Butler1234
Member
Tag an alle.
Ich musste eben unter Prozesse feststellen, da alles auf einmal total hing und langsam war, das dort was ist Namens agent.exe.
Der war über 90% also Auslastung und Arbeitsspeicher war der Wert über 800.000 K
Die Datei befindet sich hier: C:\ProgramData\Macrovision\FLEXnet Connect\6
Ich benutze AVG Internet Security und haben Windows 7 64 bit.
Nun habe ich folgendes gemacht.
Weiß jemand was damit anzufangen, wäre euch sehr dankbar um jede Hilfe.
Ich musste eben unter Prozesse feststellen, da alles auf einmal total hing und langsam war, das dort was ist Namens agent.exe.
Der war über 90% also Auslastung und Arbeitsspeicher war der Wert über 800.000 K
Die Datei befindet sich hier: C:\ProgramData\Macrovision\FLEXnet Connect\6
Ich benutze AVG Internet Security und haben Windows 7 64 bit.
Nun habe ich folgendes gemacht.
Getan gemacht, dann kam das rausSystemdetails mit RSIT prüfen
* Lade Random's System Information Tool (RSIT) von random/random herunter,
* speichere es auf Deinem Desktop.
* Schließe alle Fenster und Programme inkl. Browser.
* Starte mit Doppelklick die RSIT.exe.
* Klicke auf Continue, um die Nutzungsbedingungen zu akzeptieren.
* Wenn Du HijackThis nicht installiert hast, wird RSIT das für Dich herunterladen und installieren.
* In dem Fall bitte auch die Nutzungsbedingungen von Trend Micro für HJT akzeptieren I accept.
* Wenn Deine Firewall fragt, bitte RSIT erlauben, ins Netz zu gehen.
* Der Scan startet automatisch, RSIT checkt nun einige wichtige System-Bereiche und produziert Logfiles als Analyse-Grundlage.
* Wenn der Scan beendet ist, werden zwei Logfiles erstellt und in Deinem Editor geöffnet.
* Bitte poste den Inhalt von C:\rsit\log.txt und C:\rsit\info.txt (<= wird minimiert in der Taskleiste dargestellt) hier in den Thread.
Spoiler:
Logfile of random's system information tool 1.08 (written by random/random)
Run at 2011-02-24 14:35:37
Microsoft Windows 7
System drive C: has 55 GB (43%) free of 126 GB
Total RAM: 1791 MB (40% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:35:46, on 24.02.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\Program Files (x86)\Software4u\iPhone Explorer\Software4u.IPELauncher.exe
C:\Program Files (x86)\Hama\Common\RaUI.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\ProgramData\Macrovision\FLEXnet Connect\6\agent.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\Salva\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\Salva.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [tsnp2uvc] C:\Windows\tsnp2uvc.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [iPhone Explorer Launcher] "C:\Program Files (x86)\Software4u\iPhone Explorer\Software4u.IPELauncher.exe" /run
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST')
O4 - Global Startup: Hama Wireless LAN Utility.lnk = C:\Program Files (x86)\Hama\Common\RaUI.exe
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Free YouTube Download - C:\Users\Salva\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Salva\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10840 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-10 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG9\avgssie.dll [2011-02-05 1623392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID-Anmelde-Hilfsprogramm - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-02-06 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-09-06 1048888]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"tsnp2uvc"=C:\Windows\tsnp2uvc.exe [2008-10-21 241664]
"AVG9_TRAY"=C:\PROGRA~2\AVG\AVG9\avgtray.exe [2011-02-05 2069344]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-01-25 421160]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-26 15026056]
"ISUSPM"=C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe [2007-03-29 222128]
"iPhone Explorer Launcher"=C:\Program Files (x86)\Software4u\iPhone Explorer\Software4u.IPELauncher.exe [2011-01-13 131584]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Hama Wireless LAN Utility.lnk - C:\Program Files (x86)\Hama\Common\RaUI.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-02-24 14:32:58 ----D---- C:\Program Files (x86)\trend micro
2011-02-24 14:32:56 ----D---- C:\rsit
2011-02-24 01:43:28 ----A---- C:\Windows\SysWOW64\wcncsvc.dll
2011-02-23 16:42:05 ----A---- C:\Windows\SysWOW64\mshtml.dll
2011-02-23 16:42:01 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2011-02-23 16:42:00 ----A---- C:\Windows\SysWOW64\mstime.dll
