|
Plagegeister aller Art und deren Bekämpfung: GVU-Trojaner entfernen für AnfängerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
05.09.2012, 08:34 | #1 |
| GVU-Trojaner entfernen für Anfänger Hallo liebes Forum, ich habe seit gestern auch diesen GVU-Trojaner bei mir auf XP drauf. Mein Internet muss ich ausgeschaltet lassen, weil ansonsten wieder diese Seite erscheint. Hier im Forum und im Internet gibt es viele Lösungsansätze, aber ich blicke bei den meisten nicht durch. Bin halt doch ein recht einfacher Nutzer. Da gibt es Lösungsansätze mit Otl oder Kaspersky. Ich habe mir jetzt dieses OTL auf einem USB-Stick gespeichert (am PC auf Arbeit). Wie fahre ich heute abend mit meinem Problem-Laptop fort? Brauche ich noch weitere Sachen auf dem USB-Stick? Wenn ihr mir helfen könntet, wäre das echt klasse. Bin schon etwas verzweifelt. |
05.09.2012, 14:08 | #2 |
/// Malware-holic | GVU-Trojaner entfernen für Anfänger hi starte neu, drücke f8 wähle abgesicherter modus mit netzwerk, melde dich im betroffenen konto an.
__________________Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s C:\Windows\system32\*.tsp /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %USERPROFILE%\*.* %USERPROFILE%\Local Settings\Temp\*.exe %USERPROFILE%\Local Settings\Temp\*.dll %USERPROFILE%\Application Data\*.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs CREATERESTOREPOINT
__________________ |
05.09.2012, 20:40 | #3 |
| GVU-Trojaner entfernen für Anfänger Hallo,
__________________vielen Dank für deine Hilfe. Hier die Texte. Mein Laptop ist ein spanischer, ich hoffe, du verstehst es trotzdem. OTL.TxtOTL Logfile: Code:
ATTFilter OTL logfile created on: 05.09.2012 20:57:14 - Run 1 OTL by OldTimer - Version 3.2.61.0 Folder = C:\Documents and Settings\Herbert\Escritorio Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000407 | Country: Alemania | Language: DEU | Date Format: dd.MM.yyyy 1014,05 Mb Total Physical Memory | 440,73 Mb Available Physical Memory | 43,46% Memory free 2,38 Gb Paging File | 1,59 Gb Available in Paging File | 66,76% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa Drive C: | 35,06 Gb Total Space | 2,10 Gb Free Space | 5,98% Space Free | Partition Type: FAT32 Drive D: | 35,55 Gb Total Space | 7,79 Gb Free Space | 21,91% Space Free | Partition Type: FAT32 Computer Name: CHRISTIANE | User Name: Herbert | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012.09.05 09:06:14 | 000,599,040 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Herbert\Escritorio\OTL.exe PRC - [2012.08.29 17:49:56 | 001,193,176 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Spotify\Data\SpotifyWebHelper.exe PRC - [2012.07.18 18:04:44 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Archivos de programa\Avira\AntiVir Desktop\avshadow.exe PRC - [2012.07.18 18:04:34 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Archivos de programa\Avira\AntiVir Desktop\sched.exe PRC - [2012.07.18 18:04:24 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Archivos de programa\Avira\AntiVir Desktop\avgnt.exe PRC - [2012.07.18 18:04:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Archivos de programa\Avira\AntiVir Desktop\avguard.exe PRC - [2012.06.21 15:58:50 | 002,445,880 | ---- | M] (Check Point Software Technologies LTD) -- C:\Archivos de programa\CheckPoint\ZoneAlarm\vsmon.exe PRC - [2012.06.21 15:29:14 | 000,073,392 | ---- | M] (Check Point Software Technologies LTD) -- C:\Archivos de programa\CheckPoint\ZoneAlarm\zatray.exe PRC - [2012.04.30 21:05:22 | 000,497,280 | ---- | M] (Check Point Software Technologies) -- C:\Archivos de programa\CheckPoint\ZAForceField\ISWSVC.exe PRC - [2012.04.30 21:04:28 | 000,738,944 | ---- | M] (Check Point Software Technologies) -- C:\Archivos de programa\CheckPoint\ZAForceField\ForceField.exe PRC - [2011.07.29 00:08:12 | 001,259,376 | ---- | M] () -- C:\Archivos de programa\DivX\DivX Update\DivXUpdate.exe PRC - [2011.04.18 19:09:40 | 000,789,392 | ---- | M] (Lavasoft) -- C:\Archivos de programa\Lavasoft\Ad-Aware\AAWTray.exe PRC - [2011.04.18 19:09:38 | 001,181,328 | ---- | M] (Lavasoft) -- C:\Archivos de programa\Lavasoft\Ad-Aware\AAWService.exe PRC - [2009.11.13 06:33:56 | 000,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Archivos de programa\DNA\btdna.exe PRC - [2009.03.08 04:31:54 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msfeedssync.exe PRC - [2008.12.31 17:04:54 | 000,944,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\WGATray.exe PRC - [2008.07.11 17:51:32 | 000,423,200 | ---- | M] (Sony Corporation) -- C:\Archivos de programa\Sony\Content Transfer\ContentTransferWMDetector.exe PRC - [2008.04.13 21:18:58 | 001,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007.05.17 23:45:34 | 000,271,720 | ---- | M] (Microsoft Corporation) -- C:\Archivos de programa\Microsoft LifeCam\MSCamS32.exe PRC - [2007.04.10 23:46:52 | 000,709,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\vVX1000.exe PRC - [2005.12.01 17:38:38 | 000,458,752 | ---- | M] (Dritek System Inc.) -- C:\Archivos de programa\Launch Manager\QtZgAcer.EXE PRC - [2005.11.25 15:59:44 | 000,212,992 | ---- | M] (Acer Inc) -- C:\Acer\Empowering Technology\ePower\epm-dm.exe PRC - [2005.11.16 17:00:50 | 000,397,312 | ---- | M] (acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\Monitor.exe PRC - [2005.10.24 16:45:32 | 002,462,208 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admtray.exe PRC - [2005.10.24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) -- C:\Acer\Empowering Technology\admServ.exe PRC - [2005.10.19 09:30:16 | 000,069,632 | ---- | M] (HiTRUST) -- C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe PRC - [2005.08.31 19:59:48 | 000,114,784 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe PRC - [2005.08.31 19:59:46 | 000,249,954 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe PRC - [2005.08.31 19:59:34 | 000,147,456 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Acer\Acer Arcade\PCMService.exe PRC - [2005.08.31 19:59:22 | 001,077,376 | ---- | M] (Cyberlink) -- C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe PRC - [2005.08.31 19:59:22 | 000,061,440 | ---- | M] (Cyberlink) -- C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe PRC - [2005.01.07 16:17:16 | 000,102,491 | ---- | M] (Synaptics, Inc.) -- C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe ========== Modules (No Company Name) ========== MOD - [2012.08.29 17:49:56 | 001,193,176 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Spotify\Data\SpotifyWebHelper.exe MOD - [2012.07.18 18:04:36 | 000,398,288 | ---- | M] () -- C:\Archivos de programa\Avira\AntiVir Desktop\sqlite3.dll MOD - [2011.07.29 00:09:42 | 000,096,112 | ---- | M] () -- C:\Archivos de programa\DivX\DivX Update\DivXUpdateCheck.dll MOD - [2011.07.29 00:08:12 | 001,259,376 | ---- | M] () -- C:\Archivos de programa\DivX\DivX Update\DivXUpdate.exe MOD - [2011.04.18 19:09:44 | 000,327,000 | ---- | M] () -- C:\Archivos de programa\Lavasoft\Ad-Aware\RPAPI.dll MOD - [2008.04.13 21:18:26 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2005.11.09 22:22:14 | 000,876,544 | ---- | M] () -- C:\Archivos de programa\Intel\Wireless\Bin\Libeay32.dll MOD - [2005.11.09 22:22:14 | 000,208,965 | ---- | M] () -- C:\Archivos de programa\Intel\Wireless\Bin\iWMSProv.dll MOD - [2005.11.09 22:22:14 | 000,053,322 | ---- | M] () -- C:\Archivos de programa\Intel\Wireless\Bin\IntStngs.dll MOD - [2005.09.05 16:31:56 | 000,229,472 | ---- | M] () -- C:\Acer\Empowering Technology\NetMonitor.dll MOD - [2005.08.31 19:59:48 | 000,114,784 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe MOD - [2005.08.31 19:59:46 | 000,249,954 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe MOD - [2005.08.31 19:59:42 | 000,184,424 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapEngine.dll MOD - [2005.08.31 19:59:42 | 000,061,538 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSchMgr.dll MOD - [2005.08.31 19:59:42 | 000,028,672 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvcps.dll MOD - [2005.08.31 19:59:42 | 000,024,576 | ---- | M] () -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSchedps.dll MOD - [2005.08.24 01:24:00 | 000,010,752 | ---- | M] () -- C:\WINDOWS\system32\MSNChatHook.dll MOD - [2005.07.06 13:50:14 | 000,057,344 | ---- | M] () -- C:\Archivos de programa\Launch Manager\HokHIDKC.dll MOD - [2005.06.28 13:59:48 | 000,053,248 | ---- | M] () -- C:\Archivos de programa\ArcSoft\PhotoImpression 5\Share\PIHook.dll MOD - [2003.12.29 20:45:08 | 000,040,960 | ---- | M] () -- C:\Acer\Empowering Technology\ServiceControl.dll MOD - [2001.10.28 17:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll ========== Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- C:\Archivos de programa\Google\Update\GoogleUpdate.exe /medsvc -- (gupdatem) SRV - File not found [Auto | Stopped] -- C:\Archivos de programa\Google\Update\GoogleUpdate.exe /svc -- (gupdate1c9f1eed03b8c66) SRV - File not found [On_Demand | Stopped] -- C:\Archivos de programa\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2012.08.03 17:34:06 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Archivos de programa\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.07.18 18:04:34 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Archivos de programa\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2012.07.18 18:04:24 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Archivos de programa\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2012.06.21 15:58:50 | 002,445,880 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Archivos de programa\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon) SRV - [2012.06.07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Archivos de