![]() |
|
Log-Analyse und Auswertung: probleme mit avira, schwerwiegende fehlermeldungWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() ![]() | ![]() probleme mit avira, schwerwiegende fehlermeldung diesmal spielt der rechner meiner mutter nicht so mit, wie wir das gern hätten...
hab den CCleaner angewendet. mbam hat gar nichts gefunden. hier ist der RSIT log teil 1 Code:
ATTFilter Logfile of random's system information tool 1.06 (written by random/random) Run by *** at 2009-08-23 11:09:36 Microsoft® Windows Vista™ Home Premium Service Pack 1 System drive C: has 213 GB (72%) free of 296 GB Total RAM: 3069 MB (63% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:09:45, on 23.08.2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v8.00 (8.00.6001.18813) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\IDT\WDM\sttray.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Windows\ehome\ehtray.exe C:\Program Files\ICQ6.5\ICQ.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Brother\ControlCenter3\brccMCtl.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\wuauclt.exe C:\program files\avira\antivir desktop\avcenter.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\system32\SearchFilterHost.exe C:\Users\***\Downloads\RSIT.exe C:\Program Files\Trend Micro\HijackThis\***.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=83&bd=Pavilion&pf=cnnb R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=83&bd=Pavilion&pf=cnnb R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=83&bd=Pavilion&pf=cnnb R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=83&bd=Pavilion&pf=cnnb R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0" O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [NetFxUpdate_v1.1.4322] "C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe" 1 v1.1.4322 GAC + NI NID O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST') O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe O13 - Gopher Prefix: O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_9a642328\aestsrv.exe O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_9a642328\STacSV.exe -- End of file - 9431 bytes ======Scheduled tasks folder====== C:\Windows\tasks\User_Feed_Synchronization-{2FFBFECF-FAC5-467F-A18C-00D5F9C738E8}.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440] "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-01-18 1033512] "SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2008-04-15 442433] "UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2007-12-24 222504] "QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2008-05-14 468264] "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184] "QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-03-14 202032] "OnScreenDisplay"=C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe [2007-11-01 554288] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-05-11 40048] "HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-04-15 70912] "HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840] "hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2007-11-20 488752] "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784] "SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472] "PaperPort PTD"=C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe [2007-01-29 30248] "IndexSearch"=C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [2007-01-29 46632] "PPort11reminder"=C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe [2007-02-01 255528] "BrMfcWnd"=C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [2007-03-12 663552] "ControlCenter3"=C:\Program Files\Brother\ControlCenter3\brctrcen.exe [2007-01-26 65536] "avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153] "NetFxUpdate_v1.1.4322"=C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe [2004-08-10 106496] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920] "LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-02-26 2289664] "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952] "ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-03-01 172792] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{E54729E8-BB3D-4270-9D49-7389EA579090}"=C:\Windows\system32\EZUPBH~1.DLL [2009-01-12 49152] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableLockWorkstation"=0 "DisableTaskMgr"=0 "DisableChangePassword"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 "HideFastUserSwitching"=0 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoLogoff"=0 "NoClose"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94845558-d36c-11dd-9a32-806e6f6e6963}] shell\AutoRun\command - E:\Autorun.exe ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 months====== 2009-08-23 11:09:36 ----D---- C:\rsit 2009-08-23 11:02:20 ----D---- C:\Program Files\Trend Micro 2009-08-23 10:54:59 ----D---- C:\Windows\Minidump 2009-08-23 10:49:48 ----SHD---- C:\Config.Msi 2009-08-23 10:48:25 ----A---- C:\Windows\system32\occache.dll 2009-08-23 10:48:25 ----A---- C:\Windows\system32\jsproxy.dll 2009-08-23 10:48:24 ----A---- C:\Windows\system32\msfeedsbs.dll 2009-08-23 10:48:24 ----A---- C:\Windows\system32\msfeeds.dll 2009-08-23 10:48:24 ----A---- C:\Windows\system32\ieui.dll 2009-08-23 10:48:24 ----A---- C:\Windows\system32\iesetup.dll 2009-08-23 10:48:24 ----A---- C:\Windows\system32\iepeers.dll 2009-08-23 10:48:23 ----A---- C:\Windows\system32\wininet.dll 2009-08-23 10:48:23 ----A---- C:\Windows\system32\iernonce.dll 2009-08-23 10:48:22 ----A---- C:\Windows\system32\urlmon.dll 2009-08-23 10:48:22 ----A---- C:\Windows\system32\msfeedssync.exe 2009-08-23 10:48:22 ----A---- C:\Windows\system32\ieUnatt.exe 2009-08-23 10:48:22 ----A---- C:\Windows\system32\iesysprep.dll 2009-08-23 10:48:22 ----A---- C:\Windows\system32\iertutil.dll 2009-08-23 10:48:22 ----A---- C:\Windows\system32\iedkcs32.dll 2009-08-23 10:48:22 ----A---- C:\Windows\system32\ie4uinit.exe 2009-08-23 10:48:20 ----A---- C:\Windows\system32\ieframe.dll 2009-08-23 10:48:19 ----A---- C:\Windows\system32\mshtml.dll 2009-08-23 10:46:24 ----A---- C:\Windows\system32\mshtmler.dll 2009-08-23 10:46:24 ----A---- C:\Windows\system32\mshtmled.dll 2009-08-23 10:46:24 ----A---- C:\Windows\system32\icardie.dll 2009-08-23 10:46:24 ----A---- C:\Windows\system32\admparse.dll 2009-08-23 10:46:23 ----A---- C:\Windows\system32\msls31.dll 2009-08-23 10:46:23 ----A---- C:\Windows\system32\imgutil.dll 2009-08-23 10:46:23 ----A---- C:\Windows\system32\ieakeng.dll 2009-08-23 10:46:23 ----A---- C:\Windows\system32\dxtmsft.dll 2009-08-23 10:46:23 ----A---- C:\Windows\system32\corpol.dll 2009-08-23 10:46:22 ----A---- C:\Windows\system32\licmgr10.dll 2009-08-23 10:46:22 ----A---- C:\Windows\system32\inseng.dll 2009-08-23 10:46:22 ----A---- C:\Windows\system32\ieaksie.dll 2009-08-23 10:46:22 ----A---- C:\Windows\system32\dxtrans.dll 2009-08-23 10:46:21 ----A---- C:\Windows\system32\WinFXDocObj.exe 2009-08-23 10:46:21 ----A---- C:\Windows\system32\wextract.exe 2009-08-23 10:46:21 ----A---- C:\Windows\system32\webcheck.dll 2009-08-23 10:46:21 ----A---- C:\Windows\system32\mstime.dll 2009-08-23 10:46:21 ----A---- C:\Windows\system32\msrating.dll 2009-08-23 10:46:21 ----A---- C:\Windows\system32\ieakui.dll 2009-08-23 10:46:20 ----A---- C:\Windows\system32\pngfilt.dll 2009-08-23 10:46:20 ----A---- C:\Windows\system32\advpack.dll 2009-08-23 10:46:19 ----A---- C:\Windows\system32\ieapfltr.dll 2009-08-23 10:46:17 ----A---- C:\Windows\system32\vbscript.dll 2009-08-23 10:46:17 ----A---- C:\Windows\system32\url.dll 2009-08-23 10:46:17 ----A---- C:\Windows\system32\jscript.dll 2009-08-23 10:46:16 ----A---- C:\Windows\system32\mshta.exe 2009-08-23 10:46:16 ----A---- C:\Windows\system32\iexpress.exe 2009-08-23 10:46:15 ----A---- C:\Windows\system32\SetIEInstalledDate.exe 2009-08-23 10:46:15 ----A---- C:\Windows\system32\SetDepNx.exe 2009-08-23 10:46:15 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe 2009-08-23 10:46:15 ----A---- C:\Windows\system32\PDMSetup.exe 2009-08-23 10:42:48 ----D---- C:\Program Files\Saal Fotobuch 2009-08-23 10:27:25 ----D---- C:\Program Files\CCleaner 2009-08-22 17:10:11 ----D---- C:\Windows\system32\URTTEMP 2009-08-22 12:52:16 ----D---- C:\ProgramData\Backup 2009-08-22 12:51:45 ----A---- C:\Windows\system32\HHActiveX.dll 2009-08-22 12:51:30 ----D---- C:\Users\***\AppData\Roaming\Panda Security 2009-08-22 12:51:30 ----D---- C:\ProgramData\Panda Security 2009-08-22 12:51:30 ----D---- C:\Program Files\Panda Security 2009-08-22 11:25:38 ----D---- C:\Program Files\Common Files\Panda Security 2009-08-22 10:37:16 ----D---- C:\Users\***\AppData\Roaming\ICQ 2009-08-22 10:35:00 ----D---- C:\Program Files\ICQ6.5 2009-08-22 08:15:48 ----D---- C:\Users\***\AppData\Roaming\Malwarebytes 2009-08-22 08:15:40 ----D---- C:\ProgramData\Malwarebytes 2009-08-22 08:15:40 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2009-08-22 07:27:42 ----A---- C:\Windows\system32\EncDec.dll 2009-08-22 07:27:38 ----A---- C:\Windows\system32\psisdecd.dll 2009-08-22 07:24:22 ----A---- C:\Windows\system32\wdigest.dll 2009-08-22 07:24:22 ----A---- C:\Windows\system32\kerberos.dll 2009-08-22 07:24:21 ----A---- C:\Windows\system32\schannel.dll 2009-08-22 07:24:21 ----A---- C:\Windows\system32\msv1_0.dll 2009-08-22 07:24:21 ----A---- C:\Windows\system32\lsasrv.dll 2009-08-22 07:24:20 ----A---- C:\Windows\system32\secur32.dll 2009-08-22 07:24:20 ----A---- C:\Windows\system32\lsass.exe 2009-08-21 16:46:04 ----D---- C:\ProgramData\Avira 2009-08-16 16:45:56 ----D---- C:\Users\***\AppData\Roaming\Mozilla 2009-08-16 16:45:47 ----D---- C:\Program Files\Mozilla Firefox 2009-08-16 16:37:34 ----A---- C:\Windows\system32\t2embed.dll 2009-08-16 16:37:33 ----A---- C:\Windows\system32\fontsub.dll 2009-08-16 16:37:33 ----A---- C:\Windows\system32\dciman32.dll 2009-08-16 16:37:33 ----A---- C:\Windows\system32\atmfd.dll 2009-08-16 16:37:30 ----A---- C:\Windows\system32\winhttp.dll 2009-08-16 16:37:25 ----A---- C:\Windows\system32\atl.dll 2009-08-16 16:37:21 ----A---- C:\Windows\system32\xolehlp.dll 2009-08-16 16:37:21 ----A---- C:\Windows\system32\msdtcprx.dll 2009-08-16 16:37:19 ----A---- C:\Windows\system32\wkssvc.dll 2009-08-16 16:37:16 ----A---- C:\Windows\system32\mstscax.dll 2009-08-16 16:37:13 ----A---- C:\Windows\system32\localspl.dll 2009-08-16 16:37:10 ----A---- C:\Windows\system32\avifil32.dll 2009-08-16 16:37:03 ----A---- C:\Windows\system32\rpcss.dll 2009-08-16 16:37:03 ----A---- C:\Windows\system32\ntoskrnl.exe 2009-08-16 16:37:03 ----A---- C:\Windows\system32\ntkrnlpa.exe 2009-08-16 16:37:02 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe 2009-08-16 16:37:01 ----A---- C:\Windows\system32\sdohlp.dll 2009-08-16 16:37:01 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll 2009-08-16 16:37:01 ----A---- C:\Windows\system32\iasrecst.dll 2009-08-16 16:37:01 ----A---- C:\Windows\system32\iashost.exe 2009-08-16 16:37:01 ----A---- C:\Windows\system32\iasdatastore.dll 2009-08-16 16:37:01 ----A---- C:\Windows\system32\iasads.dll 2009-08-16 16:36:57 ----A---- C:\Windows\system32\kernel32.dll 2009-08-16 16:36:56 ----A---- C:\Windows\system32\apilogen.dll 2009-08-16 16:36:56 ----A---- C:\Windows\system32\amxread.dll 2009-08-16 16:36:30 ----A---- C:\Windows\system32\wmpdxm.dll 2009-08-16 16:36:30 ----A---- C:\Windows\system32\wmp.dll 2009-08-16 16:36:29 ----A---- C:\Windows\system32\spwmp.dll 2009-08-16 16:36:28 ----A---- C:\Windows\system32\dxmasf.dll 2009-08-16 16:36:27 ----A---- C:\Windows\system32\wmploc.DLL 2009-08-16 16:36:17 ----A---- C:\Windows\system32\rpcrt4.dll 2009-07-29 19:11:50 ----D---- C:\Program Files\dm 2009-07-29 11:09:14 ----D---- C:\Program Files\Lionhead Studios Ltd ======List of files/folders modified in the last 1 months====== 2009-08-23 11:09:39 ----D---- C:\Windows\Temp 2009-08-23 11:09:31 ----D---- C:\Windows\rescache 2009-08-23 11:02:20 ----RD---- C:\Program Files 2009-08-23 11:01:57 ----D---- C:\Windows\System32 2009-08-23 11:01:57 ----A---- C:\Windows\system32\PerfStringBackup.INI 2009-08-23 11:01:56 ----D---- C:\Windows\inf 2009-08-23 10:54:59 ----D---- C:\Windows 2009-08-23 10:52:38 ----D---- C:\Windows\system32\migration 2009-08-23 10:52:37 ----D---- C:\Windows\system32\de-DE 2009-08-23 10:52:37 ----D---- C:\Program Files\Internet Explorer 2009-08-23 10:52:33 ----D---- C:\Windows\system32\en-US 2009-08-23 10:52:33 ----D---- C:\Windows\PolicyDefinitions 2009-08-23 10:51:22 ----SHD---- C:\Windows\Installer 2009-08-23 10:51:16 ----D---- C:\Windows\Registration 2009-08-23 10:48:59 ----D---- C:\Windows\winsxs 2009-08-23 10:48:50 ----D---- C:\Windows\system32\catroot 2009-08-23 10:48:05 ----D---- C:\Windows\system32\catroot2 2009-08-23 10:45:48 ----SHD---- C:\System Volume Information 2009-08-23 10:43:24 ----RSD---- C:\Windows\assembly 2009-08-23 10:30:35 ----D---- C:\Windows\system32\drivers 2009-08-23 10:29:59 ----D---- C:\Windows\Debug 2009-08-23 10:14:03 ----D---- C:\Windows\Microsoft.NET 2009-08-23 10:09:36 ----D---- C:\Windows\ehome 2009-08-23 10:09:30 ----D---- C:\Program Files\Spybot - Search & Destroy 2009-08-23 10:09:30 ----A---- C:\Windows\DUMP4346.tmp 2009-08-23 10:05:15 ----D---- C:\ProgramData\Spybot - Search & Destroy 2009-08-23 10:03:55 ----HD---- C:\Program Files\InstallShield Installation Information 2009-08-23 10:00:47 ----HD---- C:\ProgramData 2009-08-23 09:57:29 ----D---- C:\Program Files\Microsoft Works 2009-08-23 09:56:53 ----D---- C:\ProgramData\Microsoft Help 2009-08-22 17:28:41 ----D---- C:\Windows\system32\Tasks 2009-08-22 12:59:12 ----A---- C:\Windows\win.ini 2009-08-22 11:25:38 ----D---- C:\Program Files\Common Files 2009-08-22 11:25:15 ----D---- C:\Windows\Prefetch 2009-08-22 09:55:15 ----SD---- C:\Users\***\AppData\Roaming\Microsoft 2009-08-21 16:32:58 ----D---- C:\Program Files\Common Files\Symantec Shared Geändert von dieotti (23.08.2009 um 10:38 Uhr) |
Themen zu probleme mit avira, schwerwiegende fehlermeldung |
antivir guard, avira, bho, bildschirm, browser, controlcenter, desktop, disabletaskmgr, fehler, firefox, hijack, hijackthis, home, home premium, installation, internet, internet explorer, langsam, launch, logfile, menu.exe, mozilla, programdata, programm, registry, sehr langsam, senden, sich automatisch, software, symantec, system, updates, vista, windows-sicherheitscenter, wscript.exe |