2011-02-23 16:42:00 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2011-02-23 16:41:59 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2011-02-23 16:41:59 ----A---- C:\Windows\SysWOW64\iertutil.dll
2011-02-23 16:41:59 ----A---- C:\Windows\SysWOW64\iepeers.dll
2011-02-23 16:41:58 ----A---- C:\Windows\SysWOW64\msfeedsbs.dll
2011-02-23 16:41:58 ----A---- C:\Windows\SysWOW64\licmgr10.dll
2011-02-23 16:41:57 ----A---- C:\Windows\SysWOW64\msfeedssync.exe
2011-02-23 16:40:46 ----A---- C:\Windows\SysWOW64\kerberos.dll
2011-02-23 16:40:38 ----A---- C:\Windows\SysWOW64\upnp.dll
2011-02-23 16:40:37 ----A---- C:\Windows\SysWOW64\wininet.dll
2011-02-23 16:40:37 ----A---- C:\Windows\SysWOW64\urlmon.dll
2011-02-23 16:40:37 ----A---- C:\Windows\SysWOW64\msxml6.dll
2011-02-23 16:40:37 ----A---- C:\Windows\SysWOW64\msxml3.dll
2011-02-23 16:40:36 ----A---- C:\Windows\SysWOW64\WebClnt.dll
2011-02-23 16:40:36 ----A---- C:\Windows\SysWOW64\ieframe.dll
2011-02-23 16:40:36 ----A---- C:\Windows\SysWOW64\davclnt.dll
2011-02-23 16:40:35 ----A---- C:\Windows\SysWOW64\wscapi.dll
2011-02-23 16:40:35 ----A---- C:\Windows\SysWOW64\winhttp.dll
2011-02-23 16:40:35 ----A---- C:\Windows\SysWOW64\slwga.dll
2011-02-23 16:40:26 ----A---- C:\Windows\SysWOW64\XpsPrint.dll
2011-02-23 16:40:26 ----A---- C:\Windows\SysWOW64\XpsGdiConverter.dll
2011-02-23 16:40:10 ----A---- C:\Windows\SysWOW64\vbscript.dll
2011-02-23 16:40:10 ----A---- C:\Windows\SysWOW64\jscript.dll
2011-02-23 16:40:04 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2011-02-23 16:40:04 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2011-02-23 16:40:04 ----A---- C:\Windows\SysWOW64\ntdll.dll
2011-02-23 16:40:03 ----A---- C:\Windows\SysWOW64\atmfd.dll
2011-02-23 16:40:02 ----A---- C:\Windows\SysWOW64\atmlib.dll
2011-02-23 15:16:50 ----D---- C:\Users\Salva\AppData\Roaming\Apple Computer
2011-02-23 15:16:34 ----A---- C:\Windows\SysWOW64\GEARAspi.dll
2011-02-23 15:16:21 ----D---- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-02-23 15:16:21 ----D---- C:\Program Files (x86)\iTunes
2011-02-23 15:14:42 ----D---- C:\ProgramData\Apple Computer
2011-02-23 15:14:42 ----D---- C:\Program Files (x86)\QuickTime
2011-02-23 15:14:30 ----D---- C:\Program Files (x86)\Apple Software Update
2011-02-23 15:13:56 ----D---- C:\Program Files (x86)\Bonjour
2011-02-23 15:13:49 ----D---- C:\ProgramData\Apple
2011-02-23 15:13:49 ----D---- C:\Program Files (x86)\Common Files\Apple
2011-02-22 15:57:26 ----D---- C:\temp
2011-02-21 14:20:08 ----A---- C:\Windows\SysWOW64\uxtuneup.dll
2011-02-21 14:20:06 ----A---- C:\Windows\SysWOW64\authuitu.dll
2011-02-21 14:19:35 ----D---- C:\Users\Salva\AppData\Roaming\TuneUp Software
2011-02-21 14:19:25 ----D---- C:\Program Files (x86)\TuneUp Utilities 2010
2011-02-21 14:18:42 ----D---- C:\ProgramData\TuneUp Software
2011-02-21 14:18:23 ----SHD---- C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2011-02-19 22:54:05 ----D---- C:\Users\Salva\AppData\Roaming\DVDVideoSoftIEHelpers
2011-02-19 22:53:54 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-02-19 22:53:54 ----D---- C:\Program Files (x86)\Common Files\DVDVideoSoft
2011-02-19 15:06:57 ----D---- C:\ProgramData\Canneverbe Limited
2011-02-19 15:06:56 ----D---- C:\Users\Salva\AppData\Roaming\Canneverbe Limited
2011-02-19 15:00:51 ----D---- C:\Users\Salva\AppData\Roaming\ImgBurn
2011-02-19 14:52:34 ----D---- C:\Program Files (x86)\ImgBurn
2011-02-15 21:21:36 ----D---- C:\Users\Salva\AppData\Roaming\Software4u
2011-02-15 21:21:17 ----D---- C:\Program Files (x86)\Software4u
2011-02-13 13:00:21 ----D---- C:\ProgramData\LightScribe
2011-02-09 12:34:11 ----HD---- C:\$AVG
2011-02-09 12:06:26 ----D---- C:\Users\Salva\AppData\Roaming\Macrovision
2011-02-08 15:29:44 ----D---- C:\ProgramData\Macrovision
2011-02-08 15:29:24 ----A---- C:\Windows\BADENIA.INI
2011-02-08 15:24:10 ----A---- C:\Windows\ODBC.INI
2011-02-08 15:23:51 ----D---- C:\ProgramData\Vofue
2011-02-08 15:23:43 ----D---- C:\Program Files (x86)\Common Files\cib
2011-02-08 15:23:39 ----D---- C:\Prog
2011-02-08 15:22:19 ----D---- C:\Program Files (x86)\Common Files\Adobe
2011-02-08 15:22:19 ----D---- C:\Program Files (x86)\Adobe
2011-02-08 15:21:30 ----D---- C:\ProgramData\Adobe
2011-02-06 20:17:23 ----D---- C:\ProgramData\Sun
2011-02-06 20:17:23 ----D---- C:\Program Files (x86)\Common Files\Java
2011-02-06 20:17:08 ----A---- C:\Windows\SysWOW64\javaws.exe
2011-02-06 20:17:08 ----A---- C:\Windows\SysWOW64\javaw.exe
2011-02-06 20:17:08 ----A---- C:\Windows\SysWOW64\java.exe
2011-02-06 20:17:08 ----A---- C:\Windows\SysWOW64\deployJava1.dll
2011-02-06 20:17:00 ----D---- C:\Program Files (x86)\Java
2011-02-06 04:15:45 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-02-06 00:57:36 ----D---- C:\Users\Salva\AppData\Roaming\IBKPRO
2011-02-06 00:57:27 ----D---- C:\Program Files (x86)\IncrediBackup
2011-02-06 00:51:57 ----D---- C:\ProgramData\IncrediMail
2011-02-06 00:51:57 ----D---- C:\ProgramData\IM
2011-02-06 00:51:56 ----D---- C:\Program Files (x86)\IncrediMail
2011-02-06 00:45:11 ----D---- C:\Users\Salva\AppData\Roaming\Nero
2011-02-05 21:04:37 ----D---- C:\CCcam.channelinfo_04.02.2011
2011-02-05 15:10:42 ----D---- C:\ProgramData\Nero
2011-02-05 15:10:05 ----D---- C:\Program Files (x86)\Common Files\Nero
2011-02-05 15:09:56 ----D---- C:\Program Files (x86)\Nero
2011-02-05 15:05:01 ----D---- C:\ProgramData\ICQ
2011-02-05 15:05:01 ----D---- C:\Program Files (x86)\ICQ6Toolbar
2011-02-05 15:04:52 ----D---- C:\Users\Salva\AppData\Roaming\ICQ
2011-02-05 15:04:48 ----D---- C:\Program Files (x86)\ICQ7.4
2011-02-05 14:55:38 ----D---- C:\Program Files (x86)\Common Files\LightScribe
2011-02-05 14:54:48 ----A---- C:\Windows\SysWOW64\D3DCompiler_42.dll
2011-02-05 14:54:27 ----A---- C:\Windows\SysWOW64\D3DX9_42.dll
2011-02-05 14:54:06 ----A---- C:\Windows\SysWOW64\D3DX9_40.dll
2011-02-05 14:53:49 ----A---- C:\Windows\SysWOW64\d3dx9_35.dll
2011-02-05 14:53:28 ----A---- C:\Windows\SysWOW64\d3dx9_34.dll
2011-02-05 14:53:06 ----A---- C:\Windows\SysWOW64\d3dx9_30.dll
2011-02-05 14:17:14 ----D---- C:\Windows\SysWOW64\drivers\avg
2011-02-05 00:37:43 ----D---- C:\ProgramData\avg9
2011-02-05 00:37:43 ----D---- C:\Program Files (x86)\AVG
2011-02-05 00:18:37 ----A---- C:\Windows\AutoKMS.ini
2011-02-05 00:04:09 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-02-05 00:03:26 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2011-02-05 00:03:02 ----D---- C:\Program Files (x86)\Microsoft Office
2011-02-05 00:03:00 ----D---- C:\ProgramData\Microsoft Help
2011-02-05 00:02:49 ----RHD---- C:\MSOCache
2011-02-04 22:43:38 ----D---- C:\Users\Salva\AppData\Roaming\Macromedia
2011-02-04 22:43:38 ----D---- C:\Users\Salva\AppData\Roaming\Adobe
2011-02-04 22:36:05 ----D---- C:\Windows\SysWOW64\Macromed
2011-02-04 22:30:04 ----D---- C:\Program Files (x86)\Windows Live
2011-02-04 22:29:55 ----D---- C:\Windows\PCHEALTH
2011-02-04 22:29:19 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-02-04 22:27:38 ----D---- C:\Program Files (x86)\Common Files\Windows Live
2011-02-04 22:25:52 ----D---- C:\Users\Salva\AppData\Roaming\skypePM
2011-02-04 22:22:53 ----D---- C:\Program Files (x86)\Common Files\Skype
2011-02-04 22:22:52 ----RD---- C:\Program Files (x86)\Skype
2011-02-04 22:22:52 ----D---- C:\Users\Salva\AppData\Roaming\Skype
2011-02-04 22:22:50 ----D---- C:\ProgramData\Skype
2011-02-04 22:15:25 ----D---- C:\Users\Salva\AppData\Roaming\Mozilla
2011-02-04 22:15:21 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-02-04 22:02:51 ----D---- C:\Program Files (x86)\ArcSoft
2011-02-04 22:02:51 ----A---- C:\Windows\PCDLIB32.DLL
2011-02-04 22:02:15 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2011-02-04 21:55:10 ----HD---- C:\ProgramData\CanonBJ
2011-02-04 21:53:37 ----D---- C:\Program Files (x86)\Canon
2011-02-04 21:52:40 ----D---- C:\Program Files (x86)\Common Files\SNP2UVC
2011-02-04 21:52:40 ----A---- C:\Windows\tsnp2uvc.exe
2011-02-04 21:52:40 ----A---- C:\Windows\SysWOW64\rsnp2uvc.dll
2011-02-04 21:52:40 ----A---- C:\Windows\amcap.exe
2011-02-04 21:52:27 ----D---- C:\Users\Salva\AppData\Roaming\InstallShield
2011-02-04 21:48:31 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-02-04 21:48:31 ----D---- C:\Program Files (x86)\Hama
2011-02-04 18:57:34 ----D---- C:\ProgramData\explauncher
2011-02-04 18:57:31 ----D---- C:\ProgramData\launcher
2011-02-04 18:55:29 ----D---- C:\Program Files (x86)\Paragon Software
2011-02-04 18:50:35 ----D---- C:\Users\Salva\AppData\Roaming\WinRAR
2011-02-04 18:47:40 ----D---- C:\Users\Salva\AppData\Roaming\Identities
2011-02-04 18:47:29 ----SD---- C:\Users\Salva\AppData\Roaming\Microsoft
2011-02-04 18:47:29 ----D---- C:\Users\Salva\AppData\Roaming\Media Center Programs
2011-02-04 18:47:19 ----SHD---- C:\Recovery
2011-02-04 18:47:19 ----SHD---- C:\Programme
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Vorlagen
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Startmenü
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Favoriten
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Dokumente
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Desktop
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Anwendungsdaten
2011-02-04 18:47:19 ----SHD---- C:\Dokumente und Einstellungen
2011-02-04 18:47:15 ----D---- C:\Windows\SoftwareDistribution
2011-02-04 18:40:57 ----SHD---- C:\System Volume Information
2011-02-04 18:40:53 ----D---- C:\Windows\CSC
2011-02-04 18:40:32 ----ASH---- C:\pagefile.sys
2011-02-04 18:40:32 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 months======
2011-02-24 14:35:45 ----D---- C:\Windows\Temp
2011-02-24 14:35:28 ----D---- C:\Windows\Prefetch
2011-02-24 14:32:58 ----RD---- C:\Program Files (x86)
2011-02-24 10:28:27 ----D---- C:\Windows\System32
2011-02-24 10:28:27 ----D---- C:\Windows\inf
2011-02-24 10:22:28 ----D---- C:\Windows\winsxs
2011-02-24 10:22:19 ----D---- C:\Windows\SysWOW64
2011-02-24 10:20:59 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-24 01:42:56 ----SHD---- C:\Windows\Installer
2011-02-23 15:16:21 ----RD---- C:\Program Files
2011-02-23 15:16:21 ----HD---- C:\ProgramData
2011-02-23 15:13:49 ----D---- C:\Program Files (x86)\Common Files
2011-02-23 15:10:13 ----D---- C:\Windows\Tasks
2011-02-22 11:01:05 ----D---- C:\Windows
2011-02-08 15:26:23 ----RSD---- C:\Windows\Fonts
2011-02-08 15:25:14 ----A---- C:\Windows\BSC.ini
2011-02-06 03:20:15 ----D---- C:\Windows\SysWOW64\drivers
2011-02-05 17:42:18 ----D---- C:\Windows\Logs
2011-02-05 16:56:35 ----D---- C:\Windows\Microsoft.NET
2011-02-05 16:56:09 ----RSD---- C:\Windows\assembly
2011-02-05 00:37:15 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2011-02-05 00:06:06 ----D---- C:\Windows\ShellNew
2011-02-05 00:05:28 ----D---- C:\Program Files (x86)\MSBuild
2011-02-05 00:05:17 ----SD---- C:\ProgramData\Microsoft
2011-02-05 00:05:17 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-02-05 00:03:44 ----A---- C:\Windows\win.ini
2011-02-04 22:43:38 ----D---- C:\Windows\Downloaded Program Files
2011-02-04 22:38:06 ----RSD---- C:\Windows\Media
2011-02-04 22:00:46 ----D---- C:\Windows\twain_32
2011-02-04 18:47:37 ----SHD---- C:\$Recycle.Bin
2011-02-04 18:47:26 ----RD---- C:\Users
2011-02-04 18:47:21 ----D---- C:\Windows\Panther
2011-02-04 18:44:29 ----D---- C:\Windows\rescache
2011-02-04 18:44:12 ----D---- C:\Windows\debug
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSErHrw7a;AVG9IDSErHr; C:\Windows\System32\Drivers\AVGIDSwa.sys []
R0 AvgRkx64;avgrkx64.sys; C:\Windows\System32\Drivers\avgrkx64.sys []
R0 hotcore3;hc3ServiceName; C:\Windows\system32\DRIVERS\hotcore3.sys []
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys []
R1 AvgLdx64;AVG AVI Loader Driver x64; C:\Windows\System32\Drivers\avgldx64.sys []
R1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64; C:\Windows\System32\Drivers\avgmfx64.sys []
R1 AvgTdiA;AVG Network Redirector x64; C:\Windows\System32\Drivers\avgtdia.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R3 AVGIDSDriverw7a;AVG9IDSDriver; \??\C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN764\AVGIDSDriver.sys [2011-02-05 132688]
R3 AVGIDSFilterw7a;AVG9IDSFilter; \??\C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN764\AVGIDSFilter.sys [2011-02-05 35920]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys []
R3 netr28x;Ralink 802.11n-Drahtlostreiber für Windows Vista; C:\Windows\system32\DRIVERS\netr28x.sys []
R3 NVENETFD;NVIDIA nForce-Netzwerkcontrollertreiber; C:\Windows\system32\DRIVERS\nvm62x64.sys []
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [2010-02-24 11856]
R3 usbscan;USB-Scannertreiber; C:\Windows\system32\DRIVERS\usbscan.sys []
S3 E1G60;Intel(R) PRO/1000 NDIS 6-Adaptertreiber; C:\Windows\system32\DRIVERS\E1G6032E.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys []
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys []
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys []
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-01-05 37664]
R2 avg9wd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe [2011-02-05 308136]
R2 avgfws9;AVG Firewall; C:\Program Files (x86)\AVG\AVG9\avgfws9.exe [2011-02-05 2331544]
R2 AVGIDSAgent;AVG9IDSAgent; C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-02-05 5897808]
