nicht entfernbare Icons auf dem Desktop

10.01.2005, 18:16
...neu hier

Beiträge: 2
#16 Hallo Sabina,

danke für deine Hilfe, und entschuldige, dass ich mich erst jetzt melde. Ich war zwischenzeitig im Urlaub.

Ich hab alles durchgeführt, hier jetzt die erbetenen Logs:

Ad-Aware SE Build 1.05
Logfile Created on:Montag, 10. Januar 2005 14:55:17
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R24 29.12.2004

References detected during the scan:
MRU List(TAC index:0):2 total references
Windows(TAC index:3):1 total references

Ad-Aware SE Settings
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects

10.01.2005 14:55:17 - Scan started. (Full System Scan)

MRU List Object Recognized!
Location: : S-1-5-21-1547161642-115176313-839522115-1003\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened

MRU List Object Recognized!
Location: : C:\Dokumente und Einstellungen\Willow.AEON\recent
Description : list of recently opened documents

Listing running processes

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 892
ThreadCreationTime : 10.01.2005 13:33:27
BasePriority : Normal

#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 956
ThreadCreationTime : 10.01.2005 13:33:28
BasePriority : Normal

#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 980
ThreadCreationTime : 10.01.2005 13:33:29
BasePriority : High

#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1048
ThreadCreationTime : 10.01.2005 13:33:30
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Betriebssystem Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Anwendung für Dienste und Controller
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1060
ThreadCreationTime : 10.01.2005 13:33:30
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [ati2evxx.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1216
ThreadCreationTime : 10.01.2005 13:33:30
BasePriority : Normal

#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1228
ThreadCreationTime : 10.01.2005 13:33:30
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1324
ThreadCreationTime : 10.01.2005 13:33:31
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1420
ThreadCreationTime : 10.01.2005 13:33:31
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1468
ThreadCreationTime : 10.01.2005 13:33:31
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:11 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1512
ThreadCreationTime : 10.01.2005 13:33:31
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:12 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2020
ThreadCreationTime : 10.01.2005 13:33:33
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:13 [nhksrv.exe]
FilePath : C:\WINDOWS\
ProcessID : 288
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal

#:14 [avguard.exe]
FilePath : C:\Programme\AVPersonal\
ProcessID : 260
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal

#:15 [avwupsrv.exe]
FilePath : C:\Programme\AVPersonal\
ProcessID : 340
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal

#:16 [ctsvccda.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 352
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal
FileVersion :
ProductVersion :
ProductName : Creative Service for CDROM Access
CompanyName : Creative Technology Ltd
FileDescription : Creative Service for CDROM Access
InternalName : CTsvcCDAEXE
LegalCopyright : Copyright (c) Creative Technology Ltd., 1999. All rights reserved.
OriginalFilename : CTsvcCDA.EXE

#:17 [inetinfo.exe]
FilePath : C:\WINDOWS\System32\inetsrv\
ProcessID : 404
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Internet-Informationsdienste
CompanyName : Microsoft Corporation
FileDescription : Internet-Informationsdienste
InternalName : INETINFO.EXE
LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFilename : INETINFO.EXE

#:18 [mdm.exe]
FilePath : C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\
ProcessID : 468
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal
FileVersion : 7.00.9064.9150
ProductVersion : 7.00.9064.9150
ProductName : Microsoft Development Environment
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1997-2000
OriginalFilename : mdm.exe

#:19 [msdtc.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 688
ThreadCreationTime : 10.01.2005 13:33:37
BasePriority : Normal
FileVersion : 2001.12.4414.258
ProductVersion :
ProductName : Microsoft Distributed Transaction Coordinator
CompanyName : Microsoft Corporation
FileDescription : MS DTC console program
InternalName : MSDTC.EXE
LegalCopyright : Copyright (C) Microsoft Corp. 1995-1998
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows(TM) is a trademark of Microsoft Corporation

#:20 [tcpsvcs.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1240
ThreadCreationTime : 10.01.2005 13:33:40
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : TCP/IP Services Application
InternalName : TCPSVCS.EXE
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : TCPSVCS.EXE

#:21 [snmp.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1544
ThreadCreationTime : 10.01.2005 13:33:41
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Betriebssystem Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : SNMP-Dienst
InternalName : snmp.exe
LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFilename : snmp.exe

