Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Antimalware Doctor und Security Suite (https://www.trojaner-board.de/90100-antimalware-doctor-security-suite.html)

laevalalala 27.08.2010 13:44

Hallo,

Ich habe mir die obengenannten Viren eingefangen, mein Pc zeigt somit ständig neue Fenster etc auf und es lässt sich kaum mehr was öffnen.
Wenn ich aber die Ergebnisse von dem Scan kopieren will, schließt sich das Fenster sofort. Ich denke das hat ebenfalls mit dem Virus zu tun.
Wie soll' ich weiter vor gehen?

und das hier kommt nachdem ich meinen Pc gestartet habe:
Fehler beim Laden von
C:\Users\....name..\AppData\Local\Temp\sshnas21.dll

Das angegebene Modul wurde nicht gefunden

john.doe 27.08.2010 16:20

Hallo und :hallo:

Klicke auf "Für alle Neuen" in meiner Signatur, lies alles aufmerksam und arbeite die Liste unter Punkt 2 (nur Alternative B) ab. Poste alle Logs hier hinein.

ciao, andreas

laevalalala 27.08.2010 16:41

Das Problem ist nur, dass ich keinen Log posten kann, da sich ein Fenster öffnet "Security Warning": Application cannot be executed. The file otl.exe is infected. Do you want to activate software now?
Dies Warnung kommt bei den meisten Fenstern, die ich öffnen möchte.

john.doe 27.08.2010 16:59

Mmh. Diese Meldung ist ein Fake. Lässt die sich abbrechen?

Ich brauche irgendwie die Namen der Prozesse, die bei dir laufen. Falls alles andere nicht funktioniert, dann:

[Strg][Alt][Entf] => Taskmanager => Karte Prozesse => Alle Namen notieren und hier posten

ciao, andreas

laevalalala 27.08.2010 17:03

Man kann auf "ja" oder "nein" drücken
ok, dann versuch ich's mal damit...

laevalalala 27.08.2010 17:05

hm okay, wenn ich den Task-Manager öffnen will, besteht das gleiche Problem...bis jetzt habe ich immer auf "nein" gedrückt...

john.doe 27.08.2010 17:05

Klick auf Nein. Immer. ;)

ciao, andreas

laevalalala 27.08.2010 17:08

Okay, aber dann lässt sich der Taskmanager auch nicht öffnen :/

john.doe 27.08.2010 17:19

Liste der Anhänge anzeigen (Anzahl: 1)
Nächster Versuch: Lade dir den Anhang auf deinen Desktop und starte ihn mit Doppelklick. Danach hast du ein neues Symbol mit Namen laevalalala oder laevalalala.txt. Den auch mit Doppelklick öffnen und den kompletten Text hier posten (reinschreiben).

ciao, andreas

laevalalala 27.08.2010 17:35

Nichtmal das lässt sich öffnen :/ nur ganz kurz, ich habe das jetzt glaube ich per "Druck" taste kopieren können, finde aber jetzt kein programm, in das ich die Datei einfügen kann...

john.doe 27.08.2010 17:46

Zitat:

nur ganz kurz
Ist auch richtig so. Guck mal auf deinen Desktop. Da muss ein neues Symbol sein mit Namen laevalalala oder laevalalala.txt. Da ein Doppelklick drauf, es öffnet sich der Editor und den kompletten Text hier posten (reinschreiben).

ciao, andreas

laevalalala 27.08.2010 17:49

Lösung gefunden :
[IMG]http://s10.directupload.net/images/1...p/pxfi2fzz.png[/IMG]

laevalalala 27.08.2010 17:53

den ersten teil konnte ich auch von der logdatei von malwarebytes aufschnappen...falls einem das bringt:[IMG]http://s5.directupload.net/images/10...p/hc8wuqyo.png[/IMG]

john.doe 27.08.2010 17:57

Wo ist meine Lupe? :confused:

Womit habe ich das verdient, ich habe weder Vater noch Mutter erschlagen. :heulen:

1a) Sollte der Editor noch auf sein, wähle ihn unten in der Taskleiste an.

1b) Falls nicht, noch einmal Doppelklick auf laevalalala oder laevalalala.txt

2.) [Strg]a (alles wird markiert)

3.) [Strg]c (nichts passiert)

4.) Wechsel zum Trojanerboard und klicke in den großen weißen Kasten zum Schreiben.

5.) [Strg]v (Text erscheint)

ciao, andreas

laevalalala 27.08.2010 18:01

der editor bleibt nicht offen :/ der schließt sich von alleine...aber ich kann nochmal versuchen das bild in originalgröße zu posten

laevalalala 27.08.2010 18:03

http://s10.directupload.net/images/100827/6ohq55mc.png


http://s5.directupload.net/images/100827/hc8wuqyo.png

john.doe 27.08.2010 18:19

Und nächster Versuch.

1.) Rolle das Fenster solange nach unten, bis du den Knopf Anhänge verwalten siehst.

2.) Klicke auf Anhänge verwalten.

3.) Klicke auf Auswählen.

4.) Klicke auf Desktop.

5.) Doppelklicke auf laevalalala.

6.) Klicke auf Hochladen.

7.) Klicke auf Fenster schließen (bei dem kleinen Fenster).

ciao, andreas

laevalalala 27.08.2010 18:28

*runterscroll* hmm wo genau finde ich den Knopf "Anhänge verwalten":confused:

laevalalala 27.08.2010 18:29

ahaaa gefunden ;)

john.doe 27.08.2010 18:35

:applaus: Bin voll stolz auf dich. :)

Jetzt klicke bei Malwarebytes auf "Ausgewählte Entfernen".

ciao, andreas

laevalalala 27.08.2010 18:49

nachdem ich einen scan gemacht habe?

john.doe 27.08.2010 18:51

Der Scan war doch schon fertig, sonst wäre das Log nicht gekommen. Das Log bitte hier posten (kein Screenshot!).

ciao, andreas

laevalalala 27.08.2010 18:54

jaa das schon, aber da is das problem wieder, dass ich den log net aufbekommen :( das wird immer gleich geschlossen und dann kommt wieder dieses fenster...
sind die dateien auch irgendwo gespeichert, sodass ich sie anhängen kann?

john.doe 27.08.2010 19:18

Du findest das Log im Ordner:
Zitat:

C:\Dokumente und Einstellungen\[Dein Anmeldename]\Eigene Dateien\Anwendungsdaten\Malwarebytes\Malwarebytes' Anti-Malware\Logs
ciao, andreas

laevalalala 27.08.2010 19:33

ahh ich dreh hier noch durch :D
noch ein problem, ich komm nicht auf dokumente und einstellungen..der zugriff wurde mir verweigert...und die datei "eigene dateien" zB sind auch alle "durchsichtiger hinterlegt...
komplizierte sache :D

john.doe 27.08.2010 20:12

Liste der Anhänge anzeigen (Anzahl: 1)
Lade dir den Anhang auf deinen Desktop und starte ihn mit Doppelklick. Danach ist (hoffentlich) eine Datei mit Namen mbam-log-2010-.... auf deinem Desktop.

ciao, andreas

laevalalala 27.08.2010 20:20

sind sogar 3 :D
ich hab den quick scan nochmal gemacht...ich lade einfach mal alle hoch...

john.doe 27.08.2010 20:28

Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Datenbank Version: 3986

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

14.04.2010 17:32:32
mbam-log-2010-04-14 (17-32-32).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 284088
Laufzeit: 3 Stunde(n), 16 Minute(n), 38 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 4
Infizierte Registrierungswerte: 2
Infizierte Dateiobjekte der Registrierung: 3
Infizierte Verzeichnisse: 0
Infizierte Dateien: 7

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\WEK9EMDHI9 (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yvibbbha8c (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\canaveral (Trojan.Downloader) -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: c:\windows\system32\sdra64.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: system32\sdra64.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\Windows\system32\userinit.exe,C:\Windows\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
C:\Users\Eva-Maria\AppData\Local\Temp\Dfz.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully.
C:\Users\Eva-Maria\AppData\Roaming\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.
C:\Users\Eva-Maria\Downloads\Down.by.the.riverside.piano.sheet.music.pdf.52007.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully.
C:\Users\Eva-Maria\AppData\Local\Temp\Df1.exe (Trojan.FakeAlert) -> Delete on reboot.
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\sdra64.exe (Spyware.Zbot) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
------
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Datenbank Version: 3986

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

15.04.2010 18:36:12
mbam-log-2010-04-15 (18-36-12).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 272439
Laufzeit: 1 Stunde(n), 55 Minute(n), 22 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 3
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 1

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\WEK9EMDHI9 (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wek9emdhi9 (Trojan.Agent) -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
----
Eieiei, Z-Bot, wenn wir fertig sind musst du alle deine Kennwörter ändern.

So, und jetzt die beiden Logs von OTL.

ciao, andreas

laevalalala 27.08.2010 20:34

alle meine kennwörter ?
na super :D okay...
aber ich kann otl immer noch nicht öffnen...

john.doe 27.08.2010 20:38

Zitat:

aber ich kann otl immer noch nicht öffnen...
Was genau passiert denn, wenn du ein Doppelklick auf OTL machst?

ciao, andreas

laevalalala 27.08.2010 20:42

Es kommt wieder die" Security Warning" (Application cannot be executed...the file is infected...)

john.doe 27.08.2010 20:45

:confused: Kannst du von der Meldung bitte ein Screenshot machen und hier posten.

ciao, andreas

laevalalala 27.08.2010 21:12

http://s7.directupload.net/images/100827/woarbi2y.png

so wie's ausschaut ist Antimalware Doctor schon entfernt...aber dieses Security Suite, das einem alles verbietet eben noch nicht...

john.doe 27.08.2010 21:17

Arbeite diese Anleitung ab => http://www.trojaner-board.de/83172-a...tml#post505216

ciao, andreas

laevalalala 27.08.2010 21:38

ahaaa super ,sieht doch schon besser aus!OTL Logfile:
Code:

OTL logfile created on: 27.08.2010 22:31:49 - Run 3
OTL by OldTimer - Version 3.2.1.1    Folder = C:\Users\Eva-Maria\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 48,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 78,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 312,68 Gb Free Space | 68,57% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: EVA-MARIAS-PC
Current User Name: Eva-Maria
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Eva-Maria\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Programme\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Programme\Lavasoft\Ad-Aware\AAWWSC.exe ()
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
PRC - C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Programme\EgisTec\MyWinLocker 3\x86\MWLService.exe (Egis Technology Inc.)
PRC - C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
PRC - C:\Programme\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Programme\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
PRC - C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
PRC - C:\Programme\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
PRC - C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
PRC - C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
PRC - C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Eva-Maria\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (MpfService) --  File not found
SRV - (McSysmon) --  File not found
SRV - (McShield) --  File not found
SRV - (McNASvc) --  File not found
SRV - (McAfee SiteAdvisor Service) --  File not found
SRV - (GoogleDesktopManager-051210-111108) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ICQ Service) -- C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (ePowerSvc) -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Acer Incorporated)
SRV - (MWLService) -- C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe ()
SRV - (NTI IScheduleSvc) -- C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (CLHNService) -- C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
SRV - (NTISchedulerSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.)
SRV - (NTIBackupSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (Lbd) -- C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MBAMSwissArmy) -- C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (NTIDrvr) -- C:\Windows\System32\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (ss_bmdm) -- C:\Windows\System32\drivers\ss_bmdm.sys (MCCI Corporation)
DRV - (ss_bbus) SAMSUNG USB Mobile Device (WDM) -- C:\Windows\System32\drivers\ss_bbus.sys (MCCI)
DRV - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) -- C:\Windows\System32\drivers\ss_bmdfl.sys (MCCI Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (RTHDMIAzAudService) -- C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (mwlPSDVDisk) -- C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Incorporated.)
DRV - (mwlPSDFilter) -- C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Incorporated.)
DRV - (mwlPSDNServ) -- C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Incorporated.)
DRV - (RTSTOR) -- C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (k57nd60x) Broadcom NetLink (TM) -- C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (UBHelper) -- C:\Windows\System32\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (NSCIRDA) -- C:\Windows\System32\drivers\nscirda.sys (National Semiconductor Corporation)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (DKbFltr) -- C:\Windows\System32\drivers\DKbFltr.sys (Dritek System Inc.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0709&m=aspire_7735
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0709&m=aspire_7735
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: "foxsearch"
FF - prefs.js..browser.search.defaulturl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.order.1: "foxsearch"
FF - prefs.js..browser.search.selectedEngine: "foxsearch"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {64e8cc5b-20db-4212-8320-178fc5ae71f7}:1.0
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.3
FF - prefs.js..extensions.enabledItems: silvermelxt@pardal.de:1.3.5
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.10
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100119091315
FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.12.0.36949
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: gutscheinmieze@synatix-gmbh.de:1.03
FF - prefs.js..extensions.enabledItems: ifamebook@stormvision.it:1.1
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {961408A3-C970-4577-970A-D97C29839A67}:1.3.5
FF - prefs.js..keyword.URL: "hxxp://search.sweetim.com/search.asp?src=2&q="
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "hxxp://search.sweetim.com/search.asp?src=2&q="
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2010.01.24 22:22:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.07.09 09:02:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.27 11:51:52 | 000,000,000 | ---D | M]
 
[2009.09.16 16:48:47 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Extensions
[2010.08.27 13:21:50 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions
[2010.05.26 20:22:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.05.26 20:22:22 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010.02.17 16:03:04 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010.01.13 00:20:21 | 000,000,000 | ---D | M] (FaceMod Dislike Button) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
[2010.08.27 13:21:39 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010.08.27 13:21:50 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010.08.27 12:52:28 | 000,000,000 | ---D | M] (Charamel) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{961408A3-C970-4577-970A-D97C29839A67}
[2010.07.22 13:54:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.08.27 13:21:38 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.03.06 10:57:33 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2010.03.23 18:12:41 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\gutscheinmieze@synatix-gmbh.de
[2010.06.22 22:34:23 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\ifamebook@stormvision.it
[2009.09.30 12:16:35 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\moveplayer@movenetworks.com
[2010.05.26 20:22:28 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\personas@christopher.beard
[2010.08.27 13:21:49 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\piclens@cooliris.com
[2010.08.27 13:21:39 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\silvermelxt@pardal.de
[2010.08.27 09:50:56 | 000,000,950 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\jy1c4yrj.default\searchplugins\icqplugin-1.xml
[2010.01.19 21:17:07 | 000,000,961 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\jy1c4yrj.default\searchplugins\icqplugin-2.xml
[2010.03.14 12:53:30 | 000,000,950 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\jy1c4yrj.default\searchplugins\icqplugin-3.xml
[2010.03.23 18:16:42 | 000,000,950 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\jy1c4yrj.default\searchplugins\icqplugin-4.xml
[2010.04.16 14:54:52 | 000,000,950 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\jy1c4yrj.default\searchplugins\icqplugin-5.xml
[2010.04.27 11:53:09 | 000,000,950 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\jy1c4yrj.default\searchplugins\icqplugin-6.xml
[2008.07.10 14:07:28 | 000,000,944 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\jy1c4yrj.default\searchplugins\icqplugin.xml
[2009.12.03 21:51:36 | 000,003,915 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\jy1c4yrj.default\searchplugins\sweetim.xml
[2010.03.28 17:45:22 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.01.19 21:07:05 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.03.23 18:14:51 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.04.11 00:34:04 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
[2010.03.19 10:23:30 | 000,686,592 | ---- | M] (Synatix GmbH) -- C:\Programme\Mozilla Firefox\plugins\npmieze.dll
[2010.03.14 12:53:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.03.14 12:53:00 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.03.23 18:12:42 | 000,000,143 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\foxsearch.src
[2010.03.14 12:53:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.03.14 12:53:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.03.14 12:53:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.04.27 12:04:01 | 000,002,779 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 217.23.15.139 www.google.com
O1 - Hosts: 217.23.15.139 google.com
O1 - Hosts: 217.23.15.139 google.com.au
O1 - Hosts: 217.23.15.139 www.google.com.au
O1 - Hosts: 217.23.15.139 google.be
O1 - Hosts: 217.23.15.139 www.google.be
O1 - Hosts: 217.23.15.139 google.com.br
O1 - Hosts: 217.23.15.139 www.google.com.br
O1 - Hosts: 39 more lines...
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - C:\Users\Eva-Maria\AppData\Roaming\Gutscheinmieze\toolbar.dll (Synatix GmbH)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - C:\Users\Eva-Maria\AppData\Roaming\Gutscheinmieze\toolbar.dll (Synatix GmbH)
O4 - HKLM..\Run: [Acer ePower Management] C:\Programme\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Acer Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AmIcoSinglun] C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcadeDeluxeAgent] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [EgisTecLiveUpdate] C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [LManager] C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mwlDaemon] C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [NPSStartup]  File not found
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Programme\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [{026A48E8-B136-82F6-C076-D1511E1BA01D}] C:\Users\Eva-Maria\AppData\Roaming\Biim\hiak.exe ()
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [Metropolis] C:\Users\EVA-MA~1\AppData\Local\Temp\sshnas21.DLL File not found
O4 - HKCU..\Run: [newsecureapp70700.exe] C:\Users\Eva-Maria\AppData\Roaming\9F7CB0D6ABC204D4F42E15EE8D7D4089\newsecureapp70700.exe (MS)
O4 - HKCU..\Run: [rnoymcxs] C:\Users\Eva-Maria\AppData\Local\fynqpggca\dgpbjvtshdw.exe ()
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKCU..\Run: [XBV6RD5SZF] C:\Users\EVA-MA~1\AppData\Local\Temp\Df1.exe (ApexDC++ Development Team)
O4 - Startup: C:\Users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Eva-Maria\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Programme\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Eva-Maria\Pictures\2010\Sonnenrot\37544_139724646055413_111409868886891_321838_7061603_n.jpg
O24 - Desktop BackupWallPaper: C:\Users\Eva-Maria\Pictures\2010\Sonnenrot\37544_139724646055413_111409868886891_321838_7061603_n.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.08.27 20:06:12 | 000,603,648 | ---- | C] (OldTimer Tools) -- C:\Users\Eva-Maria\Desktop\OTL.exe
[2010.08.27 09:33:42 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Local\fynqpggca
[2010.08.27 09:33:24 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Local\Windows
[2010.08.27 09:33:23 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Local\Windows Server
[2010.08.27 09:33:14 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Roaming\9F7CB0D6ABC204D4F42E15EE8D7D4089
[2010.08.26 10:37:56 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\temp
[2010.08.25 16:26:51 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\Microsoft
[2010.08.14 14:39:26 | 000,081,920 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2010.08.14 14:39:22 | 002,037,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2010.08.14 14:39:13 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010.08.14 14:39:13 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll
[2010.08.14 14:39:12 | 000,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2010.08.14 14:39:09 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll
[2010.08.14 14:38:56 | 003,600,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010.08.14 14:38:54 | 003,548,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2009.07.21 10:28:54 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010.08.27 22:33:44 | 004,980,736 | -HS- | M] () -- C:\Users\Eva-Maria\ntuser.dat
[2010.08.27 22:30:30 | 000,040,448 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\OTLSrv.exe
[2010.08.27 22:24:02 | 000,001,134 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1313689582-3900863286-3496430324-1000UA.job
[2010.08.27 22:18:05 | 000,000,300 | -H-- | M] () -- C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010.08.27 22:17:57 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010.08.27 22:17:52 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.08.27 22:17:52 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.08.27 22:17:49 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.08.27 22:17:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.08.27 22:16:26 | 000,524,288 | -HS- | M] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.08.27 22:16:26 | 000,065,536 | -HS- | M] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.08.27 22:16:22 | 003,972,002 | -H-- | M] () -- C:\Users\Eva-Maria\AppData\Local\IconCache.db
[2010.08.27 21:51:49 | 000,409,387 | ---- | M] () -- C:\Users\Eva-Maria\Documents\IMG_27082010_214730.png
[2010.08.27 21:42:00 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010.08.27 20:58:41 | 000,000,566 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Eva-Maria.job
[2010.08.27 19:39:37 | 000,006,836 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Local\d3d9caps.dat
[2010.08.27 18:26:19 | 000,000,030 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\ListMirMalDieProzesse.bat
[2010.08.27 18:24:00 | 000,001,082 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1313689582-3900863286-3496430324-1000Core.job
[2010.08.27 16:13:04 | 000,139,264 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.27 10:03:12 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.08.25 16:42:53 | 000,071,337 | ---- | M] () -- C:\Users\Eva-Maria\Documents\rockamsee.odt
[2010.08.25 16:32:12 | 000,603,648 | ---- | M] (OldTimer Tools) -- C:\Users\Eva-Maria\Desktop\OTL.exe
[2010.08.25 16:32:11 | 000,363,520 | ---- | M] (Freakhouse Multimedia GmbH) -- C:\Users\Eva-Maria\Desktop\Klick.exe
[2010.08.25 16:30:21 | 000,131,584 | --S- | M] () -- C:\Users\Eva-Maria\AppData\Local\activedsv.exe
[2010.08.21 16:01:40 | 000,002,109 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\Google Chrome.lnk
[2010.08.19 21:05:43 | 000,185,311 | ---- | M] () -- C:\Users\Eva-Maria\trinkspiel.jpg
[2010.08.17 18:25:07 | 000,002,784 | ---- | M] () -- C:\Users\Eva-Maria\.recently-used.xbel
[2010.08.17 15:08:59 | 000,001,036 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\DVDVideoSoft Free Studio.lnk
[2010.08.17 13:05:38 | 204,054,216 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010.08.15 16:23:56 | 000,327,640 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.08.27 22:18:01 | 000,000,300 | -H-- | C] () -- C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010.08.27 21:51:46 | 000,409,387 | ---- | C] () -- C:\Users\Eva-Maria\Documents\IMG_27082010_214730.png
[2010.08.27 21:40:35 | 000,040,448 | ---- | C] () -- C:\Users\Eva-Maria\Desktop\OTLSrv.exe
[2010.08.27 18:26:18 | 000,000,030 | ---- | C] () -- C:\Users\Eva-Maria\Desktop\ListMirMalDieProzesse.bat
[2010.08.25 16:42:50 | 000,071,337 | ---- | C] () -- C:\Users\Eva-Maria\Documents\rockamsee.odt
[2010.08.19 21:05:43 | 000,185,311 | ---- | C] () -- C:\Users\Eva-Maria\trinkspiel.jpg
[2010.08.17 18:25:07 | 000,002,784 | ---- | C] () -- C:\Users\Eva-Maria\.recently-used.xbel
[2010.07.19 21:07:50 | 000,000,024 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Roaming\vdnxlf.dat
[2010.04.26 20:49:01 | 000,000,032 | ---- | C] () -- C:\Windows\wininit.ini
[2010.04.20 18:40:12 | 000,000,100 | --S- | C] () -- C:\Users\Eva-Maria\AppData\Local\1711337819.dat
[2010.04.14 12:55:09 | 000,000,552 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\d3d8caps.dat
[2010.03.23 18:30:47 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.01.07 12:13:38 | 000,151,008 | ---- | C] () -- C:\Users\Eva-Maria\Orial Bold.ttf
[2010.01.05 22:54:27 | 000,000,088 | ---- | C] () -- C:\Users\Eva-Maria\VISIT DIRT2.COM FOR USAGE.txt
[2010.01.05 22:54:20 | 000,008,128 | ---- | C] () -- C:\Users\Eva-Maria\little bliss bold.otf
[2010.01.05 22:52:41 | 000,008,280 | ---- | C] () -- C:\Users\Eva-Maria\little bliss.otf
[2010.01.05 22:25:26 | 000,011,496 | ---- | C] () -- C:\Users\Eva-Maria\little bliss bold.ttf
[2010.01.05 11:53:00 | 000,050,566 | ---- | C] () -- C:\Users\Eva-Maria\littlebliss.jpg
[2010.01.05 11:33:10 | 000,011,528 | ---- | C] () -- C:\Users\Eva-Maria\little bliss.ttf
[2009.12.24 23:46:26 | 000,001,089 | ---- | C] () -- C:\Users\Eva-Maria\ScriptSERIF - READ ME.txt
[2009.12.23 15:46:43 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2009.12.23 15:46:43 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2009.12.23 15:36:08 | 000,113,152 | ---- | C] () -- C:\Users\Eva-Maria\1031.MST
[2009.12.23 15:36:08 | 000,015,832 | ---- | C] () -- C:\Users\Eva-Maria\0x0407.ini
[2009.12.23 15:35:58 | 097,979,392 | ---- | C] () -- C:\Users\Eva-Maria\Samsung New PC Studio.msi
[2009.12.22 20:40:18 | 000,298,828 | ---- | C] () -- C:\Users\Eva-Maria\script_serif.ttf
[2009.12.22 20:30:56 | 000,280,209 | ---- | C] () -- C:\Users\Eva-Maria\scriptSERIF_sample.jpg
[2009.12.22 20:04:42 | 000,242,864 | ---- | C] () -- C:\Users\Eva-Maria\script_serif_riptrash.ttf
[2009.11.15 12:45:44 | 000,537,011 | ---- | C] () -- C:\Users\Eva-Maria\ billy argel beyaond sky font.jpg
[2009.11.15 12:37:34 | 000,516,096 | ---- | C] () -- C:\Users\Eva-Maria\BEYONDSKTRIAL.ttf
[2009.11.15 11:19:36 | 000,000,134 | ---- | C] () -- C:\Users\Eva-Maria\READ ME.txt
[2009.09.24 15:39:01 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.20 11:21:32 | 000,029,696 | -H-- | C] () -- C:\Users\Eva-Maria\photothumb.db
[2009.09.17 13:25:41 | 000,087,349 | ---- | C] () -- C:\Users\Eva-Maria\0405_09780_happy_birthday.jpg
[2009.09.13 01:03:19 | 000,242,200 | ---- | C] () -- C:\Users\Eva-Maria\acer-code.jpg
[2009.09.03 15:46:08 | 000,002,712 | ---- | C] () -- C:\Users\Eva-Maria\JOEBOB graphics free trial font users license.txt
[2009.08.26 08:27:16 | 000,006,836 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\d3d9caps.dat
[2009.08.25 23:47:23 | 000,001,072 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Roaming\wklnhst.dat
[2009.08.22 01:11:33 | 000,139,264 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.08.12 17:41:40 | 004,980,736 | -HS- | C] () -- C:\Users\Eva-Maria\ntuser.dat
[2009.08.12 17:41:40 | 000,524,288 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2009.08.12 17:41:40 | 000,524,288 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2009.08.12 17:41:40 | 000,262,144 | -H-- | C] () -- C:\Users\Eva-Maria\ntuser.dat.LOG1
[2009.08.12 17:41:40 | 000,065,536 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2009.08.12 17:41:40 | 000,000,020 | -HS- | C] () -- C:\Users\Eva-Maria\ntuser.ini
[2009.08.12 17:41:40 | 000,000,000 | -H-- | C] () -- C:\Users\Eva-Maria\ntuser.dat.LOG2
[2009.07.21 10:16:20 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2009.07.21 10:16:20 | 000,011,264 | ---- | C] () -- C:\Windows\System32\atimuixx.dll
[2009.07.21 01:52:22 | 000,000,033 | ---- | C] () -- C:\Windows\LaunApp.ini
[2009.07.21 01:44:57 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini
[2009.07.21 01:44:56 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2009.04.26 15:05:36 | 000,521,608 | ---- | C] () -- C:\Users\Eva-Maria\vtks Deja Vu.ttf
[2009.03.12 12:32:52 | 000,000,028 | ---- | C] () -- C:\Windows\WisLangCode.ini
[2009.03.12 05:26:46 | 000,004,516 | ---- | C] () -- C:\ProgramData\ArcadeDeluxe2.log
[2009.02.11 22:03:58 | 000,872,448 | ---- | C] () -- C:\Windows\iconv.dll
[2009.02.11 22:03:58 | 000,743,424 | ---- | C] () -- C:\Windows\libxml2.dll
[2009.02.11 22:03:57 | 000,000,060 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2008.10.26 15:03:52 | 000,147,604 | ---- | C] () -- C:\Users\Eva-Maria\FPENSTRIAL.ttf
[2008.10.26 15:03:52 | 000,104,352 | ---- | C] () -- C:\Users\Eva-Maria\FPENSTRIAL.otf
[2008.01.21 04:23:43 | 000,131,584 | --S- | C] () -- C:\Users\Eva-Maria\AppData\Local\activedsv.exe
[2008.01.21 04:23:43 | 000,009,232 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\acleditu.dat
[2007.10.25 18:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:25:26 | 000,557,568 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005.12.10 07:56:24 | 000,047,272 | ---- | C] () -- C:\Users\Eva-Maria\FairyDustB.ttf
[2005.10.23 22:46:42 | 000,057,560 | ---- | C] () -- C:\Users\Eva-Maria\Anywhere.ttf
[2005.08.04 09:28:04 | 000,000,286 | ---- | C] () -- C:\Users\Eva-Maria\readme.txt
[2005.08.04 09:23:30 | 000,193,572 | ---- | C] () -- C:\Users\Eva-Maria\kiralynn__.ttf
[2005.05.11 03:39:36 | 000,085,808 | ---- | C] () -- C:\Users\Eva-Maria\MINUS___.TTF
[2005.03.04 19:40:38 | 000,039,648 | ---- | C] () -- C:\Users\Eva-Maria\konanur.ttf
[2004.10.27 20:24:44 | 000,034,788 | ---- | C] () -- C:\Users\Eva-Maria\Flat Earth Scribe.ttf
[2000.07.13 11:12:46 | 000,000,430 | ---- | C] () -- C:\Users\Eva-Maria\font info.txt
[1998.10.01 23:13:48 | 000,084,704 | ---- | C] () -- C:\Users\Eva-Maria\Kelt Caps Freehand.ttf
 
========== LOP Check ==========
 
[2010.04.02 22:48:04 | 000,000,000 | -HSD | M] -- C:\Users\Eva-Maria\AppData\Roaming\.#
[2010.08.27 10:32:51 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\9F7CB0D6ABC204D4F42E15EE8D7D4089
[2009.07.21 01:52:19 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Acer GameZone Console
[2009.09.06 20:05:57 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Biim
[2010.01.17 13:30:12 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Cycle of 5th
[2010.04.14 17:32:31 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Desktopicon
[2010.07.22 13:54:49 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.02.28 14:05:31 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\eSobi
[2010.03.31 00:40:30 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Facebook
[2010.08.17 18:24:16 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\gtk-2.0
[2010.03.23 18:12:41 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Gutscheinmieze
[2010.08.27 22:26:11 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Hyimro
[2010.08.23 15:02:53 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\ICQ
[2010.05.16 21:58:39 | 000,000,000 | -HSD | M] -- C:\Users\Eva-Maria\AppData\Roaming\lowsec
[2009.10.11 11:18:50 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\OpenOffice.org
[2010.05.11 19:29:55 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Osfoyd
[2009.12.23 15:52:06 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\PC Suite
[2010.07.27 11:04:34 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\PhotoScape
[2009.08.12 17:43:26 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\PowerCinema
[2009.12.23 15:46:19 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Samsung
[2009.08.25 23:47:27 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Template
[2010.08.27 22:16:40 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010.08.27 22:18:05 | 000,000,300 | -H-- | M] () -- C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:3B3A35EC
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:A8ADE5D8
< End of report >

--- --- ---

john.doe 27.08.2010 21:57

Es fehlt noch die Datei Extras.txt, die findest du auf dem Desktop.

Solltest du noch irgendetwas mit dem Computer verbinden, wie Memorysticks, Speicherkarten, Digitalkameras, Handy, externe Laufwerke, ... dann stecke vor dem Scan alles an.

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Lade dir ComboFix hier herunter auf deinen Desktop. Benenne es beim Runterladen um in cofi.exe.
http://saved.im/mtm0nzyzmzd5/cofi.jpg
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.
ciao, andreas

laevalalala 27.08.2010 22:58

Combofix Logfile:
Code:

ComboFix 10-08-27.01 - Eva-Maria 27.08.2010  23:37:34.1.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3066.1598 [GMT 2:00]
ausgeführt von:: c:\users\Eva-Maria\Desktop\cofi.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Microsoft\DesktopLayer.exe
c:\users\Eva-Maria\AppData\Local\activedsv.exe
c:\users\Eva-Maria\AppData\Local\fynqpggca
c:\users\Eva-Maria\AppData\Local\fynqpggca\dgpbjvtshdw.exe
c:\users\Eva-Maria\AppData\Local\Windows Server
c:\users\Eva-Maria\AppData\Local\Windows Server\admin.txt
c:\users\Eva-Maria\AppData\Local\Windows Server\flags.ini
c:\users\Eva-Maria\AppData\Local\Windows Server\hlp.dat
c:\users\Eva-Maria\AppData\Local\Windows Server\server.dat
c:\users\Eva-Maria\AppData\Local\Windows Server\uses32.dat
c:\users\Eva-Maria\AppData\Roaming\.#
c:\users\Eva-Maria\AppData\Roaming\.#\MBX@12E8@1CD2928.###
c:\users\Eva-Maria\AppData\Roaming\.#\MBX@12E8@1CD2958.###
c:\users\Eva-Maria\AppData\Roaming\.#\MBX@12E8@1CD2988.###
c:\users\Eva-Maria\AppData\Roaming\.#\MBX@1310@3C2928.###
c:\users\Eva-Maria\AppData\Roaming\.#\MBX@1310@3C2958.###
c:\users\Eva-Maria\AppData\Roaming\.#\MBX@1310@3C2988.###
c:\users\Eva-Maria\AppData\Roaming\9F7CB0D6ABC204D4F42E15EE8D7D4089
c:\users\Eva-Maria\AppData\Roaming\9F7CB0D6ABC204D4F42E15EE8D7D4089\enemies-names.txt
c:\users\Eva-Maria\AppData\Roaming\9F7CB0D6ABC204D4F42E15EE8D7D4089\local.ini
c:\users\Eva-Maria\AppData\Roaming\9F7CB0D6ABC204D4F42E15EE8D7D4089\lsrslt.ini
c:\users\Eva-Maria\AppData\Roaming\9F7CB0D6ABC204D4F42E15EE8D7D4089\newsecureapp70700.exe
c:\users\Eva-Maria\AppData\Roaming\Biim
c:\users\Eva-Maria\AppData\Roaming\Biim\hiak.exe
c:\users\Eva-Maria\AppData\Roaming\Desktopicon
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.drv
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.sys
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\CLSV.dll
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\CLSV.tmp
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.exe
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.sys
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\ddv.dll
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\delfile.exe
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\eb.exe
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\eb.sys
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\energy.sys
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\exec.drv
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\exec.sys
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\exec.tmp
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\fan.drv
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\fix.sys
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\FS.drv
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\FW.drv
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\FW.exe
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\hymt.dll
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\hymt.tmp
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\kernel32.exe
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\kernel32.sys
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\pal.exe
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\PE.drv
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\snl2w.exe
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\tempdoc.dll
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\tempdoc.tmp
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Templates\memory.tmp
c:\windows\system32\PRAGMAsrcr.dat

.
(((((((((((((((((((((((  Dateien erstellt von 2010-07-27 bis 2010-08-27  ))))))))))))))))))))))))))))))
.

2010-08-27 21:45 . 2010-08-27 21:45        --------        d-----w-        c:\users\Default\AppData\Local\temp
2010-08-27 21:24 . 2010-08-27 21:24        --------        d-----w-        c:\program files\CCleaner
2010-08-27 11:21 . 2010-08-18 15:12        52224        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
2010-08-27 11:21 . 2010-08-18 15:12        101376        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
2010-08-27 11:21 . 2010-06-14 10:08        4687872        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-08-27 11:21 . 2010-06-14 10:08        103424        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-08-27 11:21 . 2010-06-14 10:08        4687360        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-08-27 11:21 . 2010-06-14 10:08        545280        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-08-27 11:21 . 2010-06-14 10:08        152064        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-08-27 11:21 . 2010-06-14 10:08        57856        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-08-27 11:21 . 2010-06-14 10:08        425984        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-08-27 07:33 . 2010-08-27 20:20        --------        d-----w-        c:\users\Eva-Maria\AppData\Local\Windows
2010-08-26 08:37 . 2010-08-26 19:35        --------        d-----w-        c:\users\Eva-Maria\temp
2010-08-25 14:26 . 2010-08-26 08:37        --------        d-----w-        c:\users\Eva-Maria\Microsoft
2010-08-14 12:39 . 2010-05-27 20:08        81920        ----a-w-        c:\windows\system32\iccvid.dll
2010-08-14 12:39 . 2010-06-21 13:37        2037760        ----a-w-        c:\windows\system32\win32k.sys
2010-08-14 12:39 . 2010-06-29 15:47        834048        ----a-w-        c:\windows\system32\wininet.dll
2010-08-14 12:39 . 2010-06-28 16:13        78336        ----a-w-        c:\windows\system32\ieencode.dll
2010-08-14 12:39 . 2010-06-11 16:16        274944        ----a-w-        c:\windows\system32\schannel.dll
2010-08-14 12:39 . 2010-06-18 17:31        36864        ----a-w-        c:\windows\system32\rtutils.dll
2010-08-14 12:38 . 2010-06-08 17:35        3600768        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2010-08-14 12:38 . 2010-06-08 17:35        3548040        ----a-w-        c:\windows\system32\ntoskrnl.exe
2010-08-14 12:38 . 2010-06-11 16:15        1248768        ----a-w-        c:\windows\system32\msxml3.dll
2010-08-14 12:38 . 2010-06-18 15:04        302080        ----a-w-        c:\windows\system32\drivers\srv.sys
2010-08-14 12:38 . 2010-06-18 15:04        144896        ----a-w-        c:\windows\system32\drivers\srv2.sys
2010-08-14 12:38 . 2010-06-16 16:04        905088        ----a-w-        c:\windows\system32\drivers\tcpip.sys

.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-27 21:46 . 2009-11-12 21:27        --------        d-----w-        c:\users\Eva-Maria\AppData\Roaming\Hyimro
2010-08-27 21:45 . 2009-08-22 11:37        --------        d-----w-        c:\program files\Microsoft
2010-08-27 21:21 . 2010-03-23 16:15        --------        d-----w-        c:\users\Eva-Maria\AppData\Roaming\Skype
2010-08-27 21:21 . 2010-08-27 21:21        5464        ----a-w-        c:\windows\system32\PerfStringBackup.TMP
2010-08-27 17:41 . 2010-03-23 16:30        --------        d-----w-        c:\users\Eva-Maria\AppData\Roaming\skypePM
2010-08-27 17:39 . 2009-08-26 06:27        6836        ----a-w-        c:\users\Eva-Maria\AppData\Local\d3d9caps.dat
2010-08-27 08:03 . 2010-04-14 12:12        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2010-08-27 07:37 . 2009-08-22 10:41        --------        d-----w-        c:\program files\ICQ6Toolbar
2010-08-25 14:32 . 2010-05-26 18:22        84992        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-08-25 14:32 . 2010-05-26 18:22        388096        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-08-25 14:32 . 2010-05-26 18:22        381440        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-08-25 14:32 . 2010-05-26 18:22        1538048        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-08-25 14:32 . 2009-09-30 10:16        1015296        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000004.dll
2010-08-25 14:31 . 2010-03-06 05:30        5627904        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
2010-08-25 14:31 . 2010-01-27 03:20        5623808        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
2010-08-25 13:49 . 2009-10-11 09:22        1        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-08-23 13:02 . 2009-08-22 10:40        --------        d-----w-        c:\users\Eva-Maria\AppData\Roaming\ICQ
2010-08-23 12:30 . 2010-01-19 19:06        --------        d-----w-        c:\program files\ICQ7.0
2010-08-17 16:24 . 2009-10-20 21:44        --------        d-----w-        c:\users\Eva-Maria\AppData\Roaming\gtk-2.0
2010-08-17 13:08 . 2009-09-20 13:20        --------        d-----w-        c:\program files\Common Files\DVDVideoSoft
2010-08-15 12:52 . 2009-03-12 03:13        --------        d-----w-        c:\program files\Microsoft Works
2010-08-15 12:46 . 2009-03-12 03:11        --------        d-----w-        c:\programdata\Microsoft Help
2010-08-15 12:45 . 2006-11-02 11:18        --------        d-----w-        c:\program files\Windows Mail
2010-07-27 16:14 . 2010-07-27 15:25        57344        ----a-w-        c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-27 16:13 . 2010-07-27 15:19        --------        d-----w-        c:\programdata\DivX
2010-07-27 16:13 . 2010-07-27 15:20        --------        d-----w-        c:\program files\DivX
2010-07-27 16:13 . 2010-07-27 15:22        --------        d-----w-        c:\program files\Common Files\PX Storage Engine
2010-07-27 15:22 . 2010-07-27 15:22        --------        d-----w-        c:\users\Eva-Maria\AppData\Roaming\DivX
2010-07-27 09:04 . 2010-06-17 15:45        --------        d-----w-        c:\users\Eva-Maria\AppData\Roaming\PhotoScape
2010-07-25 11:10 . 2010-07-25 11:10        --------        d-----w-        c:\program files\Windows Portable Devices
2010-07-25 11:10 . 2006-11-02 10:25        665600        ----a-w-        c:\windows\inf\drvindex.dat
2010-07-25 11:10 . 2010-07-25 11:10        0        ---ha-w-        c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-07-25 11:10 . 2010-07-25 11:10        0        ---ha-w-        c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-07-23 21:27 . 2006-11-02 12:37        --------        d-----w-        c:\program files\Windows Calendar
2010-07-23 21:27 . 2006-11-02 12:37        --------        d-----w-        c:\program files\Windows Sidebar
2010-07-23 21:27 . 2006-11-02 12:37        --------        d-----w-        c:\program files\Windows Journal
2010-07-23 21:27 . 2006-11-02 12:37        --------        d-----w-        c:\program files\Windows Collaboration
2010-07-23 21:27 . 2006-11-02 12:37        --------        d-----w-        c:\program files\Windows Photo Gallery
2010-07-23 21:27 . 2006-11-02 12:37        --------        d-----w-        c:\program files\Windows Defender
2010-07-22 11:54 . 2010-07-22 11:54        --------        d-----w-        c:\users\Eva-Maria\AppData\Roaming\DVDVideoSoftIEHelpers
2010-07-22 11:54 . 2009-09-20 13:20        --------        d-----w-        c:\program files\DVDVideoSoft
2010-07-21 22:52 . 2010-07-19 19:07        24        ----a-w-        c:\users\Eva-Maria\AppData\Roaming\vdnxlf.dat
2010-07-20 13:36 . 2009-10-04 16:00        --------        d-----w-        c:\program files\Common Files\Symantec Shared
2010-07-19 19:09 . 2010-04-20 16:40        100        --s-a-w-        c:\users\Eva-Maria\AppData\Local\1711337819.dat
2010-07-03 09:40 . 2010-07-03 09:40        501936        ----a-w-        c:\programdata\Google\Google Toolbar\Update\gtb4695.tmp.exe
2010-06-15 11:23 . 2010-06-15 11:23        71992        ----a-w-        c:\programdata\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-14 16:37 . 2010-06-14 16:38        64288        ----a-w-        c:\windows\system32\drivers\Lbd.sys
2010-07-08 17:31 . 2009-10-30 08:32        119808        ----a-w-        c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-05-14 21:02        120104        ----a-w-        c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-04-02 102400]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-03-09 26100520]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-12 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2009-01-20 156968]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2009-01-20 202024]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-01-27 61440]
"AmIcoSinglun"="c:\program files\AmIcoSingLun\AmIcoSinglun.exe" [2008-10-24 237568]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-03-11 6957600]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-03-11 1833504]
"PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-12-05 1410344]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-02-24 870920]
"BackupManagerTray"="c:\program files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2009-04-11 249600]
"Acer ePower Management"="c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe" [2009-06-23 440864]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-05-13 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-05-14 345384]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-12-26 173288]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-08 30192]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-06-20 864112]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

c:\users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-03-18 14:32        136176        ----atw-        c:\users\Eva-Maria\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53        421888        ----a-w-        c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-09-18 13:32        149280        ----a-w-        c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-08-12 15:42        68856        ----a-w-        c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

R0 bhkrfkkk;bhkrfkkk;c:\windows\System32\drivers\ixuj.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 135664]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [x]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-08 30192]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-14 64288]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2008-12-04 19504]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2008-12-04 16432]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2008-12-04 59952]
S2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-12-18 75048]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-06-23 707104]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-03-31 233472]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-06-30 1352832]
S2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-05-14 305448]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-04-11 61184]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2008-09-04 223232]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]


--- Andere Dienste/Treiber im Speicher ---

*NewlyCreated* - FSUSBEXDISK

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners

2010-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 19:22]

2010-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 19:22]

2010-08-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1313689582-3900863286-3496430324-1000Core.job
- c:\users\Eva-Maria\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-26 14:32]

2010-08-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1313689582-3900863286-3496430324-1000UA.job
- c:\users\Eva-Maria\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-26 14:32]

2010-08-27 c:\windows\Tasks\Norton Security Scan for Eva-Maria.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-05-05 07:48]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.icq.com/
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:6522
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Free YouTube to Mp3 Converter - c:\users\Eva-Maria\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - foxsearch
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - component: c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
FF - component: c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
FF - component: c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmieze.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Eva-Maria\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\users\Eva-Maria\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\users\Eva-Maria\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000004.dll
FF - plugin: c:\users\Eva-Maria\AppData\Roaming\Mozilla\Firefox\Profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX Richtlinien ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -

WebBrowser-{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file)
HKCU-Run-{026A48E8-B136-82F6-C076-D1511E1BA01D} - c:\users\Eva-Maria\AppData\Roaming\Biim\hiak.exe
HKCU-Run-newsecureapp70700.exe - c:\users\Eva-Maria\AppData\Roaming\9F7CB0D6ABC204D4F42E15EE8D7D4089\newsecureapp70700.exe
HKCU-Run-rnoymcxs - c:\users\Eva-Maria\AppData\Local\fynqpggca\dgpbjvtshdw.exe
HKLM-Run-NPSStartup - (no file)
MSConfigStartUp-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2010-08-27 23:45
Windows 6.0.6002 Service Pack 2 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostarteinträge...

Scanne versteckte Dateien...

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2010-08-27  23:48:16
ComboFix-quarantined-files.txt  2010-08-27 21:48

Vor Suchlauf: 12 Verzeichnis(se), 337.911.660.544 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 337.863.303.168 Bytes frei

- - End Of File - - 963B02ADC554486D34E36A017979227E

--- --- ---

laevalalala 27.08.2010 22:59

muss ich jetzt alle meine passwörter ändern?

john.doe 27.08.2010 23:06

Es fehlt noch immer die Datei Extras.txt vom Desktop.
Zitat:

muss ich jetzt alle meine passwörter ändern?
Sicherer ist das allemal, also ja.

Ich brauche jetzt einige Zeit um das Log zu lesen und und Skript zu basteln. Du kannst anfangen mit Scannen.

1.) Lade und installiere den MSIE 8 => Weltweite Websites: Sprachauswahl und regionale Einstellungen

2.) Panda Active Scan
Benutze den MSIE für diesen Scan. Folgende Seite führt dich durch die Installation: PandaActiveScan2.0 Installation

Drücke auf Jetzt Scannen!

Eine Registrierung ist nicht erforderlich!

Nachdem der Scan abgeschlossen ist drücke auf das Text-Icon Export und speichere das log auf dem Desktop.
Öffne die Datei ActiveScan.txt die sich nun auf deinem Desktop befindet und poste uns den Inhalt.
ciao, andreas

laevalalala 27.08.2010 23:37

OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 27.08.2010 22:31:49 - Run 3
OTL by OldTimer - Version 3.2.1.1    Folder = C:\Users\Eva-Maria\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 48,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 78,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 312,68 Gb Free Space | 68,57% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: EVA-MARIAS-PC
Current User Name: Eva-Maria
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- C:\Users\Eva-Maria\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"AntiVirusDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00AE7C7B-DEE9-4307-AAAE-5C5B79B1D543}" = lport=10243 | protocol=6 | dir=in | app=system |
"{28457959-C5B1-4050-806C-F45BCBD67AAF}" = lport=137 | protocol=17 | dir=in | app=system |
"{319BFAA0-A829-4493-93F4-A8DC28B4527D}" = rport=139 | protocol=6 | dir=out | app=system |
"{3B3CD04E-CFC1-412E-AFD1-4D965130282D}" = rport=445 | protocol=6 | dir=out | app=system |
"{3F1A0BED-8B18-4A45-AE50-40CBD862C194}" = rport=137 | protocol=17 | dir=out | app=system |
"{57D393EC-0B2D-49A3-A893-7C6CC26B2EF7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{59EFFD2D-47F1-403F-8324-1E950DA9446D}" = lport=138 | protocol=17 | dir=in | app=system |
"{5EF1CAA7-80A3-4F4F-B865-34C8003C3876}" = rport=10243 | protocol=6 | dir=out | app=system |
"{662B99A0-E963-4A58-98AD-D0927002C35C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{791FB021-ACCB-4E0F-A6BE-23177766673F}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7CFF0581-CBE9-451D-9420-C7B44B83A227}" = rport=138 | protocol=17 | dir=out | app=system |
"{7F8C7921-F192-48A4-9BD6-3675E384B18E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8294CCAD-5D5F-4E72-9F07-B7CF6FDFBE24}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{855BED46-727A-4467-8E19-A636917608EF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8CFE33EA-4391-454E-A35F-EA43DCB93F9D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{948598FA-A43C-4A23-A242-F0CCE936BEF9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B8A75402-A86A-4FE8-9160-3FD7A46C5E1B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D4D0BDBE-EC1A-44DE-86A1-CE2BEA8C759A}" = lport=139 | protocol=6 | dir=in | app=system |
"{E64FF6B8-44AD-4436-A9B4-A3110C59EFFE}" = lport=445 | protocol=6 | dir=in | app=system |
"{ED32EEC9-BC99-4489-A67B-743BD2A241E4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FC05A707-C5E0-4425-B211-55FD1F72EA43}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0925BAD3-0FC1-41AE-B808-2F47FD31DAF1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0AD63CA4-E4FB-4FCB-9EE2-9E7B8D955EB7}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{118B082C-A442-4D30-AC6B-9AF810566476}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{1468F000-3010-43B9-B82C-3EBD3CD011A2}" = protocol=6 | dir=in | app=c:\program files\vogel verlag\fahren lernen\vogel.fahrenlernenmax.exe |
"{1FD1EE18-9B52-4A6A-BBBF-A6822980A7A6}" = protocol=17 | dir=in | app=c:\program files\vogel verlag\fahren lernen\vogel.fahrenlernenmax.exe |
"{21819292-C4FC-4D2B-A4A3-6E81788A87F2}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{267830C1-404E-4858-AE6C-7E80BBE3DC60}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"{284AE749-504A-4C3C-9F79-936BEBA0FA46}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{3A4C30CB-AA9A-4E3F-A0E5-80298DFDE5AD}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{43081B67-3649-4F44-A436-C411F1846E5E}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\pmvservice.exe |
"{44313369-55A3-4DAD-880E-2106C1031AB1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{565654F8-F40D-4390-93C6-8058E1ACD914}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{59D7ECC3-1D25-4D86-A5C5-E7571576410B}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{5C455030-3F84-4409-80AE-95CD56A8FEEE}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{5DD2B873-0719-4DF2-8BE8-79CE5621EB19}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5DF823F4-E4C2-4753-B954-03A763E32ACD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{64AA90F1-DA1D-4A45-9561-5BE57A7502A2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{67B40295-FB21-4F49-8E53-4AFBC2424B1C}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{6A9DA5E1-F641-4499-831E-E6F5529AE943}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6E3A109D-AC1A-485F-800A-32582D09EFA8}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe |
"{71B74B44-A66F-4720-AAAF-AF4AC989D8D6}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{7CFD5BF1-6E7B-4845-896E-D79FABB2BA46}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{817715C2-9EA4-470A-A160-7C75EA2E7009}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\playmovie.exe |
"{834DBB9F-6F5D-4316-AC31-E022E1CF4C1A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8C15EBE6-348E-4AC0-B360-B8B460C77FB1}" = protocol=6 | dir=out | app=system |
"{8D514C19-9B7F-4B3D-9039-760270250D49}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{98C9D060-2C3C-4A5A-8675-38FAB4A0E2BF}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{A50EBAC5-4DB5-426A-B8D7-BB1B83D78E6D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{AE4AF426-0752-41FE-A533-F7886DE302D8}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{B2D9231D-A883-44D8-9D0A-F48D59102CBE}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{B629F32A-CBAC-414B-B9C7-A4E2666E5BA2}" = protocol=17 | dir=in | app=c:\program files\vogel verlag\fahren lernen\vogel.fahrenlernenmax.exe |
"{B8F8DC52-D951-45EC-B7A0-F00403310642}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BC825CA3-DCC3-4D47-AE63-282D8037A4FA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BD4058BF-9111-4856-8D5D-6F948F6BCC76}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{BDF4E89D-B753-4BBC-B26E-148F5CFA5CAB}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{BEA626B6-140C-4DC4-AD06-572D004D03BF}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe |
"{C2498091-8D47-4620-BD12-1FF979FEA3E8}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C85167BD-EBC9-4F31-AC3A-D9A3E6E96F71}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{C90CB239-FB9F-4305-A698-388F84D2D7CD}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{CD5448DB-53EA-4994-ACD0-4D0D1A5912C2}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CEC55CBF-E0E4-4DBD-AA4C-5A746BFCF61D}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{D20E9F48-4A8F-4715-A228-4F154F1BD8E8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D34FC609-9D97-40B1-9195-08B57089E5F6}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{D8C6D2C8-A7F3-4AF4-B1BD-4A364748365D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{DB257940-256D-4C26-B3D9-B209FD460BB2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DDB8395A-3568-4DA3-B60D-12EA9A6CACEF}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{E1C6F362-C3B1-4981-861A-420CCE0B1221}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E5690112-A4EB-46E2-A558-456BA097E986}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E7CB38D5-90FC-4311-8A26-E8D14366EE74}" = protocol=6 | dir=in | app=c:\program files\vogel verlag\fahren lernen\vogel.fahrenlernenmax.exe |
"{F49B066B-0133-4E80-8BD5-94F7274BFAB8}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F603B287-4208-4C67-9724-B9FE79EC93EE}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{F6F63A39-A5CF-4F08-8607-C070100425CC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FECDE689-582B-4799-8EFC-0A62FB2E8763}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"TCP Query User{00E39D8E-1A09-4F07-B085-BB6F2171425B}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{5751046D-6650-49BE-8267-21431837F75C}C:\programdata\c68bb7f\msc68b.exe" = protocol=6 | dir=in | app=c:\programdata\c68bb7f\msc68b.exe |
"TCP Query User{91C36C6F-9508-4DDD-BE4F-437FB71ED8B0}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{CA8D4410-58CE-4A2B-A831-48F304A11FDE}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{41A64FC2-FD61-44CD-B273-469A2DD4F702}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{AE8263FC-8E2E-460A-A464-8402200519EB}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{E78CFA4C-08D6-44E8-BB30-716DCE5E86ED}C:\programdata\c68bb7f\msc68b.exe" = protocol=17 | dir=in | app=c:\programdata\c68bb7f\msc68b.exe |
"UDP Query User{EB790BA7-A1BA-4F20-95BE-756CFA628661}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{040A6E85-C23F-4A23-ADBB-821C60C5DF0F}_is1" = Fahren Lernen 1.1
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{056B935A-A03D-D0D8-4CE0-B4B337753156}" = CCC Help Chinese Standard
"{0C362375-1FE0-98C0-2C57-F4D772B8A759}" = Catalyst Control Center Graphics Full New
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83216014F0}" = Java(TM) 6 Update 14
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java(TM) 6 Update 16
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie
"{2BD2FA21-B51D-4F01-94A7-AC16737B2163}" = Adobe Flash Player 10 ActiveX
"{2C973B8B-1BB3-358B-250C-336C81A1926E}" = CCC Help Polish
"{2F2B002A-8BF5-DF1E-6D36-7900B6F868DE}" = ATI Catalyst Install Manager
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{360872CE-7A87-A4EE-AF69-EF73E5695D40}" = ccc-utility
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3CCB314A-B67C-82D0-1CC6-6BC4AE6D053E}" = Catalyst Control Center InstallProxy
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer PowerSmart Manager
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{45416928-B205-9812-2065-5794D5AC7338}" = CCC Help French
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{53E12B77-A8AC-1A15-7690-FAA711AA0B50}" = CCC Help Portuguese
"{5A64A288-025C-F952-E4E3-12FA6596922F}" = CCC Help Chinese Traditional
"{5B63A470-9334-44D1-AF61-6CE2DB565AE9}" = Orion
"{5D3A59B1-2BBF-66AF-3B5F-FC5BAA42F817}" = CCC Help Italian
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{5F19F78E-274D-8E5C-C49E-2ED722ACF70A}" = CCC Help German
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{6078A803-C98F-1F95-CEF7-0132621E6072}" = CCC Help Japanese
"{6234F3C6-F8EF-39FB-AE15-0B88E88B79F0}" = CCC Help Greek
"{62F7DA7E-CCCB-439C-A760-00C3926E761F}" = Microsoft Works
"{68301905-2DEA-41CE-A4D4-E8B443B099BA}" = MyWinLocker
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A0D64D0-CDF4-9C65-A053-6EC86AEB43CC}" = ccc-core-static
"{6A905715-6991-3517-5F04-4392FC18DB76}" = Catalyst Control Center Graphics Previews Vista
"{6EAA466F-6F35-F3B7-60B9-3D6DCA97EE02}" = Catalyst Control Center Localization All
"{71C2828F-2678-4675-BDEC-895424861262}_is1" = C:\Program Files\Acer GameZone\GameConsole
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{742A17A1-8AA4-4DCE-C881-557AC4EB793D}" = CCC Help Spanish
"{75212523-6E47-BF0F-20FF-B65E940A5DDD}" = CCC Help English
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110184263}" = Puzzle Express
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11037623}" = Tradewinds 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111205743}" = Tri-Peaks Solitaire To Go
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111232687}" = Ocean Express
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11170417}" = Luxor 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11219217}" = Cradle of Rome
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112270203}" = Dream Day Wedding
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113056167}" = Dream Day Honeymoon
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113297350}" = Cake Mania 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113494430}" = Wedding Dash
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11505173}" = Airport Mania First Flight
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}" = Dairy Dash
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115443300}" = Cooking Dash
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11551977}" = Parking Dash
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{88EB38EF-4D2C-436D-ABD3-56B232674062}" = ICQ7
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90AD0407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint 2003 Template Pack 3
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{940F9DF4-A790-EAE9-A4B1-B9F96D3C8CC9}" = CCC Help Finnish
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97BA7028-6FE4-58B5-F254-48C12AA3FBBD}" = CCC Help Swedish
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{987381F2-AA18-EF9C-9DDA-4D403FD7F3E2}" = CCC Help Turkish
"{99C85B2D-DFA4-5704-9A4C-396DDB5C6F1F}" = CCC Help Thai
"{99E862CC-6F69-4D39-99AA-DBF71BF3B585}" = OpenOffice.org 3.1
"{9AF0B106-56F1-461B-A270-95BC1682E282}" = Broadcom Gigabit NetLink Controller
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{9E6B5AEA-C8EC-916B-FDFA-91F1274CD695}" = Skins
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A75C2F92-28EC-FE11-3818-81578F3E9596}" = CCC Help Norwegian
"{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}" = Acer Crystal Eye Webcam
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA9732EB-64DD-DBA5-DFC1-705E64D3FB18}" = CCC Help Russian
"{AAE19E03-87A5-6937-F7D7-6806C5FD1D89}" = Catalyst Control Center Graphics Light
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-7AD7-1031-7B44-A90000000001}" = Adobe Reader 9 - Deutsch
"{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B15E1629-4B8C-FC02-1118-35034C235F0D}" = CCC Help Korean
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{BA165460-FCF7-4D6C-A7A2-F2321700720F}" = MobileMe Control Panel
"{BE0EC61A-02BF-E3E1-D7A8-3DDB7B58FBDF}" = PX Profile Update
"{BF91B300-EEBC-4223-96F3-0FCBF7241B50}" = AmIcoSingLun
"{C10DD83A-CB15-DD3A-FE29-89433A68F55D}" = CCC Help Dutch
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0F3E75D-6BE1-E974-2A8E-A449D3374FDB}" = Catalyst Control Center Graphics Full Existing
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DA20E1A8-07CB-4EE7-9B72-A7E28C953F0E}" = Acer Product Registration
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E24DBA75-5452-C0A1-4FF3-CB38F8245919}" = CCC Help Czech
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E430067C-7254-40B6-A8F8-5EEF57A68F1A}" = Catalyst Control Center - Branding
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E86CA8CF-F42D-9569-B2ED-5E6A0F591EA5}" = CCC Help Hungarian
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F557AF38-AB37-84A8-0148-C53B5F870373}" = CCC Help Danish
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{FF7027C7-B001-A144-C83B-03618745E975}" = Catalyst Control Center Core Implementation
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0)
"Acer Screensaver" = Acer ScreenSaver
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Audacity_is1" = Audacity 1.2.6
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"Free Studio_is1" = Free Studio version 4.2
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.8
"Google Desktop" = Google Desktop
"GridVista" = Acer GridVista
"Gutscheinmieze - Toolbar" = Gutscheinmieze - Toolbar
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"ICQToolbar" = ICQ Toolbar
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Acer Backup Manager
"InstallShield_{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"InstallShield_{BF91B300-EEBC-4223-96F3-0FCBF7241B50}" = AmIcoSingLun
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"LastFM_is1" = Last.fm 1.5.4.24567
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"NSS" = Norton Security Scan
"PhotoFiltre" = PhotoFiltre
"PhotoScape" = PhotoScape
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile Modem Device" = Samsung Mobile Modem Device Software
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software
"Security Task Manager" = Security Task Manager 1.7h
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Uninstall_is1" = Uninstall 1.0.0.1
"WinGimp-2.0_is1" = GIMP 2.6.7
"WinLiveSuite_Wave3" = Windows Live Essentials
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Antimalware Doctor" = Antimalware Doctor
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 19.08.2010 13:27:24 | Computer Name = Eva-Marias-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 19.08.2010 13:27:25 | Computer Name = Eva-Marias-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 905929
 
Error - 19.08.2010 13:27:25 | Computer Name = Eva-Marias-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 905929
 
Error - 19.08.2010 13:27:26 | Computer Name = Eva-Marias-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 19.08.2010 13:27:26 | Computer Name = Eva-Marias-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 907162
 
Error - 19.08.2010 13:27:26 | Computer Name = Eva-Marias-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 907162
 
Error - 19.08.2010 13:27:27 | Computer Name = Eva-Marias-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 19.08.2010 13:27:27 | Computer Name = Eva-Marias-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 908332
 
Error - 19.08.2010 13:27:27 | Computer Name = Eva-Marias-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 908332
 
Error - 20.08.2010 04:16:37 | Computer Name = Eva-Marias-PC | Source = WinMgmt | ID = 10
Description =
 
[ System Events ]
Error - 27.08.2010 14:05:55 | Computer Name = Eva-Marias-PC | Source = DCOM | ID = 10010
Description =
 
Error - 27.08.2010 15:15:15 | Computer Name = Eva-Marias-PC | Source = DCOM | ID = 10010
Description =
 
Error - 27.08.2010 15:37:20 | Computer Name = Eva-Marias-PC | Source = iaStor | ID = 262153
Description = Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht
 geantwortet.
 
Error - 27.08.2010 16:17:54 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 27.08.2010 16:17:54 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 27.08.2010 16:17:54 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 27.08.2010 16:17:54 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 27.08.2010 16:17:54 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7026
Description =
 
Error - 27.08.2010 16:20:40 | Computer Name = Eva-Marias-PC | Source = iaStor | ID = 262153
Description = Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht
 geantwortet.
 
Error - 27.08.2010 16:21:03 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
 
< End of report >

--- --- ---

laevalalala 28.08.2010 13:00

Die Datei ist zu groß, und wenn ich es einfüge auch zu lang, deshalb teil ich die informationen...

ANALYSIS: 2010-08-28 13:49:01
PROTECTIONS: 2
MALWARE: 14
SUSPECTS: 7
;***************************************************************************************************************************************************** ******************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================== ==============================
Windows Defender No No
Lavasoft Ad-Watch Live! Yes Yes
;===================================================================================================================================================== ==============================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================== ==============================
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No c:\users\eva-maria\appdata\roaming\microsoft\windows\cookies\eva-maria@casalemedia[1].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No c:\users\eva-maria\appdata\roaming\microsoft\windows\cookies\eva-maria@doubleclick[1].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\users\eva-maria\appdata\roaming\microsoft\windows\cookies\eva-maria@atdmt[1].txt
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No c:\users\eva-maria\appdata\roaming\microsoft\windows\cookies\eva-maria@tradedoubler[2].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No c:\users\eva-maria\appdata\roaming\microsoft\windows\cookies\eva-maria@fastclick[1].txt
00159564 Cookie/WUpd TrackingCookie No 0 Yes No c:\users\eva-maria\appdata\roaming\microsoft\windows\cookies\eva-maria@revenue[2].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No c:\users\eva-maria\appdata\roaming\microsoft\windows\cookies\eva-maria@ad.yieldmanager[1].txt
03074964 Trj/CI.A Virus/Trojan No 0 Yes No c:\qoobox\quarantine\c\users\eva-maria\appdata\roaming\9f7cb0d6abc204d4f42e15ee8d7d4089\newsecureapp70700.exe.vir
03074964 Trj/CI.A Virus/Trojan No 0 Yes No c:\qoobox\quarantine\c\users\eva-maria\appdata\roaming\microsoft\windows\templates\memory.tmp.vir
03074964 Trj/CI.A Virus/Trojan No 0 Yes No c:\qoobox\quarantine\c\users\eva-maria\appdata\local\fynqpggca\dgpbjvtshdw.exe.vir
05922253 Adware/AdOnDemand Adware No 0 No No c:\program files\dvdvideosoft\free youtube to mp3 converter\ebay_shortcuts_1045.exe[ebayshortcuts.exe]
06174175 Generic Malware Virus/Trojan No 0 Yes No c:\_otl\movedfiles\04142010_204741\c_windows\dwymua.exe
06320774 Adware/AntimalwareDoctor Adware No 0 Yes No c:\qoobox\quarantine\c\users\eva-maria\appdata\roaming\9f7cb0d6abc204d4f42e15ee8d7d4089\enemies-names.txt.vir
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\guide\howtouse-old.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\guide\left-guide.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\guide\menu-guide.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\guide\right-guide.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\home\bd-main.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\home\left-00.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\home\menu.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\home\right-main.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\home\top.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\howtouse.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1269809850420.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1269801895845.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1269800852898.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1269790530333.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1269701375579.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1269701230813.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\stars.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\soft blue.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\shades of blue.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\roses.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\peacock.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\orange circles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\hand prints.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\green bubbles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\garden.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\bears.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\stars.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\soft blue.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\shades of blue.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\roses.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\peacock.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\orange circles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\hand prints.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\green bubbles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\garden.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\bears.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\documents\downloads\www.chemie-abc.de facharbeit über photografie_files\ads.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\documents\downloads\www.chemie-abc.de facharbeit über photografie.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\documents\downloads\lochkamera – beschreibung und eigenbau (pdf) - jugendmedien_files\sh14.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\documents\downloads\lochkamera – beschreibung und eigenbau (pdf) - jugendmedien.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\documents\downloads\fotoapparat – wikipedia.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\documents\downloads\facharbeiten - kunst - gymnasium münchen maria-ward-schule.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\yahoo! inc\ytoolbar\default\app.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\yahoo! inc\ytoolbar\ced0h0u_o\app.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\yahoo! inc\ytoolbar\c00hoozt_o\app.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\yahoo! inc\ytoolbar\4l0_c0h809_o\app.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\googletoolbardata\components\suggest_window.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\components\suggest_window.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\bookmarks.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\guide\guide.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\contents\right-contents.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\contents\menu-contents.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\contents\left-00.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\contents\howtouse-old.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\howtouse\contents\contents.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1269900632676.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\windows\softwaredistribution\download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-g..edsgadget.resources_31bf3856ad364e35_6.0.6002.18005_de-de_843aacf264e54187\rssfeeds.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\programdata\icq\icqnewtab\newtab.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\writer\template\default.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\writer\html\map.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\writer\html\map-preview.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\yellowtiles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\southwest.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\snowboard.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\music.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\mosaic2.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\mosaic1.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\money.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\led.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\handprints.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\garden.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\drawing.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\dinosaur.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\colorstripe.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\cheddar.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\bubbles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\bluetiles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\bamboo.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\windows live\mail\stationery\artdeco.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\webauthenticationsheet.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\tabspreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\standarderrorpage.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\spelling.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\snippeteditor\snippeteditor.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\slidingalert.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ara\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ara\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ara\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ara\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ara\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\chs\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\chs\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\chs\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\chs\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\chs\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\cht\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\cht\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\cht\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\cht\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\cht\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\csy\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\csy\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\csy\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\csy\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\csy\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\dan\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\dan\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\dan\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\dan\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\dan\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\deu\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\deu\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\deu\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\deu\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\deu\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ell\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ell\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ell\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ell\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ell\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\enu\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\enu\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\enu\relnotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\enu\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\enu\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\enu\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\esn\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\esn\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\esn\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\esn\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\esn\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\fin\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\fin\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\fin\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\fin\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\fin\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\fra\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\fra\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\fra\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\fra\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\fra\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\heb\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\heb\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\heb\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\heb\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\heb\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\hun\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\hun\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\hun\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\hun\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\hun\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ita\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ita\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ita\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ita\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ita\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\jpn\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\jpn\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\jpn\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\jpn\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\jpn\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\kor\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\kor\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\kor\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\kor\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\kor\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\nld\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\nld\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\nld\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\nld\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\nld\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\nor\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\nor\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\nor\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\nor\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\nor\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\plk\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\plk\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\plk\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\plk\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\plk\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ptb\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ptb\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ptb\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ptb\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ptb\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ptg\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ptg\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ptg\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ptg\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\ptg\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\relnotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\rus\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\rus\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\rus\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\rus\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\rus\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\sve\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\sve\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\sve\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\sve\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\sve\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\tha\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\tha\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\tha\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\tha\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\tha\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\trk\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\trk\regs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\trk\specs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\trk\support.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\docs\trk\warranty.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\servernotfounderrorpage.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\securitypreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\searchfield.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\rsspreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\resetdialog.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\phishingalert.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\newbookmark.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\networkdiagnosticserrorpage.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\zh_tw.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\zh_cn.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\sv.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\ru.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\pt_pt.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\pt.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\pl.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\nl.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\nb.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\ko.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\ja.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\it.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\fr.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\fi.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\es.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\en.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\de.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\da.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\help\acknowledgments.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\generalpreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\ftpdirectorytemplate.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\fontpicker.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\flowviewfindbanner.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\downloadpromptdialog.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\customizetoolbar.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\cacheswindow.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\bugreport.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\bookmarktitlechange.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\bookmarksview.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\bookmarkpreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\bookmarkchooser.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\blacksearchfield.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\autofillpreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\appearancepreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\alertdialog.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\advancedpreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\safari.resources\about.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\pubsub.resources\friends.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\pubsub.resources\feedstatic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\pubsub.resources\feedcomplete.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\pubsub.resources\feed.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\pubsub.resources\entry.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\pubsub.resources\entries.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\safari\pubsub.resources\enclosure.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\quicktime\quicktime read me.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\photofiltre\photomasque.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\photofiltre\photofiltre.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\thirdpartylicensereadme.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\share\readme\readme_de.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\highlight\extension.1.0\default.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\share\readme\license_de.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\readmes\readme_de.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\readme.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\licenses\license_de.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\license.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\basis\share\template\de\internal\url_transfer.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\basis\share\dtd\math\1_01\w3c_ipr_software_notice.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\basis\share\config\wizard\web\preview.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\basis\share\config\wizard\web\layouts\frame_top\mainframe.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\basis\share\config\wizard\web\layouts\frame_right\mainframe.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\basis\share\config\wizard\web\layouts\frame_left\mainframe.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\basis\share\config\wizard\web\layouts\frame_bottom\mainframe.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\basis\program\python-core-2.6.1\lib\test\test_difflib_expect.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\basis\program\python-core-2.6.1\lib\test\sgml_input.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\openoffice.org 3\basis\help\de\err.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\norton security scan\engine\2.3.0.44\help.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\newtech infosystems\nti media maker 8\media maker\upgrade.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft sql server compact edition\v3.1\readmessce_enu.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_9226.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_9225.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_9217.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_8202.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_8201.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_8193.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_7178.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_7177.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_7169.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_6156.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\koanbox\koancontrol.htm

laevalalala 28.08.2010 13:18

06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\kernel\koanbox\middlepage.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_2055.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_2052.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_20490.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_2049.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_19466.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_18442.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_18441.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_17418.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_17417.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_16394.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_16393.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_16385.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_15370.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_15361.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_14346.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_14337.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_13322.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\airport mania first flight\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\airport mania first flight\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\airport mania first flight\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\airport mania first flight\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\airport mania first flight\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\airport mania first flight\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\airport mania first flight\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\airport mania first flight\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\help\controls.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\help\credits.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\help\gamemenus.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\help\gettingstarted.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\help\help.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\help\introduction.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\help\sysreqs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_13321.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_13313.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_12298.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_12289.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cooking dash\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cooking dash\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cooking dash\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cooking dash\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cooking dash\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cooking dash\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cooking dash\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cooking dash\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cooking dash\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_11274.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_11273.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cradle of rome\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cradle of rome\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cradle of rome\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cradle of rome\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cradle of rome\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cradle of rome\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cradle of rome\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cradle of rome\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_11265.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1124.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dairy dash\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dairy dash\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dairy dash\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dairy dash\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dairy dash\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dairy dash\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dairy dash\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dairy dash\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dairy dash\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1086.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1081.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1071.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1066.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1063.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1062.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1061.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1060.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1057.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1055.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1054.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1053.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1051.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1050.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1049.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\jewel quest solitaire\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\jewel quest solitaire\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\jewel quest solitaire\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\jewel quest solitaire\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\jewel quest solitaire\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\jewel quest solitaire\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\jewel quest solitaire\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\jewel quest solitaire\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1048.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1046.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1045.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1044.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1043.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1042.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1041.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1040.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1038.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1037.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1036.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1035.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1034.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1033.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\read_me.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1032.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1031.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1030.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1029.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1028.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\mahjong escape ancient china\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\mahjong escape ancient china\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\mahjong escape ancient china\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\mahjong escape ancient china\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\mahjong escape ancient china\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\mahjong escape ancient china\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\mahjong escape ancient china\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\mahjong escape ancient china\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1026.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_10250.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\ocean express\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\ocean express\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\ocean express\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\ocean express\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\ocean express\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\ocean express\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\ocean express\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\ocean express\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_1025.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_10249.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\parking dash\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\parking dash\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\parking dash\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\parking dash\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\parking dash\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\parking dash\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\parking dash\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\parking dash\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\parking dash\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office suite activation assistant\default_10241.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office\office12\intlband.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\puzzle express\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\puzzle express\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\puzzle express\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\puzzle express\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\puzzle express\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\puzzle express\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\puzzle express\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\puzzle express\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\microsoft office\office12\1031\pvreadme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\help\controls.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\help\credits.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\help\gamemenu.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\help\gettingstarted.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\help\help.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\help\introduction.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\help\sysreqs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\mcafee\virusscan\1031\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\mcafee\siteadvisor\scripts\balloon.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\mcafee\msk\1031\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\mcafee\msc\1031\help\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tri-peaks solitaire to go\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tri-peaks solitaire to go\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tri-peaks solitaire to go\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tri-peaks solitaire to go\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tri-peaks solitaire to go\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tri-peaks solitaire to go\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tri-peaks solitaire to go\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tri-peaks solitaire to go\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\mcafee\mps\1031\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\mcafee\mpf\1031\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\turbo pizza\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\turbo pizza\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\turbo pizza\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\turbo pizza\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\turbo pizza\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\turbo pizza\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\turbo pizza\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\turbo pizza\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\java\jre6\welcome.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\java\jre1.6.0_14\welcome.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\wedding dash\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\wedding dash\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\wedding dash\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\wedding dash\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\wedding dash\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\wedding dash\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\wedding dash\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\wedding dash\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\wedding dash\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\esobi\esobi2\config\htmlpage02.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\esobi\esobi2\config\htmlpage01.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\zuma deluxe\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\zuma deluxe\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\zuma deluxe\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\zuma deluxe\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\zuma deluxe\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\zuma deluxe\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\zuma deluxe\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\zuma deluxe\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\adobe\reader 9.0\liesmich.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\esobi\esobi2\config\ad.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\zh-tw\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\zh-cn\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\tr\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\sv\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\sl\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\sk\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\ru\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\ro\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\pt\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\pl\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\no\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\de\welcome_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\de\welcome_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_mr9600_mob.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_mr9700_mob.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_r9600_dsk.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_r9700_dsk.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_r9800_dsk.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_rx800_dsk.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcom_en-us_cycle.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\es\welcome_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\es\welcome_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\fr\welcome_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\fr\welcome_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\pt-br\welcome_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\welcome\pt-br\welcome_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\nl\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\lv\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\lt\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\ja\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\it\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\apple application support\webkit.resources\inspector\inspector.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\da.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\de.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\en.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\es.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\fi.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\fr.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\it.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\ja.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\ko.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\nb.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\nl.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\pl.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\pt_pt.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\ru.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\sv.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\zh_cn.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\apple\mobile device support\applesyncpref.resources\zh_tw.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\hu\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\hr\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\gadget.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\fr\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\fi\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\et\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\es\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\el\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\du\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\de\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\da\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\cs\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\bg\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\zh_tw.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\zh_cn.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\sv.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\ru.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\pt_pt.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\office12\1031\odinfo.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\office12\1031\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\pt.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\pl.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\smart tag\1031\mcabout.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\stationery\bears.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\stationery\garden.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\stationery\green bubbles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\stationery\hand prints.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\stationery\orange circles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\stationery\peacock.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\stationery\roses.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1269900632894.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\stationery\soft blue.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\stationery\stars.htm

laevalalala 28.08.2010 13:19

l\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\nl.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\nb.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\ko.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\ja.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\it.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\fr.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\fi.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\es.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\en.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\de.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\mobile device support\bin\applesyncpref.resources\da.lproj\yeula.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\common files\apple\apple application support\webkit.resources\inspector\inspector.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\pt-br\welcome_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\pt-br\welcome_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\fr\welcome_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\fr\welcome_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\es\welcome_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\es\welcome_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcom_en-us_cycle.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_rx800_dsk.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_r9800_dsk.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_r9700_dsk.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_r9600_dsk.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_mr9700_mob.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_mr9600_mob.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\en-us\welcome_en-us_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\de\welcome_generic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\ati technologies\ati.ace\graphics-full-existing\welcome\de\welcome_fmv.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1269900633005.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\bg\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\bg\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\bg\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\bg\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\bg\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\bg\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\bg\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\bg\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\bg\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\cz\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\cz\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\cz\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\cz\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\cz\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\cz\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\cz\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\cz\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\cz\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\da\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\da\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\da\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\da\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\da\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\da\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\da\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\da\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\da\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\de\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\de\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\de\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\de\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\de\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\de\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\de\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\de\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\de\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\du\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\du\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\du\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\du\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\du\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\du\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\du\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\du\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\du\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\en\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\en\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\en\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\en\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\en\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\en\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\en\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\en\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\en\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\es\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\es\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\es\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\es\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\es\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\es\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\es\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\es\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\es\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\et\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\et\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\et\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\et\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\et\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\et\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\et\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\et\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\et\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fi\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fi\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fi\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fi\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fi\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fi\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fi\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fi\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fi\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fr\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fr\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fr\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fr\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fr\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fr\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fr\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fr\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\fr\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\gr\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\gr\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\gr\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\gr\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\gr\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\gr\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\gr\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\gr\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\gr\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hr\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hr\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hr\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hr\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hr\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hr\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hr\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hr\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hr\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hu\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hu\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hu\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hu\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hu\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hu\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hu\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hu\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\hu\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\it\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\it\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\it\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\it\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\it\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\it\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\it\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\it\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\it\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\jp\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\jp\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\jp\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\jp\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\jp\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\jp\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\jp\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\jp\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\jp\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lt\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lt\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lt\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lt\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lt\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lt\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lt\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lt\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lt\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lv\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lv\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lv\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lv\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lv\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lv\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lv\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lv\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\lv\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\no\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\no\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\no\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\no\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\no\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\no\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\no\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\no\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\no\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pl\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pl\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pl\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pl\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pl\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pl\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pl\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pl\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pl\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pt\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pt\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pt\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pt\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pt\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pt\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pt\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pt\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\pt\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ro\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ro\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ro\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ro\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ro\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ro\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ro\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ro\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ro\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ru\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ru\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ru\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ru\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ru\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ru\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ru\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ru\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\ru\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sc\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sc\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sc\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sc\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sc\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sc\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sc\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sc\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sc\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sk\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sk\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sk\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sk\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sk\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sk\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sk\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sk\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sk\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sl\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sl\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sl\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sl\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sl\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sl\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sl\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sl\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sl\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sv\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sv\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sv\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sv\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sv\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sv\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sv\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sv\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\sv\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tc\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tc\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tc\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tc\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tc\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tc\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tc\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tc\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tc\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tu\fes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tu\fingerprint.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tu\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tu\menu_list.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tu\mywinlockerconsole.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tu\mywinlockerinitialization.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tu\psd.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tu\releasenotes.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\help\tu\troubleshooting.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\bg\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\cs\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\da\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\de\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\du\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\el\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\es\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\et\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\fi\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\fr\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\gadget.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\hr\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\hu\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\it\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\ja\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\lt\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\lv\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\nl\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\no\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\pl\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\pt\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\ro\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\ru\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\sk\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\sl\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\sv\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\tr\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\zh-cn\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\mywinlockergadget.gadget\zh-tw\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\pmm\contents\default\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\egistec\mywinlocker 3\pmm\contents\index.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\esobi\esobi2\config\ad.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\esobi\esobi2\config\htmlpage01.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\esobi\esobi2\config\htmlpage02.htm

laevalalala 28.08.2010 13:22

06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\adobe\reader 9.0\liesmich.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\zuma deluxe\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\zuma deluxe\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\zuma deluxe\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\zuma deluxe\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\zuma deluxe\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\zuma deluxe\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\zuma deluxe\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\zuma deluxe\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\wedding dash\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\wedding dash\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\wedding dash\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\wedding dash\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\wedding dash\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\wedding dash\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\wedding dash\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\wedding dash\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\wedding dash\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\turbo pizza\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\turbo pizza\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\turbo pizza\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\turbo pizza\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\turbo pizza\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\turbo pizza\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\turbo pizza\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\turbo pizza\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tri-peaks solitaire to go\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tri-peaks solitaire to go\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tri-peaks solitaire to go\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tri-peaks solitaire to go\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tri-peaks solitaire to go\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tri-peaks solitaire to go\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqapp\ver1\theme\images\xtrapreloader\connect.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqxtraz\ver1\content\avatar\avatars5.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqxtraz\ver1\content\avatar\avatars_galerry5.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqxtraz\ver1\content\avatar\connect.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqxtraz\ver1\content\contact_list\index_ga.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqxtraz\ver1\content\contact_list\main_ga.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqxtraz\ver1\content\contact_list\preload.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqxtraz\ver1\content\game_center\index5.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqxtraz\ver1\content\game_center\lobby_banner.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqxtraz\ver1\content\photo_cropper\connect_local.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqxtraz\ver1\content\photo_cropper\index3.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\services\icqxtraz\ver1\content\photo_cropper\photo_editor3.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tri-peaks solitaire to go\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tri-peaks solitaire to go\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\imapp\theme\images\xtrapreloader\connect.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\help\sysreqs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\help\introduction.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\help\help.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\help\gettingstarted.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\help\gamemenu.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\help\credits.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\tradewinds 2\help\controls.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\puzzle express\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\puzzle express\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\puzzle express\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\puzzle express\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\puzzle express\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\puzzle express\omdata\gs2.html

laevalalala 28.08.2010 13:23

06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\avatar\avatars_galerry_max1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\avatar\avatars_max1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\avatar\connect.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\ftue\ftue.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\game_center\index5_max.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\game_center\lobby_banner.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\icq_ls_me\me.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\icq_profile\icq_profile.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\icq_profile\icq_profile_ltr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\icq_profile\icq_profile_rtl.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\icq_profile\preloader.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\ls_tab\full.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\profile_forms\forms.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\profile_forms\forms_data_ltr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\profile_forms\forms_data_rtl.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\profile_forms\preloader.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\profile_lightboxs\owneremailphoneforms.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\profile_lightboxs\owneremailphoneforms_data_ltr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\profile_lightboxs\owneremailphoneforms_data_rtl.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\profile_lightboxs\preloader.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xtraz\icq\content\pumk\pumk.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\puzzle express\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\puzzle express\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\parking dash\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\parking dash\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\parking dash\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\parking dash\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\parking dash\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\parking dash\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\parking dash\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\parking dash\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\parking dash\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\ocean express\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\ocean express\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\ocean express\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\ocean express\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\ocean express\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\ocean express\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\ocean express\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\ocean express\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\mahjong escape ancient china\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\mahjong escape ancient china\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\mahjong escape ancient china\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\mahjong escape ancient china\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\mahjong escape ancient china\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\mahjong escape ancient china\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\mahjong escape ancient china\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\mahjong escape ancient china\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\luxor 2\read_me.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\luxor 2\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\luxor 2\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\luxor 2\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\luxor 2\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\luxor 2\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\luxor 2\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\luxor 2\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\luxor 2\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\jewel quest solitaire\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\jewel quest solitaire\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\jewel quest solitaire\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\jewel quest solitaire\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\jewel quest solitaire\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\jewel quest solitaire\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\jewel quest solitaire\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\jewel quest solitaire\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\galapago\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\galapago\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\galapago\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\welcome.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\galapago\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\galapago\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\galapago\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\galapago\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\galapago\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day wedding\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day wedding\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day wedding\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day wedding\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day wedding\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day wedding\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day wedding\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day wedding\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day honeymoon\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day honeymoon\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day honeymoon\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day honeymoon\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day honeymoon\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day honeymoon\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day honeymoon\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1270714806940.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dream day honeymoon\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dairy dash\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dairy dash\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dairy dash\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dairy dash\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dairy dash\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dairy dash\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\welcome.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dairy dash\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dairy dash\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\dairy dash\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cradle of rome\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cradle of rome\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cradle of rome\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cradle of rome\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cradle of rome\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cradle of rome\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office\office12\1031\pvreadme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cradle of rome\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office\office12\intlband.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_10241.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_10249.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1025.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_10250.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1026.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1028.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1029.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1030.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1031.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1032.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1033.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1034.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1035.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1036.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1037.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1038.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1040.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1041.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1042.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1043.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1044.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1045.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1046.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1048.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1049.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1050.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1051.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1053.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1054.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1055.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1057.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1060.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1061.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1062.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1063.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1066.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1071.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1081.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1086.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_1124.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_11265.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_11273.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_11274.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_12289.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_12298.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_13313.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_13321.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_13322.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_14337.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_14346.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_15361.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_15370.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_16385.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_16393.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_16394.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_17417.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_17418.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_18441.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_18442.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_19466.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2049.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_20490.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2052.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2055.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2057.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2058.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2060.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2064.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2067.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2068.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2070.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2077.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_2110.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_21514.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_3073.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_3076.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_3079.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_3081.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_3082.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_3084.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_4097.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_4100.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_4103.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_4105.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_4106.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_4108.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_5121.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_5124.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_5127.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_5129.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_5130.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_5132.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_6145.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_6153.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_6154.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_6156.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_7169.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_7177.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_7178.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_8193.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_8201.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_8202.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_9217.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_9225.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office suite activation assistant\default_9226.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft sql server compact edition\v3.1\readmessce_enu.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cradle of rome\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cooking dash\readme.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cooking dash\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\defaults\profile\bookmarks.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_bg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_cz.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_de.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_en.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_es.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_fr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_he.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_it.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_ru.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_sk.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_tr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newtab_uk.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cooking dash\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cooking dash\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cooking dash\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cooking dash\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cooking dash\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cooking dash\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cooking dash\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\res\hiddenwindow.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\help\sysreqs.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\help\introduction.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\help\help.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\help\gettingstarted.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\help\gamemenus.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\help\credits.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\cake mania 2\help\controls.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\airport mania first flight\omdata\thankyou.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\airport mania first flight\omdata\regerr.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\airport mania first flight\omdata\reg.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\airport mania first flight\omdata\images\splash2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\airport mania first flight\omdata\images\index.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\airport mania first flight\omdata\gs2.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\airport mania first flight\omdata\gs1.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer gamezone\airport mania first flight\omdata\empty.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer arcade deluxe\playmovie\kernel\koanbox\middlepage.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer arcade deluxe\playmovie\kernel\koanbox\koancontrol.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer arcade deluxe\playmovie\kernel\highlight\extension.1.0\default.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer arcade deluxe\homemedia\kernel\koanbox\koancontrol.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\virtualstore\program files\acer arcade deluxe\acer arcade deluxe\kernel\highlight\extension.1.0\default.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\microsoft\windows mail\stationery\stars.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\microsoft\windows mail\stationery\soft blue.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\microsoft\windows mail\stationery\shades of blue.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\microsoft\windows mail\stationery\roses.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\microsoft\windows mail\stationery\peacock.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\microsoft\windows mail\stationery\orange circles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\microsoft\windows mail\stationery\hand prints.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\microsoft\windows mail\stationery\green bubbles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\microsoft\windows mail\stationery\garden.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\microsoft\windows mail\stationery\bears.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\google\chrome\application\5.0.375.127\resources\inspector\inspector.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\google\chrome\application\5.0.375.127\resources\inspector\devtools.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\google\chrome\application\5.0.375.127\resources\bookmark_manager\main.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\google\chrome\application\5.0.375.126\resources\inspector\inspector.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\google\chrome\application\5.0.375.126\resources\inspector\devtools.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\google\chrome\application\5.0.375.126\resources\bookmark_manager\main.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1270034506826.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1270335093631.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\_otl\movedfiles\04142010_204741\c_users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\toolbar@ask.com\logs\asktb-log-1270480400634.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\stationery\shades of blue.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\programdata\skype\plugins\plugins\f57b48adf2224f088edd1a2b9bad84e8\pickgame.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\programdata\icq\icqnewtab\newtab.html

laevalalala 28.08.2010 13:24

06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\zh-tw\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\zh-cn\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\tr\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\sv\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\sl\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\sk\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\ru\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\upgrade.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\ro\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\pt\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\pl\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\no\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\nl\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\lv\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\lt\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\ja\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\it\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\hu\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\hr\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\gadget.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\fr\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\fi\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\et\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\es\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\el\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\du\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\de\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\da\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\cs\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows sidebar\shared gadgets\mywinlockergadget.gadget\bg\settings.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\writer\template\default.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\writer\html\map.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\writer\html\map-preview.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\yellowtiles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\southwest.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\snowboard.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\music.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\mosaic2.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\mosaic1.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\money.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\led.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\handprints.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\garden.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\drawing.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\dinosaur.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\colorstripe.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\cheddar.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\bubbles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\bluetiles.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\norton security scan\norton security scan\engine\2.7.3.34\help.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\bamboo.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows live\mail\stationery\artdeco.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\help\de\err.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\webauthenticationsheet.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\tabspreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\standarderrorpage.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\spelling.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\snippeteditor\snippeteditor.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\slidingalert.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\servernotfounderrorpage.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\securitypreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\searchfield.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\rsspreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\resetdialog.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\reader.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\phishingalert.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\newbookmark.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\networkdiagnosticserrorpage.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\zh_tw.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\zh_cn.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\sv.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\ru.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\pt_pt.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\pt.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\pl.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\nl.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\nb.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\python-core-2.6.1\lib\test\sgml_input.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\python-core-2.6.1\lib\test\test_difflib_expect.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\ko.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\ja.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\it.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\fr.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\fi.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\es.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\en.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\de.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\da.lproj\plug-ins.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\help\acknowledgments.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\generalpreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\share\config\wizard\web\layouts\frame_bottom\mainframe.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\share\config\wizard\web\layouts\frame_left\mainframe.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\share\config\wizard\web\layouts\frame_right\mainframe.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\share\config\wizard\web\layouts\frame_top\mainframe.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\share\config\wizard\web\preview.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\share\dtd\math\1_01\w3c_ipr_software_notice.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\share\template\de\internal\url_transfer.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\license.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\licenses\license_de.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\ftpdirectorytemplate.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\fontpicker.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\readme.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\readmes\readme_de.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\share\readme\license_de.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\share\readme\readme_de.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\thirdpartylicensereadme.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\flowviewfindbanner.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\extensionsview.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\extensionbuilder.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\downloadpromptdialog.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\customizetoolbar.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\cacheswindow.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\bugreport.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\bookmarktitlechange.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\bookmarksview.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\bookmarkpreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\bookmarkchooser.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\blacksearchfield.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\autofillpreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\appearancepreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\alertdialog.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\advancedpreferences.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\addressbookentryview.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\safari.resources\about.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\pubsub.resources\friends.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\pubsub.resources\feedstatic.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\pubsub.resources\feedcomplete.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\pubsub.resources\feed.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\pubsub.resources\entry.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\pubsub.resources\entries.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\safari\pubsub.resources\enclosure.html
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\quicktime read me.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\photofiltre\photomasque.htm
06484459 W32/Cosmu.A Virus No 1 Yes No c:\program files\photofiltre\photofiltre.htm
07003798 Trj/Sinowal.XEI Virus/Trojan No 1 Yes No c:\qoobox\quarantine\c\users\eva-maria\appdata\roaming\biim\hiak.exe.vir
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\transports\nclivtbtsrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\transports\nclmsbtsrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\transports\nclrssrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\transports\ncltobtsrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\transports\nclusbsrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\versitconverter.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\transports\nclbcbtsrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\sml.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\photoscape\gdiplus.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\photoscape\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\photoscape\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\photoscape\photoscape.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\photoscape\psmsghook.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\pictureviewer.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\pictureviewer.resources\en.lproj\pictureviewerlocalized.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\pictureviewer.resources\pictureviewer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\plugins\npqtplugin.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\plugins\npqtplugin2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\plugins\npqtplugin3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\plugins\npqtplugin4.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\plugins\npqtplugin5.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\plugins\npqtplugin6.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\plugins\npqtplugin7.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\qtsystem\exportcontrollerps.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\qtsystem\qtjnative.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\qtsystem\qtmlclient.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\qtsystem\quicktime.resources\en.lproj\quicktimelocalized.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\qtsystem\quicktime.resources\quicktime.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\qtsystem\quicktimeaudiosupport.resources\en.lproj\quicktimeaudiosupportlocalized.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\qtsystem\quicktimeauthoring.resources\en.lproj\quicktimeauthoringlocalized.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\qtsystem\quicktimestreaming.resources\en.lproj\quicktimestreaminglocalized.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\qtsystem\quicktimeupdatehelper.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\qtsystem\quicktimewebhelper.resources\en.lproj\quicktimewebhelperlocalized.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\quicktime\qtsystem\quicktimewebhelper.resources\quicktimewebhelper.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\secureplatformtoolkit.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\realtek\audio\ap\rtkvadda.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\realtek\audio\hda\aertsrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\pccs_lcifapi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\pccs_dbengine.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\pccs_dbapi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\pccs_abapi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\pccswpddriver.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\pccsupdater.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\nox.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\ncltools.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\nclsynchandler.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\nclsync.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\nclpimaccess.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\nclphonet.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\ncllcif.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\nclinstaller.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\nclft.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\nclds.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\nclcapability.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\nclapi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\dbaccess.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\daapi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\connapi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\confserver.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\panda security\activescan 2.0\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\ure\bin\sal3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\ure\bin\libxml2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\program\libxml2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\program\dbghelp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\xpcom_compat.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\xpcom.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\xmergesync.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\wininetbe1.uno.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\ucpdav1.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\stclient_wrapper.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\so_activex.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\smplmail.uno.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\shlxthdl\shlxthdl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\senddoc.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\sbmi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\python-core-2.6.1\lib\distutils\command\wininst-9.0.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\python-core-2.6.1\lib\distutils\command\wininst-8.0.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\python-core-2.6.1\lib\distutils\command\wininst-7.1.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\python-core-2.6.1\lib\distutils\command\wininst-6.0.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\plmi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\ooofiltproxy.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\oleautobridge.uno.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\nspr4.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\nsldap32v50.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\lpsolve55.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\libxmlsec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\libeay32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\libcurl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\inprocserv.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\icule40.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\emsermi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\directx9canvas.uno.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\directx5canvas.uno.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\components\necko.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\components\addrbook.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\bindetmi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\bf_wrappermi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\openoffice.org 3\basis\program\bf_swmi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\pc dlc driver\x86\nmwcdcls.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\anycall_land.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\backupsym.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\convlunar.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\drmcm.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\fsdevicelib64.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\fsusbexdevice.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\fsusbexdevicelib.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\fsusbexservice.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\gdiplus.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\hspio.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\installsym.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\ktfdrm20.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\ktfdrm_ucc.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\m5_emuhw.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\m5_emumapi30.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\m5_emusmw5.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\macssdk.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\mediainfo.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\medicdll.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\mmtcm3encoderdll.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\mobexdll.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\npsbinaryloader.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\npsbinaryloader2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\sch_c330.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\sch_w420.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\sch_w690.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\sch_w720.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\sch_w740.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\sch_w750.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\sph_c3450.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\sph_w4200.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\sph_w5500.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\sph_w6450.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modelextension\sph_w7100.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\modem.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\mtdes.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\newpcstudio.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsadec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsaef.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsandroiddownloader.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsappactl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsarbiter.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsasrc.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsasvr.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsawms.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npscbt.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npscm.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npscomnctrl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npscw.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsdcaatobex.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsdcagmobex.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsdcamitsobex.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsdcaobex.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsdcasw.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsdcasym.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsdevicedrm3rd.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsdevicelist.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsdm.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsfunction5.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsinternetconnector.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npslinuxmitsdownloader.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsmpgs.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsmtpexplorer.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsmusicmanager.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsmusicplayer.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsmyexplorer.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsvae.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsvctl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsvsrc.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsvsvr.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsvve.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\npsvwms.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\octans_homedl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\omnia_homedl_vista.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\omnia_homedl_xp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\resources\cgi-bin\cgi-jpegscale.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\smafmms5emu.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\starburn.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\sub3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\symbian_downloader_dll.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\tcmsencoder.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\toolkitpro1112vc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\usb drivers\7\i386\ssecuninstall.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\usb drivers\7\setup.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\usb drivers\sps3_usb_driver_setup.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\samsung\samsung new pc studio\xsyncclt.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\vogel verlag\fahren lernen\data\internetupdater.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\nortoninstaller\{397e31aa-0d78-4649-a01c-339d73a2ed35}\nss\licensetype\2.7.3.34\microsoft.vc80.crt\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\norton security scan\norton security scan\engine\2.7.3.34\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\skinmagicu.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\scd32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\ntiaspi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\msvcr71d.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\mfc71u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\mfc71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\lame_enc.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\codecs\mcmpgcap32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\atl71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\photo maker\aboutntisdk.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti ripper suite\skinmagicu.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti ripper suite\scd32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti ripper suite\plugins\wmacodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti ripper suite\plugins\wavcodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti ripper suite\plugins\oggcodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\windows media player\plugins\wmp_scrobbler.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti ripper suite\ogg.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti ripper suite\ntiaspi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti ripper suite\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti ripper suite\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti ripper suite\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti ripper suite\atisendcmd.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti jewelcase maker\scd32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti jewelcase maker\ntiaspi32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti jewelcase maker\ntiaspi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti jewelcase maker\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti jewelcase maker\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti jewelcase maker\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti jewelcase maker\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti jewelcase maker\mfc71u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti jewelcase maker\mfc71d.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti jewelcase maker\mfc71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\nti jewelcase maker\cdrw32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\wmacodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\vresizer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\slideshow.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\scd32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\plug-in\wmacodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\plug-in\wavcodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\plug-in\oggcodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\plug-in\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\plug-in\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\plug-in\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\programdata\divx\runasuser\runasuserprocess.dll

laevalalala 28.08.2010 13:24

07072361 W32/Cosmu.A Virus No 1 Yes No c:\programdata\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\programdata\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\programdata\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\programdata\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\programdata\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\programdata\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\programdata\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\uninstaller.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\plug-in\avi2mpegdeluxe.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\plug-in\apecodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\programdata\temp\{2637c347-9dad-11d6-9ea2-00055d0ca761}\postbuild.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\qoobox\quarantine\c\users\eva-maria\appdata\local\activedsv.exe.vir
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\ogg.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\pc connectivity solution\transports\nclirsrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\ntiaspi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\msxml4.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\mp3enc.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\aufilter.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\audiodvd.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\media maker\atisendcmd.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\liveupdate\scd32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\liveupdate\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\liveupdate\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\wmacodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\scd32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\ogg.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\ntiaspi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\id3lib.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\codec\wmacodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\codec\wavcodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\codec\oggcodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\codec\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\codec\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\codec\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\codec\apecodec.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti media maker 8\audio editor\atisendcmd.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\startjob.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\scheduleres.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\schedaux.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\scd32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\part32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\ntiaspi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\mfc71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\hddrw32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\client\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\client\mfc71u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\client\mfc71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\client\ace.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\nti backup now 5\cdrw32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\acer backup manager\turbodll.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\acer backup manager\ntiaspi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\acer backup manager\hddrw32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\newtech infosystems\acer backup manager\cryptopp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\plugins\npqtplugin7.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\plugins\npqtplugin6.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\plugins\npqtplugin5.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\plugins\npqtplugin4.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\plugins\npqtplugin3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\plugins\npqtplugin2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\plugins\npqtplugin.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\firefoxsrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\mozilla firefox\components\googledesktopmozilla.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft works\wksssdb.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft works\wkproof.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\microsoft office\office12\addins\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\markany\contentsafer\maclicx15.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\lavasoft\ad-aware\unrar.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\lavasoft\ad-aware\toolbox\autostart manager\autostart manager.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\launch manager\szptcutl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\launch manager\ptioutl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\launch manager\closeapp\closehookapp.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\last.fm\vistalib32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\last.fm\updater.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\last.fm\killer.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\lib\deploy\lzma.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\wsdetect.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\splashscreen.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\regutils.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\npoji610.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\new_plugin\npjp2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\net.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\management.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\jpishare.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\jpioji.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\jpinscp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\jpiexp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\jpicom.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\jli.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\jkernel.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\jdwp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\java.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\j2pkcs11.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\instrument.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\hprof.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\hpi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\deploy.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\cmm.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\client\jvm.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\axbridge.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\lib\deploy\lzma.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\lib\deploy\jqs\ie\jqs_plugin.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\wsdetect.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\splashscreen.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\regutils.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\npoji610.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\new_plugin\npjp2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\new_plugin\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\net.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\management.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\jpishare.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\jpioji.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\jpinscp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\jpiexp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\jpicom.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\jli.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\jkernel.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\jdwp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\java.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\j2pkcs11.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\instrument.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\hprof.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\hpi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\deploy.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\cmm.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\client\jvm.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre1.6.0_14\bin\axbridge.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\internet explorer\plugins\npqtplugin7.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\internet explorer\plugins\npqtplugin6.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\internet explorer\plugins\npqtplugin5.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\internet explorer\plugins\npqtplugin4.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\internet explorer\plugins\npqtplugin3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\internet explorer\plugins\npqtplugin2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\internet explorer\plugins\npqtplugin.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\installshield installation information\{bf91b300-eebc-4223-96f3-0fcbf7241b50}\setup.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\installshield installation information\{88eb38ef-4d2c-436d-abd3-56b232674062}\issetup.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\installshield installation information\{88eb38ef-4d2c-436d-abd3-56b232674062}\icq7.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\installshield installation information\{60de4033-9503-48d1-a483-7846bd217ca9}\setup.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\installshield installation information\{60de4033-9503-48d1-a483-7846bd217ca9}\issetup.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\installshield installation information\{5db1df0c-aabc-4362-8a6d-cefdfb036e41}\setup.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\installshield installation information\{3db0448d-ad82-4923-b305-d001e521a964}\setup.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\installshield installation information\{3db0448d-ad82-4923-b305-d001e521a964}\issetup.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\installshield installation information\{2637c347-9dad-11d6-9ea2-00055d0ca761}\skutil.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\installshield installation information\{2413930c-8309-47a6-bc61-5ef27a4222bc}\setup.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\installshield installation information\{15d967b5-a4be-42ae-9e84-64cd062b25aa}\setup.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\zip.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\xprt6.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\tbdiag.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\ssce5532.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\sipxtapi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\sipxmedialib.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\pb_videoconf.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\mutils.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\muiutils.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\muimessage.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\muicore.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\mreport.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\misb.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\mdb.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\mcore.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\mbcontainer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\flashplayercontrol.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\coolcore59.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\aoldiag.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq7.0\acccore.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\zip.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\xprt6.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\ssce5532.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\sipxtapi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\pb_videoconf.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\mutils.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\muiutils.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\muimessage.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\mreport.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\misb.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\mdb.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\mcore.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\flashplayercontrol.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\dbenderc14.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\coolcore49.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\icq6.5\7z.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\temp\_prev_googleuiengine.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\temp\_prev_googleservices.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\temp\_prev_googledesktopssd.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\temp\_prev_googledesktopoffice.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\temp\_prev_googledesktopnetwork3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\temp\_prev_googledesktopmozilla.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\temp\_prev_googledesktopie.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\temp\_prev_googledesktophyper.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\temp\_prev_googledesktophwp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\temp\_prev_googledesktopdeskbar2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\temp\_prev_googledesktopapi2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\pdftotext.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\googleuiengine.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\googledesktopssd.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\googledesktopoffice.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\googledesktopmozilla.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\googledesktophwp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\google\google desktop search\googledesktopdeskbar2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\esobi\esobi2\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free youtube uploader\freeyoutubeuploader.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free youtube to mp3 converter\freeyoutubetomp3converter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free youtube to ipod converter\freeyoutubetoipodconverter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free youtube to iphone converter\freeyoutubetoiphoneconverter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free youtube download\freeyoutubedownload.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free video to mp3 converter\freevideotomp3converter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free video to jpg converter\freevideotojpgconverter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free video to ipod converter\freevideotoipodconverter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free video to iphone converter\freevideotoiphoneconverter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free video to flash converter\freevideotoflashconverter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free video to dvd converter\freevideotodvdconverter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free video flip and rotate\freevideoflipandrotate.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free video dub\freevideodub.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free dvd video converter\freedvdvideoconverter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free dvd video burner\freedvdvideoburner.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free dvd decrypter\freedvddecrypter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free disc burner\freediscburner.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free audio dub\freeaudiodub.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free audio converter\freeaudioconverter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free audio cd to mp3 converter\freeaudiocdtomp3converter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free audio cd to mp3 converter\enc_aac.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free audio cd burner\freeaudiocdburner.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\dvdvideosoft\free studio\free 3gp video converter\free3gpvideoconverter.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\convesoft\orion\a.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\system\ole db\msolap80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\vc\msdia80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\translat\wtsp61ms.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\translat\msb1star.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\translat\iten\msb1iten.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\translat\geen\msb1geen.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\translat\fren\msb1fren.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\proof\msthes3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\microsoft shared\proof\1033\msgr3ge.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\installshield\professional\runtime\11\50\intel32\iuser.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\installshield\professional\runtime\11\50\intel32\iscript.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\installshield\professional\runtime\11\50\intel32\ikernel.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\installshield\iscript\iscript.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\tb\condplug.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\dll\winhttp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\dll\videorotate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\dll\videofilecutter.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\dll\uploader\dvsyoutubeuploaderj.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\dll\htmlswfgen.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\dll\dvsvideoplayerjpg.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\dll\dvsmp3tageditor.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\dll\dvsitunes.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\dll\dvsdvdvideocreater.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\dll\dvddecrypter.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\common files\dvdvideosoft\dll\audiograbberdll.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\audacity\plug-ins\sc4.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\audacity\plug-ins\hard limiter.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\audacity\plug-ins\gverb.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\audacity\audacity.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-previews-vista\cccprev.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\graphics-full-existing\dxstress.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\core-static\installshell.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\core-static\atishlx.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\core-static\atiamaxx.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati technologies\ati.ace\core-static\atiacmxx.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\ati\cim\bin\packagemanager.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\adobe\reader 9.0\reader\sqlite.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\adobe\reader 9.0\reader\authplay.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\adobe\reader 9.0\reader\agm.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\adobe\reader 9.0\reader\adobexmp.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\adobe\reader 9.0\reader\acrofx32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\adobe\reader 9.0\reader\ace.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\zuma deluxe\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\zuma deluxe\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\wedding dash\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\wedding dash\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\turbo pizza\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\turbo pizza\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tri-peaks solitaire to go\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tri-peaks solitaire to go\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\tradewinds 2\gd204.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\puzzle express\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\puzzle express\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\parking dash\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\parking dash\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\ocean express\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\ocean express\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\mahjong escape ancient china\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\mahjong escape ancient china\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\thread.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\snd3d_fmod.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\snd3d.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\platform.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\logger.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\img_tga.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\img_png.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\img_jpg.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\gfx_dx8.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\gfx_dd7.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\gfx.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\fmodex.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\file.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\luxor 2\engine.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\jewel quest solitaire\sdl_gfx.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\jewel quest solitaire\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\jewel quest solitaire\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\swiftshader.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\galapago\fmodex.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\swiftshader.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day wedding\fmodex.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\swiftshader.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\oberonsplash.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dream day honeymoon\fmodex.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dairy dash\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\dairy dash\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cradle of rome\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cradle of rome\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cooking dash\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cooking dash\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\cake mania 2\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\airport mania first flight\launch.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer gamezone\airport mania first flight\hookisolate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\xerces-c_2_6.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\webupdate.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\videofilter\cv.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\qtnetwork4.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\qtgui4.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\qtcore4.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\qt3support4.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\mm\_clplayer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\mm\_clhdplayer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\mm\_bigbang.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\mm\_audiomixer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\mm\evoparser.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\mm\clinteop.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\mfc71u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\kernel\koanbox\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\kernel\koanbox\koanbox.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\kernel\common\cldevicedetector.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\fwnet.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\clvistaaudiomixer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\clformatdetector.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\cldshowx.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\playmovie\atl71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\msvcr71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_wmplayer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_wmlibrary.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_vistaaudiomixer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_upnptvserver.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_ripper.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_imageeditor.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_effect.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_clplayer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_clnetshow.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_clnetpm.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_bigbang.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\_audiomixer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mm\evoparser.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mfc71u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\mfc71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\koan\_wingdi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\koan\_render3d.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\koan\_rdmsdx9.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\koan\_rdmsdx7.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\remoteui\pwrmgmtif.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\remoteui\clruiclient.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\remoteui\clnetpm.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\music\clalbumart.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\koanbox\koanbox.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\dmp\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\dmp\humbrella.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\dmp\dxrender.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\dmp\clweblib2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\dmp\clnetshow.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\dmp\clhttpdownload.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\common\clvfd.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\kernel\common\cldevicedetector.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\fwnet.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\dxrender.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\homemedia\atl71.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\system\_pyplayer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\system\_pydevicedetector.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\system\_pyd3dmath.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\system\_pyceseffect.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\system\_pybigbang.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\koan\_wingdi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\koan\_render3d.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\video\cv.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\video\clvistaaudiomixer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\video\cldshowx.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\video\cldrm.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\photo\treffectlib.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\photo\effectlibrary.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\photo\ces_plugin_5.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\photo\ces_plugin_3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\photo\ces_pluginhost.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\mediaobj.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\ltkrn13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\ltimg13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\ltfil13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\ltefx13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\ltdis13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\ltclr13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\lftif13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\lftga13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\lfras13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\lfpsd13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\lfpng13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\lfpcx13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\lfgif13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\lffax13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\lfcmp13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\lfbmp13n.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\dvdparser.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\fwnet.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer arcade deluxe\acer arcade deluxe\clvistaaudiomixer.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer\wr_popup\winregntuser.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer\wr_popup\unwinregntuser.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer\wr_popup\productreg.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer\acer erecovery management\readfile.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer\acer erecovery management\hidchk.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer\acer erecovery management\configtskschler.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\acer\acer erecovery management\closehandlew.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\msocache\all users\{90120000-006e-0407-0000-0000000ff1ce}-c\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\tonline\internet-erlebniswelt.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\wlanfa\issetup.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\touchpad\synaptics\setup.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setuptrk.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setuptha.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupsve.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setuprus.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupptg.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupptb.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupplk.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupnor.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupnld.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupkor.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupjpn.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupita.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setuphun.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupheb.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupfra.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupfin.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupesn.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupenu.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupell.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupdeu.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupdan.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupcsy.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupcht.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupchs.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\install\lang\setupara.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\shirpeak\vista\v32\drivers\netw5c32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\modem\agsetup2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\modem\agsetup1.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\modem\agrsmsvc.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\wiscrpcs.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\wnd2file.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\szupfutl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\szptcutl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\setupdev.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\ptioutl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\powerutl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\mixerutl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\lgkcutl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\execbat.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\dialcnt.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\closeapp\closehookapp.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\instpack\cdromutl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\launchmgr\dpoioutl.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\winsxs\r6hpravq.lm8\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\winsxs\p6hpravq.lm8\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\winsxs\jwfvlhtq.lm8\atl80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\winsxs\hwfvlhtq.lm8\atl80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\winsxs\bql1q2cs.lm8\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\winsxs\bql1q2cs.lm8\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\winsxs\9ql1q2cs.lm8\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\winsxs\9ql1q2cs.lm8\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\system32\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\system32\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\system32\mfc80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\system32\atl80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\local\windows\winhelp.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\locallow\sun\java\jre1.6.0_14\lzma.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\locallow\sun\java\jre1.6.0_16\lzma.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\facebook\npfbplugin_1_0_1.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\facebook\npfbplugin_1_0_3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\windows\system32\ansi\atl80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\system32\vcryptapi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\system32\int15.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\system32\bioone.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\system32\atsc70pba.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\program files\[productname]\tpmsvr.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\program files\[productname]\int15.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\microsoft\windows\templates\memory.tmp
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\program files\[productname]\fplaunchcache.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000004.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\libs\launchcooliris.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\libs\piclenshelper.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\program files\[productname]\compptcv32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\appdata\roaming\mozilla\firefox\profiles\jy1c4yrj.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\radiowmpcore.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\program files\[productname]\bsapi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\program files\[productname]\acerwmi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\finger\driver\sdkinstaller.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\chiinf\csver.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\wdm\vncutil.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\desktop\klick.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\desktop\otl.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\desktop\otlsrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\wdm\soundman.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\wdm\skytel.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\wdm\rtlcpl.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\wdm\rtlcpapi.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\documents\downloads\otl (1).exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\documents\downloads\otl.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\documents\downloads\otlsrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\wdm\rthdcpl.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\wdm\rtcomdll.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\documents\dvdvideosoft\cleaner.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\downloads\otl.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\eva-maria\downloads\skype410179.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\users\public\desktop\internet-erlebniswelt.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\wdm\miccal.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\wdm\alcwzrd.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\wdm\alcmtr.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\vista\waveslib.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\vista\srswow.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\vista\srstsxt.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\vista\srshp360.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\vista\sltshd32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\vista\slinit32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\vista\slh36032.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\vista\slgeq32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\vista\slcshp32.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\vista\maxxaudioeq.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\vista\aertsrv.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\rtlexupd.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\hdmi\vista\rhdmiext.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\config\azmixersel.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\chcfg.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\audio\ap\winvista\rtkvadda.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\ativga\packages\drivers\display\lh_inf\b_75279\coinst.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\ativga\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\ativga\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\ativga\bin\packagemanager.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\ativga\bin\msvcr80.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\ativga\bin\mfc80u.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\drv\ativga\bin\controlcenteractions.dll
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\autorunx\autorunx.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\acer\preload\autorun\app\arcaddlx\pcinema\skutil.dll
07072361 W32/Cosmu.A Virus Yes 2 Yes No c:\program files\quicktime\qttask.exe
07072361 W32/Cosmu.A Virus Yes 2 Yes No c:\program files\pc connectivity solution\servicelayer.exe
07072361 W32/Cosmu.A Virus Yes 2 Yes No c:\program files\ati technologies\ati.ace\core-static\clistart.exe
07072361 W32/Cosmu.A Virus Yes 2 Yes No c:\program files\amicosinglun\amicosinglun.exe
07072361 W32/Cosmu.A Virus No 1 Yes No c:\program files\java\jre6\bin\new_plugin\msvcr71.dll
07072361 W32/Cosmu.A Virus Yes 2 Yes No c:\program files\ati technologies\ati.ace\core-implementation\32\wbhelp2.dll
;===================================================================================================================================================== ==============================
SUSPECTS
Sent Location
;===================================================================================================================================================== ==============================
No c:\program files\microsoft\desktoplayer.exe
No c:\qoobox\quarantine\c\program files\microsoft\desktoplayer.exe.vir
No c:\users\eva-maria\appdata\local\windows\winhelpsrv.exe
No c:\users\eva-maria\desktop\cofi.exe
No c:\users\eva-maria\downloads\combofix.exe
No c:\users\eva-maria\microsoft\desktoplayer.exe
No c:\program files\temp\ddc.exe
;===================================================================================================================================================== ==============================
VULNERABILITIES
Id Severity Description

john.doe 28.08.2010 14:17

:eek: Wasndas?

Panda Active Scan deinstallieren. Weiter mit => http://www.trojaner-board.de/59299-a...eb-cureit.html

ciao, andreas

laevalalala 28.08.2010 14:30

das sollte ActiveScan.txt sein :D

john.doe 28.08.2010 14:36

Ich weiß, nur die Funde ergeben kein Sinn, denn das sieht aus wie ein Fileinfector. Lade bitte die Dateien:
Zitat:

c:\program files\acer gamezone\tradewinds 2\omdata\empty.html
c:\acer\preload\autorun\drv\ativga\mfc80u.dll
c:\program files\quicktime\qttask.exe
bei uns hoch. Markiere jeweils eine Zeile in der Box, kopiere sie und füge sie im Uploadchannel ein => http://www.trojaner-board.de/54791-a...ner-board.html (nur Schritt 2).

ciao, andreas

john.doe 28.08.2010 17:47

1.) Starte Malwarebytes => Karte: Aktualisierung => Klick auf: Suche nach Aktualisierungen => Karte: Suchlauf => Vollständigen Suchlauf durchführen => Scannen => Log posten

2.) Falls du im Firefox Lesezeichen hast, exportiere diese.

3.) Deinstalliere (falls vorhanden):
  • Google Toolbar for Internet Explorer
  • Java(TM) 6 Update 14
  • Java(TM) 6 Update 16
  • Ad-Aware Email Scanner for Outlook
  • CCC Help Chinese Standard
  • CCC Help Polish
  • CCC Help French
  • CCC Help Portuguese
  • CCC Help Chinese Traditional
  • CCC Help Italian
  • CCC Help Japanese
  • CCC Help Greek
  • CCC Help Spanish
  • Ask Toolbar
  • CCC Help Finnish
  • CCC Help Swedish
  • Skype Toolbars
  • CCC Help Turkish
  • CCC Help Thai
  • CCC Help Norwegian
  • Google Update Helper (falls möglich)
  • CCC Help Russian
  • Adobe Reader 9 - Deutsch
  • CCC Help Korean
  • CCC Help Dutch
  • Ad-Aware
  • CCC Help Czech
  • CCC Help Hungarian
  • CCC Help Danish
  • Acer ScreenSaver
  • Google Desktop (falls nicht benötigt)
  • Gutscheinmieze - Toolbar
  • ICQ Toolbar
  • Mozilla Firefox (3.6.3)
4.)Scripten mit Combofix
  • Öffne den Editor (Start => Zubehör => Editor ) kopiere nun folgenden Text in das weiße Feld:
Code:

KILLALL::

Driver::
bhkrfkkk
gupdate
Lbd
ICQ Service
Lavasoft Ad-Aware Service

RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=-
"swg"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"Google Desktop Search"=-
"Ad-Watch"=-
"QuickTime Task"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

Folder::
c:\users\Eva-Maria\AppData\Roaming\Biim
c:\users\Eva-Maria\AppData\Roaming\9F7CB0D6ABC204D4F42E15EE8D7D4089
c:\users\Eva-Maria\AppData\Local\fynqpggca

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1313689582-3900863286-3496430324-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1313689582-3900863286-3496430324-1000UA.job

DirLook::
c:\users\Default\AppData\Local\temp
c:\users\Eva-Maria\AppData\Local\Windows
c:\users\Eva-Maria\temp
c:\users\Eva-Maria\Microsoft
c:\program files\Microsoft
c:\users\Eva-Maria\AppData\Roaming\Hyimro

Speichere diese Datei nun auf dem Desktop unter -> cfscript.txt
  • Nun die Datei cfscript.txt auf das Symbol von Combofix ziehen!
http://users.pandora.be/bluepatchy/m...s/CFScript.gif


Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann.


5.) Installiere (Toolbars immer abwählen, Haken weg):6.) Falls du Lesezeichen exportiert hast, importiere diese wieder.

ciao, andreas

laevalalala 29.08.2010 11:14

hxxp://www.file-upload.net/download-2783453/ComboFix.txt.html

john.doe 29.08.2010 15:47

Es fehlt das Log von Malwarebytes.

ciao, andreas

laevalalala 29.08.2010 20:27

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Datenbank Version: 4500

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943

29.08.2010 21:25:04
mbam-log-2010-08-29 (21-25-04).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 312210
Laufzeit: 1 Stunde(n), 58 Minute(n), 31 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

john.doe 29.08.2010 20:40

Das mit dem ComboFix-Script hat nicht so richtig funktioniert. Deshalb noch einmal. Lade dir den Anhang auf deinen Desktop (den wir so langsam mal aufräumen müssen) und ziehe das neue Symbol (mit Namen cfscript.txt) auf das Symbol von ComboFix. Das Log wird sehr groß. Hochladen und Link posten. Du weißt ja jetzt, wie das geht. :)

ciao, andreas

laevalalala 29.08.2010 22:54

hxxp://www.file-upload.net/download-2785384/ComboFix.txt.html

john.doe 30.08.2010 20:35

Laut Logs sollte es dem Rechner wieder besser gehen. Gibt es noch irgendwelche Auffälligkeiten oder Meldungen?

1.) Säubere dein System mit CCleaner => http://www.trojaner-board.de/51464-a...-ccleaner.html

2.) Lade dir cfscript.txt auf deinen Desktop und ziehe das Symbol auf das ComboFix-Symbol.

3.) Poste das neue ComboFix-Log.

4.) Lösche alle Symbole, die du im Laufe dieser Aktion heruntergeladen hast.

ciao, andreas

laevalalala 31.08.2010 01:25

hxxp://www.file-upload.net/download-2788069/ComboFix.txt.html

nein, ich habe keine beschwerden mehr...
aber wir schütze ich mich jetzt am besten vor solchen viren? welches (kostenlose) Virenprogramm ist zu empfehlen?
Vielen vielen Dank für die hilfe =)

john.doe 01.09.2010 15:28

Diese Reaktion ist typisch.
Zitat:

aber wir schütze ich mich jetzt am besten vor solchen viren? welches (kostenlose) Virenprogramm ist zu empfehlen?
Auch wenn es die angenehme Alternative scheint, kann kein Programm dich vor dir selber schützen. Es ist und bleibt deine Verantwortung. Wir können dir nur die grundlegenden Regeln vermitteln. Hier wird üblicherweise zur Combo Avira/Malwarebytes geraten. Aber das ist nur ein bedingter Schutz. Kein Programm kann dich wirklich schützen (ich habe überhaupt kein Antivirenprogramm und Malwarebytes nur um zu schauen, ob die Leute die Updates durchgeführt haben). Es hängt einzig und allein von dir ab.

Befolge diese Regeln:
1.) Nutze nicht Programme, die von Hackern aufs Korn genommen werden (sprich kein MSIE oder Firefox). Nutze Nischenprogramme wie Opera oder Iron zum Surfen und z.B. Opera oder Thunderbird zum Mailen. Nutze Pidgin anstelle von ICQ oder Windows Live.

2.) Halte deine Software aktuell. Das gilt besonders für das Betriebssystem (Windows) aber auch für andere sicherheitskritische Software (Java, Acrobat Reader, ...). Helfen kann dir dabei => PSI - Consumer - Products

3.) Sei paranoid. Denke 37 mal nach, bevor du irgendwo draufklickst. Falls du dir nicht sicher bist, klicke nicht drauf! Egal was der Link auch verspricht.

4.) Start => Ausführen => combofix /uninstall => OK

5.) Poste neue Logs mit OTL.

ciao, andreas

laevalalala 01.09.2010 21:48

Okay, danke
also jetzt Combofix deinstallieren und dann nochmal einen OTL log posten?

john.doe 01.09.2010 21:50

Ja.

Packe den Ordner c:\qoobox mit ZIP oder RAR. Lade das Archiv bei einem Filehoster hoch (z.B. www.file-upload.net) und schicke mir den Link als Private Nachricht.

ciao, andreas

laevalalala 01.09.2010 23:43

OTL Logfile:
Code:

OTL logfile created on: 02.09.2010 00:38:15 - Run 5
OTL by OldTimer - Version 3.2.1.1    Folder = C:\Users\Eva-Maria\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 54,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 291,33 Gb Free Space | 63,89% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: EVA-MARIAS-PC
Current User Name: Eva-Maria
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\EVA-MA~1\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
PRC - C:\Users\Eva-Maria\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Secunia\PSI\psi.exe (Secunia)
PRC - C:\Programme\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - c:\Programme\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - c:\Programme\Microsoft Security Essentials\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Acer Incorporated)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Programme\EgisTec\MyWinLocker 3\x86\MWLService.exe (Egis Technology Inc.)
PRC - C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
PRC - C:\Programme\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Programme\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
PRC - C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
PRC - C:\Programme\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
PRC - C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
PRC - C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Eva-Maria\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (MpfService) --  File not found
SRV - (McSysmon) --  File not found
SRV - (McShield) --  File not found
SRV - (McNASvc) --  File not found
SRV - (McAfee SiteAdvisor Service) --  File not found
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (ePowerSvc) -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Acer Incorporated)
SRV - (MWLService) -- C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe ()
SRV - (NTI IScheduleSvc) -- C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (CLHNService) -- C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
SRV - (NTISchedulerSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.)
SRV - (NTIBackupSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (catchme) --  File not found
DRV - (PSI) -- C:\Windows\System32\drivers\psi_mf.sys (Secunia)
DRV - (MpFilter) -- C:\Windows\System32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (NTIDrvr) -- C:\Windows\System32\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (ss_bmdm) -- C:\Windows\System32\drivers\ss_bmdm.sys (MCCI Corporation)
DRV - (ss_bbus) SAMSUNG USB Mobile Device (WDM) -- C:\Windows\System32\drivers\ss_bbus.sys (MCCI)
DRV - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) -- C:\Windows\System32\drivers\ss_bmdfl.sys (MCCI Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (RTHDMIAzAudService) -- C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (mwlPSDVDisk) -- C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Incorporated.)
DRV - (mwlPSDFilter) -- C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Incorporated.)
DRV - (mwlPSDNServ) -- C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Incorporated.)
DRV - (RTSTOR) -- C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (k57nd60x) Broadcom NetLink (TM) -- C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (UBHelper) -- C:\Windows\System32\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (NSCIRDA) -- C:\Windows\System32\drivers\nscirda.sys (National Semiconductor Corporation)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (DKbFltr) -- C:\Windows\System32\drivers\DKbFltr.sys (Dritek System Inc.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.0&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2010.01.24 22:22:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.29 12:16:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.29 12:32:35 | 000,000,000 | ---D | M]
 
[2010.08.30 14:31:03 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Extensions
[2010.08.30 14:31:07 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\u9xsvhkb.default\extensions
[2010.08.30 14:31:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\u9xsvhkb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.08.30 14:31:07 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\u9xsvhkb.default\extensions\staged-xpis
[2010.08.30 14:31:10 | 000,000,687 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\u9xsvhkb.default\searchplugins\icq-search.xml
[2008.03.31 13:52:00 | 000,000,168 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\u9xsvhkb.default\searchplugins\icqplugin.gif
[2008.03.31 13:52:00 | 000,000,618 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\u9xsvhkb.default\searchplugins\icqplugin.src
[2010.08.29 12:19:36 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.01.19 21:07:05 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.03.23 18:14:51 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.08.29 12:19:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.04.11 00:34:04 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
[2010.08.29 12:18:50 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.03.19 10:23:30 | 000,686,592 | ---- | M] (Synatix GmbH) -- C:\Programme\Mozilla Firefox\plugins\npmieze.dll
[2010.07.23 02:48:56 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.07.23 02:48:56 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.07.23 02:48:56 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.07.23 02:48:56 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.07.23 02:48:56 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.08.31 02:11:14 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O4 - HKLM..\Run: [Acer ePower Management] C:\Programme\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Acer Incorporated)
O4 - HKLM..\Run: [AmIcoSinglun] C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcadeDeluxeAgent] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [EgisTecLiveUpdate] C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [LManager] C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [mwlDaemon] C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Programme\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - Startup: C:\Users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Eva-Maria\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Eva-Maria\Pictures\2010\Sonnenrot\37544_139724646055413_111409868886891_321838_7061603_n.jpg
O24 - Desktop BackupWallPaper: C:\Users\Eva-Maria\Pictures\2010\Sonnenrot\37544_139724646055413_111409868886891_321838_7061603_n.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.09.02 00:32:49 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010.09.02 00:32:49 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Local\temp
[2010.09.02 00:32:05 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010.09.02 00:20:16 | 000,000,000 | ---D | C] -- C:\cofi3059c
[2010.09.02 00:19:51 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010.08.31 20:10:14 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Security Essentials
[2010.08.29 23:04:21 | 000,221,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010.08.29 12:29:43 | 000,000,000 | ---D | C] -- C:\Programme\Adobe
[2010.08.29 12:20:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.08.29 12:20:22 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Java
[2010.08.29 12:19:32 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.08.29 12:19:32 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.08.29 12:19:32 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.08.29 12:19:32 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.08.29 12:18:21 | 000,000,000 | ---D | C] -- C:\Programme\Secunia
[2010.08.29 11:49:34 | 000,000,000 | ---D | C] -- C:\cofi15611c
[2010.08.28 03:35:26 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2010.08.28 03:35:26 | 000,420,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2010.08.28 00:42:17 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2010.08.28 00:42:15 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2010.08.28 00:42:14 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2010.08.28 00:42:13 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2010.08.28 00:42:13 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010.08.28 00:42:13 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010.08.28 00:42:11 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2010.08.28 00:42:11 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2010.08.28 00:42:10 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2010.08.28 00:42:09 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010.08.28 00:42:08 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2010.08.28 00:42:08 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2010.08.28 00:42:06 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2010.08.28 00:42:06 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2010.08.28 00:42:01 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2010.08.28 00:33:53 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2010.08.28 00:33:53 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2010.08.28 00:33:52 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2010.08.28 00:33:52 | 000,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2010.08.28 00:33:52 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2010.08.28 00:33:52 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2010.08.28 00:33:52 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\corpol.dll
[2010.08.28 00:33:51 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2010.08.28 00:33:51 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2010.08.28 00:33:51 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2010.08.28 00:33:51 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2010.08.28 00:33:50 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFXDocObj.exe
[2010.08.28 00:33:50 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2010.08.28 00:33:50 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2010.08.28 00:33:50 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2010.08.28 00:33:49 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2010.08.28 00:33:49 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2010.08.28 00:33:48 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2010.08.28 00:33:47 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2010.08.28 00:33:46 | 003,698,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2010.08.28 00:33:46 | 000,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2010.08.28 00:33:46 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PDMSetup.exe
[2010.08.28 00:33:46 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2010.08.28 00:33:46 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2010.08.28 00:33:46 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetDepNx.exe
[2010.08.28 00:31:48 | 000,000,000 | ---D | C] -- C:\Programme\Panda Security
[2010.08.27 23:34:23 | 000,000,000 | ---D | C] -- C:\cofi
[2010.08.27 23:24:19 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2010.08.27 23:23:01 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010.08.27 23:23:01 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010.08.27 23:23:01 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010.08.27 23:22:55 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010.08.27 23:20:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.08.27 20:06:12 | 000,561,664 | ---- | C] (OldTimer Tools) -- C:\Users\Eva-Maria\Desktop\OTL.exe
[2010.08.27 09:33:24 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Local\Windows
[2010.08.26 10:37:56 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\temp
[2010.08.25 16:26:51 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\Microsoft
[2010.08.14 14:39:26 | 000,081,920 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2010.08.14 14:39:22 | 002,037,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2010.08.14 14:39:09 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll
[2010.08.14 14:38:56 | 003,600,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010.08.14 14:38:54 | 003,548,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2009.07.21 10:28:54 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010.09.02 00:40:38 | 004,980,736 | -HS- | M] () -- C:\Users\Eva-Maria\ntuser.dat
[2010.09.02 00:37:45 | 000,006,836 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Local\d3d9caps.dat
[2010.09.02 00:37:08 | 000,524,288 | -HS- | M] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.09.02 00:37:08 | 000,065,536 | -HS- | M] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.09.02 00:36:57 | 003,151,654 | -H-- | M] () -- C:\Users\Eva-Maria\AppData\Local\IconCache.db
[2010.09.02 00:30:20 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010.09.02 00:30:15 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{67F42434-13A1-4949-BC57-7301C908FC3C}.job
[2010.09.02 00:04:21 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.09.02 00:04:21 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.09.01 22:04:22 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.09.01 22:04:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.08.31 20:10:14 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.08.31 02:11:14 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010.08.31 01:59:30 | 003,831,151 | R--- | M] () -- C:\Users\Eva-Maria\Desktop\cofi.exe
[2010.08.31 01:54:15 | 000,000,808 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\CCleaner.lnk
[2010.08.29 23:20:21 | 336,965,288 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010.08.29 19:07:11 | 000,000,566 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Eva-Maria.job
[2010.08.29 15:18:45 | 000,002,231 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010.08.29 12:44:51 | 000,000,056 | -H-- | M] () -- C:\Windows\System32\ezsidmv.dat
[2010.08.29 12:32:36 | 000,001,891 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010.08.29 12:18:47 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.08.29 12:18:47 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.08.29 12:18:47 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.08.29 12:18:45 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.08.29 12:16:36 | 000,001,728 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.08.28 12:22:32 | 000,044,032 | -H-- | M] () -- C:\Users\Eva-Maria\Documents\photothumb.db
[2010.08.28 12:03:38 | 000,033,792 | -H-- | M] () -- C:\Users\Eva-Maria\photothumb.db
[2010.08.28 00:05:46 | 000,114,688 | ---- | M] (Abstract Software) -- C:\Users\Public\Desktop\Internet-Erlebniswelt.exe
[2010.08.27 23:32:44 | 000,059,414 | ---- | M] () -- C:\Users\Eva-Maria\Documents\cc_20100827_233155.reg
[2010.08.27 21:51:49 | 000,409,387 | ---- | M] () -- C:\Users\Eva-Maria\Documents\IMG_27082010_214730.png
[2010.08.27 16:13:04 | 000,139,264 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.27 10:03:12 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.08.25 16:42:53 | 000,071,337 | ---- | M] () -- C:\Users\Eva-Maria\Documents\rockamsee.odt
[2010.08.25 16:32:14 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Users\Eva-Maria\Desktop\OTL.exe
[2010.08.25 16:32:12 | 000,321,536 | ---- | M] (Freakhouse Multimedia GmbH) -- C:\Users\Eva-Maria\Desktop\Klick.exe
[2010.08.21 16:01:40 | 000,002,109 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\Google Chrome.lnk
[2010.08.19 21:05:43 | 000,185,311 | ---- | M] () -- C:\Users\Eva-Maria\trinkspiel.jpg
[2010.08.17 18:25:07 | 000,002,784 | ---- | M] () -- C:\Users\Eva-Maria\.recently-used.xbel
[2010.08.17 15:08:59 | 000,001,036 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\DVDVideoSoft Free Studio.lnk
[2010.08.15 16:23:56 | 000,327,640 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.08.31 20:10:14 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.08.29 23:20:21 | 336,965,288 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010.08.29 12:44:51 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.08.29 12:32:35 | 000,001,891 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010.08.29 12:16:36 | 000,001,728 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.08.29 12:13:09 | 000,064,092 | ---- | C] () -- C:\Users\Eva-Maria\combofix.txt
[2010.08.29 11:48:31 | 000,002,055 | ---- | C] () -- C:\Users\Eva-Maria\cfscript.txt
[2010.08.28 10:20:26 | 000,000,434 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{67F42434-13A1-4949-BC57-7301C908FC3C}.job
[2010.08.28 00:38:36 | 000,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2010.08.27 23:31:57 | 000,059,414 | ---- | C] () -- C:\Users\Eva-Maria\Documents\cc_20100827_233155.reg
[2010.08.27 23:24:21 | 000,000,808 | ---- | C] () -- C:\Users\Eva-Maria\Desktop\CCleaner.lnk
[2010.08.27 23:23:01 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010.08.27 23:23:01 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010.08.27 23:23:01 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010.08.27 23:23:01 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010.08.27 23:23:01 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010.08.27 23:20:55 | 003,831,151 | R--- | C] () -- C:\Users\Eva-Maria\Desktop\cofi.exe
[2010.08.27 21:51:46 | 000,409,387 | ---- | C] () -- C:\Users\Eva-Maria\Documents\IMG_27082010_214730.png
[2010.08.25 16:42:50 | 000,071,337 | ---- | C] () -- C:\Users\Eva-Maria\Documents\rockamsee.odt
[2010.08.19 21:05:43 | 000,185,311 | ---- | C] () -- C:\Users\Eva-Maria\trinkspiel.jpg
[2010.08.17 18:25:07 | 000,002,784 | ---- | C] () -- C:\Users\Eva-Maria\.recently-used.xbel
[2010.07.19 21:07:50 | 000,000,024 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Roaming\vdnxlf.dat
[2010.04.26 20:49:01 | 000,000,032 | ---- | C] () -- C:\Windows\wininit.ini
[2010.04.20 18:40:12 | 000,000,100 | --S- | C] () -- C:\Users\Eva-Maria\AppData\Local\1711337819.dat
[2010.04.14 12:55:09 | 000,000,552 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\d3d8caps.dat
[2010.01.07 12:13:38 | 000,151,008 | ---- | C] () -- C:\Users\Eva-Maria\Orial Bold.ttf
[2010.01.05 22:54:27 | 000,000,088 | ---- | C] () -- C:\Users\Eva-Maria\VISIT DIRT2.COM FOR USAGE.txt
[2010.01.05 22:54:20 | 000,008,128 | ---- | C] () -- C:\Users\Eva-Maria\little bliss bold.otf
[2010.01.05 22:52:41 | 000,008,280 | ---- | C] () -- C:\Users\Eva-Maria\little bliss.otf
[2010.01.05 22:25:26 | 000,011,496 | ---- | C] () -- C:\Users\Eva-Maria\little bliss bold.ttf
[2010.01.05 11:53:00 | 000,050,566 | ---- | C] () -- C:\Users\Eva-Maria\littlebliss.jpg
[2010.01.05 11:33:10 | 000,011,528 | ---- | C] () -- C:\Users\Eva-Maria\little bliss.ttf
[2009.12.24 23:46:26 | 000,001,089 | ---- | C] () -- C:\Users\Eva-Maria\ScriptSERIF - READ ME.txt
[2009.12.23 15:46:43 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2009.12.23 15:46:43 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2009.12.23 15:36:08 | 000,113,152 | ---- | C] () -- C:\Users\Eva-Maria\1031.MST
[2009.12.23 15:36:08 | 000,015,832 | ---- | C] () -- C:\Users\Eva-Maria\0x0407.ini
[2009.12.23 15:35:58 | 097,979,392 | ---- | C] () -- C:\Users\Eva-Maria\Samsung New PC Studio.msi
[2009.12.22 20:40:18 | 000,298,828 | ---- | C] () -- C:\Users\Eva-Maria\script_serif.ttf
[2009.12.22 20:30:56 | 000,280,209 | ---- | C] () -- C:\Users\Eva-Maria\scriptSERIF_sample.jpg
[2009.12.22 20:04:42 | 000,242,864 | ---- | C] () -- C:\Users\Eva-Maria\script_serif_riptrash.ttf
[2009.11.15 12:45:44 | 000,537,011 | ---- | C] () -- C:\Users\Eva-Maria\ billy argel beyaond sky font.jpg
[2009.11.15 12:37:34 | 000,516,096 | ---- | C] () -- C:\Users\Eva-Maria\BEYONDSKTRIAL.ttf
[2009.11.15 11:19:36 | 000,000,134 | ---- | C] () -- C:\Users\Eva-Maria\READ ME.txt
[2009.09.24 15:39:01 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.20 11:21:32 | 000,033,792 | -H-- | C] () -- C:\Users\Eva-Maria\photothumb.db
[2009.09.17 13:25:41 | 000,087,349 | ---- | C] () -- C:\Users\Eva-Maria\0405_09780_happy_birthday.jpg
[2009.09.13 01:03:19 | 000,242,200 | ---- | C] () -- C:\Users\Eva-Maria\acer-code.jpg
[2009.09.03 15:46:08 | 000,002,712 | ---- | C] () -- C:\Users\Eva-Maria\JOEBOB graphics free trial font users license.txt
[2009.08.26 08:27:16 | 000,006,836 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\d3d9caps.dat
[2009.08.25 23:47:23 | 000,001,072 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Roaming\wklnhst.dat
[2009.08.22 01:11:33 | 000,139,264 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.08.12 17:41:40 | 004,980,736 | -HS- | C] () -- C:\Users\Eva-Maria\ntuser.dat
[2009.08.12 17:41:40 | 000,524,288 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2009.08.12 17:41:40 | 000,524,288 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2009.08.12 17:41:40 | 000,262,144 | -H-- | C] () -- C:\Users\Eva-Maria\ntuser.dat.LOG1
[2009.08.12 17:41:40 | 000,065,536 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2009.08.12 17:41:40 | 000,000,020 | -HS- | C] () -- C:\Users\Eva-Maria\ntuser.ini
[2009.08.12 17:41:40 | 000,000,000 | -H-- | C] () -- C:\Users\Eva-Maria\ntuser.dat.LOG2
[2009.07.21 10:16:20 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2009.07.21 10:16:20 | 000,011,264 | ---- | C] () -- C:\Windows\System32\atimuixx.dll
[2009.07.21 01:52:22 | 000,000,033 | ---- | C] () -- C:\Windows\LaunApp.ini
[2009.07.21 01:44:57 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini
[2009.07.21 01:44:56 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2009.04.26 15:05:36 | 000,521,608 | ---- | C] () -- C:\Users\Eva-Maria\vtks Deja Vu.ttf
[2009.03.12 12:32:52 | 000,000,028 | ---- | C] () -- C:\Windows\WisLangCode.ini
[2009.03.12 05:26:46 | 000,004,516 | ---- | C] () -- C:\ProgramData\ArcadeDeluxe2.log
[2009.02.11 22:03:58 | 000,872,448 | ---- | C] () -- C:\Windows\iconv.dll
[2009.02.11 22:03:58 | 000,743,424 | ---- | C] () -- C:\Windows\libxml2.dll
[2009.02.11 22:03:57 | 000,000,060 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2008.10.26 15:03:52 | 000,147,604 | ---- | C] () -- C:\Users\Eva-Maria\FPENSTRIAL.ttf
[2008.10.26 15:03:52 | 000,104,352 | ---- | C] () -- C:\Users\Eva-Maria\FPENSTRIAL.otf
[2008.01.21 04:23:43 | 000,009,232 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\acleditu.dat
[2007.10.25 18:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:25:26 | 000,557,568 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005.12.10 07:56:24 | 000,047,272 | ---- | C] () -- C:\Users\Eva-Maria\FairyDustB.ttf
[2005.10.23 22:46:42 | 000,057,560 | ---- | C] () -- C:\Users\Eva-Maria\Anywhere.ttf
[2005.08.04 09:28:04 | 000,000,286 | ---- | C] () -- C:\Users\Eva-Maria\readme.txt
[2005.08.04 09:23:30 | 000,193,572 | ---- | C] () -- C:\Users\Eva-Maria\kiralynn__.ttf
[2005.05.11 03:39:36 | 000,085,808 | ---- | C] () -- C:\Users\Eva-Maria\MINUS___.TTF
[2005.03.04 19:40:38 | 000,039,648 | ---- | C] () -- C:\Users\Eva-Maria\konanur.ttf
[2004.10.27 20:24:44 | 000,034,788 | ---- | C] () -- C:\Users\Eva-Maria\Flat Earth Scribe.ttf
[2000.07.13 11:12:46 | 000,000,430 | ---- | C] () -- C:\Users\Eva-Maria\font info.txt
[1998.10.01 23:13:48 | 000,084,704 | ---- | C] () -- C:\Users\Eva-Maria\Kelt Caps Freehand.ttf
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:3B3A35EC
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:A8ADE5D8
< End of report >

--- --- ---


iwie krieg ich combofix nicht deinstalliert wenn ich das bei ausführen eingebe...dann macht es nur einen durchlauf

laevalalala 02.09.2010 10:17

wie entpacke ich den ganzen ordner? geht das? oder muss ich alle dateien die dort angezeigt werden einzeln nehmen? oder muss ich den ordner "archivieren und versenden" ??

john.doe 02.09.2010 20:43

Liste der Anhänge anzeigen (Anzahl: 1)
1.) Starte den Windowsexplorer => Mausklick rechts auf den Ordner c:\qoobox => Senden an => ZIP komprimierten Ordner

2.) Lade dir anschließend (nur wenn der erste Schritt funktioniert hat) den Anhang auf deinen Desktop und starte ihn mit Doppelklick.

ciao, andreas

laevalalala 03.09.2010 02:02

ok, also den zip-ordner hab ich jetztm,
aber wenn ich schritt 2 machen will nachdem ich die datei runtergeladen habe, kommt dies hier:
Windows hat die folgenden Informationen zu diesem Dateityp. Diese Seite unterstützt Sie bei der Suche nach Software zum Öffnen dieser Datei.


Dateityp: Unknown

Beschreibung: Dieser Dateityp wird von Windows nicht erkannt.

laevalalala 03.09.2010 02:02

hxxp://www.file-upload.net/download-2794609/Qoobox.zip.html

john.doe 03.09.2010 17:28

Dein Link macht mich mehr als nur ein bisschen nervös. Mal abgesehen davon, dass du ihn eigentlich als Private Nachricht schicken solltest. enthält die Datei nichts als Müll. Keine der (verdächtigen) Dateien, die von CF als gelöscht gemeldet worden ist, lässt dich dort finden. Ist dein Antivirenprogramm angeprungen und hat haufenweise Dateien gelöscht, dich ich dringend benötige, um dich zu bereinigen?

ciao, andreas

laevalalala 03.09.2010 23:48

uups stimmt :/
hm ja, kann sein...dh? was soll ich nun machen?

john.doe 06.09.2010 19:29

1.) Mit Online-Scans kann man den kompletten Rechner auf Schädlinge prüfen lassen. Nimm am besten gleich den Internet Explorer.

Vorbereitung
  • Schließe evtl. vorhandene externe Festplatten und/oder sonstigen Wechselmedien (z. B. evtl. vorhandene USB-Sticks) an den Rechner an.
  • Bitte während der Online-Scans deaktivieren:
    Anti-Virus-Programm und Firewall.
  • Internet Explorer starten => im Menü unter Extras => Internetoption => Datenschutz => den Haken bei "Popupblocker einschalten" entfernen und
  • unter dem Reiter "Sicherheit" => die Sicherheitsstufe ggfs. auf "Mittelhoch" herabsetzen.
    Nicht vergessen, sie hinterher wieder einzuschalten bzw. die Internetoptionen wie zuvor einzustellen..
  • Während der Online-Scans auf andere Online-Aktivitäten verzichten.
  • Du musst das Herunterladen und Installieren von ActiveX-Steuerelementen (Controls) zulassen.

  • http://image.hijackthis.eu/upload/activex1.jpg
    .

ESET Online Scanner
Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.
  • Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt als Administrator starten.
  • Dein Anti-Virus-Programm während des Scans deaktivieren.
  • Button http://img695.imageshack.us/img695/1599/eset1l.jpg drücken.
    • Firefox-User: Bitte esetsmartinstaller_enu.exe downloaden.Das Firefox-Addon auf dem Desktop speichern und dann installieren.
    • IE-User: müssen das Installieren eines ActiveX Elements erlauben.
  • Setze den einen Hacken bei Yes, i accept the Terms of Use.
  • Drücke den http://img707.imageshack.us/img707/687/starteg.jpg Button.
  • Warte bis die Komponenten herunter geladen wurden.
  • Setze einen Haken bei "Remove found threads" und "Scan archives".
  • http://img707.imageshack.us/img707/687/starteg.jpg drücken.
  • Die Signaturen werden herunter geladen.Der Scan beginnt automatisch.
Wenn der Scan beendet wurde
  • Klicke Finish.
  • Browser schließen.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt suchen und mit Deinem Editor öffnen.
  • Logfile hier posten.

2.) Kaspersky - Onlinescanner

Dieser Scanner entfernt die Funde nicht, gibt aber einen guten Überblick über die vorhandene Malware.

---> hier herunterladen => Kaspersky Online Scanner
=> Hinweise zu älteren Versionen beachten!
=> Voraussetzung: Internet Explorer 6.0 oder höher
=> die nötigen ActiveX-Steuerelemente installieren => Update der Signaturen => Weiter
=> Scan-Einstellungen => Standard wählen => OK => Link "Arbeitsplatz" anklicken
=> Scan beginnt automatisch => Untersuchung wurde abgeschlossen => Protokoll speichern als
=> Dateityp auf .txt umstellen => auf dem Desktop als Kaspersky.txt speichern => Log hier posten
=> Deinstallation => Systemsteuerung => Software => Kaspersky Online Scanner entfernen

3.) Überprüfe den Rechner mit PrevXCSI. Poste ein Screenshot falls etwas gefunden werden sollte oder poste Namen und Pfade.

ciao, andreas

laevalalala 08.09.2010 08:08

hm irgendwie is der log kein wirklicher log:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK


uund:

Kaspersky
Online Scanner
Tut uns leid! Der Kaspersky Online Scanner wird gerade überarbeitet und ist deshalb nicht verfügbar. In Kürze wird er mit vielen Detail-Verbesserungen wieder online gehen.

:/

john.doe 08.09.2010 19:17

Das waren nur noch Kontrollscans und sind nicht unbedingt notwendig. Poste die beiden Logs von OTL.

Wie geht es dem Rechner? Gibt es noch irgendwelche Auffälligkeiten oder Meldungen?

ciao, andreas

laevalalala 08.09.2010 23:45

OTL Logfile:
Code:

OTL logfile created on: 09.09.2010 00:23:30 - Run 6
OTL by OldTimer - Version 3.2.1.1    Folder = C:\Users\Eva-Maria\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 48,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 73,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 279,01 Gb Free Space | 61,19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 491,73 Mb Total Space | 487,91 Mb Free Space | 99,22% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: EVA-MARIAS-PC
Current User Name: Eva-Maria
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
 
========== Processes (SafeList) ==========
 
PRC - [2010.09.02 00:37:31 | 000,204,800 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\EVA-MA~1\AppData\Local\Temp\RtkBtMnt.exe
PRC - [2010.08.27 23:59:00 | 000,282,624 | ---- | M] (AlcorMicro Co., Ltd.) -- C:\Programme\AmIcoSingLun\AmIcoSinglun.exe
PRC - [2010.08.25 16:32:14 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Users\Eva-Maria\Desktop\OTL.exe
PRC - [2010.08.18 03:58:17 | 000,945,720 | ---- | M] (Google Inc.) -- C:\Users\Eva-Maria\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2010.06.01 14:53:46 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Essentials\msseces.exe
PRC - [2010.04.28 15:06:24 | 010,358,568 | ---- | M] (Apple Inc.) -- C:\Programme\iTunes\iTunes.exe
PRC - [2010.04.16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010.03.25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- c:\Programme\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009.09.10 16:58:25 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmplayer.exe
PRC - [2009.06.23 17:19:14 | 000,711,200 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerTray.exe
PRC - [2009.06.23 17:19:14 | 000,707,104 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe
PRC - [2009.06.23 17:19:12 | 000,453,152 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerEvent.exe
PRC - [2009.05.14 23:03:30 | 000,305,448 | ---- | M] (Egis Technology Inc.) -- C:\Programme\EgisTec\MyWinLocker 3\x86\MWLService.exe
PRC - [2009.05.14 23:03:18 | 000,345,384 | ---- | M] (Egis Technology Inc.) -- C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
PRC - [2009.05.13 19:39:42 | 000,199,464 | ---- | M] (Egis Technology Inc.) -- C:\Programme\EgisTec Egis Software Update\EgisUpdate.exe
PRC - [2009.04.11 19:32:06 | 000,249,600 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Programme\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
PRC - [2009.04.11 19:32:00 | 000,061,184 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.02 19:05:22 | 000,102,400 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe
PRC - [2009.03.31 10:39:36 | 000,233,472 | ---- | M] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe
PRC - [2009.03.19 17:11:24 | 001,138,688 | ---- | M] (Last.fm) -- C:\Programme\Last.fm\LastFM.exe
PRC - [2009.03.11 02:48:30 | 006,957,600 | ---- | M] (Realtek Semiconductor) -- C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe
PRC - [2009.02.24 02:16:02 | 000,870,920 | ---- | M] (Dritek System Inc.) -- C:\Programme\Launch Manager\LManager.exe
PRC - [2009.01.21 01:41:24 | 000,202,024 | ---- | M] (CyberLink) -- C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
PRC - [2009.01.21 01:41:18 | 000,156,968 | ---- | M] (CyberLink Corp.) -- C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
PRC - [2008.12.26 17:30:58 | 000,173,288 | ---- | M] (Acer Corp.) -- C:\Programme\Acer Arcade Deluxe\PlayMovie\PMVService.exe
PRC - [2008.12.18 14:51:34 | 000,075,048 | ---- | M] () -- C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
PRC - [2008.09.23 15:11:34 | 000,144,632 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
PRC - [2008.07.29 19:29:26 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2008.03.18 21:27:12 | 000,013,312 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2010.08.25 16:32:14 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Users\Eva-Maria\Desktop\OTL.exe
MOD - [2009.06.23 17:19:38 | 000,215,584 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Acer PowerSmart Manager\SysHook.dll
MOD - [2009.04.11 08:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Auto | Stopped] --  -- (MpfService)
SRV - File not found [On_Demand | Stopped] --  -- (McSysmon)
SRV - File not found [Unknown | Stopped] --  -- (McShield)
SRV - File not found [Auto | Stopped] --  -- (McNASvc)
SRV - File not found [Auto | Stopped] --  -- (McAfee SiteAdvisor Service)
SRV - [2010.08.28 00:01:38 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010.04.16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010.03.25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2010.03.18 13:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.09.25 03:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009.06.23 17:19:14 | 000,707,104 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe -- (ePowerSvc)
SRV - [2009.05.14 23:03:30 | 000,305,448 | ---- | M] () [Auto | Running] -- C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe -- (MWLService)
SRV - [2009.04.11 19:32:00 | 000,061,184 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2009.03.31 10:39:36 | 000,233,472 | ---- | M] (Teruten) [Auto | Running] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2008.12.18 14:51:34 | 000,075,048 | ---- | M] () [Auto | Running] -- C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe -- (CLHNService)
SRV - [2008.09.23 15:11:34 | 000,144,632 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe -- (NTISchedulerSvc)
SRV - [2008.09.23 15:11:32 | 000,050,424 | ---- | M] (NewTech InfoSystems, Inc.) [On_Demand | Stopped] -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe -- (NTIBackupSvc)
SRV - [2008.03.18 21:27:12 | 000,013,312 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2010.07.07 16:05:32 | 000,014,904 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\psi_mf.sys -- (PSI)
DRV - [2010.03.25 21:30:22 | 000,151,216 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2010.03.25 21:30:22 | 000,042,368 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2009.03.31 10:39:36 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009.03.26 01:48:32 | 000,015,360 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV - [2009.03.20 11:01:26 | 000,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2009.03.20 11:01:26 | 000,090,112 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV - [2009.03.20 11:01:26 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV - [2009.03.11 02:21:12 | 002,338,720 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009.02.21 04:10:00 | 000,153,952 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtHDMIV.sys -- (RTHDMIAzAudService)
DRV - [2009.02.12 03:11:50 | 000,329,752 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2009.01.28 09:51:40 | 004,303,872 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2008.12.30 00:57:56 | 000,952,832 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008.12.05 08:55:14 | 000,204,976 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
DRV - [2008.12.04 18:34:34 | 000,059,952 | ---- | M] (Egis Incorporated.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV - [2008.12.04 18:34:34 | 000,019,504 | ---- | M] (Egis Incorporated.) [File_System | System | Running] -- C:\Windows\System32\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV - [2008.12.04 18:34:34 | 000,016,432 | ---- | M] (Egis Incorporated.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV - [2008.12.02 23:48:18 | 000,062,976 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTSTOR.sys -- (RTSTOR)
DRV - [2008.09.04 06:12:56 | 000,223,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\k57nd60x.sys -- (k57nd60x) Broadcom NetLink (TM)
DRV - [2008.03.01 01:13:38 | 001,202,560 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008.01.31 03:51:50 | 000,013,824 | ---- | M] (NewTech Infosystems Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\UBHelper.sys -- (UBHelper)
DRV - [2008.01.21 04:23:27 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
DRV - [2008.01.21 04:23:27 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2008.01.21 04:23:27 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2008.01.21 04:23:26 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2008.01.21 04:23:26 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2008.01.21 04:23:26 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2008.01.21 04:23:25 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2008.01.21 04:23:25 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2008.01.21 04:23:24 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2008.01.21 04:23:24 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2008.01.21 04:23:24 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2008.01.21 04:23:23 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2008.01.21 04:23:23 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2008.01.21 04:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2008.01.21 04:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2008.01.21 04:23:23 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2008.01.21 04:23:23 | 000,030,720 | ---- | M] (National Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nscirda.sys -- (NSCIRDA)
DRV - [2008.01.21 04:23:22 | 000,342,584 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2008.01.21 04:23:21 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2008.01.21 04:23:21 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2008.01.21 04:23:20 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2008.01.21 04:23:20 | 000,179,712 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2008.01.21 04:23:00 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2008.01.21 04:23:00 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2008.01.21 04:23:00 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007.09.17 16:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2006.11.03 07:29:38 | 000,021,264 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\DKbFltr.sys -- (DKbFltr)
DRV - [2006.11.02 11:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006.11.02 11:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006.11.02 11:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006.11.02 11:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006.11.02 11:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006.11.02 11:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006.11.02 11:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006.11.02 11:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006.11.02 11:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006.11.02 11:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006.11.02 11:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006.11.02 10:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006.11.02 10:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006.11.02 10:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006.11.02 10:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006.11.02 10:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006.11.02 10:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006.11.02 09:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.0&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2010.01.24 22:22:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.29 12:16:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.29 12:32:35 | 000,000,000 | ---D | M]
 
[2010.08.30 14:31:03 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Extensions
[2010.09.05 21:17:20 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\u9xsvhkb.default\extensions
[2010.09.02 14:48:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\u9xsvhkb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.09.05 21:17:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\u9xsvhkb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010.09.05 21:17:20 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\u9xsvhkb.default\extensions\staged-xpis
[2010.08.30 14:31:10 | 000,000,687 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\u9xsvhkb.default\searchplugins\icq-search.xml
[2008.03.31 13:52:00 | 000,000,168 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\u9xsvhkb.default\searchplugins\icqplugin.gif
[2008.03.31 13:52:00 | 000,000,618 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\u9xsvhkb.default\searchplugins\icqplugin.src
[2010.08.29 12:19:36 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.01.19 21:07:05 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.03.23 18:14:51 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.08.29 12:19:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.04.11 00:34:04 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
[2010.08.29 12:18:50 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.03.19 10:23:30 | 000,686,592 | ---- | M] (Synatix GmbH) -- C:\Programme\Mozilla Firefox\plugins\npmieze.dll
[2010.07.23 02:48:56 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.07.23 02:48:56 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.07.23 02:48:56 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.07.23 02:48:56 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.07.23 02:48:56 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.08.31 02:11:14 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O4 - HKLM..\Run: [Acer ePower Management] C:\Programme\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Acer Incorporated)
O4 - HKLM..\Run: [AmIcoSinglun] C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcadeDeluxeAgent] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [EgisTecLiveUpdate] C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [LManager] C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [mwlDaemon] C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Programme\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - Startup: C:\Users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Eva-Maria\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Eva-Maria\Pictures\2010\Sonnenrot\37544_139724646055413_111409868886891_321838_7061603_n.jpg
O24 - Desktop BackupWallPaper: C:\Users\Eva-Maria\Pictures\2010\Sonnenrot\37544_139724646055413_111409868886891_321838_7061603_n.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.08.27 23:57:58 | 000,008,482 | RHS- | M] () - F:\autorun.inf -- [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.09.07 21:39:03 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2010.09.02 11:11:28 | 000,000,000 | ---D | C] -- C:\Programme\7-Zip
[2010.09.02 00:41:22 | 000,000,000 | --SD | C] -- C:\cofi1041c
[2010.09.02 00:32:49 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010.09.02 00:32:49 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Local\temp
[2010.09.02 00:32:05 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010.09.02 00:20:16 | 000,000,000 | ---D | C] -- C:\cofi3059c
[2010.09.02 00:19:51 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010.08.31 20:10:14 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Security Essentials
[2010.08.29 23:04:21 | 000,221,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010.08.29 12:29:43 | 000,000,000 | ---D | C] -- C:\Programme\Adobe
[2010.08.29 12:20:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.08.29 12:20:22 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Java
[2010.08.29 12:19:32 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.08.29 12:19:32 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.08.29 12:19:32 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.08.29 12:19:32 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.08.29 12:18:21 | 000,000,000 | ---D | C] -- C:\Programme\Secunia
[2010.08.29 11:49:34 | 000,000,000 | ---D | C] -- C:\cofi15611c
[2010.08.28 03:35:26 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2010.08.28 03:35:26 | 000,420,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2010.08.28 00:42:17 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2010.08.28 00:42:15 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2010.08.28 00:42:14 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2010.08.28 00:42:13 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2010.08.28 00:42:13 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010.08.28 00:42:13 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010.08.28 00:42:11 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2010.08.28 00:42:11 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2010.08.28 00:42:10 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2010.08.28 00:42:09 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010.08.28 00:42:08 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2010.08.28 00:42:08 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2010.08.28 00:42:06 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2010.08.28 00:42:06 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2010.08.28 00:42:01 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2010.08.28 00:33:53 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2010.08.28 00:33:53 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2010.08.28 00:33:52 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2010.08.28 00:33:52 | 000,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2010.08.28 00:33:52 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2010.08.28 00:33:52 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2010.08.28 00:33:52 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\corpol.dll
[2010.08.28 00:33:51 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2010.08.28 00:33:51 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2010.08.28 00:33:51 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2010.08.28 00:33:51 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2010.08.28 00:33:50 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFXDocObj.exe
[2010.08.28 00:33:50 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2010.08.28 00:33:50 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2010.08.28 00:33:50 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2010.08.28 00:33:49 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2010.08.28 00:33:49 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2010.08.28 00:33:48 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2010.08.28 00:33:47 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2010.08.28 00:33:46 | 003,698,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2010.08.28 00:33:46 | 000,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2010.08.28 00:33:46 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PDMSetup.exe
[2010.08.28 00:33:46 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2010.08.28 00:33:46 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2010.08.28 00:33:46 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetDepNx.exe
[2010.08.28 00:31:48 | 000,000,000 | ---D | C] -- C:\Programme\Panda Security
[2010.08.27 23:34:23 | 000,000,000 | ---D | C] -- C:\cofi
[2010.08.27 23:24:19 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2010.08.27 23:23:01 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010.08.27 23:23:01 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010.08.27 23:23:01 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010.08.27 23:22:55 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010.08.27 23:20:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.08.27 20:06:12 | 000,561,664 | ---- | C] (OldTimer Tools) -- C:\Users\Eva-Maria\Desktop\OTL.exe
[2010.08.27 09:33:24 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Local\Windows
[2010.08.26 10:37:56 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\temp
[2010.08.25 16:26:51 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\Microsoft
[2010.08.14 14:39:26 | 000,081,920 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2010.08.14 14:39:22 | 002,037,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2010.08.14 14:39:09 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll
[2010.08.14 14:38:56 | 003,600,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010.08.14 14:38:54 | 003,548,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2009.07.21 10:28:54 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010.09.09 00:26:50 | 004,980,736 | -HS- | M] () -- C:\Users\Eva-Maria\ntuser.dat
[2010.09.09 00:25:23 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{67F42434-13A1-4949-BC57-7301C908FC3C}.job
[2010.09.08 23:50:39 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.09.08 23:50:39 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.09.08 23:50:35 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.09.08 23:50:30 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.09.08 19:36:41 | 000,524,288 | -HS- | M] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.09.08 19:36:41 | 000,065,536 | -HS- | M] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.09.08 17:39:46 | 000,006,836 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Local\d3d9caps.dat
[2010.09.08 09:14:27 | 003,749,455 | -H-- | M] () -- C:\Users\Eva-Maria\AppData\Local\IconCache.db
[2010.09.04 15:52:22 | 000,296,559 | ---- | M] () -- C:\Users\Eva-Maria\Documents\barcelona miro, dali.odt
[2010.09.04 15:49:17 | 000,023,715 | ---- | M] () -- C:\Users\Eva-Maria\Documents\stilllife with old shoe.jpg
[2010.09.04 15:31:38 | 000,040,222 | ---- | M] () -- C:\Users\Eva-Maria\Documents\joan-miro-the-garden2.jpg
[2010.09.04 15:27:20 | 000,143,326 | ---- | M] () -- C:\Users\Eva-Maria\Documents\the_persistence_of_memory_1931_salvador_dali.jpg
[2010.09.04 15:16:18 | 000,020,784 | ---- | M] () -- C:\Users\Eva-Maria\Documents\08-salvador-dali-mustache-2.jpg
[2010.09.04 15:01:57 | 000,016,072 | ---- | M] () -- C:\Users\Eva-Maria\Documents\688-1.jpg
[2010.09.03 03:00:14 | 001,356,838 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\Qoobox.zip
[2010.09.02 00:30:20 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010.08.31 20:10:14 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.08.31 02:11:14 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010.08.31 01:59:30 | 003,831,151 | R--- | M] () -- C:\Users\Eva-Maria\Desktop\cofi.exe
[2010.08.31 01:54:15 | 000,000,808 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\CCleaner.lnk
[2010.08.29 23:20:21 | 336,965,288 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010.08.29 19:07:11 | 000,000,566 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Eva-Maria.job
[2010.08.29 15:18:45 | 000,002,231 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010.08.29 12:44:51 | 000,000,056 | -H-- | M] () -- C:\Windows\System32\ezsidmv.dat
[2010.08.29 12:32:36 | 000,001,891 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010.08.29 12:18:47 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.08.29 12:18:47 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.08.29 12:18:47 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.08.29 12:18:45 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.08.29 12:16:36 | 000,001,728 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.08.28 12:22:32 | 000,044,032 | -H-- | M] () -- C:\Users\Eva-Maria\Documents\photothumb.db
[2010.08.28 12:03:38 | 000,033,792 | -H-- | M] () -- C:\Users\Eva-Maria\photothumb.db
[2010.08.28 00:05:46 | 000,114,688 | ---- | M] (Abstract Software) -- C:\Users\Public\Desktop\Internet-Erlebniswelt.exe
[2010.08.27 23:32:44 | 000,059,414 | ---- | M] () -- C:\Users\Eva-Maria\Documents\cc_20100827_233155.reg
[2010.08.27 21:51:49 | 000,409,387 | ---- | M] () -- C:\Users\Eva-Maria\Documents\IMG_27082010_214730.png
[2010.08.27 16:13:04 | 000,139,264 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.27 10:03:12 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.08.25 16:42:53 | 000,071,337 | ---- | M] () -- C:\Users\Eva-Maria\Documents\rockamsee.odt
[2010.08.25 16:32:14 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Users\Eva-Maria\Desktop\OTL.exe
[2010.08.25 16:32:12 | 000,321,536 | ---- | M] (Freakhouse Multimedia GmbH) -- C:\Users\Eva-Maria\Desktop\Klick.exe
[2010.08.21 16:01:40 | 000,002,109 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\Google Chrome.lnk
[2010.08.19 21:05:43 | 000,185,311 | ---- | M] () -- C:\Users\Eva-Maria\trinkspiel.jpg
[2010.08.17 18:25:07 | 000,002,784 | ---- | M] () -- C:\Users\Eva-Maria\.recently-used.xbel
[2010.08.17 15:08:59 | 000,001,036 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\DVDVideoSoft Free Studio.lnk
[2010.08.15 16:23:56 | 000,327,640 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.09.04 15:49:17 | 000,023,715 | ---- | C] () -- C:\Users\Eva-Maria\Documents\stilllife with old shoe.jpg
[2010.09.04 15:31:38 | 000,040,222 | ---- | C] () -- C:\Users\Eva-Maria\Documents\joan-miro-the-garden2.jpg
[2010.09.04 15:27:20 | 000,143,326 | ---- | C] () -- C:\Users\Eva-Maria\Documents\the_persistence_of_memory_1931_salvador_dali.jpg
[2010.09.04 15:16:18 | 000,020,784 | ---- | C] () -- C:\Users\Eva-Maria\Documents\08-salvador-dali-mustache-2.jpg
[2010.09.04 15:01:56 | 000,016,072 | ---- | C] () -- C:\Users\Eva-Maria\Documents\688-1.jpg
[2010.09.03 03:00:11 | 001,356,838 | ---- | C] () -- C:\Users\Eva-Maria\Desktop\Qoobox.zip
[2010.08.31 20:10:14 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.08.29 23:20:21 | 336,965,288 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010.08.29 12:44:51 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.08.29 12:32:35 | 000,001,891 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010.08.29 12:16:36 | 000,001,728 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.08.29 12:13:09 | 000,064,092 | ---- | C] () -- C:\Users\Eva-Maria\combofix.txt
[2010.08.29 11:48:31 | 000,002,055 | ---- | C] () -- C:\Users\Eva-Maria\cfscript.txt
[2010.08.28 10:20:26 | 000,000,434 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{67F42434-13A1-4949-BC57-7301C908FC3C}.job
[2010.08.28 00:38:36 | 000,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2010.08.27 23:31:57 | 000,059,414 | ---- | C] () -- C:\Users\Eva-Maria\Documents\cc_20100827_233155.reg
[2010.08.27 23:24:21 | 000,000,808 | ---- | C] () -- C:\Users\Eva-Maria\Desktop\CCleaner.lnk
[2010.08.27 23:23:01 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010.08.27 23:23:01 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010.08.27 23:23:01 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010.08.27 23:23:01 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010.08.27 23:23:01 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010.08.27 23:20:55 | 003,831,151 | R--- | C] () -- C:\Users\Eva-Maria\Desktop\cofi.exe
[2010.08.27 21:51:46 | 000,409,387 | ---- | C] () -- C:\Users\Eva-Maria\Documents\IMG_27082010_214730.png
[2010.08.25 16:42:50 | 000,071,337 | ---- | C] () -- C:\Users\Eva-Maria\Documents\rockamsee.odt
[2010.08.19 21:05:43 | 000,185,311 | ---- | C] () -- C:\Users\Eva-Maria\trinkspiel.jpg
[2010.08.17 18:25:07 | 000,002,784 | ---- | C] () -- C:\Users\Eva-Maria\.recently-used.xbel
[2010.07.19 21:07:50 | 000,000,024 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Roaming\vdnxlf.dat
[2010.04.26 20:49:01 | 000,000,032 | ---- | C] () -- C:\Windows\wininit.ini
[2010.04.20 18:40:12 | 000,000,100 | --S- | C] () -- C:\Users\Eva-Maria\AppData\Local\1711337819.dat
[2010.04.14 12:55:09 | 000,000,552 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\d3d8caps.dat
[2010.01.07 12:13:38 | 000,151,008 | ---- | C] () -- C:\Users\Eva-Maria\Orial Bold.ttf
[2010.01.05 22:54:27 | 000,000,088 | ---- | C] () -- C:\Users\Eva-Maria\VISIT DIRT2.COM FOR USAGE.txt
[2010.01.05 22:54:20 | 000,008,128 | ---- | C] () -- C:\Users\Eva-Maria\little bliss bold.otf
[2010.01.05 22:52:41 | 000,008,280 | ---- | C] () -- C:\Users\Eva-Maria\little bliss.otf
[2010.01.05 22:25:26 | 000,011,496 | ---- | C] () -- C:\Users\Eva-Maria\little bliss bold.ttf
[2010.01.05 11:53:00 | 000,050,566 | ---- | C] () -- C:\Users\Eva-Maria\littlebliss.jpg
[2010.01.05 11:33:10 | 000,011,528 | ---- | C] () -- C:\Users\Eva-Maria\little bliss.ttf
[2009.12.24 23:46:26 | 000,001,089 | ---- | C] () -- C:\Users\Eva-Maria\ScriptSERIF - READ ME.txt
[2009.12.23 15:46:43 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2009.12.23 15:46:43 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2009.12.23 15:36:08 | 000,113,152 | ---- | C] () -- C:\Users\Eva-Maria\1031.MST
[2009.12.23 15:36:08 | 000,015,832 | ---- | C] () -- C:\Users\Eva-Maria\0x0407.ini
[2009.12.23 15:35:58 | 097,979,392 | ---- | C] () -- C:\Users\Eva-Maria\Samsung New PC Studio.msi
[2009.12.22 20:40:18 | 000,298,828 | ---- | C] () -- C:\Users\Eva-Maria\script_serif.ttf
[2009.12.22 20:30:56 | 000,280,209 | ---- | C] () -- C:\Users\Eva-Maria\scriptSERIF_sample.jpg
[2009.12.22 20:04:42 | 000,242,864 | ---- | C] () -- C:\Users\Eva-Maria\script_serif_riptrash.ttf
[2009.11.15 12:45:44 | 000,537,011 | ---- | C] () -- C:\Users\Eva-Maria\ billy argel beyaond sky font.jpg
[2009.11.15 12:37:34 | 000,516,096 | ---- | C] () -- C:\Users\Eva-Maria\BEYONDSKTRIAL.ttf
[2009.11.15 11:19:36 | 000,000,134 | ---- | C] () -- C:\Users\Eva-Maria\READ ME.txt
[2009.09.24 15:39:01 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.20 11:21:32 | 000,033,792 | -H-- | C] () -- C:\Users\Eva-Maria\photothumb.db
[2009.09.17 13:25:41 | 000,087,349 | ---- | C] () -- C:\Users\Eva-Maria\0405_09780_happy_birthday.jpg
[2009.09.13 01:03:19 | 000,242,200 | ---- | C] () -- C:\Users\Eva-Maria\acer-code.jpg
[2009.09.03 15:46:08 | 000,002,712 | ---- | C] () -- C:\Users\Eva-Maria\JOEBOB graphics free trial font users license.txt
[2009.08.26 08:27:16 | 000,006,836 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\d3d9caps.dat
[2009.08.25 23:47:23 | 000,001,072 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Roaming\wklnhst.dat
[2009.08.22 01:11:33 | 000,139,264 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.08.12 17:41:40 | 004,980,736 | -HS- | C] () -- C:\Users\Eva-Maria\ntuser.dat
[2009.08.12 17:41:40 | 000,524,288 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2009.08.12 17:41:40 | 000,524,288 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2009.08.12 17:41:40 | 000,262,144 | -H-- | C] () -- C:\Users\Eva-Maria\ntuser.dat.LOG1
[2009.08.12 17:41:40 | 000,065,536 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2009.08.12 17:41:40 | 000,000,020 | -HS- | C] () -- C:\Users\Eva-Maria\ntuser.ini
[2009.08.12 17:41:40 | 000,000,000 | -H-- | C] () -- C:\Users\Eva-Maria\ntuser.dat.LOG2
[2009.07.21 10:16:20 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2009.07.21 10:16:20 | 000,011,264 | ---- | C] () -- C:\Windows\System32\atimuixx.dll
[2009.07.21 01:52:22 | 000,000,033 | ---- | C] () -- C:\Windows\LaunApp.ini
[2009.07.21 01:44:57 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini
[2009.07.21 01:44:56 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2009.04.26 15:05:36 | 000,521,608 | ---- | C] () -- C:\Users\Eva-Maria\vtks Deja Vu.ttf
[2009.03.12 12:32:52 | 000,000,028 | ---- | C] () -- C:\Windows\WisLangCode.ini
[2009.03.12 05:26:46 | 000,004,516 | ---- | C] () -- C:\ProgramData\ArcadeDeluxe2.log
[2009.02.11 22:03:58 | 000,872,448 | ---- | C] () -- C:\Windows\iconv.dll
[2009.02.11 22:03:58 | 000,743,424 | ---- | C] () -- C:\Windows\libxml2.dll
[2009.02.11 22:03:57 | 000,000,060 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2008.10.26 15:03:52 | 000,147,604 | ---- | C] () -- C:\Users\Eva-Maria\FPENSTRIAL.ttf
[2008.10.26 15:03:52 | 000,104,352 | ---- | C] () -- C:\Users\Eva-Maria\FPENSTRIAL.otf
[2008.01.21 04:23:43 | 000,009,232 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\acleditu.dat
[2007.10.25 18:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:25:26 | 000,557,568 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005.12.10 07:56:24 | 000,047,272 | ---- | C] () -- C:\Users\Eva-Maria\FairyDustB.ttf
[2005.10.23 22:46:42 | 000,057,560 | ---- | C] () -- C:\Users\Eva-Maria\Anywhere.ttf
[2005.08.04 09:28:04 | 000,000,286 | ---- | C] () -- C:\Users\Eva-Maria\readme.txt
[2005.08.04 09:23:30 | 000,193,572 | ---- | C] () -- C:\Users\Eva-Maria\kiralynn__.ttf
[2005.05.11 03:39:36 | 000,085,808 | ---- | C] () -- C:\Users\Eva-Maria\MINUS___.TTF
[2005.03.04 19:40:38 | 000,039,648 | ---- | C] () -- C:\Users\Eva-Maria\konanur.ttf
[2004.10.27 20:24:44 | 000,034,788 | ---- | C] () -- C:\Users\Eva-Maria\Flat Earth Scribe.ttf
[2000.07.13 11:12:46 | 000,000,430 | ---- | C] () -- C:\Users\Eva-Maria\font info.txt
[1998.10.01 23:13:48 | 000,084,704 | ---- | C] () -- C:\Users\Eva-Maria\Kelt Caps Freehand.ttf
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:3B3A35EC
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:A8ADE5D8
< End of report >

--- --- ---

laevalalala 09.09.2010 10:33

dem rechner gehts gut, ich bekomme keine Meldungen oder andere Auffälligkeiten mehr.

john.doe 09.09.2010 16:32

Trotz Schwierigkeiten kommen wir voran. :) Aber leider sind wir noch nicht wirklich durch. :(

1.) Fixen mit OTL
  • Starte die OTL.exe.
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Kopiere folgendes Skript:
Code:

:OTL
IE - HKLM\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522
O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Eva-Maria\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.08.27 23:57:58 | 000,008,482 | RHS- | M] () - F:\autorun.inf -- [ FAT ]
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:3B3A35EC
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:A8ADE5D8
:Commands
[purity]
[resethosts]
[emptyflash]
[emptytemp]


2.) Dein FireFox scheint mir ziemlich vermurkst (und vielleicht befallen). Exportiere deine Lesezeichen (falls vorhanden), deinstalliere Firefox, lösche die Ordner
Zitat:

C:\Users\Eva-Maria\AppData\Roaming\mozilla
C:\Programme\Mozilla Firefox
3.) Installiere Firefox => Webbrowser Firefox oder besser => Opera Web Browser

4.) Importiere deine Lesezeichen (falls vorhanden, Opera kann das auch).

5.) Erstelle und poste neue Logs mit OTL.

ciao, andreas

laevalalala 09.09.2010 19:53

OTL Logfile:
Code:

OTL logfile created on: 09.09.2010 20:51:09 - Run 7
OTL by OldTimer - Version 3.2.1.1    Folder = C:\Users\Eva-Maria\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 48,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 277,87 Gb Free Space | 60,94% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 491,73 Mb Total Space | 487,91 Mb Free Space | 99,22% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: EVA-MARIAS-PC
Current User Name: Eva-Maria
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\EVA-MA~1\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
PRC - C:\Users\Eva-Maria\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Eva-Maria\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Programme\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe (DVDVideoSoft Limited.)
PRC - C:\Programme\Secunia\PSI\psi.exe (Secunia)
PRC - C:\Programme\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Programme\iTunes\iTunes.exe (Apple Inc.)
PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - c:\Programme\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerTray.exe (Acer Incorporated)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerEvent.exe (Acer Incorporated)
PRC - C:\Programme\EgisTec\MyWinLocker 3\x86\MWLService.exe (Egis Technology Inc.)
PRC - C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
PRC - C:\Programme\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Programme\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
PRC - C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - C:\Programme\Last.fm\LastFM.exe (Last.fm)
PRC - C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
PRC - C:\Programme\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
PRC - C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
PRC - C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Eva-Maria\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Programme\Acer\Acer PowerSmart Manager\SysHook.dll (Acer Incorporated)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (MpfService) --  File not found
SRV - (McSysmon) --  File not found
SRV - (McShield) --  File not found
SRV - (McNASvc) --  File not found
SRV - (McAfee SiteAdvisor Service) --  File not found
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (ePowerSvc) -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Acer Incorporated)
SRV - (MWLService) -- C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe ()
SRV - (NTI IScheduleSvc) -- C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (CLHNService) -- C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
SRV - (NTISchedulerSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.)
SRV - (NTIBackupSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
< End of report >

--- --- ---

laevalalala 09.09.2010 20:06

wahnsinn, wie viel schwierigkeiten so ein virus machen kann oO

ich weiß nicht genau welches texokument ich hochladen soll..
OTL Logfile:
Code:

OTL logfile created on: 09.09.2010 20:50:23 - Run 7
OTL by OldTimer - Version 3.2.1.1    Folder = C:\Users\Eva-Maria\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 73,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 277,90 Gb Free Space | 60,94% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 491,73 Mb Total Space | 487,91 Mb Free Space | 99,22% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: EVA-MARIAS-PC
Current User Name: Eva-Maria
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\EVA-MA~1\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
PRC - C:\Users\Eva-Maria\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Eva-Maria\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Programme\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe (DVDVideoSoft Limited.)
PRC - C:\Programme\Secunia\PSI\psi.exe (Secunia)
PRC - C:\Programme\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Programme\iTunes\iTunes.exe (Apple Inc.)
PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - c:\Programme\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerTray.exe (Acer Incorporated)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerEvent.exe (Acer Incorporated)
PRC - C:\Programme\EgisTec\MyWinLocker 3\x86\MWLService.exe (Egis Technology Inc.)
PRC - C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
PRC - C:\Programme\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Programme\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
PRC - C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - C:\Programme\Last.fm\LastFM.exe (Last.fm)
PRC - C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
PRC - C:\Programme\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
PRC - C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
PRC - C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Eva-Maria\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Programme\Acer\Acer PowerSmart Manager\SysHook.dll (Acer Incorporated)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (MpfService) --  File not found
SRV - (McSysmon) --  File not found
SRV - (McShield) --  File not found
SRV - (McNASvc) --  File not found
SRV - (McAfee SiteAdvisor Service) --  File not found
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (ePowerSvc) -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Acer Incorporated)
SRV - (MWLService) -- C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe ()
SRV - (NTI IScheduleSvc) -- C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (CLHNService) -- C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
SRV - (NTISchedulerSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.)
SRV - (NTIBackupSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (PSI) -- C:\Windows\System32\drivers\psi_mf.sys (Secunia)
DRV - (MpFilter) -- C:\Windows\System32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (NTIDrvr) -- C:\Windows\System32\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (ss_bmdm) -- C:\Windows\System32\drivers\ss_bmdm.sys (MCCI Corporation)
DRV - (ss_bbus) SAMSUNG USB Mobile Device (WDM) -- C:\Windows\System32\drivers\ss_bbus.sys (MCCI)
DRV - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) -- C:\Windows\System32\drivers\ss_bmdfl.sys (MCCI Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (RTHDMIAzAudService) -- C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (mwlPSDVDisk) -- C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Incorporated.)
DRV - (mwlPSDFilter) -- C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Incorporated.)
DRV - (mwlPSDNServ) -- C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Incorporated.)
DRV - (RTSTOR) -- C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (k57nd60x) Broadcom NetLink (TM) -- C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (UBHelper) -- C:\Windows\System32\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (NSCIRDA) -- C:\Windows\System32\drivers\nscirda.sys (National Semiconductor Corporation)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (DKbFltr) -- C:\Windows\System32\drivers\DKbFltr.sys (Dritek System Inc.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.0&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2010.01.24 22:22:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.29 12:16:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.29 12:32:35 | 000,000,000 | ---D | M]
 
[2010.08.30 14:31:03 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Extensions
[2010.09.05 21:17:20 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\u9xsvhkb.default\extensions
[2010.09.02 14:48:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\u9xsvhkb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.09.05 21:17:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\u9xsvhkb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010.09.05 21:17:20 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\mozilla\Firefox\Profiles\u9xsvhkb.default\extensions\staged-xpis
[2010.08.30 14:31:10 | 000,000,687 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\u9xsvhkb.default\searchplugins\icq-search.xml
[2008.03.31 13:52:00 | 000,000,168 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\u9xsvhkb.default\searchplugins\icqplugin.gif
[2008.03.31 13:52:00 | 000,000,618 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Roaming\Mozilla\FireFox\Profiles\u9xsvhkb.default\searchplugins\icqplugin.src
[2010.08.29 12:19:36 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.01.19 21:07:05 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.03.23 18:14:51 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.08.29 12:19:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.04.11 00:34:04 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
[2010.08.29 12:18:50 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.03.19 10:23:30 | 000,686,592 | ---- | M] (Synatix GmbH) -- C:\Programme\Mozilla Firefox\plugins\npmieze.dll
[2010.07.23 02:48:56 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.07.23 02:48:56 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.07.23 02:48:56 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.07.23 02:48:56 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.07.23 02:48:56 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2010.08.31 02:11:14 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O4 - HKLM..\Run: [Acer ePower Management] C:\Programme\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Acer Incorporated)
O4 - HKLM..\Run: [AmIcoSinglun] C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcadeDeluxeAgent] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [EgisTecLiveUpdate] C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [LManager] C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [mwlDaemon] C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Programme\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - Startup: C:\Users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Eva-Maria\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Programme\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Eva-Maria\Pictures\2010\Sonnenrot\37544_139724646055413_111409868886891_321838_7061603_n.jpg
O24 - Desktop BackupWallPaper: C:\Users\Eva-Maria\Pictures\2010\Sonnenrot\37544_139724646055413_111409868886891_321838_7061603_n.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.08.27 23:57:58 | 000,008,482 | RHS- | M] () - F:\autorun.inf -- [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.09.07 21:39:03 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2010.09.02 11:11:28 | 000,000,000 | ---D | C] -- C:\Programme\7-Zip
[2010.09.02 00:41:22 | 000,000,000 | --SD | C] -- C:\cofi1041c
[2010.09.02 00:32:49 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010.09.02 00:32:49 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Local\temp
[2010.09.02 00:32:05 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010.09.02 00:20:16 | 000,000,000 | ---D | C] -- C:\cofi3059c
[2010.08.31 20:10:14 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Security Essentials
[2010.08.29 23:04:21 | 000,221,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010.08.29 12:29:43 | 000,000,000 | ---D | C] -- C:\Programme\Adobe
[2010.08.29 12:20:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.08.29 12:20:22 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Java
[2010.08.29 12:19:32 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.08.29 12:19:32 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.08.29 12:19:32 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.08.29 12:19:32 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.08.29 12:18:21 | 000,000,000 | ---D | C] -- C:\Programme\Secunia
[2010.08.29 11:49:34 | 000,000,000 | ---D | C] -- C:\cofi15611c
[2010.08.28 03:35:26 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2010.08.28 03:35:26 | 000,420,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2010.08.28 00:42:17 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2010.08.28 00:42:15 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2010.08.28 00:42:14 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2010.08.28 00:42:13 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2010.08.28 00:42:13 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010.08.28 00:42:13 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010.08.28 00:42:11 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2010.08.28 00:42:11 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2010.08.28 00:42:10 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2010.08.28 00:42:09 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010.08.28 00:42:08 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2010.08.28 00:42:08 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2010.08.28 00:42:06 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2010.08.28 00:42:06 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2010.08.28 00:42:01 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2010.08.28 00:33:53 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2010.08.28 00:33:53 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2010.08.28 00:33:52 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2010.08.28 00:33:52 | 000,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2010.08.28 00:33:52 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2010.08.28 00:33:52 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2010.08.28 00:33:52 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\corpol.dll
[2010.08.28 00:33:51 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2010.08.28 00:33:51 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2010.08.28 00:33:51 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2010.08.28 00:33:51 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2010.08.28 00:33:50 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFXDocObj.exe
[2010.08.28 00:33:50 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2010.08.28 00:33:50 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2010.08.28 00:33:50 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2010.08.28 00:33:49 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2010.08.28 00:33:49 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2010.08.28 00:33:48 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2010.08.28 00:33:47 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2010.08.28 00:33:46 | 003,698,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2010.08.28 00:33:46 | 000,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2010.08.28 00:33:46 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PDMSetup.exe
[2010.08.28 00:33:46 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2010.08.28 00:33:46 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2010.08.28 00:33:46 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetDepNx.exe
[2010.08.28 00:31:48 | 000,000,000 | ---D | C] -- C:\Programme\Panda Security
[2010.08.27 23:34:23 | 000,000,000 | ---D | C] -- C:\cofi
[2010.08.27 23:24:19 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2010.08.27 23:22:55 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010.08.27 23:20:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.08.27 20:06:12 | 000,561,664 | ---- | C] (OldTimer Tools) -- C:\Users\Eva-Maria\Desktop\OTL.exe
[2010.08.27 09:33:24 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Local\Windows
[2010.08.26 10:37:56 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\temp
[2010.08.25 16:26:51 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\Microsoft
[2010.08.14 14:39:26 | 000,081,920 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2010.08.14 14:39:22 | 002,037,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2010.08.14 14:39:09 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll
[2010.08.14 14:38:56 | 003,600,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010.08.14 14:38:54 | 003,548,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2009.07.21 10:28:54 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010.09.09 20:55:18 | 004,980,736 | -HS- | M] () -- C:\Users\Eva-Maria\ntuser.dat
[2010.09.09 20:55:07 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2010.09.09 20:46:36 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{67F42434-13A1-4949-BC57-7301C908FC3C}.job
[2010.09.09 20:26:20 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.09.09 20:26:20 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.09.09 20:26:16 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.09.09 20:26:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.09.09 16:01:12 | 000,524,288 | -HS- | M] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.09.09 16:01:12 | 000,065,536 | -HS- | M] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.09.09 16:01:07 | 003,752,263 | -H-- | M] () -- C:\Users\Eva-Maria\AppData\Local\IconCache.db
[2010.09.09 15:13:09 | 000,006,836 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Local\d3d9caps.dat
[2010.09.09 12:57:04 | 000,138,240 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.09.04 15:52:22 | 000,296,559 | ---- | M] () -- C:\Users\Eva-Maria\Documents\barcelona miro, dali.odt
[2010.09.04 15:49:17 | 000,023,715 | ---- | M] () -- C:\Users\Eva-Maria\Documents\stilllife with old shoe.jpg
[2010.09.04 15:31:38 | 000,040,222 | ---- | M] () -- C:\Users\Eva-Maria\Documents\joan-miro-the-garden2.jpg
[2010.09.04 15:27:20 | 000,143,326 | ---- | M] () -- C:\Users\Eva-Maria\Documents\the_persistence_of_memory_1931_salvador_dali.jpg
[2010.09.04 15:16:18 | 000,020,784 | ---- | M] () -- C:\Users\Eva-Maria\Documents\08-salvador-dali-mustache-2.jpg
[2010.09.04 15:01:57 | 000,016,072 | ---- | M] () -- C:\Users\Eva-Maria\Documents\688-1.jpg
[2010.09.03 03:00:14 | 001,356,838 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\Qoobox.zip
[2010.09.02 00:30:20 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010.08.31 20:10:14 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.08.31 01:59:30 | 003,831,151 | R--- | M] () -- C:\Users\Eva-Maria\Desktop\cofi.exe
[2010.08.31 01:54:15 | 000,000,808 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\CCleaner.lnk
[2010.08.29 23:20:21 | 336,965,288 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010.08.29 19:07:11 | 000,000,566 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Eva-Maria.job
[2010.08.29 15:18:45 | 000,002,231 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010.08.29 12:44:51 | 000,000,056 | -H-- | M] () -- C:\Windows\System32\ezsidmv.dat
[2010.08.29 12:32:36 | 000,001,891 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010.08.29 12:18:47 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.08.29 12:18:47 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.08.29 12:18:47 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.08.29 12:18:45 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.08.29 12:16:36 | 000,001,728 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.08.28 12:22:32 | 000,044,032 | -H-- | M] () -- C:\Users\Eva-Maria\Documents\photothumb.db
[2010.08.28 12:03:38 | 000,033,792 | -H-- | M] () -- C:\Users\Eva-Maria\photothumb.db
[2010.08.28 00:05:46 | 000,114,688 | ---- | M] (Abstract Software) -- C:\Users\Public\Desktop\Internet-Erlebniswelt.exe
[2010.08.27 23:32:44 | 000,059,414 | ---- | M] () -- C:\Users\Eva-Maria\Documents\cc_20100827_233155.reg
[2010.08.27 21:51:49 | 000,409,387 | ---- | M] () -- C:\Users\Eva-Maria\Documents\IMG_27082010_214730.png
[2010.08.27 10:03:12 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.08.25 16:42:53 | 000,071,337 | ---- | M] () -- C:\Users\Eva-Maria\Documents\rockamsee.odt
[2010.08.25 16:32:14 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Users\Eva-Maria\Desktop\OTL.exe
[2010.08.25 16:32:12 | 000,321,536 | ---- | M] (Freakhouse Multimedia GmbH) -- C:\Users\Eva-Maria\Desktop\Klick.exe
[2010.08.21 16:01:40 | 000,002,109 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\Google Chrome.lnk
[2010.08.19 21:05:43 | 000,185,311 | ---- | M] () -- C:\Users\Eva-Maria\trinkspiel.jpg
[2010.08.17 18:25:07 | 000,002,784 | ---- | M] () -- C:\Users\Eva-Maria\.recently-used.xbel
[2010.08.17 15:08:59 | 000,001,036 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\DVDVideoSoft Free Studio.lnk
[2010.08.15 16:23:56 | 000,327,640 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010.09.04 15:49:17 | 000,023,715 | ---- | C] () -- C:\Users\Eva-Maria\Documents\stilllife with old shoe.jpg
[2010.09.04 15:31:38 | 000,040,222 | ---- | C] () -- C:\Users\Eva-Maria\Documents\joan-miro-the-garden2.jpg
[2010.09.04 15:27:20 | 000,143,326 | ---- | C] () -- C:\Users\Eva-Maria\Documents\the_persistence_of_memory_1931_salvador_dali.jpg
[2010.09.04 15:16:18 | 000,020,784 | ---- | C] () -- C:\Users\Eva-Maria\Documents\08-salvador-dali-mustache-2.jpg
[2010.09.04 15:01:56 | 000,016,072 | ---- | C] () -- C:\Users\Eva-Maria\Documents\688-1.jpg
[2010.09.03 03:00:11 | 001,356,838 | ---- | C] () -- C:\Users\Eva-Maria\Desktop\Qoobox.zip
[2010.08.31 20:10:14 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.08.29 23:20:21 | 336,965,288 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010.08.29 12:44:51 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.08.29 12:32:35 | 000,001,891 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010.08.29 12:16:36 | 000,001,728 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.08.29 12:13:09 | 000,064,092 | ---- | C] () -- C:\Users\Eva-Maria\combofix.txt
[2010.08.29 11:48:31 | 000,002,055 | ---- | C] () -- C:\Users\Eva-Maria\cfscript.txt
[2010.08.28 10:20:26 | 000,000,434 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{67F42434-13A1-4949-BC57-7301C908FC3C}.job
[2010.08.28 00:38:36 | 000,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2010.08.27 23:31:57 | 000,059,414 | ---- | C] () -- C:\Users\Eva-Maria\Documents\cc_20100827_233155.reg
[2010.08.27 23:24:21 | 000,000,808 | ---- | C] () -- C:\Users\Eva-Maria\Desktop\CCleaner.lnk
[2010.08.27 23:23:01 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010.08.27 23:23:01 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010.08.27 23:20:55 | 003,831,151 | R--- | C] () -- C:\Users\Eva-Maria\Desktop\cofi.exe
[2010.08.27 21:51:46 | 000,409,387 | ---- | C] () -- C:\Users\Eva-Maria\Documents\IMG_27082010_214730.png
[2010.08.25 16:42:50 | 000,071,337 | ---- | C] () -- C:\Users\Eva-Maria\Documents\rockamsee.odt
[2010.08.19 21:05:43 | 000,185,311 | ---- | C] () -- C:\Users\Eva-Maria\trinkspiel.jpg
[2010.08.17 18:25:07 | 000,002,784 | ---- | C] () -- C:\Users\Eva-Maria\.recently-used.xbel
[2010.07.19 21:07:50 | 000,000,024 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Roaming\vdnxlf.dat
[2010.04.26 20:49:01 | 000,000,032 | ---- | C] () -- C:\Windows\wininit.ini
[2010.04.20 18:40:12 | 000,000,100 | --S- | C] () -- C:\Users\Eva-Maria\AppData\Local\1711337819.dat
[2010.04.14 12:55:09 | 000,000,552 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\d3d8caps.dat
[2010.01.07 12:13:38 | 000,151,008 | ---- | C] () -- C:\Users\Eva-Maria\Orial Bold.ttf
[2010.01.05 22:54:27 | 000,000,088 | ---- | C] () -- C:\Users\Eva-Maria\VISIT DIRT2.COM FOR USAGE.txt
[2010.01.05 22:54:20 | 000,008,128 | ---- | C] () -- C:\Users\Eva-Maria\little bliss bold.otf
[2010.01.05 22:52:41 | 000,008,280 | ---- | C] () -- C:\Users\Eva-Maria\little bliss.otf
[2010.01.05 22:25:26 | 000,011,496 | ---- | C] () -- C:\Users\Eva-Maria\little bliss bold.ttf
[2010.01.05 11:53:00 | 000,050,566 | ---- | C] () -- C:\Users\Eva-Maria\littlebliss.jpg
[2010.01.05 11:33:10 | 000,011,528 | ---- | C] () -- C:\Users\Eva-Maria\little bliss.ttf
[2009.12.24 23:46:26 | 000,001,089 | ---- | C] () -- C:\Users\Eva-Maria\ScriptSERIF - READ ME.txt
[2009.12.23 15:46:43 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2009.12.23 15:46:43 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2009.12.23 15:36:08 | 000,113,152 | ---- | C] () -- C:\Users\Eva-Maria\1031.MST
[2009.12.23 15:36:08 | 000,015,832 | ---- | C] () -- C:\Users\Eva-Maria\0x0407.ini
[2009.12.23 15:35:58 | 097,979,392 | ---- | C] () -- C:\Users\Eva-Maria\Samsung New PC Studio.msi
[2009.12.22 20:40:18 | 000,298,828 | ---- | C] () -- C:\Users\Eva-Maria\script_serif.ttf
[2009.12.22 20:30:56 | 000,280,209 | ---- | C] () -- C:\Users\Eva-Maria\scriptSERIF_sample.jpg
[2009.12.22 20:04:42 | 000,242,864 | ---- | C] () -- C:\Users\Eva-Maria\script_serif_riptrash.ttf
[2009.11.15 12:45:44 | 000,537,011 | ---- | C] () -- C:\Users\Eva-Maria\ billy argel beyaond sky font.jpg
[2009.11.15 12:37:34 | 000,516,096 | ---- | C] () -- C:\Users\Eva-Maria\BEYONDSKTRIAL.ttf
[2009.11.15 11:19:36 | 000,000,134 | ---- | C] () -- C:\Users\Eva-Maria\READ ME.txt
[2009.09.24 15:39:01 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.20 11:21:32 | 000,033,792 | -H-- | C] () -- C:\Users\Eva-Maria\photothumb.db
[2009.09.17 13:25:41 | 000,087,349 | ---- | C] () -- C:\Users\Eva-Maria\0405_09780_happy_birthday.jpg
[2009.09.13 01:03:19 | 000,242,200 | ---- | C] () -- C:\Users\Eva-Maria\acer-code.jpg
[2009.09.03 15:46:08 | 000,002,712 | ---- | C] () -- C:\Users\Eva-Maria\JOEBOB graphics free trial font users license.txt
[2009.08.26 08:27:16 | 000,006,836 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\d3d9caps.dat
[2009.08.25 23:47:23 | 000,001,072 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Roaming\wklnhst.dat
[2009.08.22 01:11:33 | 000,138,240 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.08.12 17:41:40 | 004,980,736 | -HS- | C] () -- C:\Users\Eva-Maria\ntuser.dat
[2009.08.12 17:41:40 | 000,524,288 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2009.08.12 17:41:40 | 000,524,288 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2009.08.12 17:41:40 | 000,262,144 | -H-- | C] () -- C:\Users\Eva-Maria\ntuser.dat.LOG1
[2009.08.12 17:41:40 | 000,065,536 | -HS- | C] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2009.08.12 17:41:40 | 000,000,020 | -HS- | C] () -- C:\Users\Eva-Maria\ntuser.ini
[2009.08.12 17:41:40 | 000,000,000 | -H-- | C] () -- C:\Users\Eva-Maria\ntuser.dat.LOG2
[2009.07.21 10:16:20 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2009.07.21 10:16:20 | 000,011,264 | ---- | C] () -- C:\Windows\System32\atimuixx.dll
[2009.07.21 01:52:22 | 000,000,033 | ---- | C] () -- C:\Windows\LaunApp.ini
[2009.07.21 01:44:57 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini
[2009.07.21 01:44:56 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2009.04.26 15:05:36 | 000,521,608 | ---- | C] () -- C:\Users\Eva-Maria\vtks Deja Vu.ttf
[2009.03.12 12:32:52 | 000,000,028 | ---- | C] () -- C:\Windows\WisLangCode.ini
[2009.03.12 05:26:46 | 000,004,516 | ---- | C] () -- C:\ProgramData\ArcadeDeluxe2.log
[2009.02.11 22:03:58 | 000,872,448 | ---- | C] () -- C:\Windows\iconv.dll
[2009.02.11 22:03:58 | 000,743,424 | ---- | C] () -- C:\Windows\libxml2.dll
[2009.02.11 22:03:57 | 000,000,060 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2008.10.26 15:03:52 | 000,147,604 | ---- | C] () -- C:\Users\Eva-Maria\FPENSTRIAL.ttf
[2008.10.26 15:03:52 | 000,104,352 | ---- | C] () -- C:\Users\Eva-Maria\FPENSTRIAL.otf
[2008.01.21 04:23:43 | 000,009,232 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\acleditu.dat
[2007.10.25 18:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:25:26 | 000,557,568 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005.12.10 07:56:24 | 000,047,272 | ---- | C] () -- C:\Users\Eva-Maria\FairyDustB.ttf
[2005.10.23 22:46:42 | 000,057,560 | ---- | C] () -- C:\Users\Eva-Maria\Anywhere.ttf
[2005.08.04 09:28:04 | 000,000,286 | ---- | C] () -- C:\Users\Eva-Maria\readme.txt
[2005.08.04 09:23:30 | 000,193,572 | ---- | C] () -- C:\Users\Eva-Maria\kiralynn__.ttf
[2005.05.11 03:39:36 | 000,085,808 | ---- | C] () -- C:\Users\Eva-Maria\MINUS___.TTF
[2005.03.04 19:40:38 | 000,039,648 | ---- | C] () -- C:\Users\Eva-Maria\konanur.ttf
[2004.10.27 20:24:44 | 000,034,788 | ---- | C] () -- C:\Users\Eva-Maria\Flat Earth Scribe.ttf
[2000.07.13 11:12:46 | 000,000,430 | ---- | C] () -- C:\Users\Eva-Maria\font info.txt
[1998.10.01 23:13:48 | 000,084,704 | ---- | C] () -- C:\Users\Eva-Maria\Kelt Caps Freehand.ttf
 
========== LOP Check ==========
 
[2009.07.21 01:52:19 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Acer GameZone Console
[2010.01.17 13:30:12 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Cycle of 5th
[2010.09.09 20:54:49 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.02.28 14:05:31 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\eSobi
[2010.03.31 00:40:30 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Facebook
[2010.08.17 18:24:16 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\gtk-2.0
[2010.08.29 11:40:36 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Gutscheinmieze
[2010.09.08 17:59:58 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\ICQ
[2010.05.16 21:58:39 | 000,000,000 | -HSD | M] -- C:\Users\Eva-Maria\AppData\Roaming\lowsec
[2009.10.11 11:18:50 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\OpenOffice.org
[2010.05.11 19:29:55 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Osfoyd
[2009.12.23 15:52:06 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\PC Suite
[2010.07.27 11:04:34 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\PhotoScape
[2009.08.12 17:43:26 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\PowerCinema
[2009.12.23 15:46:19 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Samsung
[2009.08.25 23:47:27 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Template
[2010.09.09 16:01:13 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010.09.09 20:46:36 | 000,000,434 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{67F42434-13A1-4949-BC57-7301C908FC3C}.job
 
========== Purity Check ==========
 
 
< End of report >

--- --- ---

laevalalala 09.09.2010 20:12

eigentlich brauche ich doch gar kein mozilla/firefox/opera, wenn ich chrome und explorer habe oder?

laevalalala 09.09.2010 20:14

ahaaaaaaaaaaaa gefunden:
aber ich hab glaub ich vergessen davor alles richtig einzustellen...:/

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\SearchDefaultBranded| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\StartPageCache| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{472734EA-242A-422B-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MSSE deleted successfully.
c:\Programme\Microsoft Security Essentials\msseces.exe moved successfully.
C:\Users\Eva-Maria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk moved successfully.
C:\Programme\OpenOffice.org 3\program\quickstart.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Free YouTube to Mp3 Converter\ deleted successfully.
C:\Users\Eva-Maria\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm moved successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...\ deleted successfully.
C:\Programme\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll moved successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xel exportieren\ deleted successfully.
C:\Programme\Microsoft Office\Office12\EXCEL.EXE moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}\ not found.
C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}\ not found.
File C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2670000A-7350-4f3c-8081-5663EE0C6C49}\ not found.
C:\Programme\Microsoft Office\Office12\ONBttnIE.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2670000A-7350-4f3c-8081-5663EE0C6C49}\ not found.
File C:\Programme\Microsoft Office\Office12\ONBttnIE.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{88EB38EF-4D2C-436D-ABD3-56B232674062}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88EB38EF-4D2C-436D-ABD3-56B232674062}\ not found.
C:\Programme\ICQ7.0\ICQ.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{88EB38EF-4D2C-436D-ABD3-56B232674062}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88EB38EF-4D2C-436D-ABD3-56B232674062}\ not found.
File C:\Programme\ICQ7.0\ICQ.exe not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ not found.
C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL moved successfully.
Starting removal of ActiveX control {7530BFB8-7293-4D34-9923-61A11451AFC5}
C:\Windows\Downloaded Program Files\OnlineScanner.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
C:\autoexec.bat moved successfully.
F:\autorun.inf moved successfully.
ADS C:\ProgramData\Temp:3B3A35EC deleted successfully.
ADS C:\ProgramData\Temp:DFC5A2B2 deleted successfully.
ADS C:\ProgramData\Temp:A8ADE5D8 deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Eva-Maria
->Flash cache emptied: 10872 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Eva-Maria
->Temp folder emptied: 312444 bytes
->Temporary Internet Files folder emptied: 27026809 bytes
->Java cache emptied: 2604421 bytes
->FireFox cache emptied: 30623157 bytes
->Google Chrome cache emptied: 386207326 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 820629 bytes
%systemroot%\System32 .tmp files removed: 5464 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 104506 bytes
RecycleBin emptied: 40623687 bytes

Total Files Cleaned = 466,00 mb


OTL by OldTimer - Version 3.2.1.1 log created on 09092010_205447

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

laevalalala 09.09.2010 20:18

OTL Logfile:
Code:

OTL logfile created on: 09.09.2010 21:15:14 - Run 8
OTL by OldTimer - Version 3.2.10.0    Folder = c:\Users\Eva-Maria\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 59,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 278,28 Gb Free Space | 61,03% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 491,73 Mb Total Space | 487,93 Mb Free Space | 99,23% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: EVA-MARIAS-PC
Current User Name: Eva-Maria
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\EVA-MA~1\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - c:\Users\Eva-Maria\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
PRC - C:\Users\Eva-Maria\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Programme\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - c:\Programme\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerTray.exe (Acer Incorporated)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Programme\Acer\Acer PowerSmart Manager\ePowerEvent.exe (Acer Incorporated)
PRC - C:\Programme\EgisTec\MyWinLocker 3\x86\MWLService.exe (Egis Technology Inc.)
PRC - C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
PRC - C:\Programme\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Programme\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
PRC - C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Programme\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
PRC - C:\Programme\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
PRC - C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
PRC - C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - c:\Users\Eva-Maria\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Programme\Acer\Acer PowerSmart Manager\SysHook.dll (Acer Incorporated)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (MpfService) -- C:\Program Files\McAfee\MPF\MPFSrv.exe File not found
SRV - (McSysmon) -- C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe File not found
SRV - (McShield) -- C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe File not found
SRV - (McNASvc) -- c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe File not found
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe File not found
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (WinHttpAutoProxySvc) -- winhttp.dll (Microsoft Corporation)
SRV - (ePowerSvc) -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Acer Incorporated)
SRV - (MWLService) -- C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe ()
SRV - (NTI IScheduleSvc) -- C:\Programme\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (CLHNService) -- C:\Programme\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
SRV - (NTISchedulerSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (NewTech Infosystems, Inc.)
SRV - (NTIBackupSvc) -- C:\Programme\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (PSI) -- C:\Windows\System32\drivers\psi_mf.sys (Secunia)
DRV - (MpFilter) -- C:\Windows\System32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (NTIDrvr) -- C:\Windows\System32\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (ss_bmdm) -- C:\Windows\System32\drivers\ss_bmdm.sys (MCCI Corporation)
DRV - (ss_bbus) SAMSUNG USB Mobile Device (WDM) -- C:\Windows\System32\drivers\ss_bbus.sys (MCCI)
DRV - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) -- C:\Windows\System32\drivers\ss_bmdfl.sys (MCCI Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (RTHDMIAzAudService) -- C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.)
DRV - (iaStor) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (mwlPSDVDisk) -- C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Incorporated.)
DRV - (mwlPSDFilter) -- C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Incorporated.)
DRV - (mwlPSDNServ) -- C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Incorporated.)
DRV - (RTSTOR) -- C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (k57nd60x) Broadcom NetLink (TM) -- C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (UBHelper) -- C:\Windows\System32\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (NSCIRDA) -- C:\Windows\System32\drivers\nscirda.sys (National Semiconductor Corporation)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (DKbFltr) -- C:\Windows\System32\drivers\DKbFltr.sys (Dritek System Inc.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2010.01.24 22:22:21 | 000,000,000 | ---D | M]
 
 
O1 HOSTS File: ([2010.09.09 20:55:07 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1      localhost
O4 - HKLM..\Run: [Acer ePower Management] C:\Programme\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Acer Incorporated)
O4 - HKLM..\Run: [AmIcoSinglun] C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcadeDeluxeAgent] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [EgisTecLiveUpdate] C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [LManager] C:\Programme\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mwlDaemon] C:\Programme\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Programme\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Eva-Maria\Pictures\2010\Sonnenrot\37544_139724646055413_111409868886891_321838_7061603_n.jpg
O24 - Desktop BackupWallPaper: C:\Users\Eva-Maria\Pictures\2010\Sonnenrot\37544_139724646055413_111409868886891_321838_7061603_n.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010.09.09 20:54:47 | 000,000,000 | ---D | C] -- C:\_OTL
[2010.09.07 21:39:03 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2010.09.02 11:11:28 | 000,000,000 | ---D | C] -- C:\Programme\7-Zip
[2010.09.02 00:41:22 | 000,000,000 | --SD | C] -- C:\cofi1041c
[2010.09.02 00:32:49 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010.09.02 00:32:49 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Local\temp
[2010.09.02 00:32:05 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010.09.02 00:20:16 | 000,000,000 | ---D | C] -- C:\cofi3059c
[2010.08.31 20:10:14 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Security Essentials
[2010.08.29 23:04:21 | 000,221,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010.08.29 12:29:43 | 000,000,000 | ---D | C] -- C:\Programme\Adobe
[2010.08.29 12:20:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.08.29 12:20:22 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Java
[2010.08.29 12:19:32 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.08.29 12:19:32 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.08.29 12:19:32 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.08.29 12:19:32 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.08.29 12:18:21 | 000,000,000 | ---D | C] -- C:\Programme\Secunia
[2010.08.29 11:49:34 | 000,000,000 | ---D | C] -- C:\cofi15611c
[2010.08.28 03:35:26 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2010.08.28 03:35:26 | 000,420,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2010.08.28 00:42:17 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2010.08.28 00:42:15 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2010.08.28 00:42:14 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2010.08.28 00:42:13 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2010.08.28 00:42:13 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010.08.28 00:42:13 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010.08.28 00:42:11 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2010.08.28 00:42:11 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2010.08.28 00:42:10 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2010.08.28 00:42:09 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010.08.28 00:42:08 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2010.08.28 00:42:08 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2010.08.28 00:42:06 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2010.08.28 00:42:06 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2010.08.28 00:42:01 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2010.08.28 00:33:53 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2010.08.28 00:33:53 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2010.08.28 00:33:52 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2010.08.28 00:33:52 | 000,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2010.08.28 00:33:52 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2010.08.28 00:33:52 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2010.08.28 00:33:52 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\corpol.dll
[2010.08.28 00:33:51 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2010.08.28 00:33:51 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2010.08.28 00:33:51 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2010.08.28 00:33:51 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2010.08.28 00:33:50 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFXDocObj.exe
[2010.08.28 00:33:50 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2010.08.28 00:33:50 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2010.08.28 00:33:50 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2010.08.28 00:33:49 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2010.08.28 00:33:49 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2010.08.28 00:33:48 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2010.08.28 00:33:47 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2010.08.28 00:33:46 | 003,698,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2010.08.28 00:33:46 | 000,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2010.08.28 00:33:46 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PDMSetup.exe
[2010.08.28 00:33:46 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2010.08.28 00:33:46 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2010.08.28 00:33:46 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetDepNx.exe
[2010.08.28 00:31:48 | 000,000,000 | ---D | C] -- C:\Programme\Panda Security
[2010.08.27 23:34:23 | 000,000,000 | ---D | C] -- C:\cofi
[2010.08.27 23:24:19 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2010.08.27 23:22:55 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010.08.27 09:33:24 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\AppData\Local\Windows
[2010.08.26 10:37:56 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\temp
[2010.08.25 16:26:51 | 000,000,000 | ---D | C] -- C:\Users\Eva-Maria\Microsoft
[2010.08.14 14:39:26 | 000,081,920 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2010.08.14 14:39:22 | 002,037,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2010.08.14 14:39:09 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll
[2010.08.14 14:38:56 | 003,600,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010.08.14 14:38:54 | 003,548,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2009.07.21 10:28:54 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll
 
========== Files - Modified Within 30 Days ==========
 
[2010.09.09 21:16:18 | 004,980,736 | -HS- | M] () -- C:\Users\Eva-Maria\ntuser.dat
[2010.09.09 21:16:07 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{67F42434-13A1-4949-BC57-7301C908FC3C}.job
[2010.09.09 21:00:11 | 000,080,456 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.09.09 20:58:35 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.09.09 20:58:34 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.09.09 20:58:25 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.09.09 20:58:19 | 000,327,640 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.09.09 20:58:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.09.09 20:57:09 | 000,524,288 | -HS- | M] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010.09.09 20:57:09 | 000,065,536 | -HS- | M] () -- C:\Users\Eva-Maria\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010.09.09 20:55:07 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2010.09.09 16:01:07 | 003,752,263 | -H-- | M] () -- C:\Users\Eva-Maria\AppData\Local\IconCache.db
[2010.09.09 15:13:09 | 000,006,836 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Local\d3d9caps.dat
[2010.09.09 12:57:04 | 000,138,240 | ---- | M] () -- C:\Users\Eva-Maria\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.09.04 15:52:22 | 000,296,559 | ---- | M] () -- C:\Users\Eva-Maria\Documents\barcelona miro, dali.odt
[2010.09.04 15:49:17 | 000,023,715 | ---- | M] () -- C:\Users\Eva-Maria\Documents\stilllife with old shoe.jpg
[2010.09.04 15:31:38 | 000,040,222 | ---- | M] () -- C:\Users\Eva-Maria\Documents\joan-miro-the-garden2.jpg
[2010.09.04 15:27:20 | 000,143,326 | ---- | M] () -- C:\Users\Eva-Maria\Documents\the_persistence_of_memory_1931_salvador_dali.jpg
[2010.09.04 15:16:18 | 000,020,784 | ---- | M] () -- C:\Users\Eva-Maria\Documents\08-salvador-dali-mustache-2.jpg
[2010.09.04 15:01:57 | 000,016,072 | ---- | M] () -- C:\Users\Eva-Maria\Documents\688-1.jpg
[2010.09.03 03:00:14 | 001,356,838 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\Qoobox.zip
[2010.09.02 00:30:20 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010.08.31 20:10:14 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.08.31 01:59:30 | 003,831,151 | R--- | M] () -- C:\Users\Eva-Maria\Desktop\cofi.exe
[2010.08.31 01:54:15 | 000,000,808 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\CCleaner.lnk
[2010.08.29 23:20:21 | 336,965,288 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010.08.29 19:07:11 | 000,000,566 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Eva-Maria.job
[2010.08.29 15:18:45 | 000,002,231 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010.08.29 12:44:51 | 000,000,056 | -H-- | M] () -- C:\Windows\System32\ezsidmv.dat
[2010.08.29 12:32:36 | 000,001,891 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010.08.29 12:18:47 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.08.29 12:18:47 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.08.29 12:18:47 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.08.29 12:18:45 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010.08.28 12:22:32 | 000,044,032 | -H-- | M] () -- C:\Users\Eva-Maria\Documents\photothumb.db
[2010.08.28 12:03:38 | 000,033,792 | -H-- | M] () -- C:\Users\Eva-Maria\photothumb.db
[2010.08.28 00:05:46 | 000,114,688 | ---- | M] (Abstract Software) -- C:\Users\Public\Desktop\Internet-Erlebniswelt.exe
[2010.08.27 23:32:44 | 000,059,414 | ---- | M] () -- C:\Users\Eva-Maria\Documents\cc_20100827_233155.reg
[2010.08.27 21:51:49 | 000,409,387 | ---- | M] () -- C:\Users\Eva-Maria\Documents\IMG_27082010_214730.png
[2010.08.27 10:03:12 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.08.25 16:42:53 | 000,071,337 | ---- | M] () -- C:\Users\Eva-Maria\Documents\rockamsee.odt
[2010.08.25 16:32:12 | 000,321,536 | ---- | M] (Freakhouse Multimedia GmbH) -- C:\Users\Eva-Maria\Desktop\Klick.exe
[2010.08.21 16:01:40 | 000,002,109 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\Google Chrome.lnk
[2010.08.19 21:05:43 | 000,185,311 | ---- | M] () -- C:\Users\Eva-Maria\trinkspiel.jpg
[2010.08.17 18:25:07 | 000,002,784 | ---- | M] () -- C:\Users\Eva-Maria\.recently-used.xbel
[2010.08.17 15:08:59 | 000,001,036 | ---- | M] () -- C:\Users\Eva-Maria\Desktop\DVDVideoSoft Free Studio.lnk
 
========== Files Created - No Company Name ==========
 
[2010.09.04 15:49:17 | 000,023,715 | ---- | C] () -- C:\Users\Eva-Maria\Documents\stilllife with old shoe.jpg
[2010.09.04 15:31:38 | 000,040,222 | ---- | C] () -- C:\Users\Eva-Maria\Documents\joan-miro-the-garden2.jpg
[2010.09.04 15:27:20 | 000,143,326 | ---- | C] () -- C:\Users\Eva-Maria\Documents\the_persistence_of_memory_1931_salvador_dali.jpg
[2010.09.04 15:16:18 | 000,020,784 | ---- | C] () -- C:\Users\Eva-Maria\Documents\08-salvador-dali-mustache-2.jpg
[2010.09.04 15:01:56 | 000,016,072 | ---- | C] () -- C:\Users\Eva-Maria\Documents\688-1.jpg
[2010.09.03 03:00:11 | 001,356,838 | ---- | C] () -- C:\Users\Eva-Maria\Desktop\Qoobox.zip
[2010.08.31 20:10:14 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.08.29 23:20:21 | 336,965,288 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010.08.29 12:44:51 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.08.29 12:32:35 | 000,001,891 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010.08.29 12:13:09 | 000,064,092 | ---- | C] () -- C:\Users\Eva-Maria\combofix.txt
[2010.08.29 11:48:31 | 000,002,055 | ---- | C] () -- C:\Users\Eva-Maria\cfscript.txt
[2010.08.28 10:20:26 | 000,000,434 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{67F42434-13A1-4949-BC57-7301C908FC3C}.job
[2010.08.28 00:38:36 | 000,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2010.08.27 23:31:57 | 000,059,414 | ---- | C] () -- C:\Users\Eva-Maria\Documents\cc_20100827_233155.reg
[2010.08.27 23:24:21 | 000,000,808 | ---- | C] () -- C:\Users\Eva-Maria\Desktop\CCleaner.lnk
[2010.08.27 23:23:01 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010.08.27 23:23:01 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010.08.27 23:20:55 | 003,831,151 | R--- | C] () -- C:\Users\Eva-Maria\Desktop\cofi.exe
[2010.08.27 21:51:46 | 000,409,387 | ---- | C] () -- C:\Users\Eva-Maria\Documents\IMG_27082010_214730.png
[2010.08.25 16:42:50 | 000,071,337 | ---- | C] () -- C:\Users\Eva-Maria\Documents\rockamsee.odt
[2010.08.19 21:05:43 | 000,185,311 | ---- | C] () -- C:\Users\Eva-Maria\trinkspiel.jpg
[2010.08.17 18:25:07 | 000,002,784 | ---- | C] () -- C:\Users\Eva-Maria\.recently-used.xbel
[2010.07.19 21:07:50 | 000,000,024 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Roaming\vdnxlf.dat
[2010.04.26 20:49:01 | 000,000,032 | ---- | C] () -- C:\Windows\wininit.ini
[2010.04.20 18:40:12 | 000,000,100 | --S- | C] () -- C:\Users\Eva-Maria\AppData\Local\1711337819.dat
[2010.04.14 12:55:09 | 000,000,552 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\d3d8caps.dat
[2009.12.23 15:46:43 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2009.12.23 15:46:43 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2009.09.24 15:39:01 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.08.26 08:27:16 | 000,006,836 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\d3d9caps.dat
[2009.08.25 23:47:23 | 000,001,072 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Roaming\wklnhst.dat
[2009.08.22 01:11:33 | 000,138,240 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.07.21 10:16:20 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2009.07.21 10:16:20 | 000,011,264 | ---- | C] () -- C:\Windows\System32\atimuixx.dll
[2009.07.21 01:52:22 | 000,000,033 | ---- | C] () -- C:\Windows\LaunApp.ini
[2009.07.21 01:44:57 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini
[2009.07.21 01:44:56 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2009.03.12 12:32:52 | 000,000,028 | ---- | C] () -- C:\Windows\WisLangCode.ini
[2009.03.12 05:26:46 | 000,004,516 | ---- | C] () -- C:\ProgramData\ArcadeDeluxe2.log
[2009.02.11 22:03:58 | 000,872,448 | ---- | C] () -- C:\Windows\iconv.dll
[2009.02.11 22:03:58 | 000,743,424 | ---- | C] () -- C:\Windows\libxml2.dll
[2009.02.11 22:03:57 | 000,000,060 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2008.01.21 04:23:43 | 000,009,232 | ---- | C] () -- C:\Users\Eva-Maria\AppData\Local\acleditu.dat
[2007.10.25 18:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:25:26 | 000,557,568 | ---- | C] () -- C:\Windows\System32\hpotscl1.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
 
========== LOP Check ==========
 
[2009.07.21 01:52:19 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Acer GameZone Console
[2010.01.17 13:30:12 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Cycle of 5th
[2010.09.09 20:54:49 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.02.28 14:05:31 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\eSobi
[2010.03.31 00:40:30 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Facebook
[2010.08.17 18:24:16 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\gtk-2.0
[2010.08.29 11:40:36 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Gutscheinmieze
[2010.09.08 17:59:58 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\ICQ
[2010.05.16 21:58:39 | 000,000,000 | -HSD | M] -- C:\Users\Eva-Maria\AppData\Roaming\lowsec
[2009.10.11 11:18:50 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\OpenOffice.org
[2010.05.11 19:29:55 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Osfoyd
[2009.12.23 15:52:06 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\PC Suite
[2010.07.27 11:04:34 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\PhotoScape
[2009.08.12 17:43:26 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\PowerCinema
[2009.12.23 15:46:19 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Samsung
[2009.08.25 23:47:27 | 000,000,000 | ---D | M] -- C:\Users\Eva-Maria\AppData\Roaming\Template
[2010.09.09 20:57:13 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010.09.09 21:16:07 | 000,000,434 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{67F42434-13A1-4949-BC57-7301C908FC3C}.job
 
========== Purity Check ==========
 
 
< End of report >

--- --- ---

laevalalala 09.09.2010 20:24

OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 09.09.2010 21:15:14 - Run 8
OTL by OldTimer - Version 3.2.10.0    Folder = c:\Users\Eva-Maria\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 59,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455,99 Gb Total Space | 278,28 Gb Free Space | 61,03% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 491,73 Mb Total Space | 487,93 Mb Free Space | 99,23% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: EVA-MARIAS-PC
Current User Name: Eva-Maria
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- C:\Users\Eva-Maria\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00AE7C7B-DEE9-4307-AAAE-5C5B79B1D543}" = lport=10243 | protocol=6 | dir=in | app=system |
"{28457959-C5B1-4050-806C-F45BCBD67AAF}" = lport=137 | protocol=17 | dir=in | app=system |
"{319BFAA0-A829-4493-93F4-A8DC28B4527D}" = rport=139 | protocol=6 | dir=out | app=system |
"{3B3CD04E-CFC1-412E-AFD1-4D965130282D}" = rport=445 | protocol=6 | dir=out | app=system |
"{3F1A0BED-8B18-4A45-AE50-40CBD862C194}" = rport=137 | protocol=17 | dir=out | app=system |
"{57D393EC-0B2D-49A3-A893-7C6CC26B2EF7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{59EFFD2D-47F1-403F-8324-1E950DA9446D}" = lport=138 | protocol=17 | dir=in | app=system |
"{5EF1CAA7-80A3-4F4F-B865-34C8003C3876}" = rport=10243 | protocol=6 | dir=out | app=system |
"{662B99A0-E963-4A58-98AD-D0927002C35C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{791FB021-ACCB-4E0F-A6BE-23177766673F}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7CFF0581-CBE9-451D-9420-C7B44B83A227}" = rport=138 | protocol=17 | dir=out | app=system |
"{7F8C7921-F192-48A4-9BD6-3675E384B18E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8294CCAD-5D5F-4E72-9F07-B7CF6FDFBE24}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{855BED46-727A-4467-8E19-A636917608EF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8CFE33EA-4391-454E-A35F-EA43DCB93F9D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{948598FA-A43C-4A23-A242-F0CCE936BEF9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B8A75402-A86A-4FE8-9160-3FD7A46C5E1B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D4D0BDBE-EC1A-44DE-86A1-CE2BEA8C759A}" = lport=139 | protocol=6 | dir=in | app=system |
"{E64FF6B8-44AD-4436-A9B4-A3110C59EFFE}" = lport=445 | protocol=6 | dir=in | app=system |
"{ED32EEC9-BC99-4489-A67B-743BD2A241E4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FC05A707-C5E0-4425-B211-55FD1F72EA43}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0925BAD3-0FC1-41AE-B808-2F47FD31DAF1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0AD63CA4-E4FB-4FCB-9EE2-9E7B8D955EB7}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{118B082C-A442-4D30-AC6B-9AF810566476}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{1468F000-3010-43B9-B82C-3EBD3CD011A2}" = protocol=6 | dir=in | app=c:\program files\vogel verlag\fahren lernen\vogel.fahrenlernenmax.exe |
"{1CFB9A24-8676-4CDF-AC11-3D8358181C02}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{1FD1EE18-9B52-4A6A-BBBF-A6822980A7A6}" = protocol=17 | dir=in | app=c:\program files\vogel verlag\fahren lernen\vogel.fahrenlernenmax.exe |
"{21819292-C4FC-4D2B-A4A3-6E81788A87F2}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{267830C1-404E-4858-AE6C-7E80BBE3DC60}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"{284AE749-504A-4C3C-9F79-936BEBA0FA46}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{3A4C30CB-AA9A-4E3F-A0E5-80298DFDE5AD}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{43081B67-3649-4F44-A436-C411F1846E5E}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\pmvservice.exe |
"{44313369-55A3-4DAD-880E-2106C1031AB1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{565654F8-F40D-4390-93C6-8058E1ACD914}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{59D7ECC3-1D25-4D86-A5C5-E7571576410B}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{5C455030-3F84-4409-80AE-95CD56A8FEEE}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{5DD2B873-0719-4DF2-8BE8-79CE5621EB19}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5DF823F4-E4C2-4753-B954-03A763E32ACD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{64AA90F1-DA1D-4A45-9561-5BE57A7502A2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{67B40295-FB21-4F49-8E53-4AFBC2424B1C}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{6A9DA5E1-F641-4499-831E-E6F5529AE943}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6E3A109D-AC1A-485F-800A-32582D09EFA8}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe |
"{71B74B44-A66F-4720-AAAF-AF4AC989D8D6}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{7CFD5BF1-6E7B-4845-896E-D79FABB2BA46}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{817715C2-9EA4-470A-A160-7C75EA2E7009}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\playmovie.exe |
"{834DBB9F-6F5D-4316-AC31-E022E1CF4C1A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8C15EBE6-348E-4AC0-B360-B8B460C77FB1}" = protocol=6 | dir=out | app=system |
"{8D514C19-9B7F-4B3D-9039-760270250D49}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{98C9D060-2C3C-4A5A-8675-38FAB4A0E2BF}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{A50EBAC5-4DB5-426A-B8D7-BB1B83D78E6D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{AE4AF426-0752-41FE-A533-F7886DE302D8}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{B2D9231D-A883-44D8-9D0A-F48D59102CBE}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{B629F32A-CBAC-414B-B9C7-A4E2666E5BA2}" = protocol=17 | dir=in | app=c:\program files\vogel verlag\fahren lernen\vogel.fahrenlernenmax.exe |
"{B8F8DC52-D951-45EC-B7A0-F00403310642}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BC825CA3-DCC3-4D47-AE63-282D8037A4FA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BD4058BF-9111-4856-8D5D-6F948F6BCC76}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{BDF4E89D-B753-4BBC-B26E-148F5CFA5CAB}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{BEA626B6-140C-4DC4-AD06-572D004D03BF}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe |
"{C2498091-8D47-4620-BD12-1FF979FEA3E8}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C85167BD-EBC9-4F31-AC3A-D9A3E6E96F71}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe |
"{C90CB239-FB9F-4305-A698-388F84D2D7CD}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{CC686FC8-5A62-4AAE-B9FD-0A6E94A283C2}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{CD5448DB-53EA-4994-ACD0-4D0D1A5912C2}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CEC55CBF-E0E4-4DBD-AA4C-5A746BFCF61D}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{D20E9F48-4A8F-4715-A228-4F154F1BD8E8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D34FC609-9D97-40B1-9195-08B57089E5F6}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe |
"{D8C6D2C8-A7F3-4AF4-B1BD-4A364748365D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{DB257940-256D-4C26-B3D9-B209FD460BB2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DDB8395A-3568-4DA3-B60D-12EA9A6CACEF}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{E1C6F362-C3B1-4981-861A-420CCE0B1221}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E5690112-A4EB-46E2-A558-456BA097E986}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E7CB38D5-90FC-4311-8A26-E8D14366EE74}" = protocol=6 | dir=in | app=c:\program files\vogel verlag\fahren lernen\vogel.fahrenlernenmax.exe |
"{F49B066B-0133-4E80-8BD5-94F7274BFAB8}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F603B287-4208-4C67-9724-B9FE79EC93EE}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{F6F63A39-A5CF-4F08-8607-C070100425CC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FECDE689-582B-4799-8EFC-0A62FB2E8763}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"TCP Query User{00E39D8E-1A09-4F07-B085-BB6F2171425B}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{5751046D-6650-49BE-8267-21431837F75C}C:\programdata\c68bb7f\msc68b.exe" = protocol=6 | dir=in | app=c:\programdata\c68bb7f\msc68b.exe |
"TCP Query User{91C36C6F-9508-4DDD-BE4F-437FB71ED8B0}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{CA8D4410-58CE-4A2B-A831-48F304A11FDE}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{41A64FC2-FD61-44CD-B273-469A2DD4F702}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{AE8263FC-8E2E-460A-A464-8402200519EB}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{E78CFA4C-08D6-44E8-BB30-716DCE5E86ED}C:\programdata\c68bb7f\msc68b.exe" = protocol=17 | dir=in | app=c:\programdata\c68bb7f\msc68b.exe |
"UDP Query User{EB790BA7-A1BA-4F20-95BE-756CFA628661}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{040A6E85-C23F-4A23-ADBB-821C60C5DF0F}_is1" = Fahren Lernen 1.1
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{056B935A-A03D-D0D8-4CE0-B4B337753156}" = CCC Help Chinese Standard
"{0C362375-1FE0-98C0-2C57-F4D772B8A759}" = Catalyst Control Center Graphics Full New
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java(TM) 6 Update 21
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie
"{2BD2FA21-B51D-4F01-94A7-AC16737B2163}" = Adobe Flash Player 10 ActiveX
"{2C973B8B-1BB3-358B-250C-336C81A1926E}" = CCC Help Polish
"{2F2B002A-8BF5-DF1E-6D36-7900B6F868DE}" = ATI Catalyst Install Manager
"{360872CE-7A87-A4EE-AF69-EF73E5695D40}" = ccc-utility
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3CCB314A-B67C-82D0-1CC6-6BC4AE6D053E}" = Catalyst Control Center InstallProxy
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer PowerSmart Manager
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{45416928-B205-9812-2065-5794D5AC7338}" = CCC Help French
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{53E12B77-A8AC-1A15-7690-FAA711AA0B50}" = CCC Help Portuguese
"{5A64A288-025C-F952-E4E3-12FA6596922F}" = CCC Help Chinese Traditional
"{5B63A470-9334-44D1-AF61-6CE2DB565AE9}" = Orion
"{5D3A59B1-2BBF-66AF-3B5F-FC5BAA42F817}" = CCC Help Italian
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{5F19F78E-274D-8E5C-C49E-2ED722ACF70A}" = CCC Help German
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{6078A803-C98F-1F95-CEF7-0132621E6072}" = CCC Help Japanese
"{6234F3C6-F8EF-39FB-AE15-0B88E88B79F0}" = CCC Help Greek
"{62F7DA7E-CCCB-439C-A760-00C3926E761F}" = Microsoft Works
"{68301905-2DEA-41CE-A4D4-E8B443B099BA}" = MyWinLocker
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A0D64D0-CDF4-9C65-A053-6EC86AEB43CC}" = ccc-core-static
"{6A905715-6991-3517-5F04-4392FC18DB76}" = Catalyst Control Center Graphics Previews Vista
"{6EAA466F-6F35-F3B7-60B9-3D6DCA97EE02}" = Catalyst Control Center Localization All
"{71C2828F-2678-4675-BDEC-895424861262}_is1" = C:\Program Files\Acer GameZone\GameConsole
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{742A17A1-8AA4-4DCE-C881-557AC4EB793D}" = CCC Help Spanish
"{75212523-6E47-BF0F-20FF-B65E940A5DDD}" = CCC Help English
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110184263}" = Puzzle Express
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11037623}" = Tradewinds 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111205743}" = Tri-Peaks Solitaire To Go
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111232687}" = Ocean Express
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11170417}" = Luxor 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11219217}" = Cradle of Rome
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112270203}" = Dream Day Wedding
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113056167}" = Dream Day Honeymoon
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113297350}" = Cake Mania 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113494430}" = Wedding Dash
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11505173}" = Airport Mania First Flight
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}" = Dairy Dash
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115443300}" = Cooking Dash
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11551977}" = Parking Dash
"{84ED5482-CFB0-4DD9-BF18-489FFDACD18A}" = Microsoft Antimalware Service DE-DE Language Pack
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{88EB38EF-4D2C-436D-ABD3-56B232674062}" = ICQ7
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90AD0407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint 2003 Template Pack 3
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{940F9DF4-A790-EAE9-A4B1-B9F96D3C8CC9}" = CCC Help Finnish
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97BA7028-6FE4-58B5-F254-48C12AA3FBBD}" = CCC Help Swedish
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{987381F2-AA18-EF9C-9DDA-4D403FD7F3E2}" = CCC Help Turkish
"{99C85B2D-DFA4-5704-9A4C-396DDB5C6F1F}" = CCC Help Thai
"{99E862CC-6F69-4D39-99AA-DBF71BF3B585}" = OpenOffice.org 3.1
"{9AF0B106-56F1-461B-A270-95BC1682E282}" = Broadcom Gigabit NetLink Controller
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{9E6B5AEA-C8EC-916B-FDFA-91F1274CD695}" = Skins
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A75C2F92-28EC-FE11-3818-81578F3E9596}" = CCC Help Norwegian
"{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}" = Acer Crystal Eye Webcam
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA9732EB-64DD-DBA5-DFC1-705E64D3FB18}" = CCC Help Russian
"{AAE19E03-87A5-6937-F7D7-6806C5FD1D89}" = Catalyst Control Center Graphics Light
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.3 - Deutsch
"{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B15E1629-4B8C-FC02-1118-35034C235F0D}" = CCC Help Korean
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{BA165460-FCF7-4D6C-A7A2-F2321700720F}" = MobileMe Control Panel
"{BE0EC61A-02BF-E3E1-D7A8-3DDB7B58FBDF}" = PX Profile Update
"{BF91B300-EEBC-4223-96F3-0FCBF7241B50}" = AmIcoSingLun
"{C10DD83A-CB15-DD3A-FE29-89433A68F55D}" = CCC Help Dutch
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0F3E75D-6BE1-E974-2A8E-A449D3374FDB}" = Catalyst Control Center Graphics Full Existing
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DA20E1A8-07CB-4EE7-9B72-A7E28C953F0E}" = Acer Product Registration
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E24DBA75-5452-C0A1-4FF3-CB38F8245919}" = CCC Help Czech
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E430067C-7254-40B6-A8F8-5EEF57A68F1A}" = Catalyst Control Center - Branding
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E86CA8CF-F42D-9569-B2ED-5E6A0F591EA5}" = CCC Help Hungarian
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F557AF38-AB37-84A8-0148-C53B5F870373}" = CCC Help Danish
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{FF7027C7-B001-A144-C83B-03618745E975}" = Catalyst Control Center Core Implementation
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0)
"7-Zip" = 7-Zip 4.65
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Audacity_is1" = Audacity 1.2.6
"CCleaner" = CCleaner
"ESET Online Scanner" = ESET Online Scanner v3
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"Free Studio_is1" = Free Studio version 4.2
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.8
"GridVista" = Acer GridVista
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Acer Backup Manager
"InstallShield_{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"InstallShield_{BF91B300-EEBC-4223-96F3-0FCBF7241B50}" = AmIcoSingLun
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"LastFM_is1" = Last.fm 1.5.4.24567
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft Security Essentials" = Microsoft Security Essentials
"NSS" = Norton Security Scan
"PhotoFiltre" = PhotoFiltre
"PhotoScape" = PhotoScape
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile Modem Device" = Samsung Mobile Modem Device Software
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software
"Secunia PSI" = Secunia PSI
"Security Task Manager" = Security Task Manager 1.7h
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Uninstall_is1" = Uninstall 1.0.0.1
"WinGimp-2.0_is1" = GIMP 2.6.7
"WinLiveSuite_Wave3" = Windows Live Essentials
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 29.08.2010 17:29:10 | Computer Name = Eva-Marias-PC | Source = Google Update | ID = 20
Description =
 
Error - 29.08.2010 17:37:14 | Computer Name = Eva-Marias-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 29.08.2010 17:38:01 | Computer Name = Eva-Marias-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksdb.exe".
Die
 abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0""
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
 "sxstrace.exe".
 
Error - 29.08.2010 17:38:02 | Computer Name = Eva-Marias-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\WksCal.exe".
Die
 abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0""
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
 "sxstrace.exe".
 
Error - 29.08.2010 17:38:02 | Computer Name = Eva-Marias-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe".
Die
 abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0""
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
 "sxstrace.exe".
 
Error - 29.08.2010 17:38:02 | Computer Name = Eva-Marias-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\WksWP.exe".
Die
 abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0""
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
 "sxstrace.exe".
 
Error - 29.08.2010 17:45:06 | Computer Name = Eva-Marias-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksdb.exe".
Die
 abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0""
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
 "sxstrace.exe".
 
Error - 29.08.2010 17:45:06 | Computer Name = Eva-Marias-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\WksCal.exe".
Die
 abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0""
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
 "sxstrace.exe".
 
Error - 29.08.2010 17:45:06 | Computer Name = Eva-Marias-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe".
Die
 abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0""
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
 "sxstrace.exe".
 
Error - 29.08.2010 17:45:06 | Computer Name = Eva-Marias-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\WksWP.exe".
Die
 abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0""
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
 "sxstrace.exe".
 
[ System Events ]
Error - 09.09.2010 14:26:39 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 09.09.2010 14:26:39 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 09.09.2010 14:30:16 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 09.09.2010 14:32:26 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7022
Description =
 
Error - 09.09.2010 14:54:48 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7031
Description =
 
Error - 09.09.2010 14:59:49 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 09.09.2010 14:59:49 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 09.09.2010 14:59:49 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 09.09.2010 14:59:49 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 09.09.2010 15:01:29 | Computer Name = Eva-Marias-PC | Source = Service Control Manager | ID = 7000
Description =
 
 
< End of report >

--- --- ---

john.doe 09.09.2010 20:47

Beantworte mir folgende Frage: Wie hast du dich infziert?

Das war eine rhetorische Frage. Ich erwarte keine Antwort darauf. Denn ich weiß die Antwort schon. Es war Chrome, ein Browser, den ich zwei Tage lang getestet habe und dann selbst nach Installation von Iron endgülitg von der Festplatte entfernt habe. Selbst eine Installation von Opera würde nichts bringen, du musst an brain.exe arbeiten.

Sei in Zukunft vorsichtig. Denk darüber nach, auf was du klickst.

Ein falscher Klick kann tödlich sein und das bedeutet => http://www.trojaner-board.de/51262-a...sicherung.html

Klicke bitte auf die letzten beiden Links in meiner Signatur und siehe deinen Fehler ein und viel wichtiger, lerne daraus.

Deinstalliere Eset. Starte OTL => Klick auf Bereinigung => Rechner startet neu => Fertig

Falls sonst keine Probleme existieren, dann sind wir durch.

Du bist entlassen. :)

ciao, andreas

laevalalala 09.09.2010 21:06

chrome? also chrome löschen?
aber super! vielen vielen dank! :)

laevalalala 09.09.2010 21:24

das hier wird mir vom windows sicherheitscenter vorgeschlagen:
hxxp://www.microsoft.com/security_essentials/

john.doe 09.09.2010 21:33

Ein Betriebssystem, dass dir anbietet, zusätzliche Sicherheitstools zu installieren (die IMHO nichts taugen)? Nein, halte dich an meine Ratschläge.

Microsoft bietet:
  • Windows Defender
  • Microsoft Removal Tools
  • Security Essentials
Nur, warum taugen die alle nichts und müllen nur den Rechner voll?

Es ist ganz simpel, entweder du vertraust mir oder Microsoft. Und ich rate dir: Installiere es nicht.

ciao, andreas

laevalalala 09.09.2010 22:10

okay, das ist nur so verlockend :D
also ist jetzt opera einer der sichersten browser? und chrome ganz löschen?

john.doe 09.09.2010 22:19

Naja, nicht wirklich, es hängt von dir ab. Opera fragt dich grundsätzlich, ob es ein Programm downloaden soll und warnt dich, dass es schädlich sein kann. Aber wenn du dann auf Ja klickst, dann hast du das gleiche Problem.

Deshalb klicke noch einmal auf die letzten beiden Links in meiner Signatur. Der letzte ist vermutlich einfacher für dich zu verstehen, deshalb lies zumindest den.

Und in Zukunft sei vorsichtiger. Ein falscher Klick kann tödlich sein. Und es ist egal, ob es von einem Fremden kommt oder einem Freund. Klick auf nichts, dass dir jemand zuschickt. Dann bleibt dir das, was du hinter dir hast, in Zukunft erspart. :)

ciao, andreas

laevalalala 09.09.2010 22:59

alles klar, merci beaucoup ;)

john.doe 09.09.2010 23:03

Ich mag dich auch. :)

ciao, andreas


Alle Zeitangaben in WEZ +1. Es ist jetzt 04:39 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131