Hallo, Avira meldet die o.a. Datei. Auch nach "entfernen" erscheint die Meldung wieder.
Als Anlage habe ich schon einmal das Ergebnis eines scans mit FIRST angefügt
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-07-2013
Ran by rolli (administrator) on 07-07-2013 19:48:14
Running from C:\Dokumente und Einstellungen\rolli\Eigene Dateien\Downloads
Microsoft Windows XP Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Could not list processes ===============
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [StartCCC] "C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2012-04-05] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [IntelliPoint] "C:\Programme\Microsoft IntelliPoint\ipoint.exe" [1821576 2000-01-01] (Microsoft Corporation)
HKLM\...\Run: [RTHDCPL] RTHDCPL.EXE [x]
HKLM\...\Run: [Adobe ARM] "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [LWS] C:\Programme\Logitech\LWS\Webcam Software\LWS.exe -hide [204136 2012-09-13] (Logitech Inc.)
HKLM\...\Run: [vProt] "C:\Programme\AVG Secure Search\vprot.exe" [x]
HKLM\...\Run: [Tweak UI 1.33 deutsch] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp [x]
HKLM\...\Run: [DivXUpdate] "C:\Programme\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1263952 2013-02-13] ()
HKLM\...\Run: [SunJavaUpdateSched] "C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min [345144 2013-06-20] (Avira Operations GmbH & Co. KG)
HKLM\...\RunOnce: [ Malwarebytes Anti-Malware ] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
HKLM\...\InprocServer32: [Default-wbemess] wbemess.dll ATTENTION! ====> ZeroAccess
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\RECYCLER\S-1-5-18\$d33b48330d530616596c4d4d5be6aa7a\o. ATTENTION! ====> ZeroAccess
HKCR\...0c966feabec1\InprocServer32: [Default-shell32] C:\Dokumente und Einstellungen\rolli\Lokale Einstellungen\Anwendungsdaten\{d33b4833-0d53-0616-596c-4d4d5be6aa7a}\n. ATTENTION! ====> ZeroAccess?
HKCR\...409d6c4515e9\InprocServer32: [Default-shell32] C:\RECYCLER\S-1-5-21-1715567821-746137067-682003330-1004\$d33b48330d530616596c4d4d5be6aa7a\o. ATTENTION! ====> ZeroAccess?
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about :blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog9 01 C:\Programme\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Programme\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 18 C:\Programme\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\rolli\Anwendungsdaten\Mozilla\Firefox\D:\Firefox\uulikk08.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Programme\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Programme\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Special Savings - C:\Dokumente und Einstellungen\rolli\Anwendungsdaten\Mozilla\Extensions\specialsavings@vshsolutions.com
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] C:\Programme\Gemeinsame Dateien\DVDVideoSoft\plugins\ff\
========================== Services (Whitelisted) =================
R2 AcrSch2Svc; C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe [846576 2011-07-08] (Acronis)
R2 AntiVirSchedulerService; C:\Programme\Avira\AntiVir Desktop\sched.exe [84024 2013-06-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Programme\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-20] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-06-20] (Avira Operations GmbH & Co. KG)
R2 FolderSize; C:\Programme\FolderSize\FolderSizeSvc.exe [116224 2010-04-06] (Brio)
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [116648 2012-06-15] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [116648 2012-06-15] (Google Inc.)
S3 gusvc; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [136120 2011-05-10] (Google)
R2 hasplms; C:\WINDOWS\system32\hasplms.exe [4889032 2011-12-30] (SafeNet Inc.)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [117144 2013-07-03] (Mozilla Foundation)
S3 SandraAgentSrv; C:\Programme\SiSoftware\SiSoftware Sandra Lite 2013.SP4\RpcAgentSrv.exe [71832 2009-06-15] (SiSoftware)
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [161536 2013-01-08] (Skype Technologies)
S3 WMConnectCDS; C:\Programme\Windows Media Connect 2\wmccds.exe [856064 2005-10-06] (Microsoft Corporation)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
R2 JavaQuickStarterService; "C:\Programme\Java\jre7\bin\jqs.exe" -service -config "C:\Programme\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
S2 vToolbarUpdater14.1.7; C:\Programme\Gemeinsame Dateien\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe [x]
S2 winmgmt; C:\DOKUME~1\rolli\wgsdgsdgdsgsd.dll [x]
==================== Drivers (Whitelisted) ====================
R2 aksfridge; C:\WINDOWS\system32\drivers\aksfridge.sys [367560 2011-10-04] (SafeNet Inc.)
S3 Ambfilt; C:\Windows\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R3 ati2mtag; C:\Windows\System32\DRIVERS\ati2mtag.sys [7746048 2012-04-06] (ATI Technologies Inc.)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdXP3.sys [99856 2012-02-23] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-06-20] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [33112 2013-02-11] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-06-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R2 hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [596424 2011-08-10] (SafeNet Inc.)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider)
R1 HWiNFO32; C:\Programme\HWiNFO32\HWiNFO32.SYS [21624 2012-05-10] (REALiX(tm))
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [35144 2013-02-18] ()
S3 Monfilt; C:\Windows\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
R3 MxEFLF; C:\Windows\System32\DRIVERS\MxEFLF32.sys [79688 2010-11-04] (Matrox Graphics Inc.)
R3 MxEFUF; C:\Windows\System32\DRIVERS\MxEFUF32.sys [102728 2010-11-04] (Matrox Graphics Inc.)
S3 NABTSFEC; C:\Windows\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-14] (Microsoft Corporation)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 NPF; C:\Windows\System32\drivers\NPF.sys [50704 2012-08-04] (CACE Technologies, Inc.)
R3 ousb2hub; C:\Windows\System32\DRIVERS\ousb2hub.sys [56960 2005-07-15] (OrangeWare Corporation)
R2 ousbehci; C:\Windows\System32\Drivers\ousbehci.sys [45696 2005-07-15] (OrangeWare Corporation)
R3 RTLE8023xp; C:\Windows\System32\DRIVERS\Rtenicxp.sys [327400 2000-01-01] (Realtek Semiconductor Corporation )
R3 SKYNET; C:\Windows\System32\DRIVERS\SkyNET.SYS [627288 2010-05-10] (TechniSat Digital, S.A.)
S3 SLIP; C:\Windows\System32\DRIVERS\SLIP.sys [11136 2008-04-14] (Microsoft Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
R2 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [5504 2012-06-03] ()
S3 streamip; C:\Windows\System32\DRIVERS\StreamIP.sys [15232 2008-04-14] (Microsoft Corporation)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13024 2013-01-03] ()
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [45240 2011-11-17] (Windows (R) 2000 DDK provider)
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [441608 2011-11-17] (Paragon)
R1 Uim_Vim; C:\Windows\System32\Drivers\Uim_Vim.sys [277576 2011-11-17] (Paragon)
R0 vididr; C:\Windows\System32\DRIVERS\vididr.sys [125472 2012-05-24] (Acronis)
R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [83392 2012-05-24] (Acronis)
S3 WSTCODEC; C:\Windows\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-14] (Microsoft Corporation)
S3 cpuz136; \??\C:\DOKUME~1\rolli\LOKALE~1\Temp\cpuz136\cpuz136_x32.sys [x]
S3 esgiguard; \??\C:\Programme\Enigma Software Group\SpyHunter\esgiguard.sys [x]
S4 IntelIde; No ImagePath
S3 SANDRA; \??\C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP3\WNt500x86\Sandra.sys [x]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [x]
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-07 19:47 - 2013-07-07 19:47 - 00000000 ____D C:\FRST
2013-07-07 15:55 - 2013-04-04 14:50 - 00022856 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-07-05 23:46 - 2013-07-05 23:46 - 00000759 ____A C:\Windows\ST6UNST.002
2013-07-05 22:58 - 2013-07-06 00:05 - 00065536 ____A C:\Windows\System32\config\TuneUp.evt
2013-07-04 12:33 - 2013-07-04 12:34 - 00006061 ____A C:\Windows\KB954155.log
2013-07-04 12:33 - 2013-07-04 12:33 - 00030230 ____A C:\Windows\KB941569.log
2013-07-04 12:33 - 2013-07-04 12:33 - 00009854 ____A C:\Windows\KB952069.log
2013-07-04 12:33 - 2013-07-04 12:33 - 00006028 ____A C:\Windows\KB978695.log
2013-07-04 12:33 - 2013-07-04 12:33 - 00000000 __HDC C:\Windows\$NtUninstallKB941569$
2013-07-03 21:08 - 2013-07-04 09:22 - 00001084 ____A C:\Windows\spupdsvc.log
2013-07-03 21:08 - 2013-07-03 21:08 - 00000000 __HDC C:\Windows\$NtUninstallWMCSetup$
2013-07-03 21:07 - 2013-07-03 21:09 - 00011573 ____A C:\Windows\WMCSetup.log
2013-07-03 21:07 - 2013-07-03 21:08 - 00000000 ____D C:\Windows\RegisteredPackages
2013-07-03 20:56 - 2013-07-04 09:21 - 00036088 ____A C:\Windows\wmsetup.log
2013-07-03 20:56 - 2004-03-09 00:00 - 00132880 ____A (Microsoft Corporation) C:\Windows\System32\MSINET.OCX
2013-07-03 20:45 - 2013-01-20 00:55 - 00429056 ____A (Matthew T. Ashland) C:\Windows\System32\MACDll.dll
2013-07-03 18:55 - 2013-07-03 18:55 - 00000189 ____A C:\siw_debug.txt
2013-07-03 14:02 - 2013-07-03 22:01 - 00065536 ____A C:\Windows\System32\config\WindowsPowerShell.evt
2013-07-03 14:02 - 2013-07-03 14:02 - 00000000 ____D C:\Windows\System32\windowspowershell
2013-07-03 14:00 - 2013-07-03 14:02 - 00000000 __HDC C:\Windows\$NtUninstallKB926140$
2013-07-02 14:36 - 2013-07-05 23:21 - 00000038 ____A C:\Windows\AviSplitter.INI
2013-07-02 11:14 - 2013-06-20 14:48 - 00135136 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avipbb.sys
2013-07-02 11:14 - 2013-06-20 14:48 - 00084744 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avgntflt.sys
2013-07-02 11:14 - 2013-03-06 16:13 - 00037352 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avkmgr.sys
2013-07-02 11:14 - 2012-08-27 15:50 - 00028520 ____A (Avira GmbH) C:\Windows\System32\Drivers\ssmdrv.sys
2013-07-02 11:01 - 2013-07-02 11:01 - 00000000 ____D C:\Windows\ShellNew
2013-07-02 00:49 - 2013-07-02 00:49 - 00000000 __HDC C:\Windows\$NtUninstallKB2839229$
2013-07-02 00:47 - 2013-07-02 00:47 - 00127668 ____A C:\Windows\KB2838727-IE8.log
2013-07-02 00:47 - 2013-07-02 00:47 - 00125810 ____A C:\Windows\KB2820197.log
2013-07-02 00:47 - 2013-07-02 00:47 - 00000000 __HDC C:\Windows\$NtUninstallKB2829361$
2013-07-02 00:47 - 2013-07-02 00:47 - 00000000 __HDC C:\Windows\$NtUninstallKB2820197$
2013-07-02 00:40 - 2013-07-02 00:40 - 00000000 ____D C:\Windows\Performance
2013-07-01 22:54 - 2013-07-02 00:49 - 00130678 ____A C:\Windows\KB2839229.log
2013-07-01 22:53 - 2013-07-02 00:47 - 00127112 ____A C:\Windows\KB2829361.log
==================== One Month Modified Files and Folders ========
2013-07-07 19:47 - 2013-07-07 19:47 - 00000000 ____D C:\FRST
2013-07-07 19:41 - 2012-06-15 14:08 - 00001088 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-07 19:38 - 2012-08-28 10:26 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-07 19:34 - 2012-07-01 11:43 - 00000000 ____D C:\Windows\System32\NtmsData
2013-07-07 15:55 - 2012-05-21 15:36 - 00000000 ___RD C:\Programme
2013-07-07 14:43 - 2012-05-21 14:45 - 00000000 ____D C:\Windows\Registration
2013-07-07 14:42 - 2012-05-21 14:47 - 02037982 ____A C:\Windows\WindowsUpdate.log
2013-07-07 14:39 - 2012-05-21 15:41 - 00000050 ____A C:\Windows\wiaservc.log
2013-07-07 14:39 - 2012-05-21 15:40 - 00000159 ____A C:\Windows\wiadebug.log
2013-07-07 14:38 - 2013-01-24 11:36 - 00000334 ____A C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job
2013-07-07 14:38 - 2012-06-15 14:08 - 00001084 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-07 14:38 - 2012-05-21 14:50 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-07 12:28 - 2012-05-21 16:04 - 00524288 ____A C:\Windows\System32\config\ACEEvent.evt
2013-07-07 12:28 - 2012-05-21 14:50 - 00032408 ____A C:\Windows\SchedLgU.Txt
2013-07-07 12:27 - 2013-02-02 15:02 - 00458415 ____A C:\Windows\setupapi.log
2013-07-06 00:05 - 2013-07-05 22:58 - 00065536 ____A C:\Windows\System32\config\TuneUp.evt
2013-07-05 23:46 - 2013-07-05 23:46 - 00000759 ____A C:\Windows\ST6UNST.002
2013-07-05 23:46 - 2013-01-06 15:23 - 00253952 ____N (Microsoft Corporation) C:\Windows\Setup1.exe
2013-07-05 23:46 - 2013-01-06 15:23 - 00074752 ____A (Microsoft Corporation) C:\Windows\ST6UNST.EXE
2013-07-05 23:21 - 2013-07-02 14:36 - 00000038 ____A C:\Windows\AviSplitter.INI
2013-07-05 10:57 - 2012-05-21 16:30 - 00000000 ____D C:\Windows\repair
2013-07-05 10:20 - 2004-08-04 13:00 - 00013646 ____A C:\Windows\System32\wpa.dbl
2013-07-04 12:34 - 2013-07-04 12:33 - 00006061 ____A C:\Windows\KB954155.log
2013-07-04 12:33 - 2013-07-04 12:33 - 00030230 ____A C:\Windows\KB941569.log
2013-07-04 12:33 - 2013-07-04 12:33 - 00009854 ____A C:\Windows\KB952069.log
2013-07-04 12:33 - 2013-07-04 12:33 - 00006028 ____A C:\Windows\KB978695.log
2013-07-04 12:33 - 2013-07-04 12:33 - 00000000 __HDC C:\Windows\$NtUninstallKB941569$
2013-07-04 12:33 - 2013-02-13 15:22 - 00150338 ____A C:\Windows\FaxSetup.log
2013-07-04 12:33 - 2013-02-13 15:22 - 00087802 ____A C:\Windows\ocgen.log
2013-07-04 12:33 - 2013-02-13 15:22 - 00061197 ____A C:\Windows\tsoc.log
2013-07-04 12:33 - 2013-02-13 15:22 - 00050474 ____A C:\Windows\comsetup.log
2013-07-04 12:33 - 2013-02-13 15:22 - 00032185 ____A C:\Windows\ntdtcsetup.log
2013-07-04 12:33 - 2013-02-13 15:22 - 00022558 ____A C:\Windows\iis6.log
2013-07-04 12:33 - 2013-02-13 15:22 - 00001355 ____A C:\Windows\imsins.log
2013-07-04 12:33 - 2012-06-29 11:40 - 00010080 ____A C:\Windows\System32\lvcoinst.log
2013-07-04 09:22 - 2013-07-03 21:08 - 00001084 ____A C:\Windows\spupdsvc.log
2013-07-04 09:21 - 2013-07-03 20:56 - 00036088 ____A C:\Windows\wmsetup.log
2013-07-03 22:01 - 2013-07-03 14:02 - 00065536 ____A C:\Windows\System32\config\WindowsPowerShell.evt
2013-07-03 22:01 - 2012-05-21 16:30 - 00000000 ____D C:\Windows\security
2013-07-03 21:09 - 2013-07-03 21:07 - 00011573 ____A C:\Windows\WMCSetup.log
2013-07-03 21:09 - 2013-02-13 15:22 - 00001355 ____A C:\Windows\imsins.BAK
2013-07-03 21:08 - 2013-07-03 21:08 - 00000000 __HDC C:\Windows\$NtUninstallWMCSetup$
2013-07-03 21:08 - 2013-07-03 21:07 - 00000000 ____D C:\Windows\RegisteredPackages
2013-07-03 21:08 - 2012-05-21 16:30 - 00000000 ____D C:\Windows\Help
2013-07-03 21:08 - 2012-05-21 14:48 - 00316640 ____A C:\Windows\WMSysPr9.prx
2013-07-03 18:55 - 2013-07-03 18:55 - 00000189 ____A C:\siw_debug.txt
2013-07-03 14:19 - 2012-05-21 16:00 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-03 14:02 - 2013-07-03 14:02 - 00000000 ____D C:\Windows\System32\windowspowershell
2013-07-03 14:02 - 2013-07-03 14:00 - 00000000 __HDC C:\Windows\$NtUninstallKB926140$
2013-07-02 16:23 - 2012-05-23 12:59 - 00000000 ____D C:\Windows\Downloaded Installations
2013-07-02 11:01 - 2013-07-02 11:01 - 00000000 ____D C:\Windows\ShellNew
2013-07-02 09:08 - 2012-05-21 15:35 - 00142032 ____A C:\Windows\System32\FNTCACHE.DAT
2013-07-02 00:56 - 2012-05-21 15:36 - 01168260 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-02 00:49 - 2013-07-02 00:49 - 00000000 __HDC C:\Windows\$NtUninstallKB2839229$
2013-07-02 00:49 - 2013-07-01 22:54 - 00130678 ____A C:\Windows\KB2839229.log
2013-07-02 00:47 - 2013-07-02 00:47 - 00127668 ____A C:\Windows\KB2838727-IE8.log
2013-07-02 00:47 - 2013-07-02 00:47 - 00125810 ____A C:\Windows\KB2820197.log
2013-07-02 00:47 - 2013-07-02 00:47 - 00000000 __HDC C:\Windows\$NtUninstallKB2829361$
2013-07-02 00:47 - 2013-07-02 00:47 - 00000000 __HDC C:\Windows\$NtUninstallKB2820197$
2013-07-02 00:47 - 2013-07-01 22:53 - 00127112 ____A C:\Windows\KB2829361.log
2013-07-02 00:47 - 2013-02-13 19:43 - 00010846 ____A C:\Windows\updspapi.log
2013-07-02 00:47 - 2012-05-22 15:00 - 00000000 ____D C:\Windows\ie8updates
2013-07-02 00:47 - 2012-05-22 14:57 - 00000000 ___HD C:\Windows\$hf_mig$
2013-07-02 00:40 - 2013-07-02 00:40 - 00000000 ____D C:\Windows\Performance
2013-07-01 23:38 - 2012-05-29 13:31 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-07-01 23:38 - 2012-05-29 13:31 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-07-01 22:30 - 2012-05-21 14:46 - 00000000 ____D C:\Windows\System32\Restore
2013-06-20 14:48 - 2013-07-02 11:14 - 00135136 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avipbb.sys
2013-06-20 14:48 - 2013-07-02 11:14 - 00084744 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avgntflt.sys
ZeroAccess:
C:\RECYCLER\S-1-5-21-1715567821-746137067-682003330-1004\$d33b48330d530616596c4d4d5be6aa7a
ZeroAccess:
C:\RECYCLER\S-1-5-18\$d33b48330d530616596c4d4d5be6aa7a
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2008-04-14 07:53] - [2008-04-14 07:53] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2008-04-14 07:53] - [2008-04-14 07:53] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2008-04-14 07:53] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2008-04-14 07:52] - [2008-04-14 07:52] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2008-04-14 07:53] - [2008-04-14 07:53] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2008-04-14 07:22] - [2008-04-14 07:22] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================