R2 Bonjour Service;Dienst "Bonjour"; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [2011-01-12 1403200]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 iPod Service;iPod-Dienst; C:\Program Files\iPod\bin\iPodService.exe [2011-01-25 933664]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TuneUp.Defrag;@C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [2011-02-21 607040]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
Run at 2011-02-24 14:35:37
Microsoft Windows 7
System drive C: has 55 GB (43%) free of 126 GB
Total RAM: 1791 MB (40% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:35:46, on 24.02.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\Program Files (x86)\Software4u\iPhone Explorer\Software4u.IPELauncher.exe
C:\Program Files (x86)\Hama\Common\RaUI.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\ProgramData\Macrovision\FLEXnet Connect\6\agent.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\Salva\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\Salva.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
Du hast keine Berechtigung, den Link zu sehen, bitte Anmelden oder Registrieren
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
Du hast keine Berechtigung, den Link zu sehen, bitte Anmelden oder Registrieren
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Du hast keine Berechtigung, den Link zu sehen, bitte Anmelden oder Registrieren
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Du hast keine Berechtigung, den Link zu sehen, bitte Anmelden oder Registrieren
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Du hast keine Berechtigung, den Link zu sehen, bitte Anmelden oder Registrieren
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
Du hast keine Berechtigung, den Link zu sehen, bitte Anmelden oder Registrieren
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [tsnp2uvc] C:\Windows\tsnp2uvc.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [iPhone Explorer Launcher] "C:\Program Files (x86)\Software4u\iPhone Explorer\Software4u.IPELauncher.exe" /run
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST')
O4 - Global Startup: Hama Wireless LAN Utility.lnk = C:\Program Files (x86)\Hama\Common\RaUI.exe
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Free YouTube Download - C:\Users\Salva\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Salva\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
Du hast keine Berechtigung, den Link zu sehen, bitte Anmelden oder Registrieren
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10840 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-10 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG9\avgssie.dll [2011-02-05 1623392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID-Anmelde-Hilfsprogramm - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-02-06 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-09-06 1048888]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"tsnp2uvc"=C:\Windows\tsnp2uvc.exe [2008-10-21 241664]
"AVG9_TRAY"=C:\PROGRA~2\AVG\AVG9\avgtray.exe [2011-02-05 2069344]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-01-25 421160]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-26 15026056]
"ISUSPM"=C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe [2007-03-29 222128]
"iPhone Explorer Launcher"=C:\Program Files (x86)\Software4u\iPhone Explorer\Software4u.IPELauncher.exe [2011-01-13 131584]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Hama Wireless LAN Utility.lnk - C:\Program Files (x86)\Hama\Common\RaUI.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-02-24 14:32:58 ----D---- C:\Program Files (x86)\trend micro
2011-02-24 14:32:56 ----D---- C:\rsit
2011-02-24 01:43:28 ----A---- C:\Windows\SysWOW64\wcncsvc.dll
2011-02-23 16:42:05 ----A---- C:\Windows\SysWOW64\mshtml.dll
2011-02-23 16:42:01 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2011-02-23 16:42:00 ----A---- C:\Windows\SysWOW64\mstime.dll
2011-02-23 16:42:00 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2011-02-23 16:41:59 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2011-02-23 16:41:59 ----A---- C:\Windows\SysWOW64\iertutil.dll
2011-02-23 16:41:59 ----A---- C:\Windows\SysWOW64\iepeers.dll
2011-02-23 16:41:58 ----A---- C:\Windows\SysWOW64\msfeedsbs.dll
2011-02-23 16:41:58 ----A---- C:\Windows\SysWOW64\licmgr10.dll
2011-02-23 16:41:57 ----A---- C:\Windows\SysWOW64\msfeedssync.exe
2011-02-23 16:40:46 ----A---- C:\Windows\SysWOW64\kerberos.dll
2011-02-23 16:40:38 ----A---- C:\Windows\SysWOW64\upnp.dll
2011-02-23 16:40:37 ----A---- C:\Windows\SysWOW64\wininet.dll
2011-02-23 16:40:37 ----A---- C:\Windows\SysWOW64\urlmon.dll
2011-02-23 16:40:37 ----A---- C:\Windows\SysWOW64\msxml6.dll
2011-02-23 16:40:37 ----A---- C:\Windows\SysWOW64\msxml3.dll
2011-02-23 16:40:36 ----A---- C:\Windows\SysWOW64\WebClnt.dll
2011-02-23 16:40:36 ----A---- C:\Windows\SysWOW64\ieframe.dll
2011-02-23 16:40:36 ----A---- C:\Windows\SysWOW64\davclnt.dll
2011-02-23 16:40:35 ----A---- C:\Windows\SysWOW64\wscapi.dll
2011-02-23 16:40:35 ----A---- C:\Windows\SysWOW64\winhttp.dll
2011-02-23 16:40:35 ----A---- C:\Windows\SysWOW64\slwga.dll
2011-02-23 16:40:26 ----A---- C:\Windows\SysWOW64\XpsPrint.dll
2011-02-23 16:40:26 ----A---- C:\Windows\SysWOW64\XpsGdiConverter.dll
2011-02-23 16:40:10 ----A---- C:\Windows\SysWOW64\vbscript.dll
2011-02-23 16:40:10 ----A---- C:\Windows\SysWOW64\jscript.dll
2011-02-23 16:40:04 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2011-02-23 16:40:04 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2011-02-23 16:40:04 ----A---- C:\Windows\SysWOW64\ntdll.dll
2011-02-23 16:40:03 ----A---- C:\Windows\SysWOW64\atmfd.dll
2011-02-23 16:40:02 ----A---- C:\Windows\SysWOW64\atmlib.dll
2011-02-23 15:16:50 ----D---- C:\Users\Salva\AppData\Roaming\Apple Computer
2011-02-23 15:16:34 ----A---- C:\Windows\SysWOW64\GEARAspi.dll
2011-02-23 15:16:21 ----D---- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-02-23 15:16:21 ----D---- C:\Program Files (x86)\iTunes
2011-02-23 15:14:42 ----D---- C:\ProgramData\Apple Computer
2011-02-23 15:14:42 ----D---- C:\Program Files (x86)\QuickTime
2011-02-23 15:14:30 ----D---- C:\Program Files (x86)\Apple Software Update
2011-02-23 15:13:56 ----D---- C:\Program Files (x86)\Bonjour
2011-02-23 15:13:49 ----D---- C:\ProgramData\Apple
2011-02-23 15:13:49 ----D---- C:\Program Files (x86)\Common Files\Apple
2011-02-22 15:57:26 ----D---- C:\temp
2011-02-21 14:20:08 ----A---- C:\Windows\SysWOW64\uxtuneup.dll
2011-02-21 14:20:06 ----A---- C:\Windows\SysWOW64\authuitu.dll
2011-02-21 14:19:35 ----D---- C:\Users\Salva\AppData\Roaming\TuneUp Software
2011-02-21 14:19:25 ----D---- C:\Program Files (x86)\TuneUp Utilities 2010
2011-02-21 14:18:42 ----D---- C:\ProgramData\TuneUp Software
2011-02-21 14:18:23 ----SHD---- C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2011-02-19 22:54:05 ----D---- C:\Users\Salva\AppData\Roaming\DVDVideoSoftIEHelpers
2011-02-19 22:53:54 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-02-19 22:53:54 ----D---- C:\Program Files (x86)\Common Files\DVDVideoSoft
2011-02-19 15:06:57 ----D---- C:\ProgramData\Canneverbe Limited
2011-02-19 15:06:56 ----D---- C:\Users\Salva\AppData\Roaming\Canneverbe Limited
2011-02-19 15:00:51 ----D---- C:\Users\Salva\AppData\Roaming\ImgBurn
2011-02-19 14:52:34 ----D---- C:\Program Files (x86)\ImgBurn
2011-02-15 21:21:36 ----D---- C:\Users\Salva\AppData\Roaming\Software4u
2011-02-15 21:21:17 ----D---- C:\Program Files (x86)\Software4u
2011-02-13 13:00:21 ----D---- C:\ProgramData\LightScribe
2011-02-09 12:34:11 ----HD---- C:\$AVG
2011-02-09 12:06:26 ----D---- C:\Users\Salva\AppData\Roaming\Macrovision
2011-02-08 15:29:44 ----D---- C:\ProgramData\Macrovision
2011-02-08 15:29:24 ----A---- C:\Windows\BADENIA.INI
2011-02-08 15:24:10 ----A---- C:\Windows\ODBC.INI
2011-02-08 15:23:51 ----D---- C:\ProgramData\Vofue
2011-02-08 15:23:43 ----D---- C:\Program Files (x86)\Common Files\cib
2011-02-08 15:23:39 ----D---- C:\Prog
2011-02-08 15:22:19 ----D---- C:\Program Files (x86)\Common Files\Adobe
2011-02-08 15:22:19 ----D---- C:\Program Files (x86)\Adobe
2011-02-08 15:21:30 ----D---- C:\ProgramData\Adobe
2011-02-06 20:17:23 ----D---- C:\ProgramData\Sun
2011-02-06 20:17:23 ----D---- C:\Program Files (x86)\Common Files\Java
2011-02-06 20:17:08 ----A---- C:\Windows\SysWOW64\javaws.exe
2011-02-06 20:17:08 ----A---- C:\Windows\SysWOW64\javaw.exe
2011-02-06 20:17:08 ----A---- C:\Windows\SysWOW64\java.exe
2011-02-06 20:17:08 ----A---- C:\Windows\SysWOW64\deployJava1.dll
2011-02-06 20:17:00 ----D---- C:\Program Files (x86)\Java
2011-02-06 04:15:45 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-02-06 00:57:36 ----D---- C:\Users\Salva\AppData\Roaming\IBKPRO
2011-02-06 00:57:27 ----D---- C:\Program Files (x86)\IncrediBackup
2011-02-06 00:51:57 ----D---- C:\ProgramData\IncrediMail
2011-02-06 00:51:57 ----D---- C:\ProgramData\IM
2011-02-06 00:51:56 ----D---- C:\Program Files (x86)\IncrediMail
2011-02-06 00:45:11 ----D---- C:\Users\Salva\AppData\Roaming\Nero
2011-02-05 21:04:37 ----D---- C:\CCcam.channelinfo_04.02.2011
2011-02-05 15:10:42 ----D---- C:\ProgramData\Nero
2011-02-05 15:10:05 ----D---- C:\Program Files (x86)\Common Files\Nero
2011-02-05 15:09:56 ----D---- C:\Program Files (x86)\Nero
2011-02-05 15:05:01 ----D---- C:\ProgramData\ICQ
2011-02-05 15:05:01 ----D---- C:\Program Files (x86)\ICQ6Toolbar
2011-02-05 15:04:52 ----D---- C:\Users\Salva\AppData\Roaming\ICQ
2011-02-05 15:04:48 ----D---- C:\Program Files (x86)\ICQ7.4
2011-02-05 14:55:38 ----D---- C:\Program Files (x86)\Common Files\LightScribe
2011-02-05 14:54:48 ----A---- C:\Windows\SysWOW64\D3DCompiler_42.dll
2011-02-05 14:54:27 ----A---- C:\Windows\SysWOW64\D3DX9_42.dll
2011-02-05 14:54:06 ----A---- C:\Windows\SysWOW64\D3DX9_40.dll
2011-02-05 14:53:49 ----A---- C:\Windows\SysWOW64\d3dx9_35.dll
2011-02-05 14:53:28 ----A---- C:\Windows\SysWOW64\d3dx9_34.dll
2011-02-05 14:53:06 ----A---- C:\Windows\SysWOW64\d3dx9_30.dll
2011-02-05 14:17:14 ----D---- C:\Windows\SysWOW64\drivers\avg
2011-02-05 00:37:43 ----D---- C:\ProgramData\avg9
2011-02-05 00:37:43 ----D---- C:\Program Files (x86)\AVG
2011-02-05 00:18:37 ----A---- C:\Windows\AutoKMS.ini
2011-02-05 00:04:09 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-02-05 00:03:26 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2011-02-05 00:03:02 ----D---- C:\Program Files (x86)\Microsoft Office
2011-02-05 00:03:00 ----D---- C:\ProgramData\Microsoft Help
2011-02-05 00:02:49 ----RHD---- C:\MSOCache
2011-02-04 22:43:38 ----D---- C:\Users\Salva\AppData\Roaming\Macromedia
2011-02-04 22:43:38 ----D---- C:\Users\Salva\AppData\Roaming\Adobe
2011-02-04 22:36:05 ----D---- C:\Windows\SysWOW64\Macromed
2011-02-04 22:30:04 ----D---- C:\Program Files (x86)\Windows Live
2011-02-04 22:29:55 ----D---- C:\Windows\PCHEALTH
2011-02-04 22:29:19 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-02-04 22:27:38 ----D---- C:\Program Files (x86)\Common Files\Windows Live
2011-02-04 22:25:52 ----D---- C:\Users\Salva\AppData\Roaming\skypePM
2011-02-04 22:22:53 ----D---- C:\Program Files (x86)\Common Files\Skype
2011-02-04 22:22:52 ----RD---- C:\Program Files (x86)\Skype
2011-02-04 22:22:52 ----D---- C:\Users\Salva\AppData\Roaming\Skype
2011-02-04 22:22:50 ----D---- C:\ProgramData\Skype
2011-02-04 22:15:25 ----D---- C:\Users\Salva\AppData\Roaming\Mozilla
2011-02-04 22:15:21 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-02-04 22:02:51 ----D---- C:\Program Files (x86)\ArcSoft
2011-02-04 22:02:51 ----A---- C:\Windows\PCDLIB32.DLL
2011-02-04 22:02:15 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2011-02-04 21:55:10 ----HD---- C:\ProgramData\CanonBJ
2011-02-04 21:53:37 ----D---- C:\Program Files (x86)\Canon
2011-02-04 21:52:40 ----D---- C:\Program Files (x86)\Common Files\SNP2UVC
2011-02-04 21:52:40 ----A---- C:\Windows\tsnp2uvc.exe
2011-02-04 21:52:40 ----A---- C:\Windows\SysWOW64\rsnp2uvc.dll
2011-02-04 21:52:40 ----A---- C:\Windows\amcap.exe
2011-02-04 21:52:27 ----D---- C:\Users\Salva\AppData\Roaming\InstallShield
2011-02-04 21:48:31 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-02-04 21:48:31 ----D---- C:\Program Files (x86)\Hama
2011-02-04 18:57:34 ----D---- C:\ProgramData\explauncher
2011-02-04 18:57:31 ----D---- C:\ProgramData\launcher
2011-02-04 18:55:29 ----D---- C:\Program Files (x86)\Paragon Software
2011-02-04 18:50:35 ----D---- C:\Users\Salva\AppData\Roaming\WinRAR
2011-02-04 18:47:40 ----D---- C:\Users\Salva\AppData\Roaming\Identities
2011-02-04 18:47:29 ----SD---- C:\Users\Salva\AppData\Roaming\Microsoft
2011-02-04 18:47:29 ----D---- C:\Users\Salva\AppData\Roaming\Media Center Programs
2011-02-04 18:47:19 ----SHD---- C:\Recovery
2011-02-04 18:47:19 ----SHD---- C:\Programme
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Vorlagen
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Startmenü
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Favoriten
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Dokumente
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Desktop
2011-02-04 18:47:19 ----SHD---- C:\ProgramData\Anwendungsdaten
2011-02-04 18:47:19 ----SHD---- C:\Dokumente und Einstellungen
2011-02-04 18:47:15 ----D---- C:\Windows\SoftwareDistribution
2011-02-04 18:40:57 ----SHD---- C:\System Volume Information
2011-02-04 18:40:53 ----D---- C:\Windows\CSC
2011-02-04 18:40:32 ----ASH---- C:\pagefile.sys
2011-02-04 18:40:32 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 months======
2011-02-24 14:35:45 ----D---- C:\Windows\Temp
2011-02-24 14:35:28 ----D---- C:\Windows\Prefetch
2011-02-24 14:32:58 ----RD---- C:\Program Files (x86)
2011-02-24 10:28:27 ----D---- C:\Windows\System32
2011-02-24 10:28:27 ----D---- C:\Windows\inf
2011-02-24 10:22:28 ----D---- C:\Windows\winsxs
2011-02-24 10:22:19 ----D---- C:\Windows\SysWOW64
2011-02-24 10:20:59 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-24 01:42:56 ----SHD---- C:\Windows\Installer
2011-02-23 15:16:21 ----RD---- C:\Program Files
2011-02-23 15:16:21 ----HD---- C:\ProgramData
2011-02-23 15:13:49 ----D---- C:\Program Files (x86)\Common Files
2011-02-23 15:10:13 ----D---- C:\Windows\Tasks
2011-02-22 11:01:05 ----D---- C:\Windows
2011-02-08 15:26:23 ----RSD---- C:\Windows\Fonts
2011-02-08 15:25:14 ----A---- C:\Windows\BSC.ini
2011-02-06 03:20:15 ----D---- C:\Windows\SysWOW64\drivers
2011-02-05 17:42:18 ----D---- C:\Windows\Logs
2011-02-05 16:56:35 ----D---- C:\Windows\Microsoft.NET
2011-02-05 16:56:09 ----RSD---- C:\Windows\assembly
2011-02-05 00:37:15 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2011-02-05 00:06:06 ----D---- C:\Windows\ShellNew
2011-02-05 00:05:28 ----D---- C:\Program Files (x86)\MSBuild
2011-02-05 00:05:17 ----SD---- C:\ProgramData\Microsoft
2011-02-05 00:05:17 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-02-05 00:03:44 ----A---- C:\Windows\win.ini
2011-02-04 22:43:38 ----D---- C:\Windows\Downloaded Program Files
2011-02-04 22:38:06 ----RSD---- C:\Windows\Media
2011-02-04 22:00:46 ----D---- C:\Windows\twain_32
2011-02-04 18:47:37 ----SHD---- C:\$Recycle.Bin
2011-02-04 18:47:26 ----RD---- C:\Users
2011-02-04 18:47:21 ----D---- C:\Windows\Panther
2011-02-04 18:44:29 ----D---- C:\Windows\rescache
2011-02-04 18:44:12 ----D---- C:\Windows\debug
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSErHrw7a;AVG9IDSErHr; C:\Windows\System32\Drivers\AVGIDSwa.sys []
R0 AvgRkx64;avgrkx64.sys; C:\Windows\System32\Drivers\avgrkx64.sys []
R0 hotcore3;hc3ServiceName; C:\Windows\system32\DRIVERS\hotcore3.sys []
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys []
R1 AvgLdx64;AVG AVI Loader Driver x64; C:\Windows\System32\Drivers\avgldx64.sys []
R1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64; C:\Windows\System32\Drivers\avgmfx64.sys []
R1 AvgTdiA;AVG Network Redirector x64; C:\Windows\System32\Drivers\avgtdia.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R3 AVGIDSDriverw7a;AVG9IDSDriver; \??\C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN764\AVGIDSDriver.sys [2011-02-05 132688]
R3 AVGIDSFilterw7a;AVG9IDSFilter; \??\C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN764\AVGIDSFilter.sys [2011-02-05 35920]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys []
R3 netr28x;Ralink 802.11n-Drahtlostreiber für Windows Vista; C:\Windows\system32\DRIVERS\netr28x.sys []
R3 NVENETFD;NVIDIA nForce-Netzwerkcontrollertreiber; C:\Windows\system32\DRIVERS\nvm62x64.sys []
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [2010-02-24 11856]
R3 usbscan;USB-Scannertreiber; C:\Windows\system32\DRIVERS\usbscan.sys []
S3 E1G60;Intel(R) PRO/1000 NDIS 6-Adaptertreiber; C:\Windows\system32\DRIVERS\E1G6032E.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys []
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys []
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys []
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-01-05 37664]
R2 avg9wd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe [2011-02-05 308136]
R2 avgfws9;AVG Firewall; C:\Program Files (x86)\AVG\AVG9\avgfws9.exe [2011-02-05 2331544]
R2 AVGIDSAgent;AVG9IDSAgent; C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-02-05 5897808]
R2 Bonjour Service;Dienst "Bonjour"; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [2011-01-12 1403200]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 iPod Service;iPod-Dienst; C:\Program Files\iPod\bin\iPodService.exe [2011-01-25 933664]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TuneUp.Defrag;@C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [2011-02-21 607040]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
Weiß jemand was damit anzufangen, wäre euch sehr dankbar um jede Hilfe.
Zuletzt bearbeitet von einem Moderator: