|
Log-Analyse und Auswertung: kann keine .exe-Dateien mehr öffnen, registry von virus zerschossen!?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
08.04.2009, 23:14 | #1 |
| kann keine .exe-Dateien mehr öffnen, registry von virus zerschossen!? Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:09:21, on 08.04.2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\wuauclt.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows Live\Toolbar\wltuser.exe C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://www.google.de/ig?hl=de R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1008&m=aspire_6930g R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.fsoc.de:8080 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: 76.76.101.212 006.free-counter.co.uk O1 - Hosts: 76.76.101.212 006.freecounters.co.uk O1 - Hosts: 76.76.101.212 06272002-dbase.hitcountz.net O1 - Hosts: 76.76.101.212 0stats.com O1 - Hosts: 76.76.101.212 123counter.mycomputer.com O1 - Hosts: 76.76.101.212 123counter.superstats.com O1 - Hosts: 76.76.101.212 1ca.cqcounter.com O1 - Hosts: 76.76.101.212 1uk.cqcounter.com O1 - Hosts: 76.76.101.212 1us.cqcounter.com O1 - Hosts: 76.76.101.212 1xxx.cqcounter.com O1 - Hosts: 76.76.101.212 2001-007.com O1 - Hosts: 76.76.101.212 3bc3fd26-91cf-46b2-8ec6-b1559ada0079.statcamp.net O1 - Hosts: 76.76.101.212 4-counter.com O1 - Hosts: 76.76.101.212 a796faee-7163-4757-a34f-e5b48cada4cb.statcamp.net O1 - Hosts: 76.76.101.212 abscbn.spinbox.net O1 - Hosts: 76.76.101.212 activity.serving-sys.com O1 - Hosts: 76.76.101.212 ad-logics.com O1 - Hosts: 76.76.101.212 adclient.rottentomatoes.com O1 - Hosts: 76.76.101.212 adcodes.aim4media.com O1 - Hosts: 76.76.101.212 adcounter.globeandmail.com O1 - Hosts: 76.76.101.212 adcounter.theglobeandmail.com O1 - Hosts: 76.76.101.212 addfreestats.com O1 - Hosts: 76.76.101.212 ademails.com O1 - Hosts: 76.76.101.212 adlog.com.com O1 - Hosts: 76.76.101.212 admanmail.com O1 - Hosts: 76.76.101.212 adopt.specificclick.net O1 - Hosts: 76.76.101.212 ads.tiscali.com O1 - Hosts: 76.76.101.212 ads.tiscali.it O1 - Hosts: 76.76.101.212 adult.foxcounter.com O1 - Hosts: 76.76.101.212 ai062.insightexpress.com O1 - Hosts: 76.76.101.212 ai078.insightexpressai.com O1 - Hosts: 76.76.101.212 ai087.insightexpress.com O1 - Hosts: 76.76.101.212 ai113.insightexpressai.com O1 - Hosts: 76.76.101.212 ai125.insightexpressai.com O1 - Hosts: 76.76.101.212 alpha.easy-hit-counters.com O1 - Hosts: 76.76.101.212 amateur.xxxcounter.com O1 - Hosts: 76.76.101.212 analytics.prx.org O1 - Hosts: 76.76.101.212 anm.intelli-direct.com O1 - Hosts: 76.76.101.212 arbo.hit.gemius.pl O1 - Hosts: 76.76.101.212 au.track.decideinteractive.com O1 - Hosts: 76.76.101.212 au052.insightexpress.com O1 - Hosts: 76.76.101.212 banner.0catch.com O1 - Hosts: 76.76.101.212 banners.webcounter.com O1 - Hosts: 76.76.101.212 be.sitestat.com O1 - Hosts: 76.76.101.212 best-search.cc O1 - Hosts: 76.76.101.212 beta.easy-hit-counter.com O1 - Hosts: 76.76.101.212 beta.easy-hit-counters.com O1 - Hosts: 76.76.101.212 beta.easyhitcounters.com O1 - Hosts: 76.76.101.212 bilbo.counted.com O1 - Hosts: 76.76.101.212 birta.stats.is O1 - Hosts: 76.76.101.212 bluekai.com O1 - Hosts: 76.76.101.212 bluestreak.com O1 - Hosts: 76.76.101.212 bookproplus.com O1 - Hosts: 76.76.101.212 broadcastpc.tv O1 - Hosts: 76.76.101.212 report.broadcastpc.tv O1 - Hosts: 76.76.101.212 www.broadcastpc.tv O1 - Hosts: 76.76.101.212 bserver.blick.com O1 - Hosts: 76.76.101.212 c.thecounter.de O1 - Hosts: 76.76.101.212 c1.statcounter.com O1 - Hosts: 76.76.101.212 c1.thecounter.com O1 - Hosts: 76.76.101.212 c1.thecounter.de O1 - Hosts: 76.76.101.212 c1.xxxcounter.com O1 - Hosts: 76.76.101.212 c10.statcounter.com O1 - Hosts: 76.76.101.212 c11.statcounter.com O1 - Hosts: 76.76.101.212 c12.statcounter.com O1 - Hosts: 76.76.101.212 c13.statcounter.com O1 - Hosts: 76.76.101.212 c14.statcounter.com O1 - Hosts: 76.76.101.212 c15.statcounter.com O1 - Hosts: 76.76.101.212 c16.statcounter.com O1 - Hosts: 76.76.101.212 c17.statcounter.com O1 - Hosts: 76.76.101.212 c2.gostats.com O1 - Hosts: 76.76.101.212 c2.thecounter.com O1 - Hosts: 76.76.101.212 c2.thecounter.de O1 - Hosts: 76.76.101.212 c2.xxxcounter.com O1 - Hosts: 76.76.101.212 c3.gostats.com O1 - Hosts: 76.76.101.212 c3.statcounter.com O1 - Hosts: 76.76.101.212 c3.thecounter.com O1 - Hosts: 76.76.101.212 c3.xxxcounter.com O1 - Hosts: 76.76.101.212 c4.myway.com O1 - Hosts: 76.76.101.212 c4.statcounter.com O1 - Hosts: 76.76.101.212 c5.statcounter.com O1 - Hosts: 76.76.101.212 c6.statcounter.com O1 - Hosts: 76.76.101.212 c7.statcounter.com O1 - Hosts: 76.76.101.212 c8.statcounter.com O1 - Hosts: 76.76.101.212 c9.statcounter.com O1 - Hosts: 76.76.101.212 ca.cqcounter.com O1 - Hosts: 76.76.101.212 cashcounter.com O1 - Hosts: 76.76.101.212 cb1.counterbot.com O1 - Hosts: 76.76.101.212 cdxbin.vulnerap.com O1 - Hosts: 76.76.101.212 cgi.hotstat.nl O1 - Hosts: 76.76.101.212 cgi.sexlist.com O1 - Hosts: 76.76.101.212 cgicounter.onlinehome.de O1 - Hosts: 76.76.101.212 cgicounter.puretec.de O1 - Hosts: 76.76.101.212 citrix.tradedoubler.com O1 - Hosts: 76.76.101.212 cjt1.net O1 - Hosts: 76.76.101.212 click.atdmt.com O1 - Hosts: 76.76.101.212 click.fivemtn.com O1 - Hosts: 76.76.101.212 click.investopedia.com O1 - Hosts: 76.76.101.212 click.payserve.com O1 - Hosts: 76.76.101.212 click.silvercash.com O1 - Hosts: 76.76.101.212 clickauditor.net O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\Program Files\RapidSolution\Tunebite\plugins\IE\TB_WebRipIePlugin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.415.1646\swg.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\RunServices: [Driver32] Overwritten when removing W32/Sircam-A, please delete. O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent O4 - HKCU\..\Run: [NoteTaker] C:\Program Files\NoteTaker\NoteTaker.exe -silent O4 - HKCU\..\Run: [PhonostarAgent] C:\Program Files\phonostar\ps_agent.exe O4 - HKCU\..\Run: [PhonostarTimer] C:\Program Files\phonostar\ps_timer.exe O4 - HKCU\..\Run: [RegClean Expert Scheduler] "C:\Program Files\Registry Clean Expert\RCHelper.exe" /startup O4 - Startup: Stickies.lnk = C:\Program Files\Stickies\stickies.exe O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe O13 - Gopher Prefix: O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - h**p://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - h**p://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{463FB10B-4FC8-44CD-824A-096C81AA3247}: NameServer = 62.156.190.20,192.28.103.19 O17 - HKLM\System\CCS\Services\Tcpip\..\{DC8527F0-F17B-455F-AD1B-DC74DB69DDFF}: NameServer = 62.156.190.20,192.28.103.19 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll O20 - Winlogon Notify: spba - C:\Program Files\Common Files\SPBA\homefus2.dll O23 - Service: Avira AntiVir Personal - Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 16560 bytes |
09.04.2009, 11:25 | #2 |
| kann keine .exe-Dateien mehr öffnen, registry von virus zerschossen!? Die Problemerläuterung vergessen:
__________________Also ich habe eine Datei im Torrent geladen und dann war etwas verstellt in der registry und dann hab ich tuneup drüber laufen lassen um zu reparieren und jetzt kommt bei jeder exe-datei ich sollte die dateizuordnung in der systemsteuerung benutzen. das geht aber nicht. das oben ist mein logfile. kann mir jemand helfen? |
Themen zu kann keine .exe-Dateien mehr öffnen, registry von virus zerschossen!? |
.exe-dateien, 0 bytes, adobe, antivir, antivirus, avg, avgnt, avgnt.exe, avira, bho, browser, defender, desktop, explorer, helper, hijack, hijackthis, internet, internet explorer, jusched.exe, launch, logfile, plug-in, popup, regclean, registry, rundll, senden, software, system, tuneup.defrag, tuprogst.exe, virus, vista, windows, windows defender |