programa\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012.04.30 21:05:22 | 000,497,280 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Archivos de programa\CheckPoint\ZAForceField\ISWSVC.exe -- (IswSvc) SRV - [2011.07.20 05:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv) SRV - [2011.04.18 19:09:38 | 001,181,328 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Archivos de programa\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service) SRV - [2007.05.17 23:45:34 | 000,271,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Archivos de programa\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc) SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE -- (ose) SRV - [2005.10.24 16:40:52 | 001,314,816 | ---- | M] (Avocent Inc.) [Auto | Running] -- C:\Acer\Empowering Technology\admServ.exe -- (AWService) SRV - [2005.08.31 19:59:48 | 000,114,784 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe -- (CLSched) SRV - [2005.08.31 19:59:46 | 000,249,954 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe -- (CLCapSvc) SRV - [2005.08.31 19:59:22 | 000,061,440 | ---- | M] (Cyberlink) [Auto | Running] -- C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe -- (CyberLink Media Library Service) SRV - [2005.08.03 05:18:50 | 000,086,016 | ---- | M] (CACE Technologies) [On_Demand | Unknown] -- C:\Archivos de programa\WinPCap\rpcapd.exe -- (rpcapd) SRV - [2005.04.04 00:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\ZTEWMSD_637.sys -- (ZTEWMSD_637) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbser6k.sys -- (ZTEusbser6k) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnmeaext.sys -- (ZTEusbnmeaext) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnmea.sys -- (ZTEusbnmea) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnet.sys -- (ZTEusbnet) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnmeaext2.sys -- (ZTEusbMB) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | Auto | Stopped] -- SYSTEM32\drivers\DS1410D.SYS -- (DS1410D) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ar5211.sys -- (AR5211) DRV - [2012.07.18 18:04:44 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2012.07.18 18:04:44 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2012.07.18 18:04:44 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr) DRV - [2012.06.21 15:29:14 | 000,526,640 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (Vsdatant) DRV - [2012.04.30 21:05:40 | 000,027,016 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Archivos de programa\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL) DRV - [2011.05.25 01:40:10 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss) DRV - [2010.06.17 15:14:28 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.09.23 13:55:24 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\Lbd.sys -- (Lbd) DRV - [2007.04.10 23:46:54 | 001,966,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VX1000.sys -- (VX1000) DRV - [2006.08.16 14:43:22 | 000,553,984 | ---- | M] (Marvell Semiconductor, Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETMW145.sys -- (NETMW145) DRV - [2005.12.11 07:40:44 | 001,414,656 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2005.11.17 00:45:40 | 004,069,888 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) DRV - [2005.11.09 14:45:56 | 000,013,440 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans) DRV - [2005.10.23 19:20:52 | 000,218,496 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL) DRV - [2005.10.18 01:53:24 | 000,998,656 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV) DRV - [2005.10.18 01:52:30 | 000,721,280 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf) DRV - [2005.10.15 18:20:44 | 000,012,106 | ---- | M] (OSA Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\OsaFsLoc.sys -- (OsaFsLoc) DRV - [2005.09.29 20:11:42 | 000,078,720 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp) DRV - [2005.09.13 15:34:40 | 000,004,392 | ---- | M] (OSA Technologies) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NdisFilt.sys -- (NdisFilt) DRV - [2005.09.11 19:49:44 | 003,298,432 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) DRV - [2005.08.03 05:10:14 | 000,032,512 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF) DRV - [2005.06.30 16:58:24 | 000,007,296 | ---- | M] (OSA Technologies, An Avocent Company) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osaio.sys -- (osaio) DRV - [2005.05.02 12:13:42 | 000,009,600 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETMNT.sys -- (NETMNT) DRV - [2005.04.07 18:08:46 | 000,078,208 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-shd.sys -- (EpmShd) DRV - [2005.02.23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc) DRV - [2005.01.14 15:57:16 | 000,004,010 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osanbm.sys -- (osanbm) DRV - [2005.01.13 14:46:16 | 000,069,632 | ---- | M] () [Kernel | Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15.sys) DRV - [2004.07.19 13:10:00 | 000,004,096 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-psd.sys -- (EpmPsd) DRV - [2002.10.01 14:43:32 | 000,119,798 | ---- | M] (SP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\spca561.sys -- (CA561) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKCU\..\URLSearchHook: - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {E58DC330-EA6D-453F-A1B3-F5C1AE1B8E42} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2765711 IE - HKCU\..\SearchScopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}: "URL" = hxxp://search.hotspotshield.com/g/results.php?c=s&q={searchTerms} IE - HKCU\..\SearchScopes\{E58DC330-EA6D-453F-A1B3-F5C1AE1B8E42}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&rlz= IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Hotspot Shield Private Search" FF - prefs.js..browser.search.defaultthis.engineName: "AF-HSS Customized Web Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2765711&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "about:home" FF - prefs.js..extensions.enabledAddons: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledAddons: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.145 FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.60 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.8.6 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900 FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900 FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2438727&q=" FF - prefs.js..network.proxy.type: 0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll () FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Archivos de programa\DNA\plugins\npbtdna.dll (BitTorrent, Inc.) FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Archivos de programa\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Archivos de programa\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Archivos de programa\DivX\DivX Content Uploader\npUpload.dll File not found FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: D:\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Archivos de programa\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Archivos de programa\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Archivos de programa\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Archivos de programa\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Herbert\Datos de programa\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Archivos de programa\Google\Update\1.3.21.79\npGoogleUpdate3.dll File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Archivos de programa\Google\Update\1.3.21.79\npGoogleUpdate3.dll File not found FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Herbert\Datos de programa\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Archivos de programa\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.04.11 19:49:42 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Archivos de programa\CheckPoint\ZAForceField\TrustChecker [2011.11.17 20:24:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Archivos de programa\Mozilla Firefox\components [2007.06.17 22:45:28 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Archivos de programa\Mozilla Firefox\plugins [2006.09.11 23:49:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Archivos de programa\Mozilla Thunderbird\components [2009.06.28 21:39:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Archivos de programa\Mozilla Thunderbird\plugins [2012.01.28 15:31:08 | 000,000,000 | ---D | M] [2008.12.05 07:55:56 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Extensions [2010.05.30 21:04:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2009.08.24 19:03:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a} [2009.06.18 18:21:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Extensions\mozswing@mozswing.org [2006.09.11 23:49:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\extensions [2011.05.25 01:41:04 | 000,000,915 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\conduit.xml [2012.01.16 18:14:02 | 000,002,135 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\s-amazon-de.xml [2012.04.25 17:48:22 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\icqplugin-2.xml [2012.06.30 10:25:08 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\icqplugin-3.xml [2012.08.01 20:34:58 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\icqplugin-1.xml [2012.09.04 17:59:58 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Herbert\Datos de programa\Mozilla\Firefox\Profiles\jgexpwnp.default\searchplugins\icqplugin.xml [2007.06.17 22:45:28 | 000,000,000 | ---D | M] (No name found) -- C:\Archivos de programa\Mozilla Firefox\extensions [2012.04.11 19:49:42 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\ARCHIVOS DE PROGRAMA\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5 [2008.11.30 15:53:14 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\ARCHIVOS DE PROGRAMA\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009.08.21 07:16:22 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2012.08.03 17:34:06 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Archivos de programa\mozilla firefox\components\browsercomps.dll [2010.01.13 23:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npwachk.dll [2011.04.14 05:08:00 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npdeployJava1.dll [2012.07.01 18:06:02 | 000,001,105 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\yahoo-de.xml [2012.07.01 18:06:02 | 000,001,178 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\wikipedia-de.xml [2012.07.01 18:06:02 | 000,006,805 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\leo_ende_de.xml [2012.07.01 18:06:08 | 000,001,153 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\eBay-de.xml [2012.07.01 18:06:08 | 000,002,252 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\bing.xml [2012.07.01 18:06:08 | 000,001,392 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\amazondotcom-de.xml ========== Chrome ========== CHR - homepage: hxxp://www.google.com/ CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR - homepage: hxxp://www.google.com/ CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Herbert\Configuraci\u00F3n local\Datos de programa\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Herbert\Configuraci\u00F3n local\Datos de programa\Google\Chrome\Application\21.0.1180.83\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Herbert\Configuraci\u00F3n local\Datos de programa\Google\Chrome\Application\21.0.1180.83\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Archivos de programa\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: Java(TM) Platform SE 6 U25 (Enabled) = C:\Archivos de programa\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Java Deployment Toolkit 6.0.250.6 (Enabled) = C:\Archivos de programa\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\NPOFF12.DLL CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Archivos de programa\Microsoft\Office Live\npOLW.dll CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: getPlusPlus for Adobe 16263 (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\np_gp.dll CHR - plugin: Winamp Application Detector (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\npwachk.dll CHR - plugin: king.com - Game controller for firefox (Enabled) = C:\Archivos de programa\Mozilla Firefox\plugins\npmidas.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Archivos de programa\Windows Media Player\npwmsdrm.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Archivos de programa\Windows Media Player\npdrmv2.dll CHR - plugin: npFFApi (Enabled) = C:\Archivos de programa\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll CHR - plugin: DNA Plug-in (Enabled) = C:\Archivos de programa\DNA\plugins\npbtdna.dll CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Archivos de programa\DivX\DivX OVS Helper\npovshelper.dll CHR - plugin: DivX Plus Web Player (Enabled) = C:\Archivos de programa\DivX\DivX Plus Web Player\npdivx32.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Archivos de programa\Microsoft Silverlight\4.1.10111.0\npctrl.dll CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Herbert\Configuraci\u00F3n local\Datos de programa\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: Move Media Player 7 (Enabled) = C:\Documents and Settings\Herbert\Datos de programa\Move Networks\plugins\071803000001\npqmp071803000001.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - Extension: YouTube = C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Google-Suche = C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\ CHR - Extension: Google Mail = C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2004.08.20 05:00:00 | 000,000,792 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Archivos de programa\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Archivos de programa\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\system32\ToolBand.dll (HiTRUST) O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Archivos de programa\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\system32\ToolBand.dll (HiTRUST) O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Archivos de programa\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O4 - HKLM..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe (Acer Value Labs, Taiwan) O4 - HKLM..\Run: [ADMTray.exe] C:\Acer\Empowering Technology\admtray.exe (Avocent Inc.) O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [avgnt] C:\Archivos de programa\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation) O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Archivos de programa\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation) O4 - HKLM..\Run: [DivXUpdate] C:\Archivos de programa\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe (HiTRUST) O4 - HKLM..\Run: [EPM-DM] c:\Acer\Empowering Technology\ePower\epm-dm.exe (Acer Inc) O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe (acer Inc.) O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation) O4 - HKLM..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe File not found O4 - HKLM..\Run: [ISW] C:\Archivos de programa\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies) O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.) O4 - HKLM..\Run: [LifeCam] C:\Archivos de programa\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation) O4 - HKLM..\Run: [LManager] C:\Archivos de programa\Launch Manager\QtZgAcer.EXE (Dritek System Inc.) O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe () O4 - HKLM..\Run: [PCMService] C:\Program Files\Acer\Acer Arcade\PCMService.exe (CyberLink Corp.) O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre6\bin\jusched.exe" File not found O4 - HKLM..\Run: [SynTPLpr] C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.) O4 - HKLM..\Run: [VX1000] C:\WINDOWS\vVX1000.exe (Microsoft Corporation) O4 - HKLM..\Run: [ZoneAlarm] C:\Archivos de programa\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD) O4 - HKCU..\Run: [BitTorrent DNA] C:\Archivos de programa\DNA\btdna.exe (BitTorrent, Inc.) O4 - HKCU..\Run: [Spotify] C:\Documents and Settings\Herbert\Datos de programa\Spotify\Spotify.exe (Spotify Ltd) O4 - HKCU..\Run: [Spotify Web Helper] C:\Documents and Settings\Herbert\Datos de programa\Spotify\Data\SpotifyWebHelper.exe () O4 - HKCU..\Run: [updateMgr] c:\Archivos de programa\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0 File not found O4 - HKCU..\RunOnce: [AutoLaunch] C:\Archivos de programa\Lavasoft\Ad-Aware\AutoLaunch.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Sample Toolband Serach - C:\WINDOWS\System32\ToolBand.dll (HiTRUST) O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Herbert\Datos de programa\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Herbert\Datos de programa\DVDVideoSoftIEHelpers\youtubetomp3.htm () O9 - Extra Button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Archivos de programa\ICQLite\ICQLite.exe File not found O9 - Extra 'Tools' menuitem : ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Archivos de programa\ICQLite\ICQLite.exe File not found O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} hxxp://gateway.serrasold.com/iNotes6W.cab (iNotes6 Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class) O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Archivos de programa\Archivos comunes\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Mi página de inicio actual) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Herbert\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.01.06 08:47:42 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ] O33 - MountPoints2\{54347046-0fe5-11de-87fd-001346d78640}\Shell\AutoRun\command - "" = wd_windows_tools\WDEULA.exe O33 - MountPoints2\{6c595e46-c244-11dd-87d7-001346d78640}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\setup.exe -- [2008.04.13 21:19:10 | 000,023,040 | ---- | M] (Microsoft Corporation) O33 - MountPoints2\{6cd33349-1144-11e0-8afb-0016365fac8b}\Shell - "" = AutoRun O33 - MountPoints2\{6cd33349-1144-11e0-8afb-0016365fac8b}\Shell\AutoRun\command - "" = F:\.\Setup.exe AUTORUN=1 O33 - MountPoints2\{ed7479ca-ee05-11e1-8b8c-00166f97ec3f}\Shell - "" = AutoRun O33 - MountPoints2\{ed7479ca-ee05-11e1-8b8c-00166f97ec3f}\Shell\AutoRun\command - "" = F:\Setup.exe O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (lsdelete) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ActiveX: {0213C6AF-5562-4D09-884C-2ADCFC8C2F35} - Microsoft .NET Framework 1.1 Security Update (KB2656353) ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Generación de gráficos vectoriales (VML) ActiveX: {1325db73-d9f1-48f8-8895-6d814ec58889} - Actualización de seguridad para Windows XP (KB913433) ActiveX: {1897C549-AE52-4571-8996-44854F5612B2} - Microsoft .NET Framework 1.1 Security Update (KB2656370) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Enlace dinámico de datos HTML para Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Autoría avanzada ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {462B3532-523C-57D5-40F5-A8F147B63A10} - DirectAnimation ActiveX: {4887E482-F5BB-1D5F-D599-51D8A35F4731} - Reproductor de Windows Media de Microsoft 6.4 ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - Clases Java DirectAnimation ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {83169D43-4660-4347-BC95-E9D6E6BE65CE} - .NET Framework ActiveX: {88059054-77A5-FACB-9170-03EB7073B455} - Themes Setup ActiveX: {8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Programador de tareas ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {FFF9EA0F-7EBC-B535-5224-5FDB5DC1C3B8} - NetShow ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE NetSvcs: 6to4 - File not found NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2012.09.05 20:51:07 | 000,599,040 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Herbert\Escritorio\OTL.exe [2012.09.05 18:41:24 | 000,000,000 | -HSD | C] -- C:\FOUND.000 [2012.08.24 18:09:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menú Inicio\Programas\Motorola [2012.08.24 18:09:13 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Archivos comunes\Motorola Shared [2012.08.24 18:08:33 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Switcher [2012.08.10 20:11:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Herbert\Datos de programa\Avira [2012.08.10 20:04:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Mozilla [2012.08.10 20:04:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Datos de programa\Mozilla [2012.08.10 20:00:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menú Inicio\Programas\Avira [2012.08.10 19:59:45 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avkmgr.sys [2012.08.10 19:59:44 | 000,137,928 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys [2012.08.10 19:59:44 | 000,083,392 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys [2012.08.10 19:59:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Datos de programa\Avira [2012.08.10 19:59:36 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Avira [2006.09.16 09:07:17 | 005,809,216 | ---- | C] (Hypnotizer) -- C:\Documents and Settings\All Users\hyplay.exe [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.09.05 20:57:32 | 000,000,492 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{EECED12D-F178-4617-8E24-8F18657FD4CD}.job [2012.09.05 20:56:34 | 000,002,262 | ---- | M] () -- C:\Documents and Settings\Herbert\Escritorio\Google Chrome.lnk [2012.09.05 20:49:44 | 000,000,514 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2012.09.05 20:49:32 | 000,000,514 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job [2012.09.05 20:49:28 | 000,000,514 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job [2012.09.05 20:49:20 | 000,000,514 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job [2012.09.05 20:49:14 | 000,000,514 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job [2012.09.05 20:41:52 | 000,000,451 | ---- | M] () -- C:\WINDOWS\System32\eRLog.ini [2012.09.05 20:41:00 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012.09.05 20:39:32 | 000,001,098 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012.09.05 20:39:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012.09.05 20:39:20 | 1063,374,848 | -HS- | M] () -- C:\hiberfil.sys [2012.09.05 18:33:38 | 000,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat [2012.09.05 09:06:14 | 000,599,040 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Herbert\Escritorio\OTL.exe [2012.09.04 21:37:02 | 000,001,102 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012.09.04 18:43:38 | 004,503,728 | ---- | M] () -- C:\Documents and Settings\All Users\Datos de programa\0tbpw.pad [2012.09.02 22:34:14 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Datos de programa\PKP_DLec.DAT [2012.09.02 22:34:14 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Datos de programa\PKP_DLds.DAT [2012.08.24 17:38:00 | 000,115,712 | ---- | M] () -- C:\Documents and Settings\Herbert\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.08.21 18:44:24 | 000,002,309 | ---- | M] () -- C:\Documents and Settings\All Users\Escritorio\Skype.lnk [2012.08.16 21:45:16 | 000,349,792 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012.08.15 22:38:50 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012.08.10 20:01:00 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Escritorio\Avira Control Center.lnk [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.09.05 20:49:33 | 000,000,514 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2012.09.05 20:49:29 | 000,000,514 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job [2012.09.04 18:26:57 | 004,503,728 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\0tbpw.pad [2012.08.10 20:00:59 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Escritorio\Avira Control Center.lnk [2012.08.08 19:53:51 | 000,000,514 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job [2012.08.08 19:53:48 | 000,000,514 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job [2011.12.24 18:28:15 | 000,000,033 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\droidcam-settings [2011.12.09 23:16:58 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat [2011.12.09 23:16:58 | 000,000,039 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat [2009.06.17 22:23:21 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Datos de programa\PKP_DLec.DAT [2009.06.16 22:00:34 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Datos de programa\Analog Mono [2009.06.16 22:00:34 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Herbert\Datos de programa\Action Clauses [2009.06.16 22:00:34 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Datos de programa\PKP_DLds.DAT [2007.06.30 20:36:24 | 000,001,751 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\QTSBandwidthCache [2006.09.12 11:58:55 | 000,000,305 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\addr_file.html [2006.09.12 06:12:40 | 000,115,712 | ---- | C] () -- C:\Documents and Settings\Herbert\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2006.09.08 22:09:32 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Herbert\Configuración local\Datos de programa\fusioncache.dat ========== LOP Check ========== [2006.09.08 22:17:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Acer [2006.09.18 21:36:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Autodesk [2007.07.03 21:07:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\WinZip [2008.08.14 12:23:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\ICQ [2008.11.04 15:40:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\ConeXware [2009.01.06 12:42:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\MipKukSoft [2009.06.12 23:12:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\MailFrontier [2009.06.16 22:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\EnterNHelp [2009.06.16 22:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Ultima_T15 [2009.06.16 22:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Digital Light [2009.06.16 22:01:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Nikon [2009.08.01 10:24:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Sony [2009.11.01 13:06:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Datos de programa\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} [2011.11.17 20:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\CheckPoint [2006.09.08 22:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Acer [2006.09.18 21:36:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Autodesk [2006.10.09 21:34:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\EPSON [2006.12.07 18:31:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\CDZilla [2007.01.10 12:22:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\ICQLite [2007.09.03 12:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Nikon [2008.08.14 12:22:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\ICQ [2008.10.21 15:29:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2008.11.04 16:01:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\AnotherUnzipper [2009.01.06 12:43:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\MipKukSoft [2009.01.06 12:43:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Kybtec Software [2009.04.13 15:31:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\DNA [2009.09.26 23:56:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Amazon [2009.06.28 21:40:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Thunderbird [2009.08.01 10:24:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Sony [2009.09.09 20:46:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\MSNInstaller [2010.01.22 22:54:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\LucasArts [2010.02.26 21:33:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\ProtectDisc [2010.05.26 15:10:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Softland [2010.11.01 20:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\DVDVideoSoftIEHelpers [2011.11.17 20:28:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\CheckPoint [2011.12.18 19:00:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\DVDVideoSoft [2012.04.11 20:25:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\DDMSettings [2012.05.26 11:31:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Spotify [2012.07.27 15:37:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Herbert\Datos de programa\Ad-Aware Antivirus [2012.09.05 20:49:14 | 000,000,514 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job [2012.09.05 20:49:20 | 000,000,514 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job [2012.09.05 20:49:28 | 000,000,514 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job [2012.09.05 20:57:32 | 000,000,492 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{EECED12D-F178-4617-8E24-8F18657FD4CD}.job [2012.09.05 20:49:32 | 000,000,514 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job [2012.09.05 20:49:44 | 000,000,514 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2005.12.14 05:39:18 | 000,000,000 | ---D | M] -- C:\i386 [2004.08.20 05:00:00 | 000,000,000 | ---D | M] -- C:\VALUEADD [2004.08.20 05:00:00 | 000,000,000 | ---D | M] -- C:\dotnetfx [2009.10.01 08:24:12 | 000,000,000 | ---D | M] -- C:\tmp [2012.09.05 18:41:24 | 000,000,000 | -HSD | M] -- C:\FOUND.000 [2005.12.14 05:39:24 | 000,000,000 | ---D | M] -- C:\Sysinfo [2005.12.14 05:39:20 | 000,000,000 | ---D | M] -- C:\WINDOWS [2006.01.06 08:15:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings [2006.01.06 08:20:26 | 000,000,000 | ---D | M] -- C:\Archivos de programa [2006.01.06 08:41:56 | 000,000,000 | ---D | M] -- C:\Program Files [2006.09.08 22:08:20 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2009.06.03 09:00:46 | 000,000,000 | ---D | M] -- C:\OrbSecure [2009.08.10 18:29:42 | 000,000,000 | -H-D | M] -- C:\BJPrinter [2012.07.28 10:17:00 | 000,000,000 | -HSD | M] -- C:\FOUND.010 [2006.09.08 22:11:04 | 000,000,000 | ---D | M] -- C:\Acer [2011.06.17 12:27:32 | 000,000,000 | ---D | M] -- C:\Hotspot Shield [2006.09.12 05:09:20 | 000,000,000 | -HSD | M] -- C:\Recycled [2006.09.28 21:14:18 | 000,000,000 | ---D | M] -- C:\Programm_Downloads [2007.01.22 10:44:30 | 000,000,000 | ---D | M] -- C:\Temp [2008.10.19 11:17:22 | 000,000,000 | RH-D | M] -- C:\MSOCache < %PROGRAMFILES%\*.exe > Invalid Environment Variable: LOCALAPPDATA < %systemroot%\*. /mp /s > < C:\Windows\system32\*.tsp > [2008.04.13 21:19:20 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ipconf.tsp [2008.04.13 21:19:20 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp [2008.04.13 21:19:20 | 000,266,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\h323.tsp [2008.04.13 21:19:20 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp [2008.04.13 21:19:20 | 000,207,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp [2008.04.13 21:19:20 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp [2008.04.13 21:19:20 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp [5 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] < MD5 for: AGP440.SYS > [2004.08.20 05:00:00 | 018,785,875 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys [2008.10.19 10:35:10 | 023,895,938 | ---- | M] () .cab file -- C:\i386\sp3.cab:AGP440.sys [2004.08.20 05:00:00 | 018,785,875 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys [2008.10.19 10:35:10 | 023,895,938 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys [2008.04.13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys [2008.04.13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys [2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys < MD5 for: ATAPI.SYS > [2004.08.20 05:00:00 | 018,785,875 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys [2008.10.19 10:35:10 | 023,895,938 | ---- | M] () .cab file -- C:\i386\sp3.cab:atapi.sys [2004.08.20 05:00:00 | 018,785,875 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys [2008.10.19 10:35:10 | 023,895,938 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys [2008.04.13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys [2008.04.13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys [2004.08.20 05:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys [2004.08.20 05:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0012\DriverFiles\i386\atapi.sys < MD5 for: EVENTLOG.DLL > [2008.04.13 21:18:22 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2744C713F0217BD8FFD13E2EF731371C -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll [2008.04.13 21:18:22 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2744C713F0217BD8FFD13E2EF731371C -- C:\WINDOWS\system32\eventlog.dll [2004.08.20 05:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=5696DF4EF09C375CE42FB2DDE1E68AB7 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll < MD5 for: EXPLORER.EXE > [2008.04.13 21:18:58 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=7522F548A84ABAD8FA516DE5AB3931EF -- C:\WINDOWS\explorer.exe [2008.04.13 21:18:58 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=7522F548A84ABAD8FA516DE5AB3931EF -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe [2004.08.20 05:00:00 | 001,034,752 | ---- | M] (Microsoft Corporation) MD5=89C8DD146CEAF482D82822766437D93F -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe [2007.06.13 08:10:54 | 001,035,776 | ---- | M] (Microsoft Corporation) MD5=DBB6B75CC6CB2CF8EC0BAFCA08AED6BE -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe [2007.06.13 08:22:28 | 001,035,776 | ---- | M] (Microsoft Corporation) MD5=F8DDB22B6EFC5E630D65E241074C2404 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe [2008.04.29 17:42:08 | 000,090,624 | ---- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 -- C:\Archivos de programa\CheckPoint\ZAForceField\Heuristics\explorer.exe < MD5 for: NETLOGON.DLL > [2004.08.20 05:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=7FD182B1B80117C353983565D60B1CAF -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll [2008.04.13 21:18:28 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=CD2BBB52DFAAB666B812A51B1E96F2A0 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll [2008.04.13 21:18:28 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=CD2BBB52DFAAB666B812A51B1E96F2A0 -- C:\WINDOWS\system32\netlogon.dll < MD5 for: SCECLI.DLL > [2008.04.13 21:18:36 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=B6BE3C96CD33336A551DB3F2299A8E69 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll [2008.04.13 21:18:36 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=B6BE3C96CD33336A551DB3F2299A8E69 -- C:\WINDOWS\system32\scecli.dll [2004.08.20 05:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=C6347748F2E9F310EA1E1915482ABFEF -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll < MD5 for: USER32.DLL > [2007.03.08 10:50:26 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=237FB93C6B4330D8EE7D2448CF71C5ED -- C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll [2005.03.02 13:20:22 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=37CE819E8ECB3517B9981A886876EF72 -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll [2004.08.20 05:00:00 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=5D5C9CC377A70D036816E7EA55F3CA73 -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll [2008.04.13 21:18:46 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=DA8898129E0075C7DE4DEE457514A73C -- C:\WINDOWS\ServicePackFiles\i386\user32.dll [2008.04.13 21:18:46 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=DA8898129E0075C7DE4DEE457514A73C -- C:\WINDOWS\system32\user32.dll [2005.03.02 13:10:34 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=DDA46F3DBCF32727E93976B09FBB0E83 -- C:\WINDOWS\$NtUninstallKB925902$\user32.dll [2007.03.08 10:36:30 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=FED9881C07A301271F52B51389A028C9 -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll < MD5 for: USERINIT.EXE > [2004.08.20 05:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=7B30B4D55B4562C733A5DDF6D6F72B3F -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe [2008.04.13 21:19:14 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=F5B8745B9A90EAF17E30C0574E049AA3 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe [2008.04.13 21:19:14 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=F5B8745B9A90EAF17E30C0574E049AA3 -- C:\WINDOWS\system32\userinit.exe < MD5 for: WINLOGON.EXE > [2008.04.13 21:19:16 | 000,510,976 | ---- | M] (Microsoft Corporation) MD5=213C80D912880BBF04453D09FFCCB28C -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe [2008.04.13 21:19:16 | 000,510,976 | ---- | M] (Microsoft Corporation) MD5=213C80D912880BBF04453D09FFCCB28C -- C:\WINDOWS\system32\winlogon.exe [2008.07.01 15:17:12 | 000,090,624 | ---- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 -- C:\Archivos de programa\CheckPoint\ZAForceField\Heuristics\winlogon.exe [2004.08.20 05:00:00 | 000,505,344 | ---- | M] (Microsoft Corporation) MD5=FCB59D25D628B4D3181DC816D14679DD -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe < MD5 for: WS2IFSL.SYS > [2004.08.20 05:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys [2004.08.20 05:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > [2006.01.06 08:15:18 | 000,466,944 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav [2006.01.06 08:15:18 | 000,643,072 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav [2006.01.06 08:15:20 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav < %systemroot%\system32\*.dll /lockedfiles > [5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] < %USERPROFILE%\*.* > [2012.09.05 21:12:52 | 000,001,024 | -H-- | M] () -- C:\Documents and Settings\Herbert\ntuser.dat.LOG [2012.08.29 17:42:28 | 000,000,304 | -HS- | M] () -- C:\Documents and Settings\Herbert\ntuser.ini [2012.09.02 23:50:24 | 008,077,312 | ---- | M] () -- C:\Documents and Settings\Herbert\NTUSER.DAT < %USERPROFILE%\Local Settings\Temp\*.exe > < %USERPROFILE%\Local Settings\Temp\*.dll > < %USERPROFILE%\Application Data\*.exe > < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Kmode: %SystemRoot%\system32\win32k.sys [2012.07.03 20:22:14 | 001,866,240 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 < End of report > Extras.TxtOTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 05.09.2012 20:57:14 - Run 1 OTL by OldTimer - Version 3.2.61.0 Folder = C:\Documents and Settings\Herbert\Escritorio Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000407 | Country: Alemania | Language: DEU | Date Format: dd.MM.yyyy 1014,05 Mb Total Physical Memory | 440,73 Mb Available Physical Memory | 43,46% Memory free 2,38 Gb Paging File | 1,59 Gb Available in Paging File | 66,76% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa Drive C: | 35,06 Gb Total Space | 2,10 Gb Free Space | 5,98% Space Free | Partition Type: FAT32 Drive D: | 35,55 Gb Total Space | 7,79 Gb Free Space | 21,91% Space Free | Partition Type: FAT32 Computer Name: CHRISTIANE | User Name: Herbert | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = FirefoxHTML] -- C:\Archivos de programa\Mozilla Firefox\firefox.exe (Mozilla Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Archivos de programa\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* http [open] -- "C:\Archivos de programa\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Archivos de programa\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] "DisableMonitoring" = 1 ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\Acer\Acer Arcade\PCMService.exe" = C:\Program Files\Acer\Acer Arcade\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program -- (CyberLink Corp.) "C:\Archivos de programa\Microsoft Games\Age of Empires II\EMPIRES2.ICD" = C:\Archivos de programa\Microsoft Games\Age of Empires II\EMPIRES2.ICD:*:Enabled:Age of Empires II "C:\Archivos de programa\ICQLite\ICQLite.exe" = C:\Archivos de programa\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite "C:\Documents and Settings\Herbert\Escritorio\Mazatlan 2006\LimeWire\LimeWire.exe" = C:\Documents and Settings\Herbert\Escritorio\Mazatlan 2006\LimeWire\LimeWire.exe:*:Enabled:LimeWire "C:\Archivos de programa\PFTP\PFtp.exe" = C:\Archivos de programa\PFTP\PFtp.exe:*:Enabled:The Personal FTP Server "C:\Archivos de programa\Winamp Remote\bin\Orb.exe" = C:\Archivos de programa\Winamp Remote\bin\Orb.exe:*:Enabled:Orb "C:\Archivos de programa\Winamp Remote\bin\OrbTray.exe" = C:\Archivos de programa\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray "C:\Archivos de programa\Winamp Remote\bin\OrbStreamerClient.exe" = C:\Archivos de programa\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client "C:\Archivos de programa\ICQ6\ICQ.exe" = C:\Archivos de programa\ICQ6\ICQ.exe:*:Enabled:ICQ6 "C:\Archivos de programa\DNA\btdna.exe" = C:\Archivos de programa\DNA\btdna.exe:*:Enabled:DNA -- (BitTorrent, Inc.) "C:\Archivos de programa\BitTorrent\bittorrent.exe" = C:\Archivos de programa\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent "C:\Archivos de programa\Microsoft LifeCam\LifeCam.exe" = C:\Archivos de programa\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe -- (Microsoft Corporation) "C:\Archivos de programa\Microsoft LifeCam\LifeExp.exe" = C:\Archivos de programa\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe -- (Microsoft Corporation) "C:\Archivos de programa\LimeWire\LimeWire.exe" = C:\Archivos de programa\LimeWire\LimeWire.exe:*:Enabled:LimeWire "C:\Archivos de programa\Skype\Plugin Manager\skypePM.exe" = C:\Archivos de programa\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager "C:\Archivos de programa\Steam\Steam.exe" = C:\Archivos de programa\Steam\Steam.exe:*:Enabled:Steam "C:\Archivos de programa\Spotify\spotify.exe" = C:\Archivos de programa\Spotify\spotify.exe:*:Enabled:Spotify "C:\WINDOWS\System32\ZoneLabs\vsmon.exe" = C:\WINDOWS\System32\ZoneLabs\vsmon.exe:*:Enabled:vsmon "C:\Documents and Settings\Herbert\Datos de programa\Spotify\spotify.exe" = C:\Documents and Settings\Herbert\Datos de programa\Spotify\spotify.exe:*:Enabled:Spotify -- (Spotify Ltd) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime "{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker "{15B70821-7893-4607-805A-BB80F3EA8279}" = Acer Empowering Technology framework "{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe "{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade "{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java(TM) 6 Update 25 "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6 "{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2 "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{350C9C0A-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{385979FE-DC4F-4140-8EAD-A59625000D72}" = NTI Backup NOW! 4 "{3DC172E8-CA66-4E10-A1D3-8282F4CBFCEA}" = Microsoft LifeCam "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{4B33371A-C04F-48D3-980C-285369ECD634}" = ZoneAlarm Firewall "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{556027C9-C365-476A-9DF2-19DFD0F2F767}" = PowerArchiver 2007 German "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3 "{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management "{5EFDFC8B-D438-4792-A298-E87AA9ADA816}" = Acer eDataSecurity Management "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}" = Acer eLock Management "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7B63B2922B174135AFC0E1377DD81EC2}" = "{83169D43-4660-4347-BC95-E9D6E6BE65CE}" = Microsoft .NET Framework 1.1 Spanish Language Pack "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38}" = Microsoft .NET Framework 2.0 Language Pack - DEU "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver for Mobile "{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update "{90120000-0010-0C0A-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Spanish) 12 "{90120000-0015-0C0A-0000-0000000FF1CE}" = Microsoft Office Access MUI (Spanish) 2007 "{90120000-0015-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0C0A-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Spanish) 2007 "{90120000-0016-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0C0A-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Spanish) 2007 "{90120000-0018-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0C0A-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Spanish) 2007 "{90120000-0019-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Spanish) 2007 "{90120000-001A-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0C0A-0000-0000000FF1CE}" = Microsoft Office Word MUI (Spanish) 2007 "{90120000-001B-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0403-0000-0000000FF1CE}" = Microsoft Office Proof (Catalan) 2007 "{90120000-001F-0403-0000-0000000FF1CE}_ENTERPRISE_{BEADB115-DB47-4BD0-A9EC-AE585AFAB2D8}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007 "{90120000-001F-0416-0000-0000000FF1CE}_ENTERPRISE_{8A524694-0CA4-476A-9301-B1E9D70FC952}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-042D-0000-0000000FF1CE}" = Microsoft Office Proof (Basque) 2007 "{90120000-001F-042D-0000-0000000FF1CE}_ENTERPRISE_{017A6981-5E03-4A97-830A-35FE0927BB7F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0456-0000-0000000FF1CE}" = Microsoft Office Proof (Galician) 2007 "{90120000-001F-0456-0000-0000000FF1CE}_ENTERPRISE_{A3A03B41-14EA-4E50-97D8-FCF429AE0CCB}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002C-0C0A-0000-0000000FF1CE}" = Microsoft Office Proofing (Spanish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0C0A-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Spanish) 2007 "{90120000-0044-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0C0A-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Spanish) 2007 "{90120000-006E-0C0A-0000-0000000FF1CE}_ENTERPRISE_{430AE3E6-E982-4958-90FC-1C062BC74E22}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0C0A-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Spanish) 2007 "{90120000-00A1-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0C0A-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Spanish) 2007 "{90120000-00BA-0C0A-0000-0000000FF1CE}_ENTERPRISE_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3) "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{95120000-0122-0407-0000-0000000FF1CE}" = Microsoft Office Outlook Connector "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{A2172ACA-FFA8-4808-BD20-08565C7390F9}" = OGA Notifier 1.7.0105.35.0 "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A5F68DC8-0278-4AD8-B413-861509B5F25B}" = ArcSoft Panorama Maker 3 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1 "{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer "{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C35CCBEB-5A54-4DD8-9EC8-110F2A8154B3}" = Motorola Mobile Drivers Installation 5.1.0 "{C4C255FE-BE15-4C06-AAD9-A08F2DBB2E39}" = ZoneAlarm Security "{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail "{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer "{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call "{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center "{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}" = ArcSoft PhotoImpression 5 "{D458BBDC-0363-42E0-8FF9-4736E3CB3CA2}" = Acer Screensaver "{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware "{DEE08946-40F0-4890-853E-60A6C3306041}" = Acer ePerformance Management "{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager "{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}" = Acer eSettings Management "{E431C518-2EE2-471E-9234-BE995C36D513}" = Acer eDataSecurity Management 1.00.23 "{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F48C6EA5-3B43-11D6-86A6-0050BA0259A2}" = ICatch (VI) PC Camera "{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe "{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject "Ad-Aware" = Ad-Aware "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9 "Avira AntiVir Desktop" = Avira Free Antivirus "CNXT_MODEM_HDAUDIO_AcrS009E" = HDAUDIO Soft Data Fax Modem with SmartCP "DivX Setup" = DivX-Setup "doPDF 7 printer_is1" = doPDF 7.1 printer "ENTERPRISE" = Microsoft Office Enterprise 2007 "ePresentation" = Acer ePresentation Management "GridVista" = Acer GridVista "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "Ink Monitor" = Ink Monitor "InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker "InstallShield_{15B70821-7893-4607-805A-BB80F3EA8279}" = Acer Empowering Technology framework "InstallShield_{385979FE-DC4F-4140-8EAD-A59625000D72}" = NTI Backup NOW! 4 "InstallShield_{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}" = Acer eLock Management "InstallShield_{DEE08946-40F0-4890-853E-60A6C3306041}" = Acer ePerformance Management "InstallShield_{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}" = Acer eSettings Management "IrfanView" = IrfanView (remove only) "LManager" = Launch Manager "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 2.0 Language Pack - DEU" = Microsoft .NET Framework 2.0 Language Pack - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox 14.0.1 (x86 de)" = Mozilla Firefox 14.0.1 (x86 de) "Mozilla Thunderbird (8.0)" = Mozilla Thunderbird (8.0) "MozillaMaintenanceService" = Mozilla Maintenance Service "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "Nikon FotoShare" = Nikon FotoShare "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "ProInst" = Software Intel(R) PROSet/Wireless "Revo Uninstaller" = Revo Uninstaller 1.93 "Silent Package Run-Time Sample" = Manual de la CX7700 "SynTPDeinstKey" = Synaptics Pointing Device Driver "Uninstall_is1" = Uninstall 1.0.0.1 "Winamp" = Winamp "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Reproductor de Windows Media 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinLiveSuite_Wave3" = Windows Live Essentials "WinZip" = WinZip "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "ZoneAlarm Free Firewall" = ZoneAlarm Free Firewall "ZoneAlarm LTD Toolbar" = ZoneAlarm LTD Toolbar ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "BitTorrent DNA" = DNA "Google Chrome" = Google Chrome "Move Media Player" = Move Media Player "Spotify" = Spotify "Winamp Detect" = Winamp Erkennungs-Plug-in ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 04.09.2012 13:09:04 | Computer Name = CHRISTIANE | Source = Application Error | ID = 1000 Description = Aplicación con errores: skype.exe, versión: 5.10.0.116, módulo con error: skype.exe, versión 5.10.0.116, dirección de error 0x00f240bc. Error - 04.09.2012 13:27:28 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001 Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas de diferencia para crear instantáneas. Agregue al menos una unidad NTFS al sistema con suficiente espacio en disco. Se necesitan por lo menos 100 Mb en cada volumen para poder hacer la copia de seguridad o instantánea. Error - 04.09.2012 13:37:57 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001 Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas de diferencia para crear instantáneas. Agregue al menos una unidad NTFS al sistema con suficiente espacio en disco. Se necesitan por lo menos 100 Mb en cada volumen para poder hacer la copia de seguridad o instantánea. Error - 04.09.2012 13:47:44 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001 Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas de diferencia para crear instantáneas. Agregue al menos una unidad NTFS al sistema con suficiente espacio en disco. Se necesitan por lo menos 100 Mb en cada volumen para poder hacer la copia de seguridad o instantánea. Error - 04.09.2012 13:47:47 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001 Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas de diferencia para crear instantáneas. Agregue al menos una unidad NTFS al sistema con suficiente espacio en disco. Se necesitan por lo menos 100 Mb en cada volumen para poder hacer la copia de seguridad o instantánea. Error - 04.09.2012 14:00:33 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001 Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas de diferencia para crear instantáneas. Agregue al menos una unidad NTFS al sistema con suficiente espacio en disco. Se necesitan por lo menos 100 Mb en cada volumen para poder hacer la copia de seguridad o instantánea. Error - 04.09.2012 14:06:38 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001 Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas de diferencia para crear instantáneas. Agregue al menos una unidad NTFS al sistema con suficiente espacio en disco. Se necesitan por lo menos 100 Mb en cada volumen para poder hacer la copia de seguridad o instantánea. Error - 04.09.2012 14:17:46 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001 Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas de diferencia para crear instantáneas. Agregue al menos una unidad NTFS al sistema con suficiente espacio en disco. Se necesitan por lo menos 100 Mb en cada volumen para poder hacer la copia de seguridad o instantánea. Error - 04.09.2012 14:21:30 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001 Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas de diferencia para crear instantáneas. Agregue al menos una unidad NTFS al sistema con suficiente espacio en disco. Se necesitan por lo menos 100 Mb en cada volumen para poder hacer la copia de seguridad o instantánea. Error - 04.09.2012 14:33:19 | Computer Name = CHRISTIANE | Source = VSS | ID = 4001 Description = Error del Servicio de instantáneas de volumen: no se encuentran áreas de diferencia para crear instantáneas. Agregue al menos una unidad NTFS al sistema con suficiente espacio en disco. Se necesitan por lo menos 100 Mb en cada volumen para poder hacer la copia de seguridad o instantánea. [ OSession Events ] Error - 08.02.2010 16:54:10 | Computer Name = CHRISTIANE | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 8 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 04.09.2012 13:05:54 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000 Description = El servicio DS1410D no pudo iniciarse debido al siguiente error: %%2 Error - 04.09.2012 13:05:54 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000 Description = El servicio Servicio Google Update (gupdate1c9f1eed03b8c66) no pudo iniciarse debido al siguiente error: %%2 Error - 04.09.2012 13:18:50 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000 Description = El servicio DS1410D no pudo iniciarse debido al siguiente error: %%2 Error - 04.09.2012 13:18:50 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000 Description = El servicio Servicio Google Update (gupdate1c9f1eed03b8c66) no pudo iniciarse debido al siguiente error: %%2 Error - 05.09.2012 12:23:00 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000 Description = El servicio DS1410D no pudo iniciarse debido al siguiente error: %%2 Error - 05.09.2012 12:23:00 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000 Description = El servicio Servicio Google Update (gupdate1c9f1eed03b8c66) no pudo iniciarse debido al siguiente error: %%2 Error - 05.09.2012 12:42:35 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000 Description = El servicio DS1410D no pudo iniciarse debido al siguiente error: %%2 Error - 05.09.2012 12:42:35 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000 Description = El servicio Servicio Google Update (gupdate1c9f1eed03b8c66) no pudo iniciarse debido al siguiente error: %%2 Error - 05.09.2012 14:39:40 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000 Description = El servicio DS1410D no pudo iniciarse debido al siguiente error: %%2 Error - 05.09.2012 14:39:40 | Computer Name = CHRISTIANE | Source = Service Control Manager | ID = 7000 Description = El servicio Servicio Google Update (gupdate1c9f1eed03b8c66) no pudo iniciarse debido al siguiente error: %%2 < End of report > |
06.09.2012, 13:34 | #4 |
/// Malware-holic | GVU-Trojaner entfernen für Anfänger hatte ich nicht was vom abgesicherten modus mit netzwerk gesagt? noch mal genau lesen was oben steht
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
07.09.2012, 06:58 | #5 |
| GVU-Trojaner entfernen für Anfänger Oh sorry, hatte es ein paar mal versucht, auch gerade eben und es erscheint nur eine schwarzer Bildschirm und dann nichts mehr. Hab mittlerweile auch eine systemwiederherstellung gemacht, jetzt funktioniert zwar alles wieder, aber ich bin mir nicht sicher, ob der Trojaner noch da ist. |
07.09.2012, 09:57 | #6 |
/// Malware-holic | GVU-Trojaner entfernen für Anfänger wieso tust du nicht einfach das, was da steht und machst nicht irgendwelchen anderen unsinn, da kann ich mir die arbeit auch gleich ganz sparen... also entweder du arbeitest allein weiter, dann sag bescheid, oder poste otl logs und lasse sonst den pc in ruhe und unternimm nichts mehr selbst.
__________________ --> GVU-Trojaner entfernen für Anfänger |
07.09.2012, 10:43 | #7 |
| GVU-Trojaner entfernen für Anfänger Ich komme in den gesicherten Modus nicht rein. Der Bildschirm bleibt schwarz und es passiert nichts. |
07.09.2012, 11:26 | #8 |
/// Malware-holic | GVU-Trojaner entfernen für Anfänger hi jetzt kannst du es ja im normalen tun, nach der swh sollte das ja funktionieren
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
07.09.2012, 16:59 | #9 |
| GVU-Trojaner entfernen für Anfänger Also die Texte oben habe ich nach der Wiederherstellung erstellt. Ich hatte sonst keine Möglichkeit ins Internet zu kommen. Und ich wusste auch nicht so recht, wie ich sonst die Texte hier reinkopieren könnte. |
07.09.2012, 17:15 | #10 |
/// Malware-holic | GVU-Trojaner entfernen für Anfänger malwarebytes: Downloade Dir bitte Malwarebytes
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
08.09.2012, 11:47 | #11 |
| GVU-Trojaner entfernen für Anfänger Habe es durchgeführt, hier die Infos: Malwarebytes Anti-Malware (Test) 1.62.0.1300 Malwarebytes : Free Anti-Malware download Datenbank Version: v2012.09.08.02 Windows XP Service Pack 3 x86 FAT32 Internet Explorer 8.0.6001.18702 Herbert :: CHRISTIANE [Administrator] Schutz: Aktiviert 08.09.2012 10:57:52 mbam-log-2012-09-08 (10-57-52).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 305125 Laufzeit: 1 Stunde(n), 47 Minute(n), 23 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 2 HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Documents and Settings\Herbert\Configuración local\Temp\wpbt0.dll (Trojan.FakeMS) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Documents and Settings\Herbert\Configuración local\Archivos temporales de Internet\Content.IE5\JQYC93PH\about[1].exe (Trojan.FakeMS) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) |
08.09.2012, 11:50 | #12 |
/// Malware-holic | GVU-Trojaner entfernen für Anfänger lade den CCleaner standard: CCleaner Download - CCleaner 3.22.1800 falls der CCleaner bereits instaliert, überspringen. instalieren, öffnen, extras, liste der instalierten programme, als txt speichern. öffnen. hinter, jedes von dir benötigte programm, schreibe notwendig. hinter, jedes, von dir nicht benötigte, unnötig. hinter, dir unbekannte, unbekannt. liste posten.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
09.09.2012, 10:17 | #13 |
| GVU-Trojaner entfernen für Anfänger Acer Arcade 01.01.1601 notwendig Acer eDataSecurity Management 1.00.23 Acer 08.09.2006 1.00.23 notwendig Acer eLock Management Acer Inc. 08.09.2006 1.7.9.21 notwendig Acer Empowering Technology framework Acer Inc. 08.09.2006 2.1.21.41 notwendig Acer eNet Management 01.01.1601 1.01.3.003 notwendig Acer ePerformance Management Acer Inc. 08.09.2006 1.0.10.21 notwendig Acer ePower Management 01.01.1601 1.6.8.281 notwendig Acer ePresentation Management 01.01.1601 1.1.4.819 notwendig Acer eSettings Management Acer Inc. 08.09.2006 1.2.20.35 notwendig Acer GridVista 01.01.1601 2.29.0728 notwendig Acer Screensaver acer 08.09.2006 3,03MB 1.0.0 notwendig Ad-Aware Lavasoft 01.11.2009 notwendig Adobe AIR Adobe Systems Inc. 21.10.2008 1.1.0.5790 notwendig Adobe Download Manager NOS Microsystems Ltd. 01.01.1601 1.6.2.63 Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 01.01.1601 10.0.45.2 notwendig Adobe Flash Player 11 Plugin Adobe Systems Incorporated 01.01.1601 11.4.402.265 notwendig Adobe Reader 9.1 Adobe Systems Incorporated 12.03.2009 143,00MB 9.1.0 notwendig Amazon MP3-Downloader 1.0.9 01.01.1601 notwendig ArcSoft Panorama Maker 3 ArcSoft 01.01.1601 notwendig ArcSoft PhotoImpression 5 ArcSoft 01.01.1601 notwendig Avira Free Antivirus Avira 01.01.1601 12.0.0.1167 notwendig CCleaner Piriform 22.08.2012 3.22 notwendig Content Transfer Sony Corporation 01.08.2009 12,40MB 1.0.0.07110 notwendig DivX-Setup DivX, LLC 01.01.1601 2.6.1.5 unnötig DNA BitTorrent Inc. 01.01.1601 2.2.4 (16502) unbekannt doPDF 7.1 printer Softland 26.05.2010 notwendig notwendig Google Chrome Google Inc. 20.04.2012 21.0.1180.89 notwendig HDAUDIO Soft Data Fax Modem with SmartCP 01.01.1601 notwendig High Definition Audio Driver Package - KB888111 Microsoft Corporation 01.01.1601 20040219.000000 notwendig ICatch (VI) PC Camera 01.01.1601 unnötig Ink Monitor notwendig Intel(R) Graphics Media Accelerator Driver for Mobile 01.01.1601 6.14.10.4363 notwendig IrfanView (remove only) 01.01.1601 unnötig J2SE Runtime Environment 5.0 Update 6 Sun Microsystems, Inc. 18.09.2006 145,00MB 1.5.0.60 notwendig Java(TM) 6 Update 2 Sun Microsystems, Inc. 26.08.2007 133,00MB 1.6.0.20 notwendig Java(TM) 6 Update 25 Sun Microsystems, Inc. 30.11.2008 94,47MB 6.0.250 notwendig Java(TM) 6 Update 3 Sun Microsystems, Inc. 24.11.2007 133,00MB 1.6.0.30 notwendig Java(TM) 6 Update 5 Sun Microsystems, Inc. 19.04.2008 136,00MB 1.6.0.50 notwendig Java(TM) 6 Update 7 Sun Microsystems, Inc. 17.08.2008 136,00MB 1.6.0.70 notwendig Launch Manager 01.01.1601 notwendig Malwarebytes Anti-Malware Version 1.62.0.1300 Malwarebytes Corporation 08.09.2012 1.62.0.1300 notwendig Manual de la CX7700 unnötig Microsoft .NET Framework 1.1 15.06.2012 notwendig Microsoft .NET Framework 1.1 Spanish Language Pack Microsoft 06.01.2006 3,09MB 1.1.4322 notwendig Microsoft .NET Framework 2.0 Language Pack - DEU Microsoft Corporation 01.08.2009 notwendig Microsoft .NET Framework 2.0 Service Pack 2 Microsoft Corporation 15.06.2012 191,00MB 2.2.30729 notwendig Microsoft .NET Framework 3.0 Service Pack 2 Microsoft Corporation 13.06.2012 241,00MB 3.2.30729 notwendig Microsoft .NET Framework 3.5 SP1 Microsoft Corporation 13.06.2012 notwendig Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Corporation 27.02.2008 1 notwendig Microsoft LifeCam Microsoft 16.06.2009 75,10MB 1.40.164.0 notwendig Microsoft Office Enterprise 2007 Microsoft Corporation 15.08.2012 12.0.6612.1000 notwendig Microsoft Office Live Add-in 1.3 Microsoft Corporation 15.06.2009 0,58MB 2.0.2313.0 notwendig Microsoft Office Outlook Connector Microsoft Corporation 14.01.2010 7,99MB 12.0.6423.1000 notwendig Microsoft Silverlight Microsoft Corporation 13.06.2012 185,00MB 4.1.10329.0 notwendig Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Corporation 27.02.2008 notwendig Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 01.08.2009 0,17MB 8.0.50727.4053 notwendig Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 18.06.2011 5,94MB 8.0.61001 notwendig Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Corporation 30.07.2009 0,22MB 9.0.30729.4148 notwendig Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Corporation 09.05.2011 10,87MB 9.0.30729.5570 notwendig Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 25.05.2011 10,30MB 9.0.30729 notwendig Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 25.06.2009 10,95MB 9.0.30729 notwendig Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 25.04.2011 10,86MB 9.0.30729.4148 notwendig Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 18.06.2011 10,87MB 9.0.30729.6161 notwendig Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 27.10.2011 15,17MB 10.0.40219 notwendig Motorola Mobile Drivers Installation 5.1.0 Motorola Inc. 24.08.2012 4,28MB 5.1.0 notwendig Move Media Player Move Networks 01.01.1601 notwendig Mozilla Firefox 14.0.1 (x86 de) Mozilla 01.01.1601 14.0.1 notwendig Mozilla Maintenance Service Mozilla 01.01.1601 14.0.1 notwendig Mozilla Thunderbird (8.0) Mozilla 01.01.1601 8.0 (de) notwendig MSXML 4.0 SP2 (KB927978) Microsoft Corporation 22.11.2006 2,77MB 4.20.9841.0 notwendig MSXML 4.0 SP2 (KB936181) Microsoft Corporation 14.08.2007 2,77MB 4.20.9848.0 notwendig MSXML 4.0 SP2 (KB954430) Microsoft Corporation 13.11.2008 2,90MB 4.20.9870.0 notwendig MSXML 4.0 SP2 (KB973688) Microsoft Corporation 26.11.2009 3,02MB 4.20.9876.0 notwendig MSXML 4.0 SP2 Parser and SDK Microsoft Corporation 16.06.2009 0,03MB 4.20.9818.0 notwendig Nikon FotoShare 01.01.1601 1.0.1.0 notwendig Nikon Message Center 01.01.1601 0.90.000 notwendig NTI Backup NOW! 4 NewTech Infosystems 06.01.2006 4 notwendig NTI CD & DVD-Maker NewTech Infosystems 06.01.2006 7 notwendig PDFCreator Frank Heindörfer, Philip Chinery 28.09.2006 0.9.3 notwendig PictureProject Nikon 01.01.1601 1.0 notwendig PowerArchiver 2007 German ConeXware, Inc. 04.11.2008 17,25MB 10.22.02 notwendig PowerProducer 01.01.1601 notwendig Realtek High Definition Audio Driver Realtek Semiconductor Corp. 06.01.2006 2.02 notwendig Reproductor de Windows Media 11 01.01.1601 notwendig Revo Uninstaller 1.93 VS Revo Group 01.01.1601 1.93 notwendig Skype™ 5.10 Skype Technologies S.A. 01.08.2012 103,00MB 5.10.116 notwendig Software Intel(R) PROSet/Wireless Intel Corporation 01.01.1601 notwendig Spotify Spotify AB 29.08.2012 0.8.4.124.ga3559d86 notwendig Synaptics Pointing Device Driver 01.01.1601 7.12.13.0 notwendig Uninstall 1.0.0.1 01.11.2010 notwendig Winamp Nullsoft, Inc 01.01.1601 5.572 notwendig Winamp Erkennungs-Plug-in Nullsoft, Inc 06.03.2010 1.0.0.1 notwendig Windows Internet Explorer 8 Microsoft Corporation 12.06.2009 20090308.140743 notwendig Windows Live Anmelde-Assistent Microsoft Corporation 15.06.2009 1,97MB 5.000.818.5 notwendig Windows Live Essentials Microsoft Corporation 22.04.2011 14.0.8117.0416 notwendig Windows Live-Uploadtool Microsoft Corporation 15.06.2009 0,19MB 14.0.8014.1029 notwendig Windows Media Format 11 runtime 01.01.1601 notwendig Windows Media Player Firefox Plugin Microsoft Corp 08.10.2009 0,28MB 1.0.0.8 notwendig Windows XP Service Pack 3 Microsoft Corporation 19.10.2008 20080414.031514 notwendig WinZip WinZip Computing, Inc. 01.01.1601 9.0 (6028) notwendig ZoneAlarm Free Firewall Check Point 01.01.1601 10.2.057.000 notwendig |
10.09.2012, 14:12 | #14 |
/// Malware-holic | GVU-Trojaner entfernen für Anfänger deinstaliere: Adobe Flash Player alle Adobe - Adobe Flash Player installieren neueste version laden adobe reader: Adobe - Adobe Reader herunterladen - Alle Versionen haken bei mcafee security scan raus nehmen bitte auch mal den adobe reader wie folgt konfigurieren: adobe reader öffnen, bearbeiten, voreinstellungen. allgemein: nur zertifizierte zusatz module verwenden, anhaken. internet: hier sollte alles deaktiviert werden, es ist sehr unsicher pdfs automatisch zu öffnen, zu downloaden etc. es ist immer besser diese direkt abzuspeichern da man nur so die kontrolle hat was auf dem pc vor geht. bei javascript den haken bei java script verwenden raus nehmen bei updater, automatisch instalieren wählen. übernehmen /ok deinstaliere: DivX DNA ICatch IrfanView J2SE Java: alle Download der kostenlosen Java-Software downloade java jre instalieren deinstaliere: Manual ZoneAlarm : darauf kann man beruhigt verzichten, router firewalls sind ausreichend. öffne otl, bereinigen, pc startet neu öffne CCleaner analysieren, bereinigen, pc neustarten testen wie er läuft
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
11.09.2012, 21:05 | #15 |
| GVU-Trojaner entfernen für Anfänger So, habe alles gemacht und es scheint alles normal zu laufen. Ist der Trojaner damit nun weg? |
Themen zu GVU-Trojaner entfernen für Anfänger |
abend, anfänger, arbeit, ausgeschaltet, einfacher, entfernen, erschein, forum, gespeichert, gestern, gvu trojaner entfernen windows xp, gvu-trojaner, gvu-trojaner entfernen, gvu-trojaner entfernen für anfänger, heulen, heute, interne, internet, könntet, sache, sachen, seite, usb-stick, verzweifel |