 10 Sample ImagePack
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.0213
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.8.15
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B96D2269-568B-4CBF-9332-12FAE8B158F7}" = Medieval CUE Splitter
"{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM)
"{C3273C55-E1E4-41FF-8D69-0158090DB8D8}" = Nero CoverDesigner 10 Help (CHM)
"{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10
"{C6DB958A-50CC-481B-9ED8-3BAD236F7B49}" = Microsoft Windows Debugging Symbols
"{CB33664C-5683-40AB-B968-01276F6F3446}" = ebgcRes
"{CE026CFE-73FE-4FED-9D5F-2C8D4DB512B0}" = TuneUp Utilities Language Pack (de-DE)
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{DB7C1D4A-08BA-4C7E-A8AA-B7F9BB372DCF}" = Nero Recode 10 Help (CHM)
"{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}" = Nero SoundTrax 10
"{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10
"{E712C273-7564-4C8E-AA59-0FA19BC35117}" = Nero 10 Menu TemplatePack 2
"{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10
"{F012A635-8E2C-4AF2-BD46-C508D00289B2}" = ZoneAlarm Antivirus
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F467862A-D9CA-47ED-8D81-B4B3C9399272}" = Nero MediaHub 10 Help (CHM)
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
"{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10
"5513-1208-7298-9440" = JDownloader 0.9
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Avira AntiVir Desktop" = Avira Free Antivirus
"BFGC" = Big Fish Games: Game Manager
"Black Mirror_is1" = Black Mirror 1.0de
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CCleaner" = CCleaner
"Deponia" = Deponia
"DriverAgent.exe" = DriverAgent by eSupport.com
"DVD Shrink DE_is1" = DVD Shrink 3.2 deutsch
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"Free 3GP Video Converter_is1" = Free 3GP Video Converter version 5.0.4.1228
"Free Audio CD to MP3 Converter_is1" = Free Audio CD to MP3 Converter version 1.3.12.1228
"Free Audio Converter_is1" = Free Audio Converter version 5.0.7.403
"Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 5.0.4.1228
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.20.423
"IcoFX_is1" = IcoFX 2.0
"InstallShield_{938D9C57-3CF0-4DA8-B04E-EF99501859B5}" = Mobile Phone Manager
"IsoBuster_is1" = IsoBuster 2.5
"Mahjongg Master 4" = Mahjongg Master 4
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mortimer Beckett and the Secrets of Spooky Manor" = Mortimer Beckett and the Secrets of Spooky Manor
"Mozilla Firefox 8.0 (x86 de)" = Mozilla Firefox 8.0 (x86 de)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Pen Tablet Driver" = Bamboo
"QBeez 2_is1" = QBeez 2
"QuickStores-Toolbar_is1" = QuickStores-Toolbar 1.1.0
"Sandlot Games Client Services 1.2.2_is1" = Sandlot Games Client Services 1.2.2
"Siemens DCA-140/540 USB Treiber_is1" = Siemens DCA-140/540 USB Treiber 1.0.7
"SP6" = Logitech SetPoint 6.0
"SYBEX Spieltrieb Brettspiele" = SYBEX Spieltrieb Brettspiele 1 
"Theme Resource Changer X86 v1.0" = Theme Resource Changer X86 v1.0
"TuneUp Utilities 2012" = TuneUp Utilities 2012
"Unlocker" = Unlocker 1.9.1
"Venice Deluxe_is1" = Venice Deluxe
"Winamp" = Winamp
"WinRAR archiver" = WinRAR
"WordPro V97.0" = Lotus Word Pro 97
"ZoneAlarm Free Antivirus + Firewall" = ZoneAlarm Free Antivirus + Firewall
"Zuma Deluxe" = Zuma Deluxe
"Zuma Deluxe_is1" = Zuma Deluxe
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Mozilla Firefox 13.0 (x86 de)" = Mozilla Firefox 13.0 (x86 de)
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 09.04.2012 02:23:55 | Computer Name = Homeservice-PC | Source = Windows Search Service | ID = 9002
Description = 
 
Error - 09.04.2012 02:23:55 | Computer Name = Homeservice-PC | Source = Windows Search Service | ID = 3029
Description = 
 
Error - 09.04.2012 02:23:56 | Computer Name = Homeservice-PC | Source = Windows Search Service | ID = 3029
Description = 
 
Error - 09.04.2012 02:23:56 | Computer Name = Homeservice-PC | Source = Windows Search Service | ID = 3028
Description = 
 
Error - 09.04.2012 02:23:56 | Computer Name = Homeservice-PC | Source = Windows Search Service | ID = 3058
Description = 
 
Error - 09.04.2012 02:23:56 | Computer Name = Homeservice-PC | Source = Windows Search Service | ID = 7010
Description = 
 
Error - 09.04.2012 16:33:13 | Computer Name = Homeservice-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: ForceField.exe, Version: 1.5.350.0,
 Zeitstempel: 0x4eb2a525  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0,
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00000000  ID des fehlerhaften
 Prozesses: 0xa60  Startzeit der fehlerhaften Anwendung: 0x01cd168ff30b3106  Pfad der
 fehlerhaften Anwendung: C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
Pfad
 des fehlerhaften Moduls: unknown  Berichtskennung: 3a379b78-8283-11e1-a1de-00183704109d
 
Error - 10.04.2012 14:27:19 | Computer Name = Homeservice-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: NeroExpress.exe, Version: 10.0.7.100,
 Zeitstempel: 0x4b7d43b1  Name des fehlerhaften Moduls: NeroExpress.exe, Version: 
10.0.7.100, Zeitstempel: 0x4b7d43b1  Ausnahmecode: 0xc000001d  Fehleroffset: 0x025084f1
ID
 des fehlerhaften Prozesses: 0x1660  Startzeit der fehlerhaften Anwendung: 0x01cd174696f9da5e
Pfad
 der fehlerhaften Anwendung: D:\Programme\Nero10\Nero Express\NeroExpress.exe  Pfad
 des fehlerhaften Moduls: D:\Programme\Nero10\Nero Express\NeroExpress.exe  Berichtskennung:
 ce3d8910-833a-11e1-bcd0-00183704109d
 
Error - 10.04.2012 14:27:19 | Computer Name = Homeservice-PC | Source = Application Error | ID = 1005
Description = Aus einem der folgenden Gründe kann nicht auf die Datei "" zugegriffen
 werden:  Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger mit der
 gespeicherten Datei bzw. den auf dem Computer installierten  Speichertreibern, oder
 der Datenträger fehlt.  Das Programm Nero Express wurde wegen dieses Fehlers geschlossen.

Programm:
 Nero Express  Datei:     Der Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet.
Benutzeraktion
1.
 Öffnen Sie die Datei erneut.  Diese Situation ist eventuell ein temporäres Problem,
 das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird.  2.  Wenn
 Sie weiterhin nicht auf die Datei zugreifen können und   - diese sich im Netzwerk 
befindet,   dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem
 besteht und dass eine Verbindung mit dem Server hergestellt werden kann.   - diese
 sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet,
 überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist.  3. Überprüfen
 und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu
 im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben
 Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE.
4.
 Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin
 besteht.  5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet
 werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt.
   Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware, 
um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt.    Zusätzliche
 Daten  Fehlerwert: 00000000  Datenträgertyp: 0
 
Error - 10.04.2012 21:06:43 | Computer Name = Homeservice-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: firefox.exe, Version: 11.0.0.4454,
 Zeitstempel: 0x4f5ecc44  Name des fehlerhaften Moduls: NBShell.dll, Version: 5.4.14.101,
 Zeitstempel: 0x4b8265dd  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0005dc01  ID des fehlerhaften
 Prozesses: 0x17ec  Startzeit der fehlerhaften Anwendung: 0x01cd177bb98d5d6d  Pfad der
 fehlerhaften Anwendung: D:\Programme\firefox.exe  Pfad des fehlerhaften Moduls: D:\Programme\Nero10\Nero
 BackItUp\NBShell.dll  Berichtskennung: 99e71663-8372-11e1-be43-00183704109d
 
[ System Events ]
Error - 11.06.2012 18:29:23 | Computer Name = Homeservice-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   Lbd
 
Error - 11.06.2012 18:47:09 | Computer Name = Homeservice-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   Lbd
 
Error - 11.06.2012 18:49:10 | Computer Name = Homeservice-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden
 Fehlers nicht gestartet:   %%2
 
Error - 11.06.2012 19:55:06 | Computer Name = Homeservice-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   Lbd
 
Error - 11.06.2012 19:57:06 | Computer Name = Homeservice-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden
 Fehlers nicht gestartet:   %%2
 
Error - 11.06.2012 20:46:17 | Computer Name = Homeservice-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   Lbd
 
Error - 12.06.2012 00:34:27 | Computer Name = Homeservice-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   Lbd
 
Error - 12.06.2012 10:36:51 | Computer Name = Homeservice-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   Lbd
 
Error - 12.06.2012 13:41:37 | Computer Name = Homeservice-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   Lbd
 
Error - 12.06.2012 17:57:17 | Computer Name = Homeservice-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
   Lbd
 
 
< End of report >
         
--- --- ---


Den Google Updater und Lavasoft Ad-Aware hatte ich gelöscht und anschließend den CCleaner drüberlaufen lassen aber es scheinen irgendwie immer noch ein paar Sachen vorhanden zu sein.
Das wars, von meinen Maßnahmen. Der PC hat immer noch dieselben macken

Über Tipps wäre ich sehr dankbar

Alt 15.06.2012, 22:20   #2
kira
/// Helfer-Team
 
Probleme nach Ad-Aware 10 - Standard

Probleme nach Ad-Aware 10



Hallo und Herzlich Willkommen!

Bevor wir unsere Zusammenarbeit beginnen, [Bitte Vollständig lesen]:
Zitat:
  • "Fernbehandlungen/Fernhilfe" und die damit verbundenen Haftungsrisken:
    - da die Fehlerprüfung und Handlung werden über große Entfernungen durchgeführt, besteht keine Haftung unsererseits für die daraus entstehenden Folgen.
    - also, jede Haftung für die daraus entstandene Schäden wird ausgeschlossen, ANWEISUNGEN UND DEREN BEFOLGUNG, ERFOLGT AUF DEINE EIGENE VERANTWORTUNG!
  • Charakteristische Merkmale/Profilinformationen:
    - aus der verwendeten Loglisten oder Logdateien - wie z.B. deinen Realnamen, Seriennummer in Programm etc)- kannst Du durch [X] oder Sternchen (*) ersetzen
  • Die Systemprüfung und Bereinigung:
    - kann einige Zeit in Anspruch nehmen (je nach Art der Infektion), kann aber sogar so stark kompromittiert sein, so dass eine wirkungsvolle technische Säuberung ist nicht mehr möglich bzw Du es neu installieren musst
  • Ich empfehle Dir die Anweisungen erst einmal komplett durchzulesen, bevor du es anwendest, weil wenn du etwas falsch machst, kann es wirklich gefährlich werden. Wenn du meinen Anweisungen Schritt für Schritt folgst, kann eigentlich nichts schief gehen.
  • Innerhalb der Betreuungszeit:
    - ohne Abspräche bitte nicht auf eigene Faust handeln!- bei Problemen nachfragen.
  • Die Reihenfolge:
    - genau so wie beschrieben bitte einhalten, nicht selbst die Reihenfolge wählen!
  • GECRACKTE SOFTWARE werden hier nicht geduldet!!!!
  • Ansonsten unsere Forumsregeln:
    - Bitte erst lesen, dann posten!-> Für alle Hilfesuchenden! Was muss ich vor der Eröffnung eines Themas beachten?
  • Alle Logfile mit einem vBCode Tag eingefügen, das bietet hier eine gute Übersicht, erleichtert mir die Arbeit! Falls das Logfile zu groß, teile es in mehrere Teile auf.

Sobald Du diesen Einführungstext gelesen hast, kannst Du beginnen
Für Vista und Win7:
Wichtig: Alle Befehle bitte als Administrator ausführen! rechte Maustaste auf die Eingabeaufforderung und "als Administrator ausführen" auswählen
Auf der angewählten Anwendung einen Rechtsklick (rechte Maustaste) und "Als Administrator ausführen" wählen!

Mensch, was machst Du da? Wills Du dein System kaputt scannen?
Zitat:
Eine wahlose Installation diverser Sicherheits/Entfernungstools können ganz unterschiedliche unerwünschte Wirkungen auslösen! Besser ist es, bei vermuteten Malwarebefall gezielt vorgehen bzw auf den jeweiligen Virus zugeschnittene Anleitungen und Entfernprogramme verwenden
Das Installieren von `zuviel` Software beeinträchtigt die Systemleistung und Sicherheit, verlangsamt den Start-Vorgang enorm und belastet den Arbeitsspeicher (weil laufen ja die Programme nebeneinander gleichzeitig, die viel Performance fressen, aber wenig Qualität bringen). Im Laufe der Zeit wird der rechner durch zu viel unnötigen Ballast immer langsamer, und unsicherer. Um so mehr Programme installiert sind, um so häufiger treten Probleme auf, die dann unter Umständen nur schwer lösen können. Dazu kommt noch, das einige Programme große Sicherheitsrisiken mit sich bringen, denn jede Software hat Ihre Lücken
1.
SoftonicDownloader
Programme/Treiber ausschließlich vom Herstellerseite herunterladen!! Die Softonic-Seite bietet auch Software zum Download an, da aber auch das Problem, auch jede Menge Müll (Toolbars, der Standardsuchdienst und die Standard-Startseite im Browser verändert. usw) mit installiert.

2.
Deinstalliere:
Zitat:
Spyware Terminator
dieses Programm lässt sich durch Adware finanzieren!

3.
unser Sorgenkind: ZoneAlarm:
möchte dir 4 Gründe nennen, warum nicht zu empfehlen ist:
1., In der letzten Zeit bei viele PC`s akutes Problem verbreitet hat, wie z.B.:
"Tastatur reagiert langsam, System/Internet plötzlich langsam wird, Internet funktioniert nicht, Desktopsymbole verschwunden, Programme reagieren verzögert, Abstürze usw..."
2., Bis auf die Tatsache, dass der Hersteller seine Unkosten durch "Conduit Ltd" / Adware finanziert, daher für mich sieht das nicht seriös aus, gehört in die Mülltonne !!
solange ZA installiert, nach Entfernung installiert sich Conduit eh wieder...
3., Der Angreifer kann sich jeder Zeit erhöhte Rechte verschaffen, Firewall und Virenschutz manipulieren und abschalten kann!
4., wie du siehst, hat jetzt auch nicht viel geholfen bzw das vorzeitige Eindringen dieser Malware im System nicht zuverlässig verhindern können!

ich würde ihn deinstallieren/Entfernen und die Win Firewall einschalten. Wirst Du sehen, wie dein Rechner schneller hoch fährt
Deinstallationshilfe:
Forennachricht
ZoneAlarmPro 3 vollstndig deinstallieren

4.
deinstalliere/entferne:
Zitat:
eScan
Ich würde dem Programm nicht vertrauen, da meistens die angeblichen Funde nicht nachvollziehbar sind bzw oft Fehldiagnose ausgibt

5.
zur Info:
Code:
ATTFilter
"Ad-Aware Free": jetzt läuft mit Anti-Viren-Schutz!
         
kann es zu einem Systemabsturz kommen!
Nur eine Firewall sowie ein Antiviren Programm verwenden, welche sich immer auf dem aktuellsten Stand befinden sollten!

6.
Zitat:
Achtung wichtig!:
Falls Du selber im Logfile Änderungen vorgenommen hast, musst Du durch die Originalbezeichnung ersetzen und so in Script einfügen! sonst funktioniert nicht!
(Benutzerordner, dein Name oder sonstige Änderungen durch X, Stern oder andere Namen ersetzt)
Fixen mit OTL
  • Starte die OTL.exe.
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Kopiere folgendes Skript (also - nach dem "Code", alles was in der Codebox steht! - (also beginnend mit :OTL und am Ende [emptytemp] ohne "code"!) :
Code:
ATTFilter
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.arcor.de
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.arcor.de
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.arcor.de
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.arcor.de
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.arcor.de
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2645238
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.arcor.de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.arcor.de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.arcor.de
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2645238
O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:57B2B96C
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:70E897B5
@Alternate Data Stream - 189 bytes -> C:\ProgramData\TEMP:89CC3B44
@Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:F26F5952
@Alternate Data Stream - 179 bytes -> C:\ProgramData\TEMP:B2112128
@Alternate Data Stream - 176 bytes -> C:\ProgramData\TEMP:58E38390
@Alternate Data Stream - 171 bytes -> C:\ProgramData\TEMP:6EE8565A
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:E3615992
@Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:B4258C5D
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:1B389835
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:0785072C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:F5D01D7C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:65C4D44A
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:13019F4B
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:474022C7
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:2AF322BF
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:DBC3D477
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4EC7F009
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:587F3582
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:D026A5A4
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:870649A4
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:3D36932D

:Files
C:\ProgramData\Lavasoft
C:\ProgramData\Ad-Aware Browsing Protection
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
         
  • und füge es hier ein:
  • Schließe alle Programme.
  • Klicke auf den Fix Button.
  • Klick auf .
  • OTL verlangt einen Neustart. Bitte zulassen.
  • Nach dem Neustart findest Du ein Textdokument.
    Kopiere den Inhalt hier in Code-Tags in Deinen Thread.

7.
Um festzustellen, ob veraltete oder schädliche Software unter Programme installiert sind, ich würde gerne noch all deine installierten Programme sehen:
  • Download den CCleaner herunter
  • Software-Lizenzvereinbarung lesen, falls irgendeine Toolbar angeboten wird, bitte abwählen!-> starten -> Falls nötig, auf "Deutsch" einstellen.
  • starten-> klick auf `Extras` (um auf deinem System installierte Software zu anzeigen)-> dann auf `Als Textdatei speichern...`
  • ein Textdatei wird automatisch erstellt, poste auch dieses Logfile (also die Liste alle installierten Programme...eine Textdatei)

8.
erneut einen Scan mit OTL:
  • Doppelklick auf die OTL.exe
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Oben findest Du ein Kästchen mit Ausgabe.
    Wähle bitte Standard-Ausgabe
  • Unter Extra-Registrierung wähle bitte Benutze SafeList.
  • Mache Häckchen bei LOP- und Purity-Prüfung.
  • Klicke nun auf Scan links oben.
  • Wenn der Scan beendet wurde werden zwei Logfiles erstellt.
    Du findest die Logfiles auf Deinem Desktop => OTL.txt und Extras.txt
  • Poste die Logfiles in Code-Tags hier in den Thread.

damit ich weiß, welche Änderungen Du vorgenommen hast:
Zitat:
► Berichte mir kurz über alle Umsetzungsschritte (zu jedem Punkt), die Du erledigt hast!
Zitat:
Damit dein Thread übersichtlicher und schön lesbar bleibt, am besten nutze den Code-Tags für deinen Post:
→ vor dein Log schreibst Du (also am Anfang des Logfiles):[code]
hier kommt dein Logfile rein - z.B OTL-Logfile o. sonstiges
→ dahinter - also am Ende der Logdatei: [/code]
gruß
kira
__________________

__________________

Alt 16.06.2012, 23:58   #3
Ich bin ich
 
Probleme nach Ad-Aware 10 - Standard

Probleme nach Ad-Aware 10



Hallo!
Ich habe die Regeln, bevor ich es gepostet habe, tatsächlich gelesen und bin mir auch den Risiken bewusst und auch einverstanden damit.

Naja, ich dachte je mehr scanns desto besser, da jeder scanner irgendwas gefunden hatte. Da aber durch meinem letzten scann, mein Internet nicht mehr ging, habe ich aufgehört mit diversen Scannern zu scannen
1. Spyware Terminator ist deinstalliert.
2. eScan ist deinstalliert
3. Da ich den PC mit jemanden teile, muß ich erst um "erlaubnis" Fragen, ob ich ZA löschen kann.
4. OTL Fix
Code:
ATTFilter
All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\First Home Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\First Home Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{2318C2B1-4965-11d4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found.
ADS C:\ProgramData\TEMP:57B2B96C deleted successfully.
ADS C:\ProgramData\TEMP:70E897B5 deleted successfully.
ADS C:\ProgramData\TEMP:89CC3B44 deleted successfully.
ADS C:\ProgramData\TEMP:F26F5952 deleted successfully.
ADS C:\ProgramData\TEMP:B2112128 deleted successfully.
ADS C:\ProgramData\TEMP:58E38390 deleted successfully.
ADS C:\ProgramData\TEMP:6EE8565A deleted successfully.
ADS C:\ProgramData\TEMP:E3615992 deleted successfully.
ADS C:\ProgramData\TEMP:B4258C5D deleted successfully.
ADS C:\ProgramData\TEMP:1B389835 deleted successfully.
ADS C:\ProgramData\TEMP:0785072C deleted successfully.
ADS C:\ProgramData\TEMP:F5D01D7C deleted successfully.
ADS C:\ProgramData\TEMP:65C4D44A deleted successfully.
ADS C:\ProgramData\TEMP:13019F4B deleted successfully.
ADS C:\ProgramData\TEMP:474022C7 deleted successfully.
ADS C:\ProgramData\TEMP:2AF322BF deleted successfully.
ADS C:\ProgramData\TEMP:DBC3D477 deleted successfully.
ADS C:\ProgramData\TEMP:4EC7F009 deleted successfully.
ADS C:\ProgramData\TEMP:587F3582 deleted successfully.
ADS C:\ProgramData\TEMP:D026A5A4 deleted successfully.
ADS C:\ProgramData\TEMP:870649A4 deleted successfully.
ADS C:\ProgramData\TEMP:3D36932D deleted successfully.
========== FILES ==========
File\Folder C:\ProgramData\Lavasoft not found.
File\Folder C:\ProgramData\Ad-Aware Browsing Protection not found.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Homeservice\Desktop\cmd.bat deleted successfully.
C:\Users\Homeservice\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Homeservice
->Temp folder emptied: 554783199 bytes
->Temporary Internet Files folder emptied: 1051713 bytes
->Java cache emptied: 1701888 bytes
->FireFox cache emptied: 103945584 bytes
->Flash cache emptied: 523 bytes
 
User: Public
 
User: UpdatusUser
->Temp folder emptied: 871736 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 13217576 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2963440 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 647,00 mb
 
 
OTL by OldTimer - Version 3.2.48.0 log created on 06162012_010441

Files\Folders moved on Reboot...
C:\Users\Homeservice\AppData\Local\Temp\~DF47E73A806C3D3755.TMP moved successfully.
C:\Users\Homeservice\AppData\Local\Mozilla\Firefox\Profiles\vf9d9aga.default\startupCache\startupCache.4.little moved successfully.
C:\Users\Homeservice\AppData\Local\Mozilla\Firefox\Profiles\vf9d9aga.default\Cache\_CACHE_001_ moved successfully.
C:\Users\Homeservice\AppData\Local\Mozilla\Firefox\Profiles\vf9d9aga.default\Cache\_CACHE_002_ moved successfully.
C:\Users\Homeservice\AppData\Local\Mozilla\Firefox\Profiles\vf9d9aga.default\Cache\_CACHE_003_ moved successfully.
C:\Users\Homeservice\AppData\Local\Mozilla\Firefox\Profiles\vf9d9aga.default\Cache\_CACHE_MAP_ moved successfully.
C:\Users\Homeservice\AppData\Local\Mozilla\Firefox\Profiles\vf9d9aga.default\urlclassifier3.sqlite moved successfully.
C:\Windows\temp\ZLT01c81.TMP moved successfully.

Registry entries deleted on Reboot...
         
5. Installierte Programme
Code:
ATTFilter
7-Zip 9.20		01.11.2011		
Adobe Flash Player 11 ActiveX	Adobe Systems Incorporated	07.05.2012	6,00MB	11.2.202.235
Adobe Flash Player 11 Plugin	Adobe Systems Incorporated	11.06.2012	6,00MB	11.3.300.257
Adobe Reader X (10.1.3) - Deutsch	Adobe Systems Incorporated	11.04.2012	121,5MB	10.1.3
Adobe Shockwave Player 11.6	Adobe Systems, Inc.	03.03.2012		11.6.4.634
Apple Application Support	Apple Inc.	04.01.2012	61,2MB	2.1.5
Apple Software Update	Apple Inc.	04.01.2012	2,38MB	2.1.3.127
Avira Free Antivirus	Avira	08.05.2012	108,4MB	12.0.0.1125
Bamboo	Wacom Technology Corp.	23.12.2011		
Big Fish Games: Game Manager		06.11.2011		3.0.1.60		
Canon iP2600 series		29.10.2011		
Canon My Printer		29.10.2011		
CCleaner	Piriform	24.02.2012		3.16
Debugging Tools for Windows	Microsoft Corporation	21.03.2012	24,6MB	6.4.7.2
Debugging Tools for Windows (x86)	Microsoft Corporation	20.03.2012	38,3MB	6.10.3.233
Deponia	Daedalic Entertainment	19.05.2012		1.0
DriverAgent by eSupport.com		05.11.2011		
DVD Shrink 3.2 deutsch	DVD Shrink	01.11.2011		
DVD Suite	CyberLink Corporation	01.11.2011		5.0.1319
EVEREST Home Edition v2.20	Lavalys Inc	03.04.2012		2.20
Free 3GP Video Converter version 5.0.4.1228	DVDVideoSoft Ltd.	16.02.2012	56,9MB	
Free Audio CD to MP3 Converter version 1.3.12.1228	DVDVideoSoft Ltd.	07.04.2012	63,0MB	1.3.12.1228
Free Audio Converter version 5.0.7.403	DVDVideoSoft Ltd.	07.04.2012	69,6MB	5.0.7.403
Free Video to MP3 Converter version 5.0.4.1228	DVDVideoSoft Ltd.	08.02.2012	57,2MB	
Free YouTube to MP3 Converter version 3.11.20.423	DVDVideoSoft Ltd.	02.05.2012	83,6MB	3.11.20.423
IcoFX 2.0		05.11.2011	10,8MB	
IsoBuster 2.5	Smart Projects	06.04.2012		2.5
Java(TM) 6 Update 21	Oracle	01.11.2011	94,9MB	6.0.210
Java(TM) 6 Update 29	Oracle	17.01.2012	95,0MB	6.0.290
Java(TM) 6 Update 31	Oracle	21.04.2012	95,1MB	6.0.310
Java(TM) 7 Update 1		28.10.2011		
JDownloader 0.9	AppWork GmbH	18.01.2012		0.9
Logitech SetPoint 6.0	Logitech	04.12.2011	39,1MB	6.00.68
Lotus Word Pro 97		01.11.2011		
Mahjongg Master 4		01.11.2011		
Malwarebytes Anti-Malware Version 1.61.0.1400	Malwarebytes Corporation	08.05.2012	18,0MB	1.61.0.1400
Medieval CUE Splitter	Medieval Software	07.04.2012	1,66MB	1.2.0
Microsoft Office Professional Plus 2010	Microsoft Corporation	18.11.2011		14.0.6029.1000
Microsoft PowerPoint Viewer	Microsoft Corporation	16.02.2012	186,8MB	14.0.6029.1000
Microsoft Primary Interoperability Assemblies 2005	Microsoft Corporation	28.10.2011	7,72MB	8.0.50727.42
Microsoft Silverlight	Microsoft Corporation	08.05.2012	64,8MB	5.1.10411.0
Microsoft Visual C++ 2005 Redistributable	Microsoft Corporation	01.11.2011	0,29MB	8.0.59193
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17	Microsoft Corporation	28.10.2011	0,58MB	9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148	Microsoft Corporation	28.10.2011	0,58MB	9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161	Microsoft Corporation	01.11.2011	0,59MB	9.0.30729.6161
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219	Microsoft Corporation	08.02.2012	16,5MB	10.0.40219
Microsoft Windows Debugging Symbols	Microsoft	21.03.2012	3.342MB	7601
Mobile Modem Assistant		14.04.2012		1.00.000
Mortimer Beckett and the Secrets of Spooky Manor	MumboJumbo	23.11.2011		1.1.0.0
Mozilla Firefox 13.0 (x86 de)	Mozilla	05.06.2012	4.405MB	13.0
Mozilla Firefox 8.0 (x86 de)	Mozilla	11.11.2011	3.443MB	8.0
MSXML 4.0 SP2 (KB954430)	Microsoft Corporation	29.10.2011	37,00KB	4.20.9870.0
MSXML 4.0 SP2 (KB973688)	Microsoft Corporation	29.10.2011	1,33MB	4.20.9876.0
Nero 10 ClipartPack	Nero AG	01.11.2011	26,3MB	10.0.10300.0.0
Nero 10 Menu TemplatePack 1	Nero AG	01.11.2011	59,5MB	10.0.10300.0.0
Nero 10 Menu TemplatePack 2	Nero AG	01.11.2011	182,8MB	10.0.10300.0.0
Nero 10 Menu TemplatePack 3	Nero AG	01.11.2011	241MB	10.0.10300.0.0
Nero 10 Movie ThemePack 1	Nero AG	01.11.2011	51,0MB	10.0.10300.1.0
Nero 10 Movie ThemePack 2	Nero AG	01.11.2011	315MB	10.0.10300.1.0
Nero 10 Sample ImagePack	Nero AG	01.11.2011	5,58MB	10.0.10300.0.0
Nero 10 Sample Videos	Nero AG	01.11.2011	41,7MB	10.0.10300.2.0
Nero BackItUp 10	Nero AG	01.11.2011	107,6MB	5.4.11100.14.101
Nero Burning ROM 10	Nero AG	01.11.2011	158,2MB	10.0.10700.7.100
Nero BurnRights 10	Nero AG	01.11.2011	6,31MB	4.0.10600.9.100
Nero CoverDesigner 10	Nero AG	01.11.2011	76,9MB	5.0.10500.7.100
Nero DiscCopy Gadget 10	Nero AG	01.11.2011	35,4MB	3.0.10400.6.100
Nero DiscSpeed 10	Nero AG	01.11.2011	7,37MB	6.0.10400.4.100
Nero Express 10	Nero AG	01.11.2011	159,0MB	10.0.10500.7.100
Nero InfoTool 10	Nero AG	01.11.2011	7,97MB	7.0.10400.5.100
Nero MediaHub 10	Nero AG	01.11.2011	158,3MB	1.0.11000.6.100
Nero Multimedia Suite 10	Nero AG	01.11.2011	2.285MB	10.0.11200
Nero Recode 10	Nero AG	01.11.2011	80,2MB	4.6.10600.1.100
Nero RescueAgent 10	Nero AG	01.11.2011	6,75MB	3.0.10500.5.100
Nero SoundTrax 10	Nero AG	01.11.2011	95,6MB	4.6.10500.1.100
Nero StartSmart 10	Nero AG	01.11.2011	108,6MB	10.0.10500.4.100
Nero Update	Nero AG	01.11.2011	1,39MB	1.0.0012
Nero Vision 10	Nero AG	01.11.2011	215MB	7.0.10700.4.100
Nero WaveEditor 10	Nero AG	01.11.2011	76,7MB	5.6.10500.1.100
NVIDIA 3D Vision Controller-Treiber 301.42	NVIDIA Corporation	10.06.2012		301.42
NVIDIA 3D Vision Treiber 301.42	NVIDIA Corporation	10.06.2012		301.42
NVIDIA Grafiktreiber 301.42	NVIDIA Corporation	10.06.2012		301.42
NVIDIA PhysX-Systemsoftware 9.12.0213	NVIDIA Corporation	02.04.2012		9.12.0213
NVIDIA Update 1.8.15	NVIDIA Corporation	10.06.2012		1.8.15
PIXMA Extended Survey Program		01.11.2011		
PowerDVD	CyberLink Corporation	01.11.2011		7.0.2414.0
QBeez 2		03.12.2011		
QuickTime	Apple Inc.	17.01.2012	73,3MB	7.71.80.42
Sandlot Games Client Services 1.2.2	Sandlot Games	12.02.2012		
SeaTools for Windows	Seagate Technology	02.04.2012	26,9MB	1.2.0.6
Siemens DCA-140/540 USB Treiber 1.0.7	Shaw Computerhard- & Software	14.04.2012		1.0.7
SIEMENS USB Data Cable		14.04.2012		
The Tiny Bang Story Version 1.0	My Company, Inc.	22.12.2011	174,8MB	1.0
TuneUp Utilities 2012	TuneUp Software	01.06.2012		12.0.3600.73
Unlocker 1.9.1	Cedrick Collomb	26.01.2012		1.9.1
USB/DVD-Downloadtool für Windows 7	Microsoft Corporation	02.11.2011	2,97MB	1.0.30
Venice Deluxe		28.12.2011		
Winamp	Nullsoft, Inc	23.11.2011		5.622 
Winamp Erkennungs-Plug-in	Nullsoft, Inc	23.11.2011	75,00KB	1.0.0.1
Windows Installer Clean Up	Microsoft Corporation	01.11.2011	0,11MB	2.05.00.0000
WinRAR		28.10.2011		
ZoneAlarm Free Antivirus + Firewall	Check Point	02.06.2012	302MB	10.2.047.000
Zuma Deluxe		12.03.2012
         
5. Ich habe versucht, den benutzerdefinierten scan mit OTL zu machen aber jedesmal kommt die Meldung "Out of Memory".
Soll ich dann, anstatt die Standard, den Minimal-Ausgabe machen?
MfG

Edit: Ich habe mal die Minimal-Ausgabe versucht, doch leider kommt bei der dieselbe Meldung.
__________________

Geändert von Ich bin ich (17.06.2012 um 00:41 Uhr)

Alt 17.06.2012, 05:44   #4
kira
/// Helfer-Team
 
Probleme nach Ad-Aware 10 - Standard

Probleme nach Ad-Aware 10



Zitat:
Zitat von Ich bin ich Beitrag anzeigen
3. Da ich den PC mit jemanden teile, muß ich erst um "erlaubnis" Fragen, ob
1. ZoneAlarm verwendet Adware . wenn dein Freund ihn behalten will, eine Systembereinung erübrigt sich!

2.
Zitat:
ZoneAlarm Free Antivirus + Firewall
deinen Rechner mit zwei Anti-Viren-Programmen generell `geschwächt`:
Code:
ATTFilter
Avira und ZoneAlarm
         
Wichtig:
Nur eine Firewall sowie ein Antiviren Programm verwenden, welche sich immer auf dem aktuellsten Stand befinden sollten!
Mehr AV Programme bedeutet nicht mehr Sicherheit!Die Scanner behindern sich gegenseitig (bei beiden den On-Access Scan aktiviert bzw laufen ständig im Hintergrund) und ein Systemcrash kann die Folge sein oder im schlechtesten fall, kannst Du über eine komplette Neuinstallation freuen! Deinstalliere also eines der AV-Programme und lass nur noch eins auf deinem PC laufen.
Zitat:
►Bevor du ein anderes Antivirenprogramm installierst solltest du auf jeden Fall das vorherige vollständig deinstallieren!
Je nachdem, wie Du Dich entscheidest:

Removal Tools oder Deinstallationsanleitungen für diverse Antiviren Software :

für ZA:
Deinstallationshilfe:
Forennachricht
ZoneAlarmPro 3 vollstndig deinstallieren

-> Removal Tools oder Deinstallationsanleitungen für diverse Antiviren Software
AV Deinstallations Hinweise
also Entscheide Dich für NUR einen Virenscanner und benutze diesen regelmäßig!
__________________

Warnung!:
Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein!
Anhang nicht öffnen, in unserem Forum erst nachfragen!

Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten!
Bitte diese Warnung weitergeben, wo Du nur kannst!

Alt 18.06.2012, 22:33   #5
Ich bin ich
 
Probleme nach Ad-Aware 10 - Standard

Probleme nach Ad-Aware 10



Hallo.

Also ich nutze schon seit Jahren Avira-Antivir und Zonealarm gemeinsam, zwar liest man hin und wieder mal, das sich die 2 Programme gegenseitig behindern, wie z.B.: Update funktioniert nicht, Systemscann wird nicht ausgeführt usw. Doch Probleme in dieser Art, hatte ich selbst noch nicht, abgesehen von paar adwares.
Dennoch hört man mehr schlechtes über die Windows Firewall, da diese wohl nur den "Grundschutz" bietet.


Alt 09.07.2012, 07:21   #6
kira
/// Helfer-Team
 
Probleme nach Ad-Aware 10 - Standard

Probleme nach Ad-Aware 10



wie sieht mit dir aus? Avira oder ZA?
__________________
--> Probleme nach Ad-Aware 10

Antwort

Themen zu Probleme nach Ad-Aware 10
7-zip, ad-aware, alternate, antivir, autokms, bho, black, build 7601, canon, converter, dateisystem, desktop, document, entfernen, error, festplatte, flash player, helper, heuristiks/extra, heuristiks/shuriken, hängen, install.exe, jdownloader, kaspersky, launch, locker, log file, logfile, malware, microsoft office word, mmc.exe, mp3, nicht möglich, nodrives, nt.dll, nvidia update, plug-in, regback, searchscopes, secrets, security, sekunden, senden, software, spyware, starten, svchost.exe, taskhost.exe, tr/crypt.xpack.ge, tr/crypt.xpack.gen, trojan.generic., vcredist, version=1.0, verweise, windows, windows-tool



Ähnliche Themen: Probleme nach Ad-Aware 10


  1. Probleme mit searchgol nach deltatoolbar nach installation von imgburn (Win8-x64-chrome)
    Log-Analyse und Auswertung - 31.10.2013 (29)
  2. nach trojaner nur probleme
    Log-Analyse und Auswertung - 12.06.2012 (3)
  3. Probleme nach BKA bzw GVU Bereinigung
    Log-Analyse und Auswertung - 30.03.2012 (9)
  4. Computer verhält sich weiterhin komisch,nach bereinigung mit Ad-Aware.
    Plagegeister aller Art und deren Bekämpfung - 10.03.2011 (16)
  5. Probleme nach dem Hochfahren
    Plagegeister aller Art und deren Bekämpfung - 14.07.2010 (1)
  6. Probleme nach Trojanerbefall
    Mülltonne - 21.12.2008 (0)
  7. Nach Virus PC Probleme
    Plagegeister aller Art und deren Bekämpfung - 16.06.2008 (32)
  8. Nach NT-wechsel Probleme
    Netzwerk und Hardware - 25.06.2007 (11)
  9. Ad-Aware
    Antiviren-, Firewall- und andere Schutzprogramme - 06.04.2006 (10)
  10. Probleme bei XP nach Neuinstallation
    Plagegeister aller Art und deren Bekämpfung - 16.02.2006 (7)
  11. Ad-Aware
    Antiviren-, Firewall- und andere Schutzprogramme - 17.02.2005 (4)
  12. Ad-Aware SE
    Plagegeister aller Art und deren Bekämpfung - 27.08.2004 (4)
  13. Ad Aware 6.181
    Plagegeister aller Art und deren Bekämpfung - 22.06.2004 (2)
  14. Ad-Aware
    Antiviren-, Firewall- und andere Schutzprogramme - 22.01.2004 (3)
  15. AD Aware
    Antiviren-, Firewall- und andere Schutzprogramme - 15.07.2003 (7)
  16. neu: ad-aware
    Antiviren-, Firewall- und andere Schutzprogramme - 23.02.2003 (53)

Zum Thema Probleme nach Ad-Aware 10 - Hallo zusammen! (Sollte das das falsche Forum sein, tut es mir Leid. Fast jedes passte irgendwie) Bei meinem PC sind fehler aufgetreten, als ich erfolglos versucht habe Ad-Aware 10 zu - Probleme nach Ad-Aware 10...
Archiv
Du betrachtest: Probleme nach Ad-Aware 10 auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.