#:22 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1756
ThreadCreationTime : 10.01.2005 13:33:41
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:23 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1984
ThreadCreationTime : 10.01.2005 13:33:42
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe

#:24 [mspmspsv.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2244
ThreadCreationTime : 10.01.2005 13:33:43
BasePriority : Normal
FileVersion :
ProductVersion :
ProductName : Microsoft (R) DRM
CompanyName : Microsoft Corporation
FileDescription : WMDM PMSP Service
InternalName : MSPMSPSV.EXE
LegalCopyright : Copyright (C) Microsoft Corp. 1981-2000
OriginalFilename : MSPMSPSV.EXE

#:25 [mqsvc.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2476
ThreadCreationTime : 10.01.2005 13:33:48
BasePriority : Normal
FileVersion : 5.01.1108
ProductVersion : 5.01.1108
ProductName : Microsoft Message Queue
CompanyName : Microsoft Corporation
FileDescription : Message Queuing Service
LegalCopyright : Copyright (C) Microsoft Corporation. 1981-2000
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows NT(TM) is a trademark of Microsoft Corporation
OriginalFilename : MQSVC.EXE

#:26 [mqtgsvc.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2784
ThreadCreationTime : 10.01.2005 13:33:53
BasePriority : Normal
FileVersion : 5.01.1108
ProductVersion : 5.01.1108
ProductName : Microsoft Message Queue
CompanyName : Microsoft Corporation
FileDescription : Windows NT MSMQ Trigger Service
LegalCopyright : Copyright (C) Microsoft Corporation. 1981-2000
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows NT(TM) is a trademark of Microsoft Corporation
OriginalFilename : QMTGSVC.EXE

#:27 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 3356
ThreadCreationTime : 10.01.2005 13:34:02
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:28 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 820
ThreadCreationTime : 10.01.2005 13:34:11
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:29 [ati2evxx.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1876
ThreadCreationTime : 10.01.2005 13:38:12
BasePriority : Normal

#:30 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 800
ThreadCreationTime : 10.01.2005 13:38:12
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Betriebssystem Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFilename : EXPLORER.EXE

#:31 [ctsysvol.exe]
FilePath : C:\Programme\Creative\SBAudigy2\Surround Mixer\
ProcessID : 2128
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal
FileVersion :
ProductVersion :
ProductName : Creative Volume Control
CompanyName : Creative Technology Ltd
FileDescription : CTSysVol.exe
LegalCopyright : Copyright (c) Creative Technology Ltd., 2002. All rights reserved.
OriginalFilename : CTSysVol.exe

#:32 [ctdvddet.exe]
FilePath : C:\Programme\Creative\SBAudigy2\DVDAudio\
ProcessID : 2112
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal
FileVersion :
ProductVersion :
ProductName : CTDVDDET
CompanyName : Creative Technology Ltd
FileDescription : CTDVDDET
InternalName : CTDVDDET
LegalCopyright : Copyright (c) Creative Technology Ltd., 2002. All rights reserved.
OriginalFilename : CTDVDDET.EXE

#:33 [cthelper.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 3672
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal
FileVersion : 1, 0, 0, 10
ProductVersion : 1, 0, 0, 10
ProductName : CtHelper Application
CompanyName : Creative Technology Ltd
FileDescription : CtHelper MFC Application
InternalName : CtHelper
LegalCopyright : Copyright (C) 2002
OriginalFilename : CtHelper.EXE

#:34 [dellmmkb.exe]
FilePath : C:\WINDOWS\
ProcessID : 2508
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal
FileVersion : 2.0.0
ProductVersion : 2.0.0
ProductName : Netropa Hot Key
CompanyName : Netropa Corp.
FileDescription : Netropa(tm) Hot Key
InternalName : Netropa Hot Key
LegalCopyright : Copyright © 2000-2001 Netropa Corp.
OriginalFilename : nhk.exe

#:35 [jusched.exe]
FilePath : C:\Programme\Java\j2re1.4.2_06\bin\
ProcessID : 2640
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal

#:36 [ituneshelper.exe]
FilePath : C:\Programme\iTunes\
ProcessID : 2660
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal
FileVersion :
ProductVersion :
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe

#:37 [ipodservice.exe]
FilePath : C:\Programme\iPod\bin\
ProcessID : 2692
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal
FileVersion :
ProductVersion :
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe

#:38 [logitray.exe]
FilePath : C:\Programme\Logitech\Video\
ProcessID : 2460
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal
FileVersion :
ProductVersion :
ProductName : Logitech QuickCam
CompanyName : Logitech Inc.
FileDescription : ImageStudio Tray Application
InternalName : LogiTray.exe
LegalCopyright : (c) 1996-2003 Logitech. All rights reserved.
OriginalFilename : LogiTray.exe

#:39 [qttask.exe]
FilePath : C:\Programme\QuickTime\
ProcessID : 2868
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal
FileVersion : 6.5.1
ProductVersion : QuickTime 6.5.1
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2004
OriginalFilename : QTTask.exe

#:40 [lvcomsx.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2884
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal
FileVersion :
ProductVersion :
ProductName : Logitech QuickCam
CompanyName : Logitech Inc.
FileDescription : LVCom Server
InternalName : LVComS.exe
LegalCopyright : (c) 1996-2004 Logitech. All rights reserved.
OriginalFilename : LVComS.exe

#:41 [avgnt.exe]
FilePath : C:\Programme\AVPersonal\
ProcessID : 1052
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal

#:42 [teatimer.exe]
FilePath : C:\Programme\Spybot - Search & Destroy\
ProcessID : 2116
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Idle
FileVersion : 1, 3, 0, 12
ProductVersion : 1, 3, 0, 12
ProductName : Spybot - Search & Destroy
CompanyName : Safer Networking Limited
FileDescription : System settings protector
InternalName : TeaTimer
LegalCopyright : © 2000-2004 Patrick M. Kolla / Safer Networking Limited. Alle Rechte vorbehalten.
LegalTrademarks : "Spybot" und "Spybot - Search & Destroy" sind registrierte Warenzeichen.
OriginalFilename : TeaTimer.exe
Comments : Schützt Systemeinstellungen vor ungewollten Änderungen.

#:43 [wcescomm.exe]
FilePath : C:\Programme\Microsoft ActiveSync\
ProcessID : 3072
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal
FileVersion :
ProductVersion : 3.8.5004
ProductName : Microsoft ActiveSync
CompanyName : Microsoft Corporation
FileDescription : ActiveSync Connection Manager
InternalName : wcescomm
LegalCopyright : Copyright © 1995-2004 Microsoft Corp. Alle Rechte vorbehalten.
LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation.
OriginalFilename : WCESCOMM.EXE

#:44 [osd.exe]
FilePath : C:\Programme\Netropa\
ProcessID : 316
ThreadCreationTime : 10.01.2005 13:38:17
BasePriority : Normal
FileVersion : 2.02
ProductVersion : 2.02
ProductName : Onscreen Display
CompanyName : Netropa Corp.
FileDescription : Netropa(r) Onscreen Display
InternalName : OSD
LegalCopyright : Copyright © 1997-2001 Netropa Corp.
OriginalFilename : osd.exe

#:45 [acrotray.exe]
FilePath : C:\Programme\Adobe\Acrobat 6.0\Distillr\
ProcessID : 3268
ThreadCreationTime : 10.01.2005 13:38:17
BasePriority : Normal
FileVersion :
ProductVersion :
ProductName : AcroTray - Adobe Acrobat Distiller helper application.
CompanyName : Adobe Systems Inc.
FileDescription : AcroTray
InternalName : AcroTray
LegalCopyright : Copyright 1984-2003 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename : AcroTray.exe

#:46 [boinc_gui.exe]
FilePath : C:\Programme\BOINC\
ProcessID : 2944
ThreadCreationTime : 10.01.2005 13:38:17
BasePriority : Normal
FileVersion : 4.13
ProductVersion : 4.13
ProductName : BOINC Core Client
CompanyName : Space Sciences Laboratory
FileDescription : boinc_gui
InternalName : boinc_gui
LegalCopyright : Copyright © 2004 University of California
OriginalFilename : boinc_gui.exe

#:47 [setiathome_4.08_windows_intelx86.exe]
FilePath : C:\Programme\BOINC\projects\\
ProcessID : 3316
ThreadCreationTime : 10.01.2005 13:38:17
BasePriority : Idle

#:48 [firefox.exe]
FilePath : C:\Programme\Mozilla Firefox\
ProcessID : 3628
ThreadCreationTime : 10.01.2005 13:46:09
BasePriority : Normal

#:49 [ad-aware.exe]
FilePath : C:\Programme\Lavasoft\Ad-Aware SE Personal\
ProcessID : 2848
ThreadCreationTime : 10.01.2005 13:54:51
BasePriority : Normal
FileVersion :
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
New critical objects: 0
Objects found so far: 2

Started registry scan

Windows Object Recognized!
Type : RegData
Data :
Category : Vulnerability
Comment : Possible virus infection, REG file extension compromised
Object : regfile\shell\open\command
Value :
Data :

Registry Scan result:
New critical objects: 1
Objects found so far: 3

Started deep registry scan

Deep registry scan result:
New critical objects: 0
Objects found so far: 3

Started Tracking Cookie scan

Tracking cookie scan result:
New critical objects: 0
Objects found so far: 3

Deep scanning and examining files (C;)

Disk Scan Result for C:\
New critical objects: 0
Objects found so far: 3

Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".

Hosts file scan result:
2 entries scanned.
New critical objects:0
Objects found so far: 3

Performing conditional scans...

Conditional scan result:
New critical objects: 0
Objects found so far: 3

15:12:28 Scan Complete

Summary Of This Scan
Total scanning time:00:17:11.32
Objects scanned:155743
Objects identified:1
Objects ignored:0
New critical objects:1

mwav log

Mon Jan 10 15:26:48 2005 => File C:\WINDOWS\system32\KILLAPPS.EXE tagged as not-a-virus:RiskWare.Tool.KillApp.b. No Action Taken.

Mon Jan 10 15:39:05 2005 => File C:\Dokumente und Einstellungen\Willow.AEON\.jpi_cache\jar\1.0\ infected by "Trojan-Downloader.Java.OpenStream.t" Virus. Action Taken: No Action Taken.

Mon Jan 10 15:40:14 2005 => File C:\Dokumente und Einstellungen\Willow.AEON\Anwendungsdaten\ACD Systems\Catalogs\Backup\BKID_000000\BKUP_000000002560 infected by "not-a-virus:AdWare.ToolBar.Quick.a" Virus. Action Taken: No Action Taken.

Mon Jan 10 15:45:37 2005 => File C:\Dokumente und Einstellungen\Willow.AEON\Eigene Dateien\Eigene Downloads\hijackthis\backups\backup-20050102-202934-357.dll infected by "" Virus. Action Taken: No Action Taken.

Mon Jan 10 15:57:36 2005 => File C:\Programme\C2Media\Setup.exe infected by "" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:27:08 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP122\A0011916.dll infected by "not-a-virus:AdWare.Altnet.c" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:27:31 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP123\A0011981.EXE infected by "not-a-virus:AdWare.Toolbar.MyWay.b" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:27:31 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP123\A0011982.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.f" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:27:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012027.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:27:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012028.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:27:47 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012033.exe infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:27:59 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012086.DLL infected by "not-a-virus:AdWare.Toolbar.MyWay.c" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:48:44 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036147.exe infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:48:45 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036150.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:48:45 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036152.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:48:45 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036155.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:48:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036169.dll infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:48:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036170.exe infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:48:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036172.exe infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.

Mon Jan 10 16:59:32 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP246\A0044637.exe infected by "not-a-virus:AdWare.Gator.3202" Virus. Action Taken: No Action Taken.

Mon Jan 10 17:46:16 2005 => ***** Checking for specific ITW Viruses *****
Mon Jan 10 17:46:16 2005 => Checking for Welchia Virus...
Mon Jan 10 17:46:16 2005 => Checking for LovGate Virus...
Mon Jan 10 17:46:16 2005 => Checking for CodeRed Virus...
Mon Jan 10 17:46:16 2005 => Checking for OpaServ Virus...
Mon Jan 10 17:46:16 2005 => Checking for Sobig.e Virus...
Mon Jan 10 17:46:16 2005 => Checking for Winupie Virus...
Mon Jan 10 17:46:16 2005 => Checking for Swen Virus...
Mon Jan 10 17:46:16 2005 => Checking for JS.Fortnight Virus...
Mon Jan 10 17:46:16 2005 => Checking for Novarg Virus...
Mon Jan 10 17:46:16 2005 => Checking for Pagabot Virus...
Mon Jan 10 17:46:16 2005 => Checking for Parite.b Virus...
Mon Jan 10 17:46:16 2005 => Checking for Parite.a Virus...

Mon Jan 10 17:46:16 2005 => ***** Scanning complete. *****

Mon Jan 10 17:46:16 2005 => Total Files Scanned: 108027
Mon Jan 10 17:46:16 2005 => Total Virus(es) Found: 27
Mon Jan 10 17:46:16 2005 => Total Disinfected Files: 0
Mon Jan 10 17:46:16 2005 => Total Files Renamed: 0
Mon Jan 10 17:46:16 2005 => Total Deleted Files: 0
Mon Jan 10 17:46:16 2005 => Total Errors: 165
Mon Jan 10 17:46:16 2005 => Time Elapsed: 02:26:45
Mon Jan 10 17:46:16 2005 => Virus Database Date: 2005/01/10
Mon Jan 10 17:46:16 2005 => Virus Database Count: 115105

Mon Jan 10 17:46:16 2005 => Scan Completed.

Mon Jan 10 17:47:17 2005 => Virus Database Date: 2005/01/10
Mon Jan 10 17:47:17 2005 => Virus Database Count: 115105
Mon Jan 10 17:47:21 2005 => AV Library Unloaded (3)...
Mon Jan 10 17:59:52 2005 => **********************************************************
Mon Jan 10 17:59:52 2005 => eScan AntiVirus Toolkit Utility.
Mon Jan 10 17:59:52 2005 => Copyright © 2003-2004, MicroWorld Technologies Inc.
Mon Jan 10 17:59:52 2005 => **********************************************************
Mon Jan 10 17:59:52 2005 => Version 4.7.7 (C:\bases\
Mon Jan 10 17:59:52 2005 => Log File: C:\bases\mwav.log
Mon Jan 10 17:59:52 2005 => Latest Date of files inside MWAV: 10 Jan 2005 12:00:47.
Mon Jan 10 17:59:53 2005 => AV Library Loaded...
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\kavss.exe
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\Getvlist.exe
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\kavss.dll
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\kavssdi.dll
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\kavssi.dll
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\kavvlg.dll
Mon Jan 10 17:59:54 2005 => Scanning File C:\bases\msvlclnt.dll
Mon Jan 10 17:59:54 2005 => Scanning File C:\bases\ipc.dll
Mon Jan 10 17:59:54 2005 => Scanning File C:\bases\main.avi
Mon Jan 10 17:59:54 2005 => Scanning File C:\bases\virus.avi
Mon Jan 10 17:59:54 2005 => Virus Database Date: 2005/01/10
Mon Jan 10 17:59:54 2005 => Virus Database Count: 115105

Hijack log neu ( der is aber anders, da ich gestern software für meinen neuen Handheld installiert hab)

Logfile of HijackThis v1.99.0
Scan saved at 17:48:28, on 10.01.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\Programme\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Programme\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Dokumente und Einstellungen\Willow.AEON\Eigene Dateien\Eigene Downloads\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUp.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Programme\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Programme\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Programme\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programme\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programme\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programme\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: BOINC.lnk = C:\Programme\BOINC\boinc_gui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Alles mit FlashGet laden - C:\Programme\FlashGet\jc_all.htm
O8 - Extra context menu item: Mit FlashGet laden - C:\Programme\FlashGet\jc_link.htm
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Mobilen Favoriten erstellen - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) -
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.4.2_06) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} (DoomCln Object) -
O16 - DPF: {A8658086-E6AC-4957-BC8E-8D54A7E8A790} (GDIChk Object) -
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.4.0_01) -
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Plug-in 1.4.1_02) -
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} (Java Plug-in 1.4.2_04) -
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Java Plug-in 1.4.2_06) -
O16 - DPF: {FB48C7B0-EB66-4BE6-A1C5-9DDF3C37249A} (MCSendMessageHandler Class) -
O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: Netropa NHK Server - Unknown - C:\WINDOWS\Nhksrv.exe
O23 - Service: Intel(R) NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe

So, ich bedanke schonmal im Vorraus für deine Hilfe. Ich hoffe das ist bald alles geklärt.

Dieser Beitrag wurde am 10.01.2005 um 18:18 Uhr von simon_heim editiert.
Seitenanfang Seitenende
Um auf dieses Thema zu ANTWORTEN
bitte erst » hier kostenlos registrieren!!

Folgende Themen könnten Dich auch interessieren: