Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: GVU-Trojaner entfernen für Anfänger

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 05.09.2012, 08:34   #1
KristyMaz
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



Hallo liebes Forum,

ich habe seit gestern auch diesen GVU-Trojaner bei mir auf XP drauf. Mein Internet muss ich ausgeschaltet lassen, weil ansonsten wieder diese Seite erscheint.
Hier im Forum und im Internet gibt es viele Lösungsansätze, aber ich blicke bei den meisten nicht durch. Bin halt doch ein recht einfacher Nutzer. Da gibt es Lösungsansätze mit Otl oder Kaspersky.
Ich habe mir jetzt dieses OTL auf einem USB-Stick gespeichert (am PC auf Arbeit). Wie fahre ich heute abend mit meinem Problem-Laptop fort?
Brauche ich noch weitere Sachen auf dem USB-Stick?
Wenn ihr mir helfen könntet, wäre das echt klasse. Bin schon etwas verzweifelt.

Alt 05.09.2012, 14:08   #2
markusg
/// Malware-holic
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



hi starte neu, drücke f8 wähle abgesicherter modus mit netzwerk, melde dich im betroffenen konto an.
Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die
    OTL.exe
    .
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Kopiere nun den Inhalt in die
    Textbox.
Code:
ATTFilter
activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
C:\Windows\system32\*.tsp
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT
         
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread
__________________

__________________

Alt 05.09.2012, 20:40   #3
KristyMaz
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



Hallo,

vielen Dank für deine Hilfe. Hier die Texte. Mein Laptop ist ein spanischer, ich hoffe, du verstehst es trotzdem.



OTL.Txt
OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 05.09.2012 20:57:14 - Run 1
OTL by OldTimer - Version 3.2.61.0     Folder = C:\Documents and Settings\Herbert\Escritorio
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Alemania | Language: DEU | Date Format: dd.MM.yyyy
 
1014,05 Mb Total Physical Memory | 440,73 Mb Available Physical Memory | 43,46% Memory free
2,38 Gb Paging File | 1,59 Gb Available in Paging File | 66,76% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa
Drive C: | 35,06 Gb Total Space | 2,10 Gb Free Space | 5,98% Space Free | Partition Type: FAT32
Drive D: | 35,55 Gb Total Space | 7,79 Gb Free Space | 21,91% Space Free | Partition Type: FAT32
 
Computer Name: CHRISTIANE | User Name: Herbert | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.09.05 09:06:14 | 000,599,040 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Herbert\Escritorio\OTL.exe
PRC - [2012.08.29 17:49:56 | 001,193,176 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Spotify\Data\SpotifyWebHelper.exe
PRC - [2012.07.18 18:04:44 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Archivos de programa\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.07.18 18:04:34 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Archivos de programa\Avira\AntiVir Desktop\sched.exe
PRC - [2012.07.18 18:04:24 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Archivos de programa\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.07.18 18:04:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Archivos de programa\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.06.21 15:58:50 | 002,445,880 | ---- | M] (Check Point Software Technologies LTD) -- C:\Archivos de programa\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2012.06.21 15:29:14 | 000,073,392 | ---- | M] (Check Point Software Technologies LTD) -- C:\Archivos de programa\CheckPoint\ZoneAlarm\zatray.exe
PRC - [2012.04.30 21:05:22 | 000,497,280 | ---- | M] (Check Point Software Technologies) -- C:\Archivos de programa\CheckPoint\ZAForceField\ISWSVC.exe
PRC - [2012.04.30 21:04:28 | 000,738,944 | ---- | M] (Check Point Software Technologies) -- C:\Archivos de programa\CheckPoint\ZAForceField\ForceField.exe
PRC - [2011.07.29 00:08:12 | 001,259,376 | ---- | M] () -- C:\Archivos de programa\DivX\DivX Update\DivXUpdate.exe
PRC - [2011.04.18 19:09:40 | 000,789,392 | ---- | M] (Lavasoft) -- C:\Archivos de programa\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011.04.18 19:09:38 | 001,181,328 | ---- | M] (Lavasoft) -- C:\Archivos de programa\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009.11.13 06:33:56 | 000,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Archivos de programa\DNA\btdna.exe
PRC - [2009.03.08 04:31:54 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msfeedssync.exe
PRC - [2008.12.31 17:04:54 | 000,944,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\WGATray.exe
PRC - [2008.07.11 17:51:32 | 000,423,200 | ---- | M] (Sony Corporation) -- C:\Archivos de programa\Sony\Content Transfer\ContentTransferWMDetector.exe
PRC - [2008.04.13 21:18:58 | 001,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.05.17 23:45:34 | 000,271,720 | ---- | M] (Microsoft Corporation) -- C:\Archivos de programa\Microsoft LifeCam\MSCamS32.exe
PRC - [2007.04.10 23:46:52 | 000,709,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\vVX1000.exe
PRC - [2005.12.01 17:38:38 | 000,458,752 | ---- | M] (Dritek System Inc.) -- C:\Archivos de programa\Launch Manager\QtZgAcer.EXE
PRC - [2005.11.25 15:59:44 | 000,212,992 | ---- | M] (Acer Inc) -- C:\Acer\Empowering Technology\ePower\epm-dm.exe
PRC - [2005.11.16 17:00:50 | 000,397,312 | ---- | M] (acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\Monitor.exe
PRC - [2005.10.24 16:45:32 | 002,462,208 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admtray.exe
PRC - [2005.10.24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admServ.exe
PRC - [2005.10.19 09:30:16 | 000,069,632 | ---- | M] (HiTRUST) -- C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
PRC - [2005.08.31 19:59:48 | 000,114,784 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
PRC - [2005.08.31 19:59:46 | 000,249,954 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
PRC - [2005.08.31 19:59:34 | 000,147,456 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Acer\Acer Arcade\PCMService.exe
PRC - [2005.08.31 19:59:22 | 001,077,376 | ---- | M] (Cyberlink) -- C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
PRC - [2005.08.31 19:59:22 | 000,061,440 | ---- | M] (Cyberlink) -- C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
PRC - [2005.01.07 16:17:16 | 000,102,491 | ---- | M] (Synaptics, Inc.) -- C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.08.29 17:49:56 | 001,193,176 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Spotify\Data\SpotifyWebHelper.exe
MOD - [2012.07.18 18:04:36 | 000,398,288 | ---- | M] () -- C:\Archivos de programa\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2011.07.29 00:09:42 | 000,096,112 | ---- | M] () -- C:\Archivos de programa\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.07.29 00:08:12 | 001,259,376 | ---- | M] () -- C:\Archivos de programa\DivX\DivX Update\DivXUpdate.exe
MOD - [2011.04.18 19:09:44 | 000,327,000 | ---- | M] () -- C:\Archivos de programa\Lavasoft\Ad-Aware\RPAPI.dll
MOD - [2008.04.13 21:18:26 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2005.11.09 22:22:14 | 000,876,544 | ---- | M] () -- C:\Archivos de programa\Intel\Wireless\Bin\Libeay32.dll
MOD - [2005.11.09 22:22:14 | 000,208,965 | ---- | M] () -- C:\Archivos de programa\Intel\Wireless\Bin\iWMSProv.dll
MOD - [2005.11.09 22:22:14 | 000,053,322 | ---- | M] () -- C:\Archivos de programa\Intel\Wireless\Bin\IntStngs.dll
MOD - [2005.09.05 16:31:56 | 000,229,472 | ---- | M] () -- C:\Acer\Empowering Technology\NetMonitor.dll
MOD - [2005.08.31 19:59:48 | 000,114,784 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
MOD - [2005.08.31 19:59:46 | 000,249,954 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
MOD - [2005.08.31 19:59:42 | 000,184,424 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapEngine.dll
MOD - [2005.08.31 19:59:42 | 000,061,538 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSchMgr.dll
MOD - [2005.08.31 19:59:42 | 000,028,672 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvcps.dll
MOD - [2005.08.31 19:59:42 | 000,024,576 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSchedps.dll
MOD - [2005.08.24 01:24:00 | 000,010,752 | ---- | M] () -- C:\WINDOWS\system32\MSNChatHook.dll
MOD - [2005.07.06 13:50:14 | 000,057,344 | ---- | M] () -- C:\Archivos de programa\Launch Manager\HokHIDKC.dll
MOD - [2005.06.28 13:59:48 | 000,053,248 | ---- | M] () -- C:\Archivos de programa\ArcSoft\PhotoImpression 5\Share\PIHook.dll
MOD - [2003.12.29 20:45:08 | 000,040,960 | ---- | M] () -- C:\Acer\Empowering Technology\ServiceControl.dll
MOD - [2001.10.28 17:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll
 
 
========== Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] -- C:\Archivos de programa\Google\Update\GoogleUpdate.exe /medsvc -- (gupdatem)
SRV - File not found [Auto | Stopped] -- C:\Archivos de programa\Google\Update\GoogleUpdate.exe /svc -- (gupdate1c9f1eed03b8c66)
SRV - File not found [On_Demand | Stopped] -- C:\Archivos de programa\NOS\bin\getPlus_Helper.dll -- (getPlusHelper)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012.08.03 17:34:06 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Archivos de programa\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.18 18:04:34 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Archivos de programa\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.07.18 18:04:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Archivos de programa\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.06.21 15:58:50 | 002,445,880 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Archivos de programa\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon)
SRV - [2012.06.07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Archivos de programa\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.04.30 21:05:22 | 000,497,280 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Archivos de programa\CheckPoint\ZAForceField\ISWSVC.exe -- (IswSvc)
SRV - [2011.07.20 05:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2011.04.18 19:09:38 | 001,181,328 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Archivos de programa\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2007.05.17 23:45:34 | 000,271,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Archivos de programa\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2005.10.24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) [Auto | Running] -- C:\Acer\Empowering Technology\admServ.exe -- (AWService)
SRV - [2005.08.31 19:59:48 | 000,114,784 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe -- (CLSched)
SRV - [2005.08.31 19:59:46 | 000,249,954 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe -- (CLCapSvc)
SRV - [2005.08.31 19:59:22 | 000,061,440 | ---- | M] (Cyberlink) [Auto | Running] -- C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe -- (CyberLink Media Library Service)
SRV - [2005.08.03 05:18:50 | 000,086,016 | ---- | M] (CACE Technologies) [On_Demand | Unknown] -- C:\Archivos de programa\WinPCap\rpcapd.exe -- (rpcapd)
SRV - [2005.04.04 00:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\ZTEWMSD_637.sys -- (ZTEWMSD_637)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnmeaext.sys -- (ZTEusbnmeaext)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnet.sys -- (ZTEusbnet)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnmeaext2.sys -- (ZTEusbMB)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | Auto | Stopped] -- SYSTEM32\drivers\DS1410D.SYS -- (DS1410D)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ar5211.sys -- (AR5211)
DRV - [2012.07.18 18:04:44 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.07.18 18:04:44 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.07.18 18:04:44 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012.06.21 15:29:14 | 000,526,640 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (Vsdatant)
DRV - [2012.04.30 21:05:40 | 000,027,016 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Archivos de programa\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
DRV - [2011.05.25 01:40:10 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2010.06.17 15:14:28 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.09.23 13:55:24 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\Lbd.sys -- (Lbd)
DRV - [2007.04.10 23:46:54 | 001,966,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VX1000.sys -- (VX1000)
DRV - [2006.08.16 14:43:22 | 000,553,984 | ---- | M] (Marvell Semiconductor, Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETMW145.sys -- (NETMW145)
DRV - [2005.12.11 07:40:44 | 001,414,656 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005.11.17 00:45:40 | 004,069,888 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService)
DRV - [2005.11.09 14:45:56 | 000,013,440 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2005.10.23 19:20:52 | 000,218,496 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005.10.18 01:53:24 | 000,998,656 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005.10.18 01:52:30 | 000,721,280 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005.10.15 18:20:44 | 000,012,106 | ---- | M] (OSA Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\OsaFsLoc.sys -- (OsaFsLoc)
DRV - [2005.09.29 20:11:42 | 000,078,720 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2005.09.13 15:34:40 | 000,004,392 | ---- | M] (OSA Technologies) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NdisFilt.sys -- (NdisFilt)
DRV - [2005.09.11 19:49:44 | 003,298,432 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51)
DRV - [2005.08.03 05:10:14 | 000,032,512 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2005.06.30 16:58:24 | 000,007,296 | ---- | M] (OSA Technologies, An Avocent Company) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osaio.sys -- (osaio)
DRV - [2005.05.02 12:13:42 | 000,009,600 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETMNT.sys -- (NETMNT)
DRV - [2005.04.07 18:08:46 | 000,078,208 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-shd.sys -- (EpmShd)
DRV - [2005.02.23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2005.01.14 15:57:16 | 000,004,010 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osanbm.sys -- (osanbm)
DRV - [2005.01.13 14:46:16 | 000,069,632 | ---- | M] () [Kernel | Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15.sys)
DRV - [2004.07.19 13:10:00 | 000,004,096 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-psd.sys -- (EpmPsd)
DRV - [2002.10.01 14:43:32 | 000,119,798 | ---- | M] (SP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\spca561.sys -- (CA561)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {E58DC330-EA6D-453F-A1B3-F5C1AE1B8E42}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2765711
IE - HKCU\..\SearchScopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}: "URL" = hxxp://search.hotspotshield.com/g/results.php?c=s&q={searchTerms}
IE - HKCU\..\SearchScopes\{E58DC330-EA6D-453F-A1B3-F5C1AE1B8E42}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&rlz=
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Hotspot Shield Private Search"
FF - prefs.js..browser.search.defaultthis.engineName: "AF-HSS Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2765711&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledAddons: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.145
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.60
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.8.6
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2438727&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Archivos de programa\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Archivos de programa\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Archivos de programa\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Archivos de programa\DivX\DivX Content Uploader\npUpload.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: D:\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Archivos de programa\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Archivos de programa\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Archivos de programa\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Archivos de programa\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Herbert\Datos de programa\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Archivos de programa\Google\Update\1.3.21.79\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Archivos de programa\Google\Update\1.3.21.79\npGoogleUpdate3.dll File not found
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Herbert\Datos de programa\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Archivos de programa\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.04.11 19:49:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Archivos de programa\CheckPoint\ZAForceField\TrustChecker [2011.11.17 20:24:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Archivos de programa\Mozilla Firefox\components [2007.06.17 22:45:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Archivos de programa\Mozilla Firefox\plugins [2006.09.11 23:49:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Archivos de programa\Mozilla Thunderbird\components [2009.06.28 21:39:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Archivos de programa\Mozilla Thunderbird\plugins [2012.01.28 15:31:08 | 000,000,000 | ---D | M]
 
[2008.12.05 07:55:56 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Extensions
[2010.05.30 21:04:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009.08.24 19:03:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2009.06.18 18:21:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Extensions\mozswing@mozswing.org
[2006.09.11 23:49:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\extensions
[2011.05.25 01:41:04 | 000,000,915 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\conduit.xml
[2012.01.16 18:14:02 | 000,002,135 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\s-amazon-de.xml
[2012.04.25 17:48:22 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\icqplugin-2.xml
[2012.06.30 10:25:08 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\icqplugin-3.xml
[2012.08.01 20:34:58 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\icqplugin-1.xml
[2012.09.04 17:59:58 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\icqplugin.xml
[2007.06.17 22:45:28 | 000,000,000 | ---D | M] (No name found) -- C:\Archivos de programa\Mozilla Firefox\extensions
[2012.04.11 19:49:42 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\ARCHIVOS DE PROGRAMA\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2008.11.30 15:53:14 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\ARCHIVOS DE PROGRAMA\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009.08.21 07:16:22 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012.08.03 17:34:06 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Archivos de programa\mozilla firefox\components\browsercomps.dll
[2010.01.13 23:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npwachk.dll
[2011.04.14 05:08:00 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npdeployJava1.dll
[2012.07.01 18:06:02 | 000,001,105 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\yahoo-de.xml
[2012.07.01 18:06:02 | 000,001,178 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.01 18:06:02 | 000,006,805 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.01 18:06:08 | 000,001,153 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.01 18:06:08 | 000,002,252 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\bing.xml
[2012.07.01 18:06:08 | 000,001,392 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\amazondotcom-de.xml
 
========== Chrome  ==========
 
CHR - homepage: hxxp://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Herbert\Configuraci\u00F3n local\Datos de programa\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Herbert\Configuraci\u00F3n local\Datos de programa\Google\Chrome\Application\21.0.1180.83\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Herbert\Configuraci\u00F3n local\Datos de programa\Google\Chrome\Application\21.0.1180.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Archivos de programa\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java(TM) Platform SE 6 U25 (Enabled) = C:\Archivos de programa\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.250.6 (Enabled) = C:\Archivos de programa\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Archivos de programa\Microsoft\Office Live\npOLW.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: getPlusPlus for Adobe 16263 (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: king.com - Game controller for firefox (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\npmidas.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Archivos de programa\Windows Media Player\npwmsdrm.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Archivos de programa\Windows Media Player\npdrmv2.dll
CHR - plugin: npFFApi (Enabled) = C:\Archivos de programa\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
CHR - plugin: DNA Plug-in (Enabled) = C:\Archivos de programa\DNA\plugins\npbtdna.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Archivos de programa\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Archivos de programa\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Archivos de programa\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Herbert\Configuraci\u00F3n local\Datos de programa\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Move Media Player 7 (Enabled) = C:\Documents and Settings\Herbert\Datos de programa\Move Networks\plugins\071803000001\npqmp071803000001.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Google Mail = C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2004.08.20 05:00:00 | 000,000,792 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Archivos de programa\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Archivos de programa\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\system32\ToolBand.dll (HiTRUST)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Archivos de programa\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\system32\ToolBand.dll (HiTRUST)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Archivos de programa\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe (Acer Value Labs, Taiwan)
O4 - HKLM..\Run: [ADMTray.exe] C:\Acer\Empowering Technology\admtray.exe (Avocent Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Archivos de programa\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Archivos de programa\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Archivos de programa\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe (HiTRUST)
O4 - HKLM..\Run: [EPM-DM] c:\Acer\Empowering Technology\ePower\epm-dm.exe (Acer Inc)
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe (acer Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe File not found
O4 - HKLM..\Run: [ISW] C:\Archivos de programa\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [LifeCam] C:\Archivos de programa\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LManager] C:\Archivos de programa\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PCMService] C:\Program Files\Acer\Acer Arcade\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre6\bin\jusched.exe" File not found
O4 - HKLM..\Run: [SynTPLpr] C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [VX1000] C:\WINDOWS\vVX1000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm] C:\Archivos de programa\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Archivos de programa\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [Spotify] C:\Documents and Settings\Herbert\Datos de programa\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Documents and Settings\Herbert\Datos de programa\Spotify\Data\SpotifyWebHelper.exe ()
O4 - HKCU..\Run: [updateMgr] c:\Archivos de programa\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0 File not found
O4 - HKCU..\RunOnce: [AutoLaunch] C:\Archivos de programa\Lavasoft\Ad-Aware\AutoLaunch.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Sample Toolband Serach - C:\WINDOWS\System32\ToolBand.dll (HiTRUST)
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Herbert\Datos de programa\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Herbert\Datos de programa\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Archivos de programa\ICQLite\ICQLite.exe File not found
O9 - Extra 'Tools' menuitem : ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Archivos de programa\ICQLite\ICQLite.exe File not found
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} hxxp://gateway.serrasold.com/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Archivos de programa\Archivos comunes\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Mi página de inicio actual) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.01.06 08:47:42 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O33 - MountPoints2\{54347046-0fe5-11de-87fd-001346d78640}\Shell\AutoRun\command - "" = wd_windows_tools\WDEULA.exe
O33 - MountPoints2\{6c595e46-c244-11dd-87d7-001346d78640}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\setup.exe -- [2008.04.13 21:19:10 | 000,023,040 | ---- | M] (Microsoft Corporation)
O33 - MountPoints2\{6cd33349-1144-11e0-8afb-0016365fac8b}\Shell - "" = AutoRun
O33 - MountPoints2\{6cd33349-1144-11e0-8afb-0016365fac8b}\Shell\AutoRun\command - "" = F:\.\Setup.exe AUTORUN=1
O33 - MountPoints2\{ed7479ca-ee05-11e1-8b8c-00166f97ec3f}\Shell - "" = AutoRun
O33 - MountPoints2\{ed7479ca-ee05-11e1-8b8c-00166f97ec3f}\Shell\AutoRun\command - "" = F:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
ActiveX: {0213C6AF-5562-4D09-884C-2ADCFC8C2F35} - Microsoft .NET Framework 1.1 Security Update (KB2656353)
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Generación de gráficos vectoriales (VML)
ActiveX: {1325db73-d9f1-48f8-8895-6d814ec58889} - Actualización de seguridad para Windows XP (KB913433)
ActiveX: {1897C549-AE52-4571-8996-44854F5612B2} - Microsoft .NET Framework 1.1 Security Update (KB2656370)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Enlace dinámico de datos HTML para Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Autoría avanzada
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {462B3532-523C-57D5-40F5-A8F147B63A10} - DirectAnimation
ActiveX: {4887E482-F5BB-1D5F-D599-51D8A35F4731} - Reproductor de Windows Media de Microsoft 6.4
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - Clases Java DirectAnimation
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {83169D43-4660-4347-BC95-E9D6E6BE65CE} - .NET Framework
ActiveX: {88059054-77A5-FACB-9170-03EB7073B455} - Themes Setup
ActiveX: {8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Programador de tareas
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {FFF9EA0F-7EBC-B535-5224-5FDB5DC1C3B8} - NetShow
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
 
NetSvcs: 6to4 -  File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.05 20:51:07 | 000,599,040 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Herbert\Escritorio\OTL.exe
[2012.09.05 18:41:24 | 000,000,000 | -HSD | C] -- C:\FOUND.000
[2012.08.24 18:09:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menú Inicio\Programas\Motorola
[2012.08.24 18:09:13 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Archivos comunes\Motorola Shared
[2012.08.24 18:08:33 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Switcher
[2012.08.10 20:11:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Herbert\Datos de programa\Avira
[2012.08.10 20:04:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Mozilla
[2012.08.10 20:04:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Datos de programa\Mozilla
[2012.08.10 20:00:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menú Inicio\Programas\Avira
[2012.08.10 19:59:45 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avkmgr.sys
[2012.08.10 19:59:44 | 000,137,928 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2012.08.10 19:59:44 | 000,083,392 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2012.08.10 19:59:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Datos de programa\Avira
[2012.08.10 19:59:36 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Avira
[2006.09.16 09:07:17 | 005,809,216 | ---- | C] (Hypnotizer) -- C:\Documents and Settings\All Users\hyplay.exe
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.05 20:57:32 | 000,000,492 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{EECED12D-F178-4617-8E24-8F18657FD4CD}.job
[2012.09.05 20:56:34 | 000,002,262 | ---- | M] () -- C:\Documents and Settings\Herbert\Escritorio\Google Chrome.lnk
[2012.09.05 20:49:44 | 000,000,514 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012.09.05 20:49:32 | 000,000,514 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2012.09.05 20:49:28 | 000,000,514 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2012.09.05 20:49:20 | 000,000,514 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2012.09.05 20:49:14 | 000,000,514 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2012.09.05 20:41:52 | 000,000,451 | ---- | M] () -- C:\WINDOWS\System32\eRLog.ini
[2012.09.05 20:41:00 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.09.05 20:39:32 | 000,001,098 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.09.05 20:39:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.09.05 20:39:20 | 1063,374,848 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.05 18:33:38 | 000,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
[2012.09.05 09:06:14 | 000,599,040 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Herbert\Escritorio\OTL.exe
[2012.09.04 21:37:02 | 000,001,102 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.09.04 18:43:38 | 004,503,728 | ---- | M] () -- C:\Documents and Settings\All Users\Datos de programa\0tbpw.pad
[2012.09.02 22:34:14 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Datos de programa\PKP_DLec.DAT
[2012.09.02 22:34:14 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Datos de programa\PKP_DLds.DAT
[2012.08.24 17:38:00 | 000,115,712 | ---- | M] () -- C:\Documents and Settings\Herbert\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.08.21 18:44:24 | 000,002,309 | ---- | M] () -- C:\Documents and Settings\All Users\Escritorio\Skype.lnk
[2012.08.16 21:45:16 | 000,349,792 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.08.15 22:38:50 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012.08.10 20:01:00 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Escritorio\Avira Control Center.lnk
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.09.05 20:49:33 | 000,000,514 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012.09.05 20:49:29 | 000,000,514 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2012.09.04 18:26:57 | 004,503,728 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\0tbpw.pad
[2012.08.10 20:00:59 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Escritorio\Avira Control Center.lnk
[2012.08.08 19:53:51 | 000,000,514 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2012.08.08 19:53:48 | 000,000,514 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2011.12.24 18:28:15 | 000,000,033 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\droidcam-settings
[2011.12.09 23:16:58 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2011.12.09 23:16:58 | 000,000,039 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2009.06.17 22:23:21 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Datos de programa\PKP_DLec.DAT
[2009.06.16 22:00:34 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Datos de programa\Analog Mono
[2009.06.16 22:00:34 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Herbert\Datos de programa\Action Clauses
[2009.06.16 22:00:34 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Datos de programa\PKP_DLds.DAT
[2007.06.30 20:36:24 | 000,001,751 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\QTSBandwidthCache
[2006.09.12 11:58:55 | 000,000,305 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\addr_file.html
[2006.09.12 06:12:40 | 000,115,712 | ---- | C] () -- C:\Documents and Settings\Herbert\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006.09.08 22:09:32 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Herbert\Configuración local\Datos de programa\fusioncache.dat
 
========== LOP Check ==========
 
[2006.09.08 22:17:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Acer
[2006.09.18 21:36:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Autodesk
[2007.07.03 21:07:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\WinZip
[2008.08.14 12:23:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\ICQ
[2008.11.04 15:40:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\ConeXware
[2009.01.06 12:42:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\MipKukSoft
[2009.06.12 23:12:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\MailFrontier
[2009.06.16 22:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\EnterNHelp
[2009.06.16 22:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Ultima_T15
[2009.06.16 22:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Digital Light
[2009.06.16 22:01:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Nikon
[2009.08.01 10:24:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Sony
[2009.11.01 13:06:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Datos de programa\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2011.11.17 20:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\CheckPoint
[2006.09.08 22:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Acer
[2006.09.18 21:36:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Autodesk
[2006.10.09 21:34:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\EPSON
[2006.12.07 18:31:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\CDZilla
[2007.01.10 12:22:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\ICQLite
[2007.09.03 12:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Nikon
[2008.08.14 12:22:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\ICQ
[2008.10.21 15:29:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008.11.04 16:01:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\AnotherUnzipper
[2009.01.06 12:43:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\MipKukSoft
[2009.01.06 12:43:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Kybtec Software
[2009.04.13 15:31:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\DNA
[2009.09.26 23:56:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Amazon
[2009.06.28 21:40:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Thunderbird
[2009.08.01 10:24:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Sony
[2009.09.09 20:46:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\MSNInstaller
[2010.01.22 22:54:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\LucasArts
[2010.02.26 21:33:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\ProtectDisc
[2010.05.26 15:10:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Softland
[2010.11.01 20:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\DVDVideoSoftIEHelpers
[2011.11.17 20:28:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\CheckPoint
[2011.12.18 19:00:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\DVDVideoSoft
[2012.04.11 20:25:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\DDMSettings
[2012.05.26 11:31:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Spotify
[2012.07.27 15:37:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Ad-Aware Antivirus
[2012.09.05 20:49:14 | 000,000,514 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
[2012.09.05 20:49:20 | 000,000,514 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
[2012.09.05 20:49:28 | 000,000,514 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
[2012.09.05 20:57:32 | 000,000,492 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{EECED12D-F178-4617-8E24-8F18657FD4CD}.job
[2012.09.05 20:49:32 | 000,000,514 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
[2012.09.05 20:49:44 | 000,000,514 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %SYSTEMDRIVE%\*. >
[2005.12.14 05:39:18 | 000,000,000 | ---D | M] -- C:\i386
[2004.08.20 05:00:00 | 000,000,000 | ---D | M] -- C:\VALUEADD
[2004.08.20 05:00:00 | 000,000,000 | ---D | M] -- C:\dotnetfx
[2009.10.01 08:24:12 | 000,000,000 | ---D | M] -- C:\tmp
[2012.09.05 18:41:24 | 000,000,000 | -HSD | M] -- C:\FOUND.000
[2005.12.14 05:39:24 | 000,000,000 | ---D | M] -- C:\Sysinfo
[2005.12.14 05:39:20 | 000,000,000 | ---D | M] -- C:\WINDOWS
[2006.01.06 08:15:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings
[2006.01.06 08:20:26 | 000,000,000 | ---D | M] -- C:\Archivos de programa
[2006.01.06 08:41:56 | 000,000,000 | ---D | M] -- C:\Program Files
[2006.09.08 22:08:20 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2009.06.03 09:00:46 | 000,000,000 | ---D | M] -- C:\OrbSecure
[2009.08.10 18:29:42 | 000,000,000 | -H-D | M] -- C:\BJPrinter
[2012.07.28 10:17:00 | 000,000,000 | -HSD | M] -- C:\FOUND.010
[2006.09.08 22:11:04 | 000,000,000 | ---D | M] -- C:\Acer
[2011.06.17 12:27:32 | 000,000,000 | ---D | M] -- C:\Hotspot Shield
[2006.09.12 05:09:20 | 000,000,000 | -HSD | M] -- C:\Recycled
[2006.09.28 21:14:18 | 000,000,000 | ---D | M] -- C:\Programm_Downloads
[2007.01.22 10:44:30 | 000,000,000 | ---D | M] -- C:\Temp
[2008.10.19 11:17:22 | 000,000,000 | RH-D | M] -- C:\MSOCache
 
< %PROGRAMFILES%\*.exe >
Invalid Environment Variable: LOCALAPPDATA
 
< %systemroot%\*. /mp /s >
 
< C:\Windows\system32\*.tsp >
[2008.04.13 21:19:20 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ipconf.tsp
[2008.04.13 21:19:20 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2008.04.13 21:19:20 | 000,266,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\h323.tsp
[2008.04.13 21:19:20 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2008.04.13 21:19:20 | 000,207,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
[2008.04.13 21:19:20 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2008.04.13 21:19:20 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[5 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
 
< MD5 for: AGP440.SYS  >
[2004.08.20 05:00:00 | 018,785,875 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys
[2008.10.19 10:35:10 | 023,895,938 | ---- | M] () .cab file -- C:\i386\sp3.cab:AGP440.sys
[2004.08.20 05:00:00 | 018,785,875 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.10.19 10:35:10 | 023,895,938 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
 
< MD5 for: ATAPI.SYS  >
[2004.08.20 05:00:00 | 018,785,875 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys
[2008.10.19 10:35:10 | 023,895,938 | ---- | M] () .cab file -- C:\i386\sp3.cab:atapi.sys
[2004.08.20 05:00:00 | 018,785,875 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.10.19 10:35:10 | 023,895,938 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.20 05:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004.08.20 05:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0012\DriverFiles\i386\atapi.sys
 
< MD5 for: EVENTLOG.DLL  >
[2008.04.13 21:18:22 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2744C713F0217BD8FFD13E2EF731371C -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.13 21:18:22 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2744C713F0217BD8FFD13E2EF731371C -- C:\WINDOWS\system32\eventlog.dll
[2004.08.20 05:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=5696DF4EF09C375CE42FB2DDE1E68AB7 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
 
< MD5 for: EXPLORER.EXE  >
[2008.04.13 21:18:58 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=7522F548A84ABAD8FA516DE5AB3931EF -- C:\WINDOWS\explorer.exe
[2008.04.13 21:18:58 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=7522F548A84ABAD8FA516DE5AB3931EF -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004.08.20 05:00:00 | 001,034,752 | ---- | M] (Microsoft Corporation) MD5=89C8DD146CEAF482D82822766437D93F -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007.06.13 08:10:54 | 001,035,776 | ---- | M] (Microsoft Corporation) MD5=DBB6B75CC6CB2CF8EC0BAFCA08AED6BE -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007.06.13 08:22:28 | 001,035,776 | ---- | M] (Microsoft Corporation) MD5=F8DDB22B6EFC5E630D65E241074C2404 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2008.04.29 17:42:08 | 000,090,624 | ---- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 -- C:\Archivos de programa\CheckPoint\ZAForceField\Heuristics\explorer.exe
 
< MD5 for: NETLOGON.DLL  >
[2004.08.20 05:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=7FD182B1B80117C353983565D60B1CAF -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.13 21:18:28 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=CD2BBB52DFAAB666B812A51B1E96F2A0 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.13 21:18:28 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=CD2BBB52DFAAB666B812A51B1E96F2A0 -- C:\WINDOWS\system32\netlogon.dll
 
< MD5 for: SCECLI.DLL  >
[2008.04.13 21:18:36 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=B6BE3C96CD33336A551DB3F2299A8E69 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.13 21:18:36 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=B6BE3C96CD33336A551DB3F2299A8E69 -- C:\WINDOWS\system32\scecli.dll
[2004.08.20 05:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=C6347748F2E9F310EA1E1915482ABFEF -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
 
< MD5 for: USER32.DLL  >
[2007.03.08 10:50:26 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=237FB93C6B4330D8EE7D2448CF71C5ED -- C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
[2005.03.02 13:20:22 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=37CE819E8ECB3517B9981A886876EF72 -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2004.08.20 05:00:00 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=5D5C9CC377A70D036816E7EA55F3CA73 -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll
[2008.04.13 21:18:46 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=DA8898129E0075C7DE4DEE457514A73C -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.13 21:18:46 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=DA8898129E0075C7DE4DEE457514A73C -- C:\WINDOWS\system32\user32.dll
[2005.03.02 13:10:34 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=DDA46F3DBCF32727E93976B09FBB0E83 -- C:\WINDOWS\$NtUninstallKB925902$\user32.dll
[2007.03.08 10:36:30 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=FED9881C07A301271F52B51389A028C9 -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2004.08.20 05:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=7B30B4D55B4562C733A5DDF6D6F72B3F -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008.04.13 21:19:14 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=F5B8745B9A90EAF17E30C0574E049AA3 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.13 21:19:14 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=F5B8745B9A90EAF17E30C0574E049AA3 -- C:\WINDOWS\system32\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2008.04.13 21:19:16 | 000,510,976 | ---- | M] (Microsoft Corporation) MD5=213C80D912880BBF04453D09FFCCB28C -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.13 21:19:16 | 000,510,976 | ---- | M] (Microsoft Corporation) MD5=213C80D912880BBF04453D09FFCCB28C -- C:\WINDOWS\system32\winlogon.exe
[2008.07.01 15:17:12 | 000,090,624 | ---- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 -- C:\Archivos de programa\CheckPoint\ZAForceField\Heuristics\winlogon.exe
[2004.08.20 05:00:00 | 000,505,344 | ---- | M] (Microsoft Corporation) MD5=FCB59D25D628B4D3181DC816D14679DD -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2004.08.20 05:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2004.08.20 05:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2006.01.06 08:15:18 | 000,466,944 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
[2006.01.06 08:15:18 | 000,643,072 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2006.01.06 08:15:20 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
 
< %systemroot%\system32\*.dll /lockedfiles >
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
 
< %USERPROFILE%\*.* >
[2012.09.05 21:12:52 | 000,001,024 | -H-- | M] () -- C:\Documents and Settings\Herbert\ntuser.dat.LOG
[2012.08.29 17:42:28 | 000,000,304 | -HS- | M] () -- C:\Documents and Settings\Herbert\ntuser.ini
[2012.09.02 23:50:24 | 008,077,312 | ---- | M] () -- C:\Documents and Settings\Herbert\NTUSER.DAT
 
< %USERPROFILE%\Local Settings\Temp\*.exe >
 
< %USERPROFILE%\Local Settings\Temp\*.dll >
 
< %USERPROFILE%\Application Data\*.exe >
 
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Kmode: %SystemRoot%\system32\win32k.sys [2012.07.03 20:22:14 | 001,866,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

< End of report >
         
--- --- ---




Extras.TxtOTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 05.09.2012 20:57:14 - Run 1
OTL by OldTimer - Version 3.2.61.0     Folder = C:\Documents and Settings\Herbert\Escritorio
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Alemania | Language: DEU | Date Format: dd.MM.yyyy
 
1014,05 Mb Total Physical Memory | 440,73 Mb Available Physical Memory | 43,46% Memory free
2,38 Gb Paging File | 1,59 Gb Available in Paging File | 66,76% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa
Drive C: | 35,06 Gb Total Space | 2,10 Gb Free Space | 5,98% Space Free | Partition Type: FAT32
Drive D: | 35,55 Gb Total Space | 7,79 Gb Free Space | 21,91% Space Free | Partition Type: FAT32
 
Computer Name: CHRISTIANE | User Name: Herbert | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] -- C:\Archivos de programa\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Archivos de programa\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
http [open] -- "C:\Archivos de programa\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Archivos de programa\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Acer\Acer Arcade\PCMService.exe" = C:\Program Files\Acer\Acer Arcade\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program -- (CyberLink Corp.)
"C:\Archivos de programa\Microsoft Games\Age of Empires II\EMPIRES2.ICD" = C:\Archivos de programa\Microsoft Games\Age of Empires II\EMPIRES2.ICD:*:Enabled:Age of Empires II
"C:\Archivos de programa\ICQLite\ICQLite.exe" = C:\Archivos de programa\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite
"C:\Documents and Settings\Herbert\Escritorio\Mazatlan 2006\LimeWire\LimeWire.exe" = C:\Documents and Settings\Herbert\Escritorio\Mazatlan 2006\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"C:\Archivos de programa\PFTP\PFtp.exe" = C:\Archivos de programa\PFTP\PFtp.exe:*:Enabled:The Personal FTP Server
"C:\Archivos de programa\Winamp Remote\bin\Orb.exe" = C:\Archivos de programa\Winamp Remote\bin\Orb.exe:*:Enabled:Orb
"C:\Archivos de programa\Winamp Remote\bin\OrbTray.exe" = C:\Archivos de programa\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray
"C:\Archivos de programa\Winamp Remote\bin\OrbStreamerClient.exe" = C:\Archivos de programa\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client
"C:\Archivos de programa\ICQ6\ICQ.exe" = C:\Archivos de programa\ICQ6\ICQ.exe:*:Enabled:ICQ6
"C:\Archivos de programa\DNA\btdna.exe" = C:\Archivos de programa\DNA\btdna.exe:*:Enabled:DNA -- (BitTorrent, Inc.)
"C:\Archivos de programa\BitTorrent\bittorrent.exe" = C:\Archivos de programa\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"C:\Archivos de programa\Microsoft LifeCam\LifeCam.exe" = C:\Archivos de programa\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe -- (Microsoft Corporation)
"C:\Archivos de programa\Microsoft LifeCam\LifeExp.exe" = C:\Archivos de programa\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe -- (Microsoft Corporation)
"C:\Archivos de programa\LimeWire\LimeWire.exe" = C:\Archivos de programa\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"C:\Archivos de programa\Skype\Plugin Manager\skypePM.exe" = C:\Archivos de programa\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"C:\Archivos de programa\Steam\Steam.exe" = C:\Archivos de programa\Steam\Steam.exe:*:Enabled:Steam
"C:\Archivos de programa\Spotify\spotify.exe" = C:\Archivos de programa\Spotify\spotify.exe:*:Enabled:Spotify
"C:\WINDOWS\System32\ZoneLabs\vsmon.exe" = C:\WINDOWS\System32\ZoneLabs\vsmon.exe:*:Enabled:vsmon
"C:\Documents and Settings\Herbert\Datos de programa\Spotify\spotify.exe" = C:\Documents and Settings\Herbert\Datos de programa\Spotify\spotify.exe:*:Enabled:Spotify -- (Spotify Ltd)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"{15B70821-7893-4607-805A-BB80F3EA8279}" = Acer Empowering Technology framework
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java(TM) 6 Update 25
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{350C9C0A-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{385979FE-DC4F-4140-8EAD-A59625000D72}" = NTI Backup NOW! 4
"{3DC172E8-CA66-4E10-A1D3-8282F4CBFCEA}" = Microsoft LifeCam
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4B33371A-C04F-48D3-980C-285369ECD634}" = ZoneAlarm Firewall
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{556027C9-C365-476A-9DF2-19DFD0F2F767}" = PowerArchiver 2007 German
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
"{5EFDFC8B-D438-4792-A298-E87AA9ADA816}" = Acer eDataSecurity Management
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}" = Acer eLock Management
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = 
"{83169D43-4660-4347-BC95-E9D6E6BE65CE}" = Microsoft .NET Framework 1.1 Spanish Language Pack
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38}" = Microsoft .NET Framework 2.0 Language Pack - DEU
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver for Mobile
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0010-0C0A-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders  (Spanish) 12
"{90120000-0015-0C0A-0000-0000000FF1CE}" = Microsoft Office Access MUI (Spanish) 2007
"{90120000-0015-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0C0A-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Spanish) 2007
"{90120000-0016-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0C0A-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Spanish) 2007
"{90120000-0018-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0C0A-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Spanish) 2007
"{90120000-0019-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Spanish) 2007
"{90120000-001A-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0C0A-0000-0000000FF1CE}" = Microsoft Office Word MUI (Spanish) 2007
"{90120000-001B-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0403-0000-0000000FF1CE}" = Microsoft Office Proof (Catalan) 2007
"{90120000-001F-0403-0000-0000000FF1CE}_ENTERPRISE_{BEADB115-DB47-4BD0-A9EC-AE585AFAB2D8}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007
"{90120000-001F-0416-0000-0000000FF1CE}_ENTERPRISE_{8A524694-0CA4-476A-9301-B1E9D70FC952}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-042D-0000-0000000FF1CE}" = Microsoft Office Proof (Basque) 2007
"{90120000-001F-042D-0000-0000000FF1CE}_ENTERPRISE_{017A6981-5E03-4A97-830A-35FE0927BB7F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0456-0000-0000000FF1CE}" = Microsoft Office Proof (Galician) 2007
"{90120000-001F-0456-0000-0000000FF1CE}_ENTERPRISE_{A3A03B41-14EA-4E50-97D8-FCF429AE0CCB}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0C0A-0000-0000000FF1CE}" = Microsoft Office Proofing (Spanish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0C0A-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Spanish) 2007
"{90120000-0044-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0C0A-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Spanish) 2007
"{90120000-006E-0C0A-0000-0000000FF1CE}_ENTERPRISE_{430AE3E6-E982-4958-90FC-1C062BC74E22}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0C0A-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Spanish) 2007
"{90120000-00A1-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0C0A-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Spanish) 2007
"{90120000-00BA-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0407-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2172ACA-FFA8-4808-BD20-08565C7390F9}" = OGA Notifier 1.7.0105.35.0
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5F68DC8-0278-4AD8-B413-861509B5F25B}" = ArcSoft Panorama Maker 3
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C35CCBEB-5A54-4DD8-9EC8-110F2A8154B3}" = Motorola Mobile Drivers Installation 5.1.0
"{C4C255FE-BE15-4C06-AAD9-A08F2DBB2E39}" = ZoneAlarm Security
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}" = ArcSoft PhotoImpression 5
"{D458BBDC-0363-42E0-8FF9-4736E3CB3CA2}" = Acer Screensaver
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DEE08946-40F0-4890-853E-60A6C3306041}" = Acer ePerformance Management
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}" = Acer eSettings Management
"{E431C518-2EE2-471E-9234-BE995C36D513}" = Acer eDataSecurity Management 1.00.23
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F48C6EA5-3B43-11D6-86A6-0050BA0259A2}" = ICatch (VI) PC Camera
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9
"Avira AntiVir Desktop" = Avira Free Antivirus
"CNXT_MODEM_HDAUDIO_AcrS009E" = HDAUDIO Soft Data Fax Modem with SmartCP
"DivX Setup" = DivX-Setup
"doPDF 7 printer_is1" = doPDF 7.1 printer
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ePresentation" = Acer ePresentation Management
"GridVista" = Acer GridVista
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Ink Monitor" = Ink Monitor
"InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"InstallShield_{15B70821-7893-4607-805A-BB80F3EA8279}" = Acer Empowering Technology framework
"InstallShield_{385979FE-DC4F-4140-8EAD-A59625000D72}" = NTI Backup NOW! 4
"InstallShield_{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}" = Acer eLock Management
"InstallShield_{DEE08946-40F0-4890-853E-60A6C3306041}" = Acer ePerformance Management
"InstallShield_{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}" = Acer eSettings Management
"IrfanView" = IrfanView (remove only)
"LManager" = Launch Manager
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0 Language Pack - DEU" = Microsoft .NET Framework 2.0 Language Pack - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 14.0.1 (x86 de)" = Mozilla Firefox 14.0.1 (x86 de)
"Mozilla Thunderbird (8.0)" = Mozilla Thunderbird (8.0)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nikon FotoShare" = Nikon FotoShare
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ProInst" = Software Intel(R) PROSet/Wireless
"Revo Uninstaller" = Revo Uninstaller 1.93
"Silent Package Run-Time Sample" = Manual de la CX7700
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Uninstall_is1" = Uninstall 1.0.0.1
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Reproductor de Windows Media 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoneAlarm Free Firewall" = ZoneAlarm Free Firewall
"ZoneAlarm LTD Toolbar" = ZoneAlarm LTD Toolbar
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA
"Google Chrome" = Google Chrome
"Move Media Player" = Move Media Player
"Spotify" = Spotify
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 04.09.2012 13:09:04 | Computer Name = CHRISTIANE | Source = Application Error | ID = 1000
Description = Aplicación con errores: skype.exe, versión: 5.10.0.116, módulo con
 error: skype.exe, versión 5.10.0.116, dirección de error 0x00f240bc.
 
Error - 04.09.2012 13:27:28 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001
Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas
 de  diferencia para crear instantáneas. Agregue al menos una unidad NTFS al  sistema
 con suficiente espacio en disco. Se necesitan por lo menos 100 Mb  en cada volumen
 para poder hacer la copia de seguridad o instantánea.
 
Error - 04.09.2012 13:37:57 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001
Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas
 de  diferencia para crear instantáneas. Agregue al menos una unidad NTFS al  sistema
 con suficiente espacio en disco. Se necesitan por lo menos 100 Mb  en cada volumen
 para poder hacer la copia de seguridad o instantánea.
 
Error - 04.09.2012 13:47:44 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001
Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas
 de  diferencia para crear instantáneas. Agregue al menos una unidad NTFS al  sistema
 con suficiente espacio en disco. Se necesitan por lo menos 100 Mb  en cada volumen
 para poder hacer la copia de seguridad o instantánea.
 
Error - 04.09.2012 13:47:47 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001
Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas
 de  diferencia para crear instantáneas. Agregue al menos una unidad NTFS al  sistema
 con suficiente espacio en disco. Se necesitan por lo menos 100 Mb  en cada volumen
 para poder hacer la copia de seguridad o instantánea.
 
Error - 04.09.2012 14:00:33 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001
Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas
 de  diferencia para crear instantáneas. Agregue al menos una unidad NTFS al  sistema
 con suficiente espacio en disco. Se necesitan por lo menos 100 Mb  en cada volumen
 para poder hacer la copia de seguridad o instantánea.
 
Error - 04.09.2012 14:06:38 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001
Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas
 de  diferencia para crear instantáneas. Agregue al menos una unidad NTFS al  sistema
 con suficiente espacio en disco. Se necesitan por lo menos 100 Mb  en cada volumen
 para poder hacer la copia de seguridad o instantánea.
 
Error - 04.09.2012 14:17:46 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001
Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas
 de  diferencia para crear instantáneas. Agregue al menos una unidad NTFS al  sistema
 con suficiente espacio en disco. Se necesitan por lo menos 100 Mb  en cada volumen
 para poder hacer la copia de seguridad o instantánea.
 
Error - 04.09.2012 14:21:30 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001
Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas
 de  diferencia para crear instantáneas. Agregue al menos una unidad NTFS al  sistema
 con suficiente espacio en disco. Se necesitan por lo menos 100 Mb  en cada volumen
 para poder hacer la copia de seguridad o instantánea.
 
Error - 04.09.2012 14:33:19 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001
Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas
 de  diferencia para crear instantáneas. Agregue al menos una unidad NTFS al  sistema
 con suficiente espacio en disco. Se necesitan por lo menos 100 Mb  en cada volumen
 para poder hacer la copia de seguridad o instantánea.
 
[ OSession Events ]
Error - 08.02.2010 16:54:10 | Computer Name = CHRISTIANE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 8
 seconds with 0 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 04.09.2012 13:05:54 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000
Description = El servicio DS1410D no pudo iniciarse debido al siguiente error:   %%2
 
Error - 04.09.2012 13:05:54 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000
Description = El servicio Servicio Google Update (gupdate1c9f1eed03b8c66) no pudo
 iniciarse debido al siguiente error:   %%2
 
Error - 04.09.2012 13:18:50 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000
Description = El servicio DS1410D no pudo iniciarse debido al siguiente error:   %%2
 
Error - 04.09.2012 13:18:50 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000
Description = El servicio Servicio Google Update (gupdate1c9f1eed03b8c66) no pudo
 iniciarse debido al siguiente error:   %%2
 
Error - 05.09.2012 12:23:00 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000
Description = El servicio DS1410D no pudo iniciarse debido al siguiente error:   %%2
 
Error - 05.09.2012 12:23:00 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000
Description = El servicio Servicio Google Update (gupdate1c9f1eed03b8c66) no pudo
 iniciarse debido al siguiente error:   %%2
 
Error - 05.09.2012 12:42:35 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000
Description = El servicio DS1410D no pudo iniciarse debido al siguiente error:   %%2
 
Error - 05.09.2012 12:42:35 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000
Description = El servicio Servicio Google Update (gupdate1c9f1eed03b8c66) no pudo
 iniciarse debido al siguiente error:   %%2
 
Error - 05.09.2012 14:39:40 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000
Description = El servicio DS1410D no pudo iniciarse debido al siguiente error:   %%2
 
Error - 05.09.2012 14:39:40 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000
Description = El servicio Servicio Google Update (gupdate1c9f1eed03b8c66) no pudo
 iniciarse debido al siguiente error:   %%2
 
 
< End of report >
         
--- --- ---
__________________

Alt 06.09.2012, 13:34   #4
markusg
/// Malware-holic
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



hatte ich nicht was vom abgesicherten modus mit netzwerk gesagt?
noch mal genau lesen was oben steht
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 07.09.2012, 06:58   #5
KristyMaz
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



Oh sorry, hatte es ein paar mal versucht, auch gerade eben und es erscheint nur eine schwarzer Bildschirm und dann nichts mehr. Hab mittlerweile auch eine systemwiederherstellung gemacht, jetzt funktioniert zwar alles wieder, aber ich bin mir nicht sicher, ob der Trojaner noch da ist.


Alt 07.09.2012, 09:57   #6
markusg
/// Malware-holic
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



wieso tust du nicht einfach das, was da steht und machst nicht irgendwelchen anderen unsinn, da kann ich mir die arbeit auch gleich ganz sparen...
also entweder du arbeitest allein weiter, dann sag bescheid, oder poste otl logs und lasse sonst den pc in ruhe und unternimm nichts mehr selbst.
__________________
--> GVU-Trojaner entfernen für Anfänger

Alt 07.09.2012, 10:43   #7
KristyMaz
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



Ich komme in den gesicherten Modus nicht rein. Der Bildschirm bleibt schwarz und es passiert nichts.

Alt 07.09.2012, 11:26   #8
markusg
/// Malware-holic
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



hi
jetzt kannst du es ja im normalen tun, nach der swh sollte das ja funktionieren
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 07.09.2012, 16:59   #9
KristyMaz
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



Also die Texte oben habe ich nach der Wiederherstellung erstellt. Ich hatte sonst keine Möglichkeit ins Internet zu kommen. Und ich wusste auch nicht so recht, wie ich sonst die Texte hier reinkopieren könnte.

Alt 07.09.2012, 17:15   #10
markusg
/// Malware-holic
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 08.09.2012, 11:47   #11
KristyMaz
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



Habe es durchgeführt, hier die Infos:

Malwarebytes Anti-Malware (Test) 1.62.0.1300
Malwarebytes : Free Anti-Malware download

Datenbank Version: v2012.09.08.02

Windows XP Service Pack 3 x86 FAT32
Internet Explorer 8.0.6001.18702
Herbert :: CHRISTIANE [Administrator]

Schutz: Aktiviert

08.09.2012 10:57:52
mbam-log-2012-09-08 (10-57-52).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 305125
Laufzeit: 1 Stunde(n), 47 Minute(n), 23 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 2
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Documents and Settings\Herbert\Configuración local\Temp\wpbt0.dll (Trojan.FakeMS) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Documents and Settings\Herbert\Configuración local\Archivos temporales de Internet\Content.IE5\JQYC93PH\about[1].exe (Trojan.FakeMS) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Alt 08.09.2012, 11:50   #12
markusg
/// Malware-holic
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



lade den CCleaner standard:
CCleaner Download - CCleaner 3.22.1800
falls der CCleaner
bereits instaliert, überspringen.
instalieren, öffnen, extras, liste der instalierten programme, als txt speichern. öffnen.
hinter, jedes von dir benötigte programm, schreibe notwendig.
hinter, jedes, von dir nicht benötigte, unnötig.
hinter, dir unbekannte, unbekannt.
liste posten.
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 09.09.2012, 10:17   #13
KristyMaz
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



Acer Arcade 01.01.1601 notwendig
Acer eDataSecurity Management 1.00.23 Acer 08.09.2006 1.00.23 notwendig
Acer eLock Management Acer Inc. 08.09.2006 1.7.9.21 notwendig
Acer Empowering Technology framework Acer Inc. 08.09.2006 2.1.21.41 notwendig
Acer eNet Management 01.01.1601 1.01.3.003 notwendig
Acer ePerformance Management Acer Inc. 08.09.2006 1.0.10.21 notwendig
Acer ePower Management 01.01.1601 1.6.8.281 notwendig
Acer ePresentation Management 01.01.1601 1.1.4.819 notwendig
Acer eSettings Management Acer Inc. 08.09.2006 1.2.20.35 notwendig
Acer GridVista 01.01.1601 2.29.0728 notwendig
Acer Screensaver acer 08.09.2006 3,03MB 1.0.0 notwendig
Ad-Aware Lavasoft 01.11.2009 notwendig
Adobe AIR Adobe Systems Inc. 21.10.2008 1.1.0.5790 notwendig
Adobe Download Manager NOS Microsystems Ltd. 01.01.1601 1.6.2.63
Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 01.01.1601 10.0.45.2 notwendig
Adobe Flash Player 11 Plugin Adobe Systems Incorporated 01.01.1601 11.4.402.265 notwendig
Adobe Reader 9.1 Adobe Systems Incorporated 12.03.2009 143,00MB 9.1.0 notwendig
Amazon MP3-Downloader 1.0.9 01.01.1601 notwendig
ArcSoft Panorama Maker 3 ArcSoft 01.01.1601 notwendig
ArcSoft PhotoImpression 5 ArcSoft 01.01.1601 notwendig
Avira Free Antivirus Avira 01.01.1601 12.0.0.1167 notwendig
CCleaner Piriform 22.08.2012 3.22 notwendig
Content Transfer Sony Corporation 01.08.2009 12,40MB 1.0.0.07110 notwendig
DivX-Setup DivX, LLC 01.01.1601 2.6.1.5 unnötig
DNA BitTorrent Inc. 01.01.1601 2.2.4 (16502) unbekannt
doPDF 7.1 printer Softland 26.05.2010 notwendig notwendig
Google Chrome Google Inc. 20.04.2012 21.0.1180.89 notwendig
HDAUDIO Soft Data Fax Modem with SmartCP 01.01.1601 notwendig
High Definition Audio Driver Package - KB888111 Microsoft Corporation 01.01.1601 20040219.000000 notwendig
ICatch (VI) PC Camera 01.01.1601 unnötig
Ink Monitor notwendig
Intel(R) Graphics Media Accelerator Driver for Mobile 01.01.1601 6.14.10.4363 notwendig
IrfanView (remove only) 01.01.1601 unnötig
J2SE Runtime Environment 5.0 Update 6 Sun Microsystems, Inc. 18.09.2006 145,00MB 1.5.0.60 notwendig
Java(TM) 6 Update 2 Sun Microsystems, Inc. 26.08.2007 133,00MB 1.6.0.20 notwendig
Java(TM) 6 Update 25 Sun Microsystems, Inc. 30.11.2008 94,47MB 6.0.250 notwendig
Java(TM) 6 Update 3 Sun Microsystems, Inc. 24.11.2007 133,00MB 1.6.0.30 notwendig
Java(TM) 6 Update 5 Sun Microsystems, Inc. 19.04.2008 136,00MB 1.6.0.50 notwendig
Java(TM) 6 Update 7 Sun Microsystems, Inc. 17.08.2008 136,00MB 1.6.0.70 notwendig
Launch Manager 01.01.1601 notwendig
Malwarebytes Anti-Malware Version 1.62.0.1300 Malwarebytes Corporation 08.09.2012 1.62.0.1300 notwendig
Manual de la CX7700 unnötig
Microsoft .NET Framework 1.1 15.06.2012 notwendig
Microsoft .NET Framework 1.1 Spanish Language Pack Microsoft 06.01.2006 3,09MB 1.1.4322 notwendig
Microsoft .NET Framework 2.0 Language Pack - DEU Microsoft Corporation 01.08.2009 notwendig
Microsoft .NET Framework 2.0 Service Pack 2 Microsoft Corporation 15.06.2012 191,00MB 2.2.30729 notwendig
Microsoft .NET Framework 3.0 Service Pack 2 Microsoft Corporation 13.06.2012 241,00MB 3.2.30729 notwendig
Microsoft .NET Framework 3.5 SP1 Microsoft Corporation 13.06.2012 notwendig
Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Corporation 27.02.2008 1 notwendig
Microsoft LifeCam Microsoft 16.06.2009 75,10MB 1.40.164.0 notwendig
Microsoft Office Enterprise 2007 Microsoft Corporation 15.08.2012 12.0.6612.1000 notwendig
Microsoft Office Live Add-in 1.3 Microsoft Corporation 15.06.2009 0,58MB 2.0.2313.0 notwendig
Microsoft Office Outlook Connector Microsoft Corporation 14.01.2010 7,99MB 12.0.6423.1000 notwendig
Microsoft Silverlight Microsoft Corporation 13.06.2012 185,00MB 4.1.10329.0 notwendig
Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Corporation 27.02.2008 notwendig
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 01.08.2009 0,17MB 8.0.50727.4053 notwendig
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 18.06.2011 5,94MB 8.0.61001 notwendig
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Corporation 30.07.2009 0,22MB 9.0.30729.4148 notwendig
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Corporation 09.05.2011 10,87MB 9.0.30729.5570 notwendig
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 25.05.2011 10,30MB 9.0.30729 notwendig
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 25.06.2009 10,95MB 9.0.30729 notwendig
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 25.04.2011 10,86MB 9.0.30729.4148 notwendig
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 18.06.2011 10,87MB 9.0.30729.6161 notwendig
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 27.10.2011 15,17MB 10.0.40219 notwendig
Motorola Mobile Drivers Installation 5.1.0 Motorola Inc. 24.08.2012 4,28MB 5.1.0 notwendig
Move Media Player Move Networks 01.01.1601 notwendig
Mozilla Firefox 14.0.1 (x86 de) Mozilla 01.01.1601 14.0.1 notwendig
Mozilla Maintenance Service Mozilla 01.01.1601 14.0.1 notwendig
Mozilla Thunderbird (8.0) Mozilla 01.01.1601 8.0 (de) notwendig
MSXML 4.0 SP2 (KB927978) Microsoft Corporation 22.11.2006 2,77MB 4.20.9841.0 notwendig
MSXML 4.0 SP2 (KB936181) Microsoft Corporation 14.08.2007 2,77MB 4.20.9848.0 notwendig
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 13.11.2008 2,90MB 4.20.9870.0 notwendig
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 26.11.2009 3,02MB 4.20.9876.0 notwendig
MSXML 4.0 SP2 Parser and SDK Microsoft Corporation 16.06.2009 0,03MB 4.20.9818.0 notwendig
Nikon FotoShare 01.01.1601 1.0.1.0 notwendig
Nikon Message Center 01.01.1601 0.90.000 notwendig
NTI Backup NOW! 4 NewTech Infosystems 06.01.2006 4 notwendig
NTI CD & DVD-Maker NewTech Infosystems 06.01.2006 7 notwendig
PDFCreator Frank Heindörfer, Philip Chinery 28.09.2006 0.9.3 notwendig
PictureProject Nikon 01.01.1601 1.0 notwendig
PowerArchiver 2007 German ConeXware, Inc. 04.11.2008 17,25MB 10.22.02 notwendig
PowerProducer 01.01.1601 notwendig
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 06.01.2006 2.02 notwendig
Reproductor de Windows Media 11 01.01.1601 notwendig
Revo Uninstaller 1.93 VS Revo Group 01.01.1601 1.93 notwendig
Skype™ 5.10 Skype Technologies S.A. 01.08.2012 103,00MB 5.10.116 notwendig
Software Intel(R) PROSet/Wireless Intel Corporation 01.01.1601 notwendig
Spotify Spotify AB 29.08.2012 0.8.4.124.ga3559d86 notwendig
Synaptics Pointing Device Driver 01.01.1601 7.12.13.0 notwendig
Uninstall 1.0.0.1 01.11.2010 notwendig
Winamp Nullsoft, Inc 01.01.1601 5.572 notwendig
Winamp Erkennungs-Plug-in Nullsoft, Inc 06.03.2010 1.0.0.1 notwendig
Windows Internet Explorer 8 Microsoft Corporation 12.06.2009 20090308.140743 notwendig
Windows Live Anmelde-Assistent Microsoft Corporation 15.06.2009 1,97MB 5.000.818.5 notwendig
Windows Live Essentials Microsoft Corporation 22.04.2011 14.0.8117.0416 notwendig
Windows Live-Uploadtool Microsoft Corporation 15.06.2009 0,19MB 14.0.8014.1029 notwendig
Windows Media Format 11 runtime 01.01.1601 notwendig
Windows Media Player Firefox Plugin Microsoft Corp 08.10.2009 0,28MB 1.0.0.8 notwendig
Windows XP Service Pack 3 Microsoft Corporation 19.10.2008 20080414.031514 notwendig
WinZip WinZip Computing, Inc. 01.01.1601 9.0 (6028) notwendig
ZoneAlarm Free Firewall Check Point 01.01.1601 10.2.057.000 notwendig

Alt 10.09.2012, 14:12   #14
markusg
/// Malware-holic
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



deinstaliere:
Adobe Flash Player alle
Adobe - Adobe Flash Player installieren
neueste version laden
adobe reader:
Adobe - Adobe Reader herunterladen - Alle Versionen
haken bei mcafee security scan raus nehmen

bitte auch mal den adobe reader wie folgt konfigurieren:
adobe reader öffnen, bearbeiten, voreinstellungen.
allgemein:
nur zertifizierte zusatz module verwenden, anhaken.
internet:
hier sollte alles deaktiviert werden, es ist sehr unsicher pdfs automatisch zu öffnen, zu downloaden etc.
es ist immer besser diese direkt abzuspeichern da man nur so die kontrolle hat was auf dem pc vor geht.
bei javascript den haken bei java script verwenden raus nehmen
bei updater, automatisch instalieren wählen.
übernehmen /ok



deinstaliere:
DivX
DNA
ICatch
IrfanView
J2SE
Java: alle
Download der kostenlosen Java-Software
downloade java jre instalieren

deinstaliere:
Manual
ZoneAlarm : darauf kann man beruhigt verzichten, router firewalls sind ausreichend.

öffne otl, bereinigen, pc startet neu
öffne CCleaner analysieren, bereinigen, pc neustarten testen wie er läuft
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 11.09.2012, 21:05   #15
KristyMaz
 
GVU-Trojaner entfernen für Anfänger - Standard

GVU-Trojaner entfernen für Anfänger



So, habe alles gemacht und es scheint alles normal zu laufen.
Ist der Trojaner damit nun weg?

Antwort

Themen zu GVU-Trojaner entfernen für Anfänger
abend, anfänger, arbeit, ausgeschaltet, einfacher, entfernen, erschein, forum, gespeichert, gestern, gvu trojaner entfernen windows xp, gvu-trojaner, gvu-trojaner entfernen, gvu-trojaner entfernen für anfänger, heulen, heute, interne, internet, könntet, sache, sachen, seite, usb-stick, verzweifel



Ähnliche Themen: GVU-Trojaner entfernen für Anfänger


  1. habe eventuell Trojaner auf PC - bin Anfänger!
    Alles rund um Windows - 21.07.2015 (1)
  2. Antivir Security Pro entfernen für Anfänger !
    Plagegeister aller Art und deren Bekämpfung - 29.10.2013 (3)
  3. Gvu Trojaner/Schwarzer Bildschirm/Anfänger-frage
    Plagegeister aller Art und deren Bekämpfung - 09.07.2013 (32)
  4. GVU Trojaner Vista anfänger!
    Plagegeister aller Art und deren Bekämpfung - 11.03.2013 (6)
  5. Trojaner-Anfänger
    Diskussionsforum - 12.10.2011 (2)
  6. Log checken (Anfänger)
    Log-Analyse und Auswertung - 16.01.2010 (1)
  7. Trojaner "PWS-LegMir.gen.k.dll" brauche Hilfe beim Entfernen, da Anfänger
    Plagegeister aller Art und deren Bekämpfung - 10.05.2008 (26)
  8. Anfänger mit einem Trojaner.
    Plagegeister aller Art und deren Bekämpfung - 05.01.2008 (7)
  9. Trojaner-bekämpfung für Anfänger
    Plagegeister aller Art und deren Bekämpfung - 07.05.2007 (12)
  10. Anfänger hat Verdacht auf Trojaner! Bitte um Hilfe
    Log-Analyse und Auswertung - 21.04.2007 (8)
  11. Trojaner lassen sich nicht entfernen/Anfänger
    Plagegeister aller Art und deren Bekämpfung - 05.08.2006 (1)
  12. HELP MY! ich bin anfänger!
    Plagegeister aller Art und deren Bekämpfung - 05.07.2006 (1)
  13. O.K. Anfänger
    Mülltonne - 29.06.2006 (1)
  14. Anfänger braucht Hilfe/Trojaner an Bord?
    Log-Analyse und Auswertung - 05.12.2005 (10)
  15. Bitte helft mir (bin Anfänger) - habe mir Trojaner eingefangen
    Log-Analyse und Auswertung - 16.10.2004 (9)
  16. anfänger fragen
    Plagegeister aller Art und deren Bekämpfung - 23.11.2003 (2)
  17. PHP für Anfänger
    Alles rund um Windows - 13.02.2003 (8)

Zum Thema GVU-Trojaner entfernen für Anfänger - Hallo liebes Forum, ich habe seit gestern auch diesen GVU-Trojaner bei mir auf XP drauf. Mein Internet muss ich ausgeschaltet lassen, weil ansonsten wieder diese Seite erscheint. Hier im Forum - GVU-Trojaner entfernen für Anfänger...
Archiv
Du betrachtest: GVU-Trojaner entfernen für Anfänger auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.