Hello everybody!
As many other here, I have a hijacking problem: by searching via Google I will be redirected to other sites. The problem occures not just with IE, but also with Firefox and Opera. The redirection is not the only symptom: I can't access some internetsites; can't download updates etc.
I've just checked my system with Hijack This; here is the log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:17:57, on 26.09.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\Java\jre6\bin\jqs.exe
C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
C:\Programme\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
C:\Programme\Norton PC Checkup\Engine\2.0.6.11\SymcPCCULaunchSvc.exe
C:\Programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Programme\samsung\Samsung Network Manager\SNMWLANService.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe
C:\Programme\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis(2).exe
C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis(3).exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/accounts/ServiceLogi…tmpl=googlemail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Programme\AskBarDis\bar\bin\askBar.dll (file missing)
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programme\Norton AntiVirus\Engine\18.1.0.37\IPSBHO.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll (file missing)
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Programme\IDM\QUICKfind\PlugIns\IEHelp.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Programme\AskBarDis\bar\bin\askBar.dll (file missing)
O4 - HKLM\..\Run: [EPSON Stylus Photo R240 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE /P30 "EPSON Stylus Photo R240 Series" /O6 "USB004" /M "Stylus Photo R240"
O4 - HKLM\..\Run: [HPLJ Config] C:\Programme\Hewlett-Packard\hp LaserJet 1010 Series\SetConfig.exe -c Direct -p DOT4_001 -pn "hp LaserJet 1010 Series Driver" -n 0 -l 1033 -sl 120000
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://axis.udm.net/activex/AMC.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{89B3BBA4-9F78-4EE6-9BD6-9871B4029C23}: NameServer = 93.188.163.185,93.188.166.185
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1BE9A58-7EA5-4B3B-87A6-7FE19D946D05}: NameServer = 93.188.163.185,93.188.166.185
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.163.185,93.188.166.185
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 93.188.163.185,93.188.166.185
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.163.185,93.188.166.185
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Google Update Service (gupdate1c9fd69e5bf5f8c) (gupdate1c9fd69e5bf5f8c) - Google Inc. - C:\Programme\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Programme\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Programme\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Programme\Norton PC Checkup\Engine\2.0.6.11\SymcPCCULaunchSvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Samsung Update Plus - Unknown owner - C:\Programme\Samsung\Samsung Update Plus\SLUBackgroundService.exe
O23 - Service: SNM WLAN Service - Unknown owner - C:\Programme\samsung\Samsung Network Manager\SNMWLANService.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O24 - Desktop Component 0: (no name) - http://www.izhneftemash.ru/foto/image.aspx…w=450&h=320
–
End of file - 9026 bytes
Many thanks for your help or advise on this problem.
Hi Mimino, welcome to the forum.
To make cleaning this machine easier
Please do not uninstall/install any programs unless asked to
It is more difficult when files/programs are appearing in/disappearing from the logs. Please do not run any scans other than those requested Please follow all instructions in the order posted All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked. Do not attach any logs/reports, etc.. unless specifically requested to do so. If you have problems with or do not understand the instructions, Please ask before continuing. Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
Open
hijackthis , do a system scan only and checkmark these lines, if present
O17 - O17 - HKLM\System\CCS\Services\Tcpip\..\{89B3BBA4-9F78-4EE6-9BD6-9871B4029C23}: NameServer = 93.188.163.185,93.188.166.185
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1BE9A58-7EA5-4B3B-87A6-7FE19D946D05}: NameServer = 93.188.163.185,93.188.166.185
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.163.185,93.188.166.185
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 93.188.163.185,93.188.166.185
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.163.185,93.188.166.185
Close
ALL other windows/browsers and click
Fix Checked . Answer
Yes if prompted. Close HJT.
Next
Download
OTL to your Desktop
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. Click on Minimal Output at the top Download the following file scan.txt to your Desktop . Click here to download it . You may need to right click on it and select "Save" Double click inside the Custom Scan box at the bottom A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel" Click the OK button and navigate to the file scan.txt which we just saved to your desktop Select scan.txt and click Open. Writing will now appear under the Custom Scan box Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt . These are saved in the same location as OTL. Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
Next
Go
HERE to get a randomly named copy of GMER. Scroll down to the
Download section and click
Download EXE . Save it to your desktop.
Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent . If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO .
[external image: Posted Image]
Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Uncheck the following … IAT/EAT Drives/Partition other than Systemdrive (typically C:\) Show All (don't miss this one ) Then click the Scan button & wait for it to finish. Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
If GMER will not run in normal windows, please run it in Saffe Mode
Please post back with
Please describe all symptoms you are experiencing.
Thanks
Hello oldman960!
Thank you so much for answering me!
As you said, I scanned the scan.txt with OLT, but instead of two notepad files it opened just one - OTL.Txt. Here it is:
OTL logfile created on: 27.09.2010 18:58:40 - Run 2
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Dokumente und Einstellungen\Sveta\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 64,00% Memory free
5,00 Gb Paging File | 4,00 Gb Available in Paging File | 89,00% Paging File free
Paging file location(s): C:\pagefile.sys 2877 2877 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 94,22 Gb Total Space | 68,26 Gb Free Space | 72,45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SVETLANA
Current User Name: Sveta
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Dokumente und Einstellungen\Sveta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Norton PC Checkup\Engine\2.0.6.11\SymcPCCULaunchSvc.exe (Symantec Corporation)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Programme\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Programme\Samsung\Samsung Network Manager\SNMWLANService.exe ()
PRC - C:\WINDOWS\system32\PAStiSvc.exe ()
PRC - C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\system32\brss01a.exe (brother Industries Ltd)
========== Modules (SafeList) ==========
MOD - C:\Dokumente und Einstellungen\Sveta\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Norton PC Checkup Application Launcher) – C:\Programme\Norton PC Checkup\Engine\2.0.6.11\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (NAV) – C:\Programme\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe (Symantec Corporation)
SRV - (McComponentHostService) – C:\Programme\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (PCCUJobMgr) – C:\Programme\Norton PC Checkup\Engine\2.0.6.11\ccSvcHst.exe (Symantec Corporation)
SRV - (Samsung Update Plus) – C:\Programme\Samsung\Samsung Update Plus\SLUBackgroundService.exe ()
SRV - (LightScribeService) – C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (SNM WLAN Service) – C:\Programme\samsung\Samsung Network Manager\SNMWLANService.exe ()
SRV - (IDriverT) – C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (STI Simulator) – C:\WINDOWS\system32\PAStiSvc.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (ose) – C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Brother XP spl Service) – C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
========== Driver Services (SafeList) ==========
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (PAC207) – C:\WINDOWS\System32\DRIVERS\pfc027.sys File not found
DRV - (hwusbdev) – C:\WINDOWS\System32\DRIVERS\ewusbdev.sys File not found
DRV - (hwdatacard) – C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys File not found
DRV - (NAVEX15) – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20100927.002\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20100927.002\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20100901.003\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\NAV\1201000.025\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1201000.025\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1201000.025\Ironx86.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20100924.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMDS.SYS (Symantec Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (w200obex) – C:\WINDOWS\system32\drivers\w200obex.sys (MCCI)
DRV - (w200mdm) – C:\WINDOWS\system32\drivers\w200mdm.sys (MCCI)
DRV - (w200mdfl) – C:\WINDOWS\system32\drivers\w200mdfl.sys (MCCI)
DRV - (w200bus) Sony Ericsson W200 driver (WDM) – C:\WINDOWS\system32\drivers\w200bus.sys (MCCI)
DRV - (VVBackd5) – C:\WINDOWS\System32\drivers\VVBackd5.sys ()
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (ZDCNDIS5) – C:\WINDOWS\ZDCndis5.sys (ZDC., Inc. (ZDC))
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (DNSeFilter) – C:\WINDOWS\system32\drivers\SamsungEDS.SYS (Samsung Electronics,.LTD)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (SSB2413) – C:\WINDOWS\system32\drivers\SSB2413.sys (Atheros Communications, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (DOSMEMIO) – C:\WINDOWS\system32\MEMIO.SYS ()
DRV - (BALU) – C:\WINDOWS\system32\drivers\balu.sys ()
DRV - (SUEPD) – C:\WINDOWS\system32\drivers\SUE_PD.sys (Samsung)
DRV - (rtl8139) NT-Treiber für Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (RITCPT) – C:\WINDOWS\System32\drivers\RITCPT.SYS ()
DRV - (FBAPI) – C:\WINDOWS\system32\drivers\FBAPI.sys ()
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/accounts/ServiceLogi…tmpl=googlemail
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.startup.homepage: "mail.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007.08.22 14:11:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2010.09.25 14:01:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Programme\Mozilla Firefox\components [2010.09.25 20:01:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2010.09.25 20:01:15 | 000,000,000 | —D | M]
[2009.07.28 20:14:33 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Extensions
[2010.09.26 20:53:44 | 000,000,000 | —D | M] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Firefox\Profiles\mhq82cpm.default\extensions
[2010.04.05 22:21:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Firefox\Profiles\mhq82cpm.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2007.08.25 13:18:45 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mozilla\Firefox\Profiles\mhq82cpm.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010.09.26 20:31:16 | 000,000,000 | —D | M] – C:\Programme\Mozilla Firefox\extensions
[2010.09.14 23:32:39 | 000,001,392 | —- | M] () – C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.09.14 23:32:39 | 000,002,344 | —- | M] () – C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.09.14 23:32:39 | 000,006,805 | —- | M] () – C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.09.14 23:32:39 | 000,001,178 | —- | M] () – C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.09.14 23:32:39 | 000,001,105 | —- | M] () – C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2010.09.25 17:23:33 | 000,000,820 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Programme\AskBarDis\bar\bin\askBar.dll File not found
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programme\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programme\Norton AntiVirus\Engine\18.1.0.37\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (CNavExtBho Class) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll File not found
O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Programme\IDM\QUICKfind\PlugIns\IEHelp.dll ()
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Programme\AskBarDis\bar\bin\askBar.dll File not found
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Programme\AskBarDis\bar\bin\askBar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EPSON Stylus Photo R240 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE File not found
O4 - HKLM..\Run: [HPLJ Config] C:\Programme\Hewlett-Packard\hp LaserJet 1010 Series\SetConfig.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programme\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://axis.udm.net/activex/AMC.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 () - http://www.izhneftemash.ru/foto/image.aspx…w=450&h;=320
O24 - Desktop Components:1 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.10.09 20:18:53 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\Shell - "" = AutoRun
O33 - MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{26e7d15c-270e-11df-9a52-0013773197b5}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\Shell - "" = AutoRun
O33 - MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{26e7d160-270e-11df-9a52-0013773197b5}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\Shell - "" = AutoRun
O33 - MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{35bc88f8-700a-11db-a6b2-0013773197b5}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\Shell - "" = AutoRun
O33 - MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{432b284c-279c-11df-9a58-0013773197b5}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)
========== Files/Folders - Created Within 30 Days ==========
[2010.09.27 18:25:55 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010.09.27 05:33:32 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Dokumente und Einstellungen\Sveta\Desktop\OTL.exe
[2010.09.27 05:32:55 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Desktop\backups
[2010.09.26 23:16:51 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis(3).exe
[2010.09.26 23:13:20 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis(2).exe
[2010.09.26 23:08:25 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Desktop\NPE
[2010.09.26 22:34:37 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Desktop\IE8
[2010.09.26 22:06:35 | 000,071,398 | —- | C] (jpshortstuff) – C:\Dokumente und Einstellungen\Sveta\Desktop\GooredFix(2).exe
[2010.09.26 22:03:49 | 000,050,688 | —- | C] (Atribune.org) – C:\Dokumente und Einstellungen\Sveta\Desktop\ATF_Cleaner.exe
[2010.09.26 21:59:45 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis.exe
[2010.09.26 21:50:34 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Desktop\tdsskiller
[2010.09.26 21:48:33 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Desktop\GooredFix Backups
[2010.09.26 21:42:02 | 000,071,398 | —- | C] (jpshortstuff) – C:\Dokumente und Einstellungen\Sveta\Desktop\GooredFix.exe
[2010.09.26 21:20:08 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Desktop\HIjackthis
[2010.09.26 20:45:57 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Desktop\lesezeichen
[2010.09.26 15:01:09 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Tific
[2010.09.26 15:01:09 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Tific
[2010.09.26 13:56:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NortonPCCheckup\0200060.00B
[2010.09.26 13:30:21 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\NPE
[2010.09.26 13:01:42 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Opera
[2010.09.26 13:01:42 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Opera
[2010.09.26 13:01:16 | 000,000,000 | —D | C] – C:\Programme\Opera
[2010.09.25 20:03:14 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\McAfee Security Scan
[2010.09.25 20:03:14 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\McAfee
[2010.09.25 20:03:09 | 000,000,000 | —D | C] – C:\Programme\McAfee Security Scan
[2010.09.25 16:24:07 | 000,000,000 | —D | C] – C:\Qoobox
[2010.09.25 14:00:15 | 000,126,512 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010.09.25 14:00:15 | 000,060,808 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010.09.25 14:00:15 | 000,000,000 | —D | C] – C:\Programme\Symantec
[2010.09.25 13:59:52 | 000,369,072 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NAV\1201000.025\symtdi.sys
[2010.09.25 13:59:52 | 000,331,312 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NAV\1201000.025\symtdiv.sys
[2010.09.25 13:59:51 | 000,666,672 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NAV\1201000.025\SymEFA.sys
[2010.09.25 13:59:51 | 000,489,008 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NAV\1201000.025\srtsp.sys
[2010.09.25 13:59:51 | 000,339,504 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NAV\1201000.025\SymDS.sys
[2010.09.25 13:59:51 | 000,294,448 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NAV\1201000.025\symnets.sys
[2010.09.25 13:59:51 | 000,050,096 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NAV\1201000.025\srtspx.sys
[2010.09.25 13:59:50 | 000,134,704 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\NAV\1201000.025\Ironx86.sys
[2010.09.25 13:59:07 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NAV
[2010.09.25 13:59:07 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NAV\1201000.025
[2010.09.25 13:59:03 | 000,000,000 | —D | C] – C:\Programme\Windows Sidebar
[2010.09.25 13:59:03 | 000,000,000 | —D | C] – C:\Programme\Norton AntiVirus
[2010.09.21 15:47:28 | 000,000,000 | —D | C] – C:\Programme\Universal Extractor
[2010.09.21 15:43:32 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Mario_Schneider
[2010.09.21 15:43:15 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Mario Schneider
[2010.09.19 11:13:52 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Eigene Dateien\Ekho Moskvy
[2010.09.17 17:26:20 | 000,000,000 | —D | C] – C:\Programme\Gemeinsame Dateien\Apple
[2010.09.16 22:25:19 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Eigene Dateien\Neuer Ordner
[2010.09.16 21:52:05 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Tific
[2010.09.16 21:52:04 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Tific
[2010.09.16 21:51:13 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\NortonPCCheckup
[2010.09.16 21:51:12 | 000,000,000 | —D | C] – C:\Programme\Norton PC Checkup
[2010.09.16 21:51:08 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton
[2010.09.16 21:50:23 | 000,000,000 | —D | C] – C:\Programme\NortonInstaller
[2010.09.16 21:50:23 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NortonInstaller
[2010.09.12 21:56:14 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\Sveta\Eigene Dateien\Eigene Musik
[2010.09.04 15:23:31 | 000,075,264 | —- | C] (SEIKO EPSON CORPORATION) – C:\WINDOWS\System32\E_FLBBEE.DLL
[2010.09.04 15:23:31 | 000,062,976 | —- | C] (SEIKO EPSON CORPORATION) – C:\WINDOWS\System32\E_FD4BBEE.DLL
[2010.09.04 15:21:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2010.09.04 15:21:29 | 000,000,000 | —D | C] – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\EPSON
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.09.27 18:49:41 | 000,645,356 | —- | M] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\Cat.DB
[2010.09.27 05:33:33 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Dokumente und Einstellungen\Sveta\Desktop\OTL.exe
[2010.09.27 00:25:00 | 000,001,208 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3771985245-72322722-229232620-1006UA.job
[2010.09.27 00:07:00 | 000,001,088 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.09.26 23:16:51 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis(3).exe
[2010.09.26 23:13:21 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis(2).exe
[2010.09.26 23:04:56 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010.09.26 23:04:26 | 000,001,084 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.09.26 23:04:24 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010.09.26 23:04:22 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010.09.26 23:04:18 | 2011,316,224 | -HS- | M] () – C:\hiberfil.sys
[2010.09.26 23:02:55 | 004,976,640 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\ntuser.dat
[2010.09.26 23:02:50 | 000,000,300 | -HS- | M] () – C:\Dokumente und Einstellungen\Sveta\ntuser.ini
[2010.09.26 22:06:35 | 000,071,398 | —- | M] (jpshortstuff) – C:\Dokumente und Einstellungen\Sveta\Desktop\GooredFix(2).exe
[2010.09.26 22:03:49 | 000,050,688 | —- | M] (Atribune.org) – C:\Dokumente und Einstellungen\Sveta\Desktop\ATF_Cleaner.exe
[2010.09.26 21:59:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis.exe
[2010.09.26 21:49:47 | 001,193,882 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Desktop\tdsskiller.zip
[2010.09.26 21:42:03 | 000,071,398 | —- | M] (jpshortstuff) – C:\Dokumente und Einstellungen\Sveta\Desktop\GooredFix.exe
[2010.09.26 20:56:27 | 000,000,418 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{17A5E491-0DBB-40A1-85C3-BC4969F1A904}.job
[2010.09.26 20:49:25 | 000,004,566 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010.09.26 20:49:21 | 001,079,434 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010.09.26 20:49:21 | 000,463,074 | —- | M] () – C:\WINDOWS\System32\perfh007.dat
[2010.09.26 20:49:21 | 000,444,876 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010.09.26 20:49:21 | 000,086,142 | —- | M] () – C:\WINDOWS\System32\perfc007.dat
[2010.09.26 20:49:21 | 000,072,752 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010.09.26 15:25:01 | 000,001,156 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3771985245-72322722-229232620-1006Core.job
[2010.09.26 15:00:54 | 000,001,908 | —- | M] () – C:\Dokumente und Einstellungen\All Users\Desktop\Norton PC Checkup.LNK
[2010.09.26 13:01:29 | 000,000,572 | —- | M] () – C:\Dokumente und Einstellungen\All Users\Desktop\Opera.lnk
[2010.09.25 20:03:10 | 000,001,583 | —- | M] () – C:\Dokumente und Einstellungen\All Users\Desktop\McAfee Security Scan Plus.lnk
[2010.09.25 20:01:24 | 000,001,566 | —- | M] () – C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2010.09.25 17:23:33 | 000,000,820 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010.09.25 14:00:15 | 000,126,512 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010.09.25 14:00:15 | 000,060,808 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010.09.25 14:00:15 | 000,007,456 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010.09.25 14:00:15 | 000,000,805 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010.09.25 13:59:57 | 000,001,849 | —- | M] () – C:\Dokumente und Einstellungen\All Users\Desktop\Norton AntiVirus.LNK
[2010.09.25 13:28:09 | 000,000,000 | —- | M] () – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\N360BUOptions.ini
[2010.09.22 15:44:02 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.09.19 11:02:53 | 000,002,509 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Microsoft Office Word 2003.lnk
[2010.09.17 22:12:43 | 000,000,978 | —- | M] () – C:\WINDOWS\win.ini
[2010.09.17 22:12:43 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010.09.17 22:12:43 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2010.09.17 21:53:39 | 000,096,696 | —- | M] () – C:\WINDOWS\hplj1010.his
[2010.09.17 21:53:39 | 000,008,263 | —- | M] () – C:\WINDOWS\hplj1010.ini
[2010.09.17 21:50:27 | 000,002,301 | —- | M] () – C:\WINDOWS\hplj1010.hi1
[2010.09.17 21:50:27 | 000,000,648 | —- | M] () – C:\WINDOWS\hplj1010.bu1
[2010.09.17 21:27:47 | 000,000,073 | -HS- | M] () – C:\cj.ini
[2010.09.17 17:29:30 | 000,039,268 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010.09.17 17:12:26 | 000,001,709 | —- | M] () – C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2010.09.17 16:57:39 | 001,126,130 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Eigene Dateien\MMX6RegistryBackup_9-17-2010_16.57.37.reg
[2010.09.17 06:25:47 | 000,001,887 | —- | M] () – C:\Dokumente und Einstellungen\All Users\Desktop\Google Планета Земля.lnk
[2010.09.16 18:07:47 | 000,000,172 | —- | M] () – C:\WINDOWS\System32\drivers\NortonPCCheckup\0200060.00B\isolate.ini
[2010.09.15 20:39:26 | 000,041,984 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Corporate Identity steuern.doc
[2010.09.04 22:43:47 | 000,017,408 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Eigene Dateien\PR-Praktika & Jobs.xls
[2010.09.04 13:46:02 | 000,020,480 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Eigene Dateien\PR Praktikum und Job.doc
[2010.09.04 13:41:55 | 000,002,537 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Microsoft Office Excel 2003.lnk
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.09.26 21:49:46 | 001,193,882 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Desktop\tdsskiller.zip
[2010.09.26 14:59:47 | 2011,316,224 | -HS- | C] () – C:\hiberfil.sys
[2010.09.26 13:56:52 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\NortonPCCheckup\0200060.00B\isolate.ini
[2010.09.26 13:01:26 | 000,000,572 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Desktop\Opera.lnk
[2010.09.25 20:03:10 | 000,001,583 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Desktop\McAfee Security Scan Plus.lnk
[2010.09.25 20:01:23 | 000,001,566 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2010.09.25 14:00:24 | 000,645,356 | —- | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\Cat.DB
[2010.09.25 14:00:15 | 000,007,456 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010.09.25 14:00:15 | 000,000,805 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010.09.25 13:59:56 | 000,001,849 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Desktop\Norton AntiVirus.LNK
[2010.09.25 13:59:28 | 000,003,373 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\SymEFA.inf
[2010.09.25 13:59:28 | 000,002,792 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\SymDS.inf
[2010.09.25 13:59:28 | 000,001,473 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\SymNetV.inf
[2010.09.25 13:59:28 | 000,001,445 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\SymNet.inf
[2010.09.25 13:59:28 | 000,001,389 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\srtspx.inf
[2010.09.25 13:59:28 | 000,001,383 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\srtsp.inf
[2010.09.25 13:59:28 | 000,000,741 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\Iron.inf
[2010.09.25 13:59:09 | 000,007,787 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\symnetv.cat
[2010.09.25 13:59:09 | 000,007,446 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\SymNet.cat
[2010.09.25 13:59:09 | 000,007,444 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\SymEFA.cat
[2010.09.25 13:59:09 | 000,007,442 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\srtspx.cat
[2010.09.25 13:59:09 | 000,007,438 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\SymDS.cat
[2010.09.25 13:59:09 | 000,007,438 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\srtsp.cat
[2010.09.25 13:59:08 | 000,007,438 | R— | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\iron.cat
[2010.09.25 13:59:07 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\NAV\1201000.025\isolate.ini
[2010.09.25 13:28:09 | 000,000,000 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\N360BUOptions.ini
[2010.09.22 18:19:50 | 004,976,640 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\ntuser.dat
[2010.09.17 21:51:24 | 000,238,799 | —- | C] () – C:\WINDOWS\hplj1010.hi2
[2010.09.17 21:51:24 | 000,015,151 | —- | C] () – C:\WINDOWS\hplj1010.bu2
[2010.09.17 21:50:20 | 000,002,301 | —- | C] () – C:\WINDOWS\hplj1010.hi1
[2010.09.17 21:50:20 | 000,000,648 | —- | C] () – C:\WINDOWS\hplj1010.bu1
[2010.09.17 17:29:30 | 000,039,268 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010.09.17 16:57:39 | 001,126,130 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Eigene Dateien\MMX6RegistryBackup_9-17-2010_16.57.37.reg
[2010.09.17 06:25:47 | 000,001,887 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Desktop\Google Планета Земля.lnk
[2010.09.16 21:51:39 | 000,001,908 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Desktop\Norton PC Checkup.LNK
[2010.09.15 20:39:26 | 000,041,984 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Desktop\Corporate Identity steuern.doc
[2010.09.04 21:15:53 | 000,001,208 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3771985245-72322722-229232620-1006UA.job
[2010.09.04 21:15:51 | 000,001,156 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3771985245-72322722-229232620-1006Core.job
[2010.09.04 15:30:44 | 000,017,408 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Eigene Dateien\PR-Praktika & Jobs.xls
[2010.09.04 13:40:05 | 000,020,480 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Eigene Dateien\PR Praktikum und Job.doc
[2010.08.24 21:24:33 | 000,000,032 | —- | C] () – C:\WINDOWS\cd-start.INI
[2010.03.31 12:57:38 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010.03.06 14:16:18 | 000,000,000 | —- | C] () – C:\WINDOWS\prestopm.INI
[2010.03.06 14:08:41 | 000,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2010.03.06 14:08:01 | 000,000,191 | -H– | C] () – C:\WINDOWS\NsNetScan.ini
[2010.03.06 13:55:36 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\IPPCPUID.DLL
[2010.03.06 13:55:36 | 000,000,105 | —- | C] () – C:\WINDOWS\UMXADDIN.INI
[2010.03.06 13:55:36 | 000,000,093 | —- | C] () – C:\WINDOWS\PM20.INI
[2010.03.06 13:55:14 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2010.03.06 13:53:33 | 000,000,074 | —- | C] () – C:\WINDOWS\PMINI.ini
[2010.03.04 07:55:42 | 000,000,355 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009.07.05 13:32:15 | 000,001,759 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\QTSBandwidthCache
[2008.10.31 21:21:40 | 000,008,263 | —- | C] () – C:\WINDOWS\hplj1010.ini
[2008.10.31 21:20:58 | 000,000,375 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2008.10.31 21:20:56 | 000,000,998 | —- | C] () – C:\WINDOWS\hpbvnstp.ini
[2008.10.31 21:20:47 | 000,196,608 | R— | C] () – C:\WINDOWS\System32\hpbvnstp.dll
[2008.10.26 23:52:09 | 000,001,753 | —- | C] () – C:\WINDOWS\System32\Vadim_KBD.ini
[2007.08.31 15:10:01 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2007.08.31 15:10:01 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2007.08.31 15:09:50 | 000,001,162 | —- | C] () – C:\WINDOWS\System32\W32N55.INI
[2007.07.26 04:53:34 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007.07.26 04:49:28 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007.05.15 16:24:53 | 000,016,393 | —- | C] () – C:\WINDOWS\LxFrame.ini
[2007.05.15 16:24:35 | 000,000,031 | —- | C] () – C:\WINDOWS\LxTrans.INI
[2007.03.25 15:18:57 | 000,001,993 | —- | C] () – C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\hpzinstall.log
[2007.03.25 15:16:06 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
[2007.03.25 15:16:05 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007.03.24 22:11:58 | 000,000,468 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2007.03.24 22:11:58 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2007.03.24 22:11:58 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2007.03.17 20:06:56 | 000,000,084 | —- | C] () – C:\WINDOWS\winamp.ini
[2007.02.17 20:33:17 | 000,000,417 | —- | C] () – C:\WINDOWS\vbface.INI
[2007.02.11 03:15:52 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007.02.04 22:59:21 | 000,000,400 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007.01.21 20:50:54 | 000,038,912 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.01.15 04:18:25 | 000,001,753 | —- | C] () – C:\WINDOWS\System32\Sveta_KBD.ini
[2007.01.15 04:17:32 | 000,000,138 | —- | C] () – C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007.01.14 03:40:50 | 000,179,831 | —- | C] () – C:\WINDOWS\System32\drivers\VVBackd5.sys
[2007.01.14 03:38:21 | 000,001,753 | —- | C] () – C:\WINDOWS\System32\Viktor_KBD.ini
[2006.11.12 17:40:22 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\FKStampPainter20.dll
[2006.11.10 09:41:11 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006.10.10 04:53:10 | 000,000,420 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006.10.09 20:54:14 | 000,000,135 | R— | C] () – C:\WINDOWS\System32\lngEng.ini
[2006.10.09 20:54:14 | 000,000,117 | —- | C] () – C:\WINDOWS\System32\lngKor.ini
[2006.10.09 20:40:47 | 000,043,512 | —- | C] () – C:\WINDOWS\System32\drivers\RITCPT.SYS
[2006.10.09 20:40:39 | 000,005,088 | —- | C] () – C:\WINDOWS\System32\drivers\FBAPI.sys
[2006.10.09 20:40:39 | 000,001,755 | —- | C] () – C:\WINDOWS\System32\Administrator_KBD.ini
[2006.10.09 20:40:39 | 000,001,697 | —- | C] () – C:\WINDOWS\System32\MagicKBD.INI
[2006.10.09 20:40:36 | 000,003,425 | —- | C] () – C:\WINDOWS\System32\KBDR.INI
[2006.10.09 20:40:36 | 000,002,741 | —- | C] () – C:\WINDOWS\System32\KBDD.INI
[2006.10.09 20:40:36 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDO.INI
[2006.10.09 20:40:36 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDC.INI
[2006.10.09 20:40:36 | 000,002,606 | —- | C] () – C:\WINDOWS\System32\KBDB.INI
[2006.10.09 20:40:36 | 000,002,236 | —- | C] () – C:\WINDOWS\System32\KBDQ.INI
[2006.10.09 20:40:36 | 000,001,956 | —- | C] () – C:\WINDOWS\System32\KBDE.INI
[2006.10.09 20:40:36 | 000,001,885 | —- | C] () – C:\WINDOWS\System32\KBDP.INI
[2006.10.09 20:40:36 | 000,001,857 | —- | C] () – C:\WINDOWS\System32\KBDUU.INI
[2006.10.09 20:40:36 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDG.INI
[2006.10.09 20:40:36 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDA.INI
[2006.10.09 20:40:36 | 000,001,834 | —- | C] () – C:\WINDOWS\System32\KBDU.INI
[2006.10.09 20:40:36 | 000,001,819 | —- | C] () – C:\WINDOWS\System32\KBDN.INI
[2006.10.09 20:40:36 | 000,001,699 | —- | C] () – C:\WINDOWS\System32\KBDT.INI
[2006.10.09 20:40:36 | 000,001,697 | —- | C] () – C:\WINDOWS\System32\KBDV.INI
[2006.10.09 20:40:36 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\KBDS.INI
[2006.10.09 20:40:36 | 000,001,476 | —- | C] () – C:\WINDOWS\System32\KBDF.INI
[2006.10.09 20:38:15 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2006.10.09 20:38:08 | 000,000,508 | —- | C] () – C:\WINDOWS\SamsungBluetooth.ini
[2006.10.09 20:36:21 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2006.10.09 20:31:02 | 000,004,300 | —- | C] () – C:\WINDOWS\System32\MEMIO.SYS
[2006.10.06 18:43:16 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\LXPrnUtil10.dll
[2006.09.29 15:12:12 | 000,303,104 | —- | C] () – C:\WINDOWS\System32\dnt27VC8.dll
[2006.09.24 21:04:42 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\dntvmc27VC8.dll
[2006.09.24 21:03:32 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dntvm27VC8.dll
[2006.09.21 13:53:28 | 000,282,679 | —- | C] () – C:\WINDOWS\System32\dnt27.dll
[2006.09.21 13:52:24 | 000,077,882 | —- | C] () – C:\WINDOWS\System32\dntvmc27.dll
[2006.09.21 13:52:14 | 000,077,881 | —- | C] () – C:\WINDOWS\System32\dntvm27.dll
[2006.07.06 21:21:44 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\AVSAudioWideStereoDMO.dll
[2006.07.06 21:21:42 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\AVSAudioAmp.dll
[2005.11.09 12:13:48 | 000,282,624 | —- | C] () – C:\WINDOWS\System32\dnt27VC7.dll
[2005.11.09 12:11:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dntvmc27VC7.dll
[2005.11.09 12:11:30 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\dntvm27VC7.dll
[2005.08.05 14:26:04 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005.07.15 12:47:44 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\drivers\balu.sys
[2005.05.04 13:00:06 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\MMedia10VC7.dll
[2005.01.25 16:15:42 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\PA207USD.DLL
[2004.08.17 16:57:24 | 000,327,680 | —- | C] () – C:\WINDOWS\System32\QFClient2.dll
[2004.05.06 14:07:32 | 000,241,664 | —- | C] () – C:\WINDOWS\System32\dnt26VC7.dll
[2004.05.06 14:05:04 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dntvmc26VC7.dll
[2004.05.06 14:04:42 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dntvm26VC7.dll
[2003.09.05 12:25:54 | 000,237,623 | —- | C] () – C:\WINDOWS\System32\dnt26.dll
[2003.09.05 12:25:52 | 000,073,785 | —- | C] () – C:\WINDOWS\System32\dntvm26.dll
[2003.09.05 12:03:30 | 000,077,882 | —- | C] () – C:\WINDOWS\System32\dntvmc26.dll
[2003.07.14 17:10:57 | 000,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL
[2003.02.20 18:53:42 | 000,005,702 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001.12.12 11:41:36 | 000,041,472 | —- | C] () – C:\WINDOWS\System32\W32btstp.dll
[2001.12.12 11:41:36 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\W32btxlt.dll
[2001.10.10 08:57:58 | 000,073,786 | —- | C] () – C:\WINDOWS\System32\dntvmc23.dll
[2001.10.10 08:57:58 | 000,061,497 | —- | C] () – C:\WINDOWS\System32\dntvm23.dll
[2001.03.07 08:02:30 | 000,229,431 | —- | C] () – C:\WINDOWS\System32\dnt23.dll
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006.10.09 20:18:53 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010.09.17 22:12:43 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2004.08.10 14:00:00 | 000,004,952 | RHS- | M] () – C:\bootfont.bin
[2010.09.17 21:27:47 | 000,000,073 | -HS- | M] () – C:\cj.ini
[2006.10.09 20:18:53 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007.01.14 07:45:08 | 000,314,880 | -HS- | M] () – C:\ehthumbs.db
[2010.09.26 23:04:18 | 2011,316,224 | -HS- | M] () – C:\hiberfil.sys
[2008.12.06 22:49:25 | 000,024,294 | —- | M] () – C:\installer_debug.txt
[2006.10.09 20:18:53 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006.10.09 20:18:53 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004.08.10 14:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009.07.08 11:59:59 | 000,251,712 | RHS- | M] () – C:\ntldr
[2010.09.26 23:04:16 | 3016,753,152 | -HS- | M] () – C:\pagefile.sys
[2006.10.09 20:36:27 | 000,000,499 | —- | M] () – C:\RHDSetup.log
[2006.10.09 20:54:26 | 000,000,170 | —- | M] () – C:\Setup.log
[2007.11.09 23:14:01 | 000,230,432 | —- | M] () – C:\StiImg.dat
[2010.09.26 21:52:03 | 000,046,190 | —- | M] () – C:\TDSSKiller.2.4.2.1_26.09.2010_21.51.18_log.txt
[2010.09.26 22:09:29 | 000,044,550 | —- | M] () – C:\TDSSKiller.2.4.2.1_26.09.2010_22.08.39_log.txt
[2008.08.20 21:32:41 | 000,000,150 | —- | M] () – C:\YServer.txt
< %systemroot%\Fonts\*.com >
[2006.04.18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006.06.29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006.04.18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006.06.29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006.10.09 20:18:01 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004.02.09 00:00:00 | 000,026,285 | —- | M] (Brother Industries ,Ltd ) – C:\WINDOWS\system32\spool\prtprocs\w32x86\brmfpp1.dll
[2008.07.06 14:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007.04.09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008.07.06 12:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006.10.09 22:07:11 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006.10.09 22:07:11 | 000,663,552 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006.10.09 22:07:11 | 000,421,888 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006.10.09 20:31:26 | 000,000,079 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Desktop anzeigen.scf
[2007.01.15 04:18:15 | 000,000,175 | -HS- | M] () – C:\Dokumente und Einstellungen\Sveta\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010.09.26 22:03:49 | 000,050,688 | —- | M] (Atribune.org) – C:\Dokumente und Einstellungen\Sveta\Desktop\ATF_Cleaner.exe
[2010.09.26 22:06:35 | 000,071,398 | —- | M] (jpshortstuff) – C:\Dokumente und Einstellungen\Sveta\Desktop\GooredFix(2).exe
[2010.09.26 21:42:03 | 000,071,398 | —- | M] (jpshortstuff) – C:\Dokumente und Einstellungen\Sveta\Desktop\GooredFix.exe
[2010.09.26 23:13:21 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis(2).exe
[2010.09.26 23:16:51 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis(3).exe
[2010.09.26 21:59:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Dokumente und Einstellungen\Sveta\Desktop\HiJackThis.exe
[2010.09.27 05:33:33 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Dokumente und Einstellungen\Sveta\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2010.09.27 05:33:11 | 000,081,920 | -HS- | M] () – C:\Dokumente und Einstellungen\Sveta\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2007.06.29 12:02:06 | 000,318,464 | —- | M] (Microsoft Corporation) – C:\WINDOWS\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
[2006.01.27 13:58:26 | 000,479,232 | —- | M] (Intel Corporation) – C:\WINDOWS\Installer\iProInst.exe
[8 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.exe >
[2008.04.14 04:22:54 | 001,695,232 | —- | M] (Microsoft Corporation) – C:\Programme\Messenger\msmsgs.exe
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< %USERPROFILE%\Templates\*.tmp >
< %SYSTEMDRIVE%\explorexxx.exe\*.* >
< %Windir%\Installer\*.tmp >
[8 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
< %systemroot%\System32\*.xco >
< %ProgramFiles%\system32\*.* >
< %systemroot%\System32\windos\*.* >
< %SystemRoot%\system32\sandbox\*.* >
< %SystemRoot%\system32\*.amo >
< %SystemRoot%\system32\Windows Live\*.* >
< %ProgramFiles%\logs\*.* >
< %ProgramFiles%\Bifrost\*.* >
< %SystemRoot%\system32\*.goo >
< %systemroot%\system32\IME\*.* >
< %systemroot%\BackUp\*.* >
< %systemroot%\system32\*.ico >
[2005.12.28 12:04:18 | 000,000,766 | —- | M] () – C:\WINDOWS\system32\ACUICO.ico
[7 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system\*.dat >
< %systemroot%\system\*.exe >
< %AppData%\Macromedia\Common\*.* >
< %SYSTEMDRIVE%\dir\*.* /s >
< %systemroot%\system32\ras\*.exe >
< %SYSTEMDRIVE%\MFILES\*.* >
< %SYSTEMDRIVE%\mDNSRespon.exe\*.* >
< %systemroot%\system32\services\*.* >
< %systemroot%\Spooler\*.* >
< %ProgramFiles%\system32\*.* >
< %systemroot%\system32\Setup\*.dll /x >
< %systemroot%\system32\*.mine >
< %SYSTEMDRIVE%\cleansweep.exe\*.* >
< %systemroot%\system32\ras\*.dll >
< %systemroot%\system32\ras\*.drv >
< %systemroot%\*.iq >
< %systemroot%\system32\XP\*.* >
< %SYSTEMDRIVE%\Extracted\*.* >
< %systemroot%\system32\windows\*.* >
< %systemroot%\logs\*.* >
< %SYSTEMDRIVE%\Win.Msi\*.* >
< %systemroot%\regedit\*.* >
< %systemroot%\system32\skype\*.* >
< %AppData%\Adobe\dlluplwin25\*.* >
< %UserProfile%\*.dat >
[2010.09.26 23:02:55 | 004,976,640 | —- | M] () – C:\Dokumente und Einstellungen\Sveta\ntuser.dat
< %UserProfile%\*.dll >
< %systemroot%\system32\*.sxo >
< %SYSTEMDRIVE%\Gazma\*.* /s >
< %systemroot%\system32\spynet\*.* >
< %systemroot%\system32\System\*.* >
< %appdata%\Microsoft\Windows\*.* >
< %systemroot%\system32\WinDir\*.* >
< %systemroot%\_\*.* >
< %systemroot%\system32\windows32\*.* >
< %ProgramFiles%\win\*.* >
< %AppData%\Microsoft\CD Burning\*.* >
< %systemroot%\*.cab >
< %systemroot%\K.Backup\*.* >
< %ProgramFiles%\Massenger\*.* >
< %systemroot%\System32\*.doc >
< %systemroot%\Office12\*.* >
< %systemroot%\System32\Rundl32.exe\*.* >
< %ProgramFiles%\yahoo.net\*.* >
< %systemroot%\system32\*.igo >
< %systemroot%\*.rew >
< %systemroot%\System32\spool\DRIVERS\W32X86\3\*.exe >
[2002.06.29 03:01:00 | 000,100,864 | —- | M] (Brother Industries Ltd.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\brqikmon.exe
[2002.06.07 05:00:00 | 000,028,160 | —- | M] (SEIKO EPSON CORP.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\EPIBSR30.EXE
[2009.06.16 07:05:00 | 000,812,984 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\EPUPDATE.EXE
[2003.10.08 07:06:20 | 000,045,056 | —- | M] (SEIKO EPSON Corporation) – C:\WINDOWS\system32\spool\drivers\w32x86\3\EPUTIX24.EXE
[2003.01.14 04:00:00 | 000,151,552 | —- | M] (SEIKO EPSON CORP.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_DMSG00.EXE
[2003.01.09 05:00:00 | 000,144,384 | —- | M] (SEIKO EPSON CORP.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_DPPE03.EXE
[2006.09.25 04:06:00 | 000,253,952 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FAMDBEE.EXE
[2006.03.20 04:01:00 | 000,151,552 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FAMTBEE.EXE
[2006.03.20 04:02:00 | 000,118,784 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FARNBEE.EXE
[2006.09.21 04:01:00 | 000,139,264 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIBEE.EXE
[2006.09.14 01:01:00 | 000,155,648 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FBCSBEE.EXE
[2006.04.26 01:00:00 | 000,036,864 | —- | M] (SEIKO EPSON CORP.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FBSRBEE.EXE
[2006.10.16 09:50:00 | 000,084,480 | —- | M] (SEIKO EPSON Corporation) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FHUTBEE.EXE
[2009.03.10 04:00:00 | 000,204,800 | —- | M] (SEIKO EPSON CORP.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FPREBEE.EXE
[2004.02.19 07:03:00 | 000,065,536 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S00RP1.EXE
[2003.10.15 04:02:00 | 000,099,840 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S0HIC1.EXE
[2003.02.14 04:06:00 | 000,105,984 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10MT1.EXE
[2003.02.14 04:04:00 | 000,077,312 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10RN1.EXE
[2003.05.19 04:11:00 | 000,200,704 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S1T0A1.EXE
[2006.04.18 04:00:00 | 000,102,400 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S30RP1.EXE
[2003.05.16 05:13:00 | 000,139,264 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SIINS1.EXE
[2004.04.30 06:07:00 | 000,122,880 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\SAGENT4.EXE
< %USERPROFILE%\.COMMgr\*.* >
< %USERPROFILE%\Desktop\*.bat >
< %PROGRAMFILES%\Common Files\Real\visualizations\*.* >
< %PROGRAMFILES%\Internet Explorer\*.Jmp >
< %PROGRAMFILES%\Windows NT\system\*.dll >
< %systemroot%\system32\*.ext >
< %systemroot%\system32\Com\*.cfg >
< %systemroot%\system32\btz\*.* >
< %systemroot%\system32\EMP\*.* >
< %systemroot%\system32\expo\*.* >
< %systemroot%\system32\inet2\*.* >
< %systemroot%\system32\xrem\*.* >
< %ProgramFiles%\Microsoft\*.* >
< %systemroot%\usgwmt\*.* >
< %ProgramFiles%\B\*.* >
< %SYSTEMDRIVE%\lspp\*.* >
< %systemroot%\Kral\*.* >
< %SYSTEMDRIVE%\windowsdvd.exe\*.* >
< %systemroot%\system32\*.ipo >
< %SYSTEMDRIVE%\usxxxxxxxx.exe\*.* >
< %systemroot%\system32\*.mof >
< %systemroot%\*.atm >
< %systemroot%\system32\svhost\*.* >
< %ProgramFiles%\system32\*.* >
< %ProgramFiles%\Docmentt\*.* >
< %systemroot%\Help\*.vbs >
< %ProgramFiles%\Windows WinSxs\*.* /s >
< %ProgramFiles%\Outlook Express\IDT\*.* /s >
< %ProgramFiles%\Microsoft Office\365\*.* /s >
< %ProgramFiles%\Windows Live\*.* >
< %systemroot%\system32\win32\*.* >
< %SYSTEMDRIVE%\RECYCLER\*.* >
< %systemroot%\Fresh1\*.* >
< %ProgramFiles%\Kekj\*.* /s >
< %systemroot%\GDU\*.* >
< %systemroot%\KA\*.* >
< %systemroot%\R\*.* >
< %systemroot%\system32\*.fyo >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-27 16:27:26
< End of report >
I first read your answer today early in the morning. I was a bit in a harry so I did - by mistake - the scanning with OLT first without putting the
scan.txt inside of the
Custom Scan box . And the programme gave that
Extras.Txt . After that I put
scan.txt in the
Custom Scan box and did the scanning again, and after that I got the second file -
OTL.Txt
Here is the Extras.Txt, I got in the morning:
OTL Extras logfile created on: 27.09.2010 05:38:43 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Dokumente und Einstellungen\Sveta\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 68,00% Memory free
5,00 Gb Paging File | 4,00 Gb Available in Paging File | 91,00% Paging File free
Paging file location(s): C:\pagefile.sys 2877 2877 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 94,22 Gb Total Space | 68,37 Gb Free Space | 72,56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SVETLANA
Current User Name: Sveta
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Programme\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Programme\Gemeinsame Dateien\aol\ACS\AOLacsd.exe" = C:\Programme\Gemeinsame Dateien\aol\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Programme\Gemeinsame Dateien\aol\ACS\AOLDial.exe" = C:\Programme\Gemeinsame Dateien\aol\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Programme\AOL 9.0\waol.exe" = C:\Programme\AOL 9.0\waol.exe:*:Enabled:AOL 9.0 – File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Programme\Gemeinsame Dateien\aol\ACS\AOLacsd.exe" = C:\Programme\Gemeinsame Dateien\aol\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Programme\Gemeinsame Dateien\aol\ACS\AOLDial.exe" = C:\Programme\Gemeinsame Dateien\aol\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Programme\AOL 9.0\waol.exe" = C:\Programme\AOL 9.0\waol.exe:*:Enabled:AOL 9.0 – File not found
"C:\Programme\Google\Google Talk\googletalk.exe" = C:\Programme\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk – File not found
"C:\Programme\Yahoo!\Messenger\YahooMessenger.exe" = C:\Programme\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Programme\Yahoo!\Messenger\YServer.exe" = C:\Programme\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – File not found
"C:\Programme\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe" = C:\Programme\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe:*:Disabled:javaw – File not found
"C:\Programme\NewSoft\Presto! PageManager 6\NetGroup.exe" = C:\Programme\NewSoft\Presto! PageManager 6\NetGroup.exe:*:Enabled:NewSoft Network Group – (NewSoft Technology Corporation)
"C:\Programme\Java\jre6\bin\java.exe" = C:\Programme\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Anwendungsdaten\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Temp\7zS253.tmp\SymNRT.exe" = C:\Dokumente und Einstellungen\Sveta\Lokale Einstellungen\Temp\7zS253.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool – File not found
"C:\Programme\Opera\opera.exe" = C:\Programme\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{17283B95-21A8-4996-97DA-547A48DB266F}" = DisplayManager
"{17CA6206-7109-4426-8EE0-1BD0BE54BCC9}" = Management Center
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{18E65799-76BD-46EF-9E53-972FE5A40736}" = Opera 10.62
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = PowerStarter
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{22E95014-3038-4909-8708-48AE7FEFBF05}" = DSL Connection Manager
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{28DA872A-0848-48CF-B749-19A198157A2A}" = mDriver
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Magic Doctor
"{34A350D1-64FB-36D8-9D0C-1CD8E392DBA5}" = Google Talk Plugin
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}" = Skype Plugin Manager
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Планета Земля
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{580183A6-FF92-11D5-9294-0050BA073EEC}" = Presto! PageManager 6
"{593AFFA4-D08E-4272-BABB-420949D32A10}" = QUICKfind
"{5E7893B4-B73E-47D6-AEA8-1AF111E479CB}" = Lexware business office pro 2007 (Demo)
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Samsung Battery Manager
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79221CA7-A39A-4AE5-A558-B5D928393FC4}_is1" = File Extractor v0.9.9
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7B9A0203-AFB3-4C59-B844-0E41DC299848}" = Lexware business office pro 2007 (Demo)
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}" = ATI Parental Control & Encoder
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9F7AF7CD-E3D0-4C68-A3BA-C76C359B3AA8}" = LightScribe 1.4.105.1
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A999CE76-D054-4684-80C7-53FC9243E019}" = EasyBox
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABB14904-A11B-4F42-996C-80FD608A0F17}" = Samsung EDS
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.4 - Deutsch
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B18B7901-4025-4BFF-9DA2-BCC45F594DE2}" = Atheros WLAN Client
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{BD723E53-A42C-4702-AA04-1D74A0311590}" = Magic Keyboard
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C765D9FF-4A34-4BF1-9F91-E9A3C60C86FC}" = ArcSoft VideoImpression 2
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0
"{E12DA139-1E5B-46DB-BAEA-683DC9F27CBC}" = ATI Catalyst Control Center
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EF99C14B-17C2-4994-B5C1-EB204A343A6F}" = User's Guide
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = SENS LT56ADW Modem
"All ATI Software" = ATI - Dienstprogramm zur Deinstallation der Software
"AOL YGP Screensaver" = AOL Meine Fotos Bildschirmschoner
"ATI Display Driver" = ATI Display Driver
"EPSON Printer and Utilities" = EPSON-Drucker-Software
"HP Imaging Device Functions" = HP Imaging Device Functions 5.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"InstallShield_{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75
"InstallShield_{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSDOrganizer_is1" = MSD Organizer 7.50
"MSMONEYV70" = Microsoft Money 99
"NAV" = Norton AntiVirus
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NortonPCCheckup" = Norton PC Checkup
"ProInst" = Intel® PROSet/Wireless Software
"Radio France_is1" = Radio France 1.1.1
"RestoreIT!" = Recover Pro
"Skype_is1" = Skype 3.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ToolBand.SkypeIEToolbarToolbar" = Skype add-on for IE
"Uninstall_is1" = Uninstall 1.0.0.1
"Universal Extractor_is1" = Universal Extractor 1.6.1
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip Self-Extractor" = WinZip Self-Extractor
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 26.09.2010 16:48:54 | Computer Name = SVETLANA | Source = crypt32 | ID = 131080
Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer
von <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
ist fehlgeschlagen mit dem Fehler: Diese Netzwerkverbindung ist nicht vorhanden.
.
Error - 26.09.2010 16:48:54 | Computer Name = SVETLANA | Source = crypt32 | ID = 131083
Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen
Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
ist fehlgeschlagen mit dem Fehler: Ein erforderliches Zertifikat befindet sich
nicht im Gultigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel
in der signierten Datei. .
Error - 26.09.2010 16:48:54 | Computer Name = SVETLANA | Source = crypt32 | ID = 131080
Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer
von <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
ist fehlgeschlagen mit dem Fehler: Diese Netzwerkverbindung ist nicht vorhanden.
.
Error - 26.09.2010 16:48:54 | Computer Name = SVETLANA | Source = crypt32 | ID = 131083
Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen
Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
ist fehlgeschlagen mit dem Fehler: Ein erforderliches Zertifikat befindet sich
nicht im Gultigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel
in der signierten Datei. .
Error - 26.09.2010 16:48:54 | Computer Name = SVETLANA | Source = crypt32 | ID = 131080
Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer
von <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
ist fehlgeschlagen mit dem Fehler: Diese Netzwerkverbindung ist nicht vorhanden.
.
Error - 26.09.2010 16:49:05 | Computer Name = SVETLANA | Source = crypt32 | ID = 131080
Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer
von <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
ist fehlgeschlagen mit dem Fehler: A connection with the server could not be established
.
Error - 26.09.2010 16:49:05 | Computer Name = SVETLANA | Source = crypt32 | ID = 131080
Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer
von <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
ist fehlgeschlagen mit dem Fehler: Diese Netzwerkverbindung ist nicht vorhanden.
.
Error - 26.09.2010 17:04:40 | Computer Name = SVETLANA | Source = crypt32 | ID = 131083
Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen
Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
ist fehlgeschlagen mit dem Fehler: Ein erforderliches Zertifikat befindet sich
nicht im Gultigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel
in der signierten Datei. .
Error - 26.09.2010 17:04:40 | Computer Name = SVETLANA | Source = crypt32 | ID = 131083
Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen
Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
ist fehlgeschlagen mit dem Fehler: Ein erforderliches Zertifikat befindet sich
nicht im Gultigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel
in der signierten Datei. .
Error - 26.09.2010 17:04:42 | Computer Name = SVETLANA | Source = crypt32 | ID = 131080
Description = Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer
von <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
ist fehlgeschlagen mit dem Fehler: A connection with the server could not be established
.
[ System Events ]
Error - 26.09.2010 09:53:28 | Computer Name = SVETLANA | Source = Service Control Manager | ID = 7016
Description = Der Dienst "BrSplService" hat einen ungultigen aktuellen Status gemeldet:
0
Error - 26.09.2010 12:35:57 | Computer Name = SVETLANA | Source = Windows Update Agent | ID = 16
Description = Verbindung nicht moglich: Es konnte keine Verbindung mit dem Dienst
"Automatische Updates" hergestellt werden, daher konnen Updates nicht nach dem
angegebenen Zeitplan heruntergeladen und installiert werden. Es wird weiterhin versucht,
eine Verbindung herzustellen.
Error - 26.09.2010 14:11:52 | Computer Name = SVETLANA | Source = Ftdisk | ID = 262189
Description = Das System konnte den Treiber fur das Speicherabbild nicht laden.
Error - 26.09.2010 14:11:52 | Computer Name = SVETLANA | Source = Ftdisk | ID = 262193
Description = Die Konfiguration der Auslagerungsdatei fur das Speicherabbild ist
fehlgeschlagen. Stellen Sie sicher, dass eine Auslagerungsdatei auf der Startpartition
vorhanden ist und dass diese gro? genug ist, um den gesamten physikalischen Speicher
abbilden zu konnen.
Error - 26.09.2010 14:11:55 | Computer Name = SVETLANA | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Media Center Receiver Service" wurde mit folgendem Fehler
beendet: %%2147746132
Error - 26.09.2010 15:54:15 | Computer Name = SVETLANA | Source = sr | ID = 1
Description = Beim Verarbeiten der Datei "" auf Volume "HarddiskVolume1" ist im
Wiederherstellungsfilter der unerwartete Fehler "0xC0000001" aufgetreten. Die Volumeuberwachung
wurde angehalten.
Error - 26.09.2010 15:54:33 | Computer Name = SVETLANA | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Media Center Receiver Service" wurde mit folgendem Fehler
beendet: %%2147746132
Error - 26.09.2010 16:12:17 | Computer Name = SVETLANA | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Media Center Receiver Service" wurde mit folgendem Fehler
beendet: %%2147746132
Error - 26.09.2010 16:45:55 | Computer Name = SVETLANA | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Media Center Receiver Service" wurde mit folgendem Fehler
beendet: %%2147746132
Error - 26.09.2010 17:04:38 | Computer Name = SVETLANA | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Media Center Receiver Service" wurde mit folgendem Fehler
beendet: %%2147746132
< End of report >
May I use this Extras.Txt in the further process?
Thank you again for your help!!!
Hi Mimino,
The Extra.txt will only be produced the first time OTL was ran. The one you posted will be fine.
I see you ran some tools before posting here. I will need to see the logs from Combofix and TDSKiller.
The combofix log can be found at C:\combofix.txt. The TDSKiller log should be on the desktop. Please post both logs. Do not run the tools again.
How are you making out with the GMER scan?
Thanks
Hi oldman960!
I've just tried to run GMER. The scanning itself was actually OK, but I could't save the file (it seems to be rather big). So I'm going to repeat the whole thing again.
After that I'll look for those logs from Combofix and TDSKiller.
Thank you!
Hi oldman960!
The scanning with GMER runs without problem; no warnings while checking. There is one problem though - I can't save the log file (too big, I guess).
Good news: I can open the internetsites, which I couldn't open before (e.g. uploads from Microsoft and Symantec). No redirecting so far.
I'll look for the Combofix and TDSKiller logs later today.
Thank you!
Hi Mimino,
Did you uncheck the boxes as instructed?
Post the combofix log and the TDSKiller log. They will give us a starting point.
Hi oldman960!
Regarding GMER: the boxes IAT / EAT and Show all were unchecked.
I can't find Combofix file on my machine. As far as Iremember, I didn't run it - just downloaded.
I found two TDS Killer logs . They seem quite identicall, but I place them both here:
Log Nr. 1 :
2010/09/26 21:51:18.0015 TDSS rootkit removing tool 2.4.2.1 Sep 7 2010 14:43:44
2010/09/26 21:51:18.0015 ================================================================================
2010/09/26 21:51:18.0015 SystemInfo:
2010/09/26 21:51:18.0015
2010/09/26 21:51:18.0015 OS Version: 5.1.2600 ServicePack: 3.0
2010/09/26 21:51:18.0015 Product type: Workstation
2010/09/26 21:51:18.0015 ComputerName: SVETLANA
2010/09/26 21:51:18.0015 UserName: Sveta
2010/09/26 21:51:18.0015 Windows directory: C:\WINDOWS
2010/09/26 21:51:18.0015 System windows directory: C:\WINDOWS
2010/09/26 21:51:18.0015 Processor architecture: Intel x86
2010/09/26 21:51:18.0015 Number of processors: 2
2010/09/26 21:51:18.0015 Page size: 0x1000
2010/09/26 21:51:18.0015 Boot type: Normal boot
2010/09/26 21:51:18.0015 ================================================================================
2010/09/26 21:51:18.0703 Initialize success
2010/09/26 21:51:23.0125 ================================================================================
2010/09/26 21:51:23.0125 Scan started
2010/09/26 21:51:23.0125 Mode: Manual;
2010/09/26 21:51:23.0125 ================================================================================
2010/09/26 21:51:25.0171 ACPI (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/09/26 21:51:25.0218 ACPIEC (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2010/09/26 21:51:25.0406 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2010/09/26 21:51:25.0468 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2010/09/26 21:51:25.0593 AgereSoftModem (90456051c422e09bc36e6340dd891f0c) C:\WINDOWS\system32\DRIVERS\AGRSM.sys
2010/09/26 21:51:26.0031 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/09/26 21:51:26.0062 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/09/26 21:51:26.0281 ati2mtag (d371d3f40051a1f602c85cef5c787d76) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2010/09/26 21:51:26.0453 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2010/09/26 21:51:26.0515 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2010/09/26 21:51:26.0578 BALU (94a2be1176051be5db2eba07cf53e4bb) C:\WINDOWS\system32\DRIVERS\balu.sys
2010/09/26 21:51:26.0640 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2010/09/26 21:51:26.0859 BHDrvx86 (5138da8715da5f9823b753b6cb36a9a9) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20100901.003\BHDrvx86.sys
2010/09/26 21:51:27.0046 BrScnUsb (6cf3aed19c2185c60de2ae50ee37a342) C:\WINDOWS\system32\Drivers\BrScnUsb.sys
2010/09/26 21:51:27.0125 BTWUSB (50dd29591e9e6c24e262854ab1d4ea20) C:\WINDOWS\system32\Drivers\btwusb.sys
2010/09/26 21:51:27.0187 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2010/09/26 21:51:27.0250 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2010/09/26 21:51:27.0343 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2010/09/26 21:51:27.0468 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2010/09/26 21:51:27.0500 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2010/09/26 21:51:27.0578 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2010/09/26 21:51:27.0625 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2010/09/26 21:51:27.0765 Disk (56c1b758c6a15586a845899a8cc58bf8) C:\WINDOWS\system32\DRIVERS\disk.sys
2010/09/26 21:51:27.0765 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\disk.sys. Real md5: 56c1b758c6a15586a845899a8cc58bf8, Fake md5: 044452051f3e02e7963599fc8f4f3e25
2010/09/26 21:51:27.0781 Disk - detected Rootkit.Win32.TDSS.tdl3 (0)
2010/09/26 21:51:27.0859 dmboot (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
2010/09/26 21:51:28.0015 dmio (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
2010/09/26 21:51:28.0046 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2010/09/26 21:51:28.0093 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2010/09/26 21:51:28.0156 DNSeFilter (459a946c0766aa3d342d0f0ded90cf8d) C:\WINDOWS\system32\drivers\SamsungEDS.sys
2010/09/26 21:51:28.0203 DOSMEMIO (8a4cb9438571814b128b6dc30d698064) C:\WINDOWS\system32\MEMIO.SYS
2010/09/26 21:51:28.0390 Dot4 (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys
2010/09/26 21:51:28.0453 Dot4Print (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
2010/09/26 21:51:28.0531 dot4usb (29e86af2f3457d0441348020fe3cfbd0) C:\WINDOWS\system32\DRIVERS\dot4usb.sys
2010/09/26 21:51:28.0609 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2010/09/26 21:51:28.0703 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys
2010/09/26 21:51:28.0781 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
2010/09/26 21:51:28.0937 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2010/09/26 21:51:29.0000 FBAPI (47c5ac0b87567b0876081183de9a4704) C:\WINDOWS\system32\drivers\FBAPI.sys
2010/09/26 21:51:29.0031 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2010/09/26 21:51:29.0062 Fips (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
2010/09/26 21:51:29.0093 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2010/09/26 21:51:29.0140 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2010/09/26 21:51:29.0281 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2010/09/26 21:51:29.0312 Ftdisk (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2010/09/26 21:51:29.0375 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2010/09/26 21:51:29.0453 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2010/09/26 21:51:29.0625 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2010/09/26 21:51:29.0765 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2010/09/26 21:51:29.0796 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2010/09/26 21:51:29.0828 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2010/09/26 21:51:29.0921 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2010/09/26 21:51:30.0375 i8042prt (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2010/09/26 21:51:30.0593 IDSxpx86 (231c3f6d5c520e99924e1e37401a90c4) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20100924.001\IDSxpx86.sys
2010/09/26 21:51:30.0718 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2010/09/26 21:51:31.0046 IntcAzAudAddService (2389f12f0ed506176b7c29c8144cea09) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2010/09/26 21:51:31.0250 intelppm (4c7d2750158ed6e7ad642d97bffae351) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2010/09/26 21:51:31.0312 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2010/09/26 21:51:31.0375 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2010/09/26 21:51:31.0437 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2010/09/26 21:51:31.0562 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2010/09/26 21:51:31.0593 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2010/09/26 21:51:31.0656 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2010/09/26 21:51:31.0718 isapnp (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2010/09/26 21:51:31.0765 Kbdclass (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2010/09/26 21:51:31.0812 kbdhid (b6d6c117d771c98130497265f26d1882) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2010/09/26 21:51:31.0875 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2010/09/26 21:51:32.0000 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2010/09/26 21:51:32.0125 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
2010/09/26 21:51:32.0171 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2010/09/26 21:51:32.0203 Modem (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
2010/09/26 21:51:32.0234 Mouclass (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2010/09/26 21:51:32.0296 mouhid (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2010/09/26 21:51:32.0421 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2010/09/26 21:51:32.0468 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2010/09/26 21:51:32.0546 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2010/09/26 21:51:32.0671 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2010/09/26 21:51:32.0750 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010/09/26 21:51:32.0796 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010/09/26 21:51:32.0828 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2010/09/26 21:51:32.0875 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2010/09/26 21:51:32.0984 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2010/09/26 21:51:33.0046 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2010/09/26 21:51:33.0078 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2010/09/26 21:51:33.0343 NAVENG (0953bb24c1e70a99c315f44f15993c17) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20100926.003\NAVENG.SYS
2010/09/26 21:51:33.0437 NAVEX15 (3ddb0bef60b65df6b110c23e17cd67dc) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20100926.003\NAVEX15.SYS
2010/09/26 21:51:33.0578 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2010/09/26 21:51:33.0609 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2010/09/26 21:51:33.0656 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2010/09/26 21:51:33.0687 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2010/09/26 21:51:33.0734 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2010/09/26 21:51:33.0781 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
2010/09/26 21:51:33.0812 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2010/09/26 21:51:33.0937 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2010/09/26 21:51:34.0015 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2010/09/26 21:51:34.0062 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2010/09/26 21:51:34.0203 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2010/09/26 21:51:34.0250 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2010/09/26 21:51:34.0265 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2010/09/26 21:51:34.0390 Parport (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\drivers\Parport.sys
2010/09/26 21:51:34.0437 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2010/09/26 21:51:34.0484 ParVdm (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
2010/09/26 21:51:34.0546 PCI (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
2010/09/26 21:51:34.0671 PCIIde (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
2010/09/26 21:51:34.0703 Pcmcia (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2010/09/26 21:51:34.0921 pfc (6c1618a07b49e3873582b6449e744088) C:\WINDOWS\system32\drivers\pfc.sys
2010/09/26 21:51:35.0015 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2010/09/26 21:51:35.0046 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2010/09/26 21:51:35.0093 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2010/09/26 21:51:35.0218 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2010/09/26 21:51:35.0421 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2010/09/26 21:51:35.0468 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2010/09/26 21:51:35.0500 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2010/09/26 21:51:35.0531 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2010/09/26 21:51:35.0578 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2010/09/26 21:51:35.0640 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2010/09/26 21:51:35.0750 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2010/09/26 21:51:35.0812 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2010/09/26 21:51:35.0875 redbook (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
2010/09/26 21:51:35.0937 rimmptsk (7a6648b61661b1421ffab762e391e33f) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
2010/09/26 21:51:35.0953 rimsptsk (8f7012d1b6a71ee9c23ce93dcdbf9f4b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
2010/09/26 21:51:36.0000 rismxdp (3ac17802740c3a4764dc9750e92e6233) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
2010/09/26 21:51:36.0046 RITCPT (f76971070b64a4e7ea3da23b772ca356) C:\WINDOWS\system32\drivers\RITCPT.sys
2010/09/26 21:51:36.0125 RTL8023xp (7988bfe882bcd94199225b5c3482f1bd) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys
2010/09/26 21:51:36.0234 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
2010/09/26 21:51:36.0312 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
2010/09/26 21:51:36.0359 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2010/09/26 21:51:36.0421 Serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2010/09/26 21:51:36.0453 Serial (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\drivers\Serial.sys
2010/09/26 21:51:36.0515 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys
2010/09/26 21:51:36.0625 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys
2010/09/26 21:51:36.0687 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2010/09/26 21:51:36.0765 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2010/09/26 21:51:36.0843 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2010/09/26 21:51:36.0875 sr (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
2010/09/26 21:51:37.0015 SRTSP (d0ab8e989935d895f1bed8f607fa0948) C:\WINDOWS\system32\drivers\NAV\1201000.025\SRTSP.SYS
2010/09/26 21:51:37.0156 SRTSPX (fae9f5558a1f53670e579f9ffb4a67cc) C:\WINDOWS\system32\drivers\NAV\1201000.025\SRTSPX.SYS
2010/09/26 21:51:37.0218 Srv (da852e3e0bf1cea75d756f9866241e57) C:\WINDOWS\system32\DRIVERS\srv.sys
2010/09/26 21:51:37.0328 SSB2413 (50f32945c148d5a866c1f55bd89097e5) C:\WINDOWS\system32\DRIVERS\SSB2413.sys
2010/09/26 21:51:37.0406 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2010/09/26 21:51:37.0500 SUEPD (c0137b5947ae3d3fc1c17ba6fdfb3dad) C:\WINDOWS\system32\DRIVERS\SUE_PD.sys
2010/09/26 21:51:37.0593 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2010/09/26 21:51:37.0656 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2010/09/26 21:51:37.0843 SymDS (67e83f8c7e80dc898a1d73b38412ba7a) C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMDS.SYS
2010/09/26 21:51:37.0984 SymEFA (3986a8de371e985ba6c82eb8da3b1e98) C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMEFA.SYS
2010/09/26 21:51:38.0078 SymEvent (5c76a63fac8a5580c5a1c4a4ed827782) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
2010/09/26 21:51:38.0140 SymIRON (8ae632773b5192dce48f4ec8de753863) C:\WINDOWS\system32\drivers\NAV\1201000.025\Ironx86.SYS
2010/09/26 21:51:38.0281 SYMTDI (34ff2368b7914d1b29d16aba865e982d) C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMTDI.SYS
2010/09/26 21:51:38.0531 SynTP (91ce9afbbd011ff6b0ae15ee3a62edcc) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2010/09/26 21:51:38.0593 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2010/09/26 21:51:38.0656 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2010/09/26 21:51:38.0781 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2010/09/26 21:51:38.0828 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2010/09/26 21:51:38.0890 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2010/09/26 21:51:38.0984 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2010/09/26 21:51:39.0093 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2010/09/26 21:51:39.0234 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2010/09/26 21:51:39.0296 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2010/09/26 21:51:39.0343 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2010/09/26 21:51:39.0375 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
2010/09/26 21:51:39.0406 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2010/09/26 21:51:39.0468 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2010/09/26 21:51:39.0484 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2010/09/26 21:51:39.0546 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2010/09/26 21:51:39.0703 VolSnap (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
2010/09/26 21:51:39.0750 VVBackd5 (f653c52252a6935864a6913ae863004b) C:\WINDOWS\system32\drivers\VVBackd5.sys
2010/09/26 21:51:39.0828 w200bus (34923e278eac7ddcea717ae1fcf592f6) C:\WINDOWS\system32\DRIVERS\w200bus.sys
2010/09/26 21:51:39.0875 w200mdfl (eff90a983cd3deab05922242e8072dc6) C:\WINDOWS\system32\DRIVERS\w200mdfl.sys
2010/09/26 21:51:40.0000 w200mdm (f03da4fbb2708a0b5409ea63e88c0f50) C:\WINDOWS\system32\DRIVERS\w200mdm.sys
2010/09/26 21:51:40.0046 w200obex (8405be0bba1ccf26d0fbdd26be03c816) C:\WINDOWS\system32\DRIVERS\w200obex.sys
2010/09/26 21:51:40.0109 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2010/09/26 21:51:40.0187 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2010/09/26 21:51:40.0312 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2010/09/26 21:51:40.0359 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2010/09/26 21:51:40.0468 ZDCNDIS5 (78f79ac18214e335442ed8cddf09cd6b) C:\WINDOWS\ZDCNDIS5.sys
2010/09/26 21:51:40.0515 ================================================================================
2010/09/26 21:51:40.0515 Scan finished
2010/09/26 21:51:40.0515 ================================================================================
2010/09/26 21:51:40.0531 Detected object count: 1
2010/09/26 21:51:55.0828 Disk (56c1b758c6a15586a845899a8cc58bf8) C:\WINDOWS\system32\DRIVERS\disk.sys
2010/09/26 21:51:55.0828 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\disk.sys. Real md5: 56c1b758c6a15586a845899a8cc58bf8, Fake md5: 044452051f3e02e7963599fc8f4f3e25
2010/09/26 21:51:56.0578 Backup copy found, using it..
2010/09/26 21:51:56.0937 C:\WINDOWS\system32\DRIVERS\disk.sys - will be cured after reboot
2010/09/26 21:51:56.0937 Rootkit.Win32.TDSS.tdl3(Disk) - User select action: Cure
2010/09/26 21:52:03.0031 Deinitialize success
Log Nr. 2 :
2010/09/26 22:08:39.0015 TDSS rootkit removing tool 2.4.2.1 Sep 7 2010 14:43:44
2010/09/26 22:08:39.0015 ================================================================================
2010/09/26 22:08:39.0015 SystemInfo:
2010/09/26 22:08:39.0015
2010/09/26 22:08:39.0015 OS Version: 5.1.2600 ServicePack: 3.0
2010/09/26 22:08:39.0015 Product type: Workstation
2010/09/26 22:08:39.0015 ComputerName: SVETLANA
2010/09/26 22:08:39.0015 UserName: Sveta
2010/09/26 22:08:39.0015 Windows directory: C:\WINDOWS
2010/09/26 22:08:39.0015 System windows directory: C:\WINDOWS
2010/09/26 22:08:39.0015 Processor architecture: Intel x86
2010/09/26 22:08:39.0015 Number of processors: 2
2010/09/26 22:08:39.0015 Page size: 0x1000
2010/09/26 22:08:39.0015 Boot type: Normal boot
2010/09/26 22:08:39.0015 ================================================================================
2010/09/26 22:08:39.0671 Initialize success
2010/09/26 22:08:40.0937 ================================================================================
2010/09/26 22:08:40.0937 Scan started
2010/09/26 22:08:40.0937 Mode: Manual;
2010/09/26 22:08:40.0937 ================================================================================
2010/09/26 22:08:42.0250 ACPI (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/09/26 22:08:42.0296 ACPIEC (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2010/09/26 22:08:42.0390 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2010/09/26 22:08:42.0500 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2010/09/26 22:08:42.0625 AgereSoftModem (90456051c422e09bc36e6340dd891f0c) C:\WINDOWS\system32\DRIVERS\AGRSM.sys
2010/09/26 22:08:43.0046 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/09/26 22:08:43.0093 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/09/26 22:08:43.0203 ati2mtag (d371d3f40051a1f602c85cef5c787d76) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2010/09/26 22:08:43.0328 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2010/09/26 22:08:43.0390 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2010/09/26 22:08:43.0437 BALU (94a2be1176051be5db2eba07cf53e4bb) C:\WINDOWS\system32\DRIVERS\balu.sys
2010/09/26 22:08:43.0515 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2010/09/26 22:08:43.0734 BHDrvx86 (5138da8715da5f9823b753b6cb36a9a9) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20100901.003\BHDrvx86.sys
2010/09/26 22:08:43.0890 BrScnUsb (6cf3aed19c2185c60de2ae50ee37a342) C:\WINDOWS\system32\Drivers\BrScnUsb.sys
2010/09/26 22:08:43.0953 BTWUSB (50dd29591e9e6c24e262854ab1d4ea20) C:\WINDOWS\system32\Drivers\btwusb.sys
2010/09/26 22:08:44.0000 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2010/09/26 22:08:44.0062 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2010/09/26 22:08:44.0140 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2010/09/26 22:08:44.0187 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2010/09/26 22:08:44.0296 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2010/09/26 22:08:44.0375 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2010/09/26 22:08:44.0421 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2010/09/26 22:08:44.0703 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2010/09/26 22:08:44.0796 dmboot (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys
2010/09/26 22:08:44.0921 dmio (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys
2010/09/26 22:08:44.0968 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2010/09/26 22:08:45.0015 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2010/09/26 22:08:45.0093 DNSeFilter (459a946c0766aa3d342d0f0ded90cf8d) C:\WINDOWS\system32\drivers\SamsungEDS.sys
2010/09/26 22:08:45.0140 DOSMEMIO (8a4cb9438571814b128b6dc30d698064) C:\WINDOWS\system32\MEMIO.SYS
2010/09/26 22:08:45.0343 Dot4 (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys
2010/09/26 22:08:45.0406 Dot4Print (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
2010/09/26 22:08:45.0484 dot4usb (29e86af2f3457d0441348020fe3cfbd0) C:\WINDOWS\system32\DRIVERS\dot4usb.sys
2010/09/26 22:08:45.0562 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2010/09/26 22:08:45.0671 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys
2010/09/26 22:08:45.0750 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
2010/09/26 22:08:45.0890 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2010/09/26 22:08:45.0968 FBAPI (47c5ac0b87567b0876081183de9a4704) C:\WINDOWS\system32\drivers\FBAPI.sys
2010/09/26 22:08:46.0015 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2010/09/26 22:08:46.0046 Fips (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys
2010/09/26 22:08:46.0078 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2010/09/26 22:08:46.0140 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2010/09/26 22:08:46.0250 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2010/09/26 22:08:46.0281 Ftdisk (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2010/09/26 22:08:46.0343 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2010/09/26 22:08:46.0390 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2010/09/26 22:08:46.0453 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2010/09/26 22:08:46.0562 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2010/09/26 22:08:46.0640 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2010/09/26 22:08:46.0687 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2010/09/26 22:08:46.0750 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2010/09/26 22:08:46.0968 i8042prt (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2010/09/26 22:08:47.0203 IDSxpx86 (231c3f6d5c520e99924e1e37401a90c4) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20100924.001\IDSxpx86.sys
2010/09/26 22:08:47.0312 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2010/09/26 22:08:47.0625 IntcAzAudAddService (2389f12f0ed506176b7c29c8144cea09) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2010/09/26 22:08:47.0875 intelppm (4c7d2750158ed6e7ad642d97bffae351) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2010/09/26 22:08:47.0921 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2010/09/26 22:08:47.0968 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2010/09/26 22:08:48.0015 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2010/09/26 22:08:48.0062 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2010/09/26 22:08:48.0156 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2010/09/26 22:08:48.0203 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2010/09/26 22:08:48.0250 isapnp (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2010/09/26 22:08:48.0296 Kbdclass (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2010/09/26 22:08:48.0343 kbdhid (b6d6c117d771c98130497265f26d1882) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2010/09/26 22:08:48.0406 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2010/09/26 22:08:48.0437 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2010/09/26 22:08:48.0656 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
2010/09/26 22:08:48.0703 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2010/09/26 22:08:48.0781 Modem (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys
2010/09/26 22:08:48.0875 Mouclass (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2010/09/26 22:08:48.0953 mouhid (66a6f73c74e1791464160a7065ce711a) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2010/09/26 22:08:49.0015 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2010/09/26 22:08:49.0125 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2010/09/26 22:08:49.0218 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2010/09/26 22:08:49.0375 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2010/09/26 22:08:49.0421 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010/09/26 22:08:49.0484 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010/09/26 22:08:49.0515 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2010/09/26 22:08:49.0578 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2010/09/26 22:08:49.0625 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2010/09/26 22:08:49.0656 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2010/09/26 22:08:49.0703 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2010/09/26 22:08:49.0984 NAVENG (0953bb24c1e70a99c315f44f15993c17) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20100926.003\NAVENG.SYS
2010/09/26 22:08:50.0093 NAVEX15 (3ddb0bef60b65df6b110c23e17cd67dc) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20100926.003\NAVEX15.SYS
2010/09/26 22:08:50.0218 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2010/09/26 22:08:50.0265 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2010/09/26 22:08:50.0328 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2010/09/26 22:08:50.0359 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2010/09/26 22:08:50.0406 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2010/09/26 22:08:50.0468 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
2010/09/26 22:08:50.0500 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2010/09/26 22:08:50.0609 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2010/09/26 22:08:50.0718 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2010/09/26 22:08:50.0781 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2010/09/26 22:08:50.0906 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2010/09/26 22:08:50.0953 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2010/09/26 22:08:50.0984 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2010/09/26 22:08:51.0109 Parport (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\drivers\Parport.sys
2010/09/26 22:08:51.0125 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2010/09/26 22:08:51.0187 ParVdm (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys
2010/09/26 22:08:51.0234 PCI (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys
2010/09/26 22:08:51.0312 PCIIde (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys
2010/09/26 22:08:51.0406 Pcmcia (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2010/09/26 22:08:51.0671 pfc (6c1618a07b49e3873582b6449e744088) C:\WINDOWS\system32\drivers\pfc.sys
2010/09/26 22:08:51.0781 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2010/09/26 22:08:51.0812 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2010/09/26 22:08:51.0875 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2010/09/26 22:08:51.0937 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2010/09/26 22:08:52.0156 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2010/09/26 22:08:52.0250 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2010/09/26 22:08:52.0281 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2010/09/26 22:08:52.0343 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2010/09/26 22:08:52.0375 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2010/09/26 22:08:52.0421 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2010/09/26 22:08:52.0484 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2010/09/26 22:08:52.0546 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2010/09/26 22:08:52.0609 redbook (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys
2010/09/26 22:08:52.0687 rimmptsk (7a6648b61661b1421ffab762e391e33f) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
2010/09/26 22:08:52.0734 rimsptsk (8f7012d1b6a71ee9c23ce93dcdbf9f4b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
2010/09/26 22:08:52.0781 rismxdp (3ac17802740c3a4764dc9750e92e6233) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
2010/09/26 22:08:52.0843 RITCPT (f76971070b64a4e7ea3da23b772ca356) C:\WINDOWS\system32\drivers\RITCPT.sys
2010/09/26 22:08:53.0000 RTL8023xp (7988bfe882bcd94199225b5c3482f1bd) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys
2010/09/26 22:08:53.0046 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
2010/09/26 22:08:53.0171 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
2010/09/26 22:08:53.0250 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2010/09/26 22:08:53.0343 Serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2010/09/26 22:08:53.0375 Serial (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\drivers\Serial.sys
2010/09/26 22:08:53.0484 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys
2010/09/26 22:08:53.0578 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys
2010/09/26 22:08:53.0640 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2010/09/26 22:08:53.0734 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2010/09/26 22:08:53.0843 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2010/09/26 22:08:53.0875 sr (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys
2010/09/26 22:08:54.0015 SRTSP (d0ab8e989935d895f1bed8f607fa0948) C:\WINDOWS\system32\drivers\NAV\1201000.025\SRTSP.SYS
2010/09/26 22:08:54.0140 SRTSPX (fae9f5558a1f53670e579f9ffb4a67cc) C:\WINDOWS\system32\drivers\NAV\1201000.025\SRTSPX.SYS
2010/09/26 22:08:54.0187 Srv (da852e3e0bf1cea75d756f9866241e57) C:\WINDOWS\system32\DRIVERS\srv.sys
2010/09/26 22:08:54.0296 SSB2413 (50f32945c148d5a866c1f55bd89097e5) C:\WINDOWS\system32\DRIVERS\SSB2413.sys
2010/09/26 22:08:54.0390 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2010/09/26 22:08:54.0515 SUEPD (c0137b5947ae3d3fc1c17ba6fdfb3dad) C:\WINDOWS\system32\DRIVERS\SUE_PD.sys
2010/09/26 22:08:54.0593 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2010/09/26 22:08:54.0656 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2010/09/26 22:08:54.0859 SymDS (67e83f8c7e80dc898a1d73b38412ba7a) C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMDS.SYS
2010/09/26 22:08:55.0000 SymEFA (3986a8de371e985ba6c82eb8da3b1e98) C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMEFA.SYS
2010/09/26 22:08:55.0109 SymEvent (5c76a63fac8a5580c5a1c4a4ed827782) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
2010/09/26 22:08:55.0234 SymIRON (8ae632773b5192dce48f4ec8de753863) C:\WINDOWS\system32\drivers\NAV\1201000.025\Ironx86.SYS
2010/09/26 22:08:55.0312 SYMTDI (34ff2368b7914d1b29d16aba865e982d) C:\WINDOWS\system32\drivers\NAV\1201000.025\SYMTDI.SYS
2010/09/26 22:08:55.0453 SynTP (91ce9afbbd011ff6b0ae15ee3a62edcc) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2010/09/26 22:08:55.0515 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2010/09/26 22:08:55.0625 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2010/09/26 22:08:55.0703 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2010/09/26 22:08:55.0781 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2010/09/26 22:08:55.0828 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2010/09/26 22:08:55.0921 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2010/09/26 22:08:56.0031 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2010/09/26 22:08:56.0140 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2010/09/26 22:08:56.0218 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2010/09/26 22:08:56.0250 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2010/09/26 22:08:56.0281 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
2010/09/26 22:08:56.0328 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2010/09/26 22:08:56.0390 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2010/09/26 22:08:56.0484 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2010/09/26 22:08:56.0546 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2010/09/26 22:08:56.0640 VolSnap (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys
2010/09/26 22:08:56.0734 VVBackd5 (f653c52252a6935864a6913ae863004b) C:\WINDOWS\system32\drivers\VVBackd5.sys
2010/09/26 22:08:56.0859 w200bus (34923e278eac7ddcea717ae1fcf592f6) C:\WINDOWS\system32\DRIVERS\w200bus.sys
2010/09/26 22:08:56.0937 w200mdfl (eff90a983cd3deab05922242e8072dc6) C:\WINDOWS\system32\DRIVERS\w200mdfl.sys
2010/09/26 22:08:56.0984 w200mdm (f03da4fbb2708a0b5409ea63e88c0f50) C:\WINDOWS\system32\DRIVERS\w200mdm.sys
2010/09/26 22:08:57.0046 w200obex (8405be0bba1ccf26d0fbdd26be03c816) C:\WINDOWS\system32\DRIVERS\w200obex.sys
2010/09/26 22:08:57.0109 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2010/09/26 22:08:57.0281 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2010/09/26 22:08:57.0484 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2010/09/26 22:08:57.0531 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2010/09/26 22:08:57.0593 ZDCNDIS5 (78f79ac18214e335442ed8cddf09cd6b) C:\WINDOWS\ZDCNDIS5.sys
2010/09/26 22:08:58.0375 ================================================================================
2010/09/26 22:08:58.0375 Scan finished
2010/09/26 22:08:58.0375 ================================================================================
2010/09/26 22:09:29.0953 Deinitialize success
I have a question: my Norton Antivirus offers a kind of special antivirus programm Norton Power Eraser - should I try it ?
Many thanks again!
Hi Mimino,
I have a question: my Norton Antivirus offers a kind of special antivirus programm Norton Power Eraser - should I try it ?
Please do not use it while we are cleaning this machine.
From Symantec
there is a risk that it can select some legitimate programs for removal. You should use this tool very carefully, and only after you have exhausted other options.
http://security.symantec.com/nbrt/npe.asp?lcid=4105
TDSKiller found and replaced an infected driver. It seemed have worked because the second TDSKiller log is clean.
Don't worry about GMER for the moment.
Please download
MBR.exe and save it to your
desktop
Double click on the
MBR.exe file to run it.
A log will be produced,
MBR.log on your desktop.
Please open this log in Notepad and post its contents in your next reply.
Please post back with
How is the computer? Any problems?
Thanks
Hi oldman960!
I downloaded MBR.exe and started it, but there was nothing after it, just a little black window appeared for a sec. - there was something written on it, but I couldn't read. No MBR log files either.
The computer runs perfectly - no redirections, all the sites are accesible. I didn't noticed anything.
As you say, TDS Killer found something, but it didn't solve my redirection problem and the connection to some webpages was also only partly possible - only with Opera in turbo regime. This is why I came to the forum.
I think, that stuff you placed here at the very beginning of our conversation have made the job - no problems after that.
Thanks a lot!
Hi
It looks like mbr.exe ran correctly. The log will be located in the same place you ran it from. I asked you to download it to your desktop so the log should be on the desktop. However if you downloaded it to a different location then the log would be found there.
Hi oldman960!
OK, I managed to start MBR.exe - after unpacking…
Here is the log:
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 1 !
Thanks!
Hi Mimino,
Thanks, that looks ok.
You have old outdated vulnerable java installed.
Go to Start > Control Panel > Add/Remove programs and uninstall
2SE Runtime Environment 5.0
Java™ 6 Update 3
Java™ 6 Update 7
Do not uninstall
Java™ 6 Update 14
Still in Control panel.
Locate the Java icon (it looks like a coffee cup) double click it to open it click the Update tab Click update now
After the java is updated, reboot your computer if not prompted to.
Next
Double click on
OTL.exe Under the Custom Scans/Fixes box at the bottom, paste in the following Do Not copy the word CODE please note the fix starts with the :
:Services
:Files
ipconfig /flushdns /c
:Commands
[emptytemp]
[Reboot]
Then click the
Run Fix button at the top
Let the program run unhindered Please save the resulting log to be posted in your next reply.
Next
Download and save to your desktop
Malwarebytes Anti-Malware
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware , then click Finish. If an update is found, it will download and install the latest version. Once the program has loaded, select "Perform Quick Scan ", then click Scan . The scan may take some time to finish,so please be patient. When the scan is complete, click OK, then Show Results to view the results. Make sure that everything is checked , and click Remove Selected . When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note) The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
Please post back with
Thanks
Hi oldman960!
Java is udated.
Here is the last OTL log:
All processes killed
========== SERVICES/DRIVERS ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Auflцsungscache wurde geleert.
C:\Dokumente und Einstellungen\Sveta\Desktop\cmd.bat deleted successfully.
C:\Dokumente und Einstellungen\Sveta\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56545 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33999 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Sveta
->Temp folder emptied: 9362762 bytes
->Temporary Internet Files folder emptied: 16010114 bytes
->Java cache emptied: 41915735 bytes
->FireFox cache emptied: 75884770 bytes
->Apple Safari cache emptied: 28138496 bytes
->Opera cache emptied: 29881515 bytes
->Flash cache emptied: 1752193 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 4148615 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 173371679 bytes
RecycleBin emptied: 783 bytes
Total Files Cleaned = 363,00 mb
OTL by OldTimer - Version 3.2.14.1 log created on 09302010_191255
Files\Folders moved on Reboot…
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_770.dat not found!
Registry entries deleted on Reboot…
Regarding MBAM, I did the scanning first in a "quick" regime - one virus was found.
Here is the logfile (in German):
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Datenbank Version: 4724
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
30.09.2010 19:42:13
mbam-log-2010-09-30 (19-42-13).txt
Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 152091
Laufzeit: 11 Minute(n), 57 Sekunde(n)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlьssel: 1
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0
Infizierte Speicherprozesse:
(Keine bцsartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bцsartigen Objekte gefunden)
Infizierte Registrierungsschlьssel:
HKEY_CURRENT_USER\dark (Trojan.Banker) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
(Keine bцsartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung:
(Keine bцsartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bцsartigen Objekte gefunden)
Infizierte Dateien:
(Keine bцsartigen Objekte gefunden)
After that I decided to scan in a full regime : 6 viruses were found.
Here is the log file:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4724
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
30.09.2010 20:41:51
mbam-log-2010-09-30 (20-41-51).txt
Scan type: Full scan (C:\|)
Objects scanned: 225834
Time elapsed: 52 minute(s), 50 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\System Volume Information\_restore{E4C05149-6828-43F1-A09F-7C4B06F50333}\RP633\A0076560.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{E4C05149-6828-43F1-A09F-7C4B06F50333}\RP549\A0069877.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{E4C05149-6828-43F1-A09F-7C4B06F50333}\RP564\A0070579.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{E4C05149-6828-43F1-A09F-7C4B06F50333}\RP577\A0071858.exe (Trojan.Cycler) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{E4C05149-6828-43F1-A09F-7C4B06F50333}\RP577\A0071874.exe (Trojan.Cycler) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{E4C05149-6828-43F1-A09F-7C4B06F50333}\RP577\A0071880.exe (Trojan.Cycler) -> Quarantined and deleted successfully.
Thank you!
Hi Mimino,
The last delections were in some System Restore points. Those will be cleaned up when we remove the tools.
One more scan to do.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
Please go to
Kaspersky website and perform an online antivirus scan.
Read through the requirements and privacy statement and click on Accept button. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run. When the downloads have finished, click on Settings . Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
Spyware, Adware, Dialers, and other potentially dangerous programs Archives Mail databases Click on My Computer under Scan . Once the scan is complete, it will display the results. Click on View Scan Report . You will see a list of infected items there. Click on Save Report As …. Change the Files of type to Text file (.txt) Set the Save In to Desktop click the Save button. Please post this log in your next reply.
Next
Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted. When the window appears, underneath Output at the top change it to Minimal Output UNCheck the boxes beside LOP Check and Purity Check .Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window,
OTL.Txt ( no
Extras.Txt this time. )
Please post back with
Any problems?
